Perplexity's privacy policy (its "Privacy Notice", last updated July 8, 2026) says that the consumer app processes your prompts, uploads and account data, may use that data to improve its AI models, and shares some identifiers with advertising partners, but does not sell personal data or send prompt content to advertisers. Free, Pro and Max users can switch off model training with the "AI data retention" toggle, while Perplexity states that Enterprise data is never used for training and that the Chat Completions API keeps no request content. For EU and UK users, Perplexity names VeraSafe as its GDPR Article 27 representative and DPO and relies on the EU-U.S. Data Privacy Framework for transfers.
This page summarises only what Perplexity itself publishes. All sources below were retrieved on September 28, 2026; policies change, so check the linked originals before you rely on any detail. This is a factual overview, not legal advice.
Sources used on this page
- Perplexity Privacy Notice (last updated July 8, 2026)
- Help Center: Data Collection at Perplexity (last modified September 3, 2026)
- Help Center: GDPR Compliance at Perplexity (last modified September 14, 2026)
- API docs: Privacy & Security
- API docs: Perplexity Crawlers
Which products the privacy policy covers
The Privacy Notice applies to data that Perplexity AI, Inc. and its affiliates collect through their websites, the Comet browser, the mobile apps and other consumer services. It explicitly does not apply to the Enterprise and API offerings, "where we act as a service provider or processor". In GDPR terms, that is the most important sentence in the document: for the consumer app Perplexity describes itself as the party deciding about the data, for Enterprise and API it positions itself as processor for the customer. Perplexity also publishes a separate Data Processing Addendum for business customers.
What data Perplexity collects
According to the Privacy Notice, Perplexity collects data in three ways: directly from you (account creation, queries, uploads, purchases, support contact), automatically (cookies, pixels, device data, server logs) and from other sources such as affiliates, vendors, social media and publicly available sources. The examples it lists include:
- User content: prompts, queries, uploads and any other data you choose to provide, plus data about the output and what you create (collections, pages, Spaces).
- Account data: name, contact details, username and password, in some cases device and network identifiers, and the actions you perform while logged in.
- Location: general location derived from your IP address, used for location-specific queries.
- Device data: operating system, hardware specifications, IP address, crash and error information.
- Web usage: via cookies or pixels, which links you click "or what you type as a prompt", timing of use, referrer and device data.
- Comet browser: depending on your settings, browsing history and engagement when Comet is synced with your Perplexity account.
- Voice and health data: processed based on consent when you use voice features or health-related services.
The Notice also lists sensitive data you might volunteer in a prompt (for example health, religious beliefs or sexual orientation). Perplexity states it receives such information if you choose to enter it. The practical conclusion is simple: whatever you type is user content under this policy.
Does Perplexity use your chats to train AI?
For consumer accounts, yes, unless you opt out. The Privacy Notice lists "improve or create services and products, including our AI models" among its purposes. The Help Center article on data collection is more specific: for Free, Pro and Max users, "AI Data Retention is enabled by default". You can switch it off under Account, Preferences, "AI data retention" toggle. Perplexity adds three limitations:
- The opt-out only applies to data collected after the opt-out date.
- Previously collected training data "cannot be deleted or removed".
- The setting applies per individual user, not per team.
For Enterprise Pro and Enterprise Max, the same article states that data is never used for AI training, uploaded files are kept for 7 days, and Perplexity has zero data retention and zero data training agreements with third-party model providers such as OpenAI and Anthropic.
Consumer app vs. Enterprise vs. API at a glance
| Topic | Consumer (Free, Pro, Max) | Enterprise Pro / Max | API (Chat Completions) |
|---|---|---|---|
| Privacy Notice applies? | Yes | No, Perplexity acts as service provider / processor | No, Perplexity acts as service provider / processor |
| Model training | On by default, opt-out via "AI data retention" | Never, per Help Center | No training on customer data, per API docs |
| Retention | As long as the account is active; removal within 30 days after account deletion | Uploaded files 7 days; custom retention for larger organisations | Zero Data Retention; only billing metadata (tokens, model, timestamp, API key) |
| Advertising | Identifiers and network activity may be shared with advertising partners; no prompt content to advertisers | Not described in the Privacy Notice | Not described |
Advertising, cookies and data sharing
The July 2026 update summary says Perplexity added detail on cookies and first-party advertising measurement and clarified that it does "not sell your personal data or send your queries, prompts, or conversation content to advertisers". The sharing table in the same Notice still lists "Advertising Partners" as recipients for identifiers, commercial information, internet activity and non-precise geolocation, under the heading "Sharing for Targeted Advertising". Both statements can be true at once: prompt text stays out, but tracking-related identifiers may flow to ad partners.
Your controls, as listed by Perplexity: the cookie consent pop-up on its websites, Global Privacy Control (GPC) signals where required by law, the advertising settings of your mobile device, third-party cookie blocking in Comet, and Incognito mode in the app and on parts of the website, which does not save search activity across sessions. Perplexity states it does not recognise "Do Not Track".
Your GDPR rights at Perplexity, step by step
The GDPR Help Center article explains how Perplexity handles data subject requests. The practical route:
- Access: self-service. Sign in, open Account details and click Export my data. You receive a download link by email.
- Delete single threads or files: use the delete functions in the product. Perplexity says it will not process these via the formal privacy form.
- Erasure: a GDPR erasure request always means deletion of the whole account. Deleting specific time periods, sessions or queries is not offered under this right. Account deletion can take up to 30 days, and signing back in before it completes cancels the request.
- Rectification, restriction, objection, portability: via the data request form or support@perplexity.ai.
- Response time: Perplexity states it responds within 30 days and may extend by up to two months under Article 12(3) GDPR.
For EU and UK matters, the Privacy Notice names VeraSafe Ireland Ltd. and VeraSafe United Kingdom Ltd. as representatives under Article 27 GDPR, and VeraSafe as Perplexity's data protection officer. If you are not satisfied with the answer, the Notice points to your right to complain to your local supervisory authority.
International transfers
Perplexity states that data may be processed outside your country, including in the United States. It says it complies with the EU-U.S. Data Privacy Framework and the UK Extension, and that you can request a copy of the Standard Contractual Clauses it uses for transfers out of the EEA or UK. Unresolved DPF complaints can go to the dispute resolution provider listed on the Data Privacy Framework website.
What this means for teams using Perplexity
My reading of these documents, not legal advice: the consumer policy and the business offerings follow different logic, and the risk sits in the gap between them. An employee using a personal Free or Pro account for work falls under the consumer Notice with training on by default. If your organisation wants processor terms, that is what the Enterprise plans and the DPA are for. Three checks follow directly from Perplexity's own statements:
- Which plan does each team member actually use, and is "AI data retention" switched off on consumer accounts?
- Does anyone paste customer or employee data into prompts? Under the Notice, that content is processed like any other user content.
- If you build on the API, does your own privacy notice mention it? The API's zero data retention covers Perplexity's side, not your obligations towards your users.
For the organisational side (policies, DPIA, vendor documentation) see our Perplexity compliance guide.
The other side: what Perplexity collects from your website
Privacy questions usually focus on what users type into Perplexity. For website owners, the second question is which of their own content Perplexity fetches. The official crawler documentation names two user agents:
- PerplexityBot surfaces and links websites in Perplexity's search results. Perplexity states it "is not used to crawl content for AI foundation models" and recommends allowing it in robots.txt if you want to appear in results.
- Perplexity-User fetches pages when a user asks a question. Because a user triggered the request, Perplexity says this fetcher "generally ignores robots.txt rules".
Perplexity publishes the IP ranges for both agents as JSON files and says robots.txt changes can take up to 24 hours to take effect. Blocking PerplexityBot therefore mainly removes you from Perplexity's search results; it does not stop user-triggered fetches. Before you decide, check what your robots.txt and firewall currently allow with the free AI crawler check. If you want to know whether Perplexity actually cites your pages, our GEO audit measures that across AI search engines.
FAQ
Is my data safe with Perplexity AI?
Perplexity says it uses reasonable efforts to protect personal data, and its API documentation lists a SOC 2 Type II report. Its Privacy Notice also states that no method of transmission or storage is fully secure. Treat prompts as data that leaves your organisation.
Are Perplexity AI chats private?
Chats are stored with your account and, on consumer plans, may be used for model training unless you switch off "AI data retention". Perplexity states it does not send prompt content to advertisers. Incognito mode avoids saving search activity across sessions.
How do I stop Perplexity from training on my data?
Go to Account, Preferences and switch off the "AI data retention" toggle. According to Perplexity, this only affects data collected after the change, and data already used for training cannot be removed.
Can I delete my Perplexity data under the GDPR?
Yes. Single threads and files are deleted in the product itself. A formal GDPR erasure request always deletes the entire account; Perplexity says deletion can take up to 30 days and that it responds to requests within 30 days.
Who is Perplexity's GDPR representative in the EU?
The Privacy Notice names VeraSafe Ireland Ltd. (EU) and VeraSafe United Kingdom Ltd. (UK) as Article 27 representatives, and VeraSafe as data protection officer.
Does PerplexityBot use my website content to train AI models?
According to Perplexity's crawler documentation, PerplexityBot is used for search results and not to crawl content for AI foundation models. Perplexity-User fetches pages on behalf of users and generally ignores robots.txt.
Ready for better AI visibility?
Test now for free how well your website is optimized for AI search engines.
Start Free AnalysisRelated GEO Topics
Share Article
About the Author
- Structured data for AI crawlers
- Include clear facts & statistics
- Formulate quotable snippets
- Integrate FAQ sections
- Demonstrate expertise & authority


