Perplexity
Published October 6, 2026· By Juan Martinez
In This Article
Perplexity is an answer engine rather than a chat assistant in the usual sense: every question goes to the live web, and the reply comes back as a written summary with numbered citations to the pages it drew on. Perplexity AI, Inc. was founded in San Francisco in August 2022 and launched the search product on 7 December 2022. It is reviewed here on the same five criteria as every other assistant in this section, and the result splits the way it does for most mainstream products: strong scores on what it does, weak scores on how it handles what you type. You can ask a question without an account, which is a real point in its favour, but conversations are stored on Perplexity’s servers in a form the company can read, and training on consumer data is switched on by default.
Privacy Architecture
The one structural advantage is that an account is optional. A question can be asked in a browser without signing in, and signing in is what turns on saved history. That removes the email address or linked identity from the picture for anyone who uses Perplexity for one-off lookups, and it is more than products that require sign-up before the first message can offer.
Everything past that point works against the user. Perplexity’s Privacy Notice says its services may collect your general location from the IP address you connect from, and nothing in its documentation says the IP address is separated from the request before it is processed. Products that do strip identity at a proxy layer describe the mechanism, because it is the claim their design rests on; here there is no such claim, only the statement that location is read from it. The notice also lists the usual automatic collection: cookies, pixels, device information and server logs, alongside the queries and uploaded documents themselves.
Storage is server-side and readable by Perplexity. Traffic is encrypted in transit with SSL/TLS, and the security documentation describes production hosting on AWS behind Cloudflare. At-rest encryption with AES-256 is documented for files brought in through Enterprise connectors, but no statement about at-rest encryption for consumer conversations was found. Either way, this is not zero-access encryption: the operator holds whatever keys exist, and who reads your history is decided by policy, not by cryptography. There is no secure-enclave or confidential-compute claim for the consumer product.
Training is the most consequential default. Perplexity’s help center states that for Free, Pro and Max users, AI data retention is enabled by default, and that “If the toggle is enabled, your data is being collected for AI training.” The control sits under Account settings, Preferences, and it is a single switch rather than a support request. Two caveats come with it, both stated by Perplexity itself: the opt-out applies only to data collected after the opt-out date, and data already collected for training cannot be deleted or removed. A user who finds the toggle a month in has already contributed a month of queries, permanently. A second help article describes the same control as an AI Data Usage toggle in Settings and confirms that search queries and feedback reports are used to improve the product, so the naming is not even consistent across the documentation a user would read to find it.
Enterprise shows that a different default is possible. Perplexity states that Enterprise data is never used for AI training, that uploaded files are retained for 7 days, and that Enterprise is covered by Zero Data Retention and Zero Data Training agreements with its model providers. None of that is described for the consumer plans, and Perplexity notes that moving from Enterprise down to a Free or other non-Enterprise plan puts the data back under the consumer default. The protective configuration exists and is sold to organisations; individuals get the opposite and have to change it themselves.
Retention for consumer accounts is open-ended. The help center says personal information is kept as long as the account is active and removed from Perplexity’s servers within 30 days of account deletion, which is requested through a form rather than a button in settings. The Privacy Notice is looser still: data is kept only as long as necessary for the purposes it lists, with no fixed period, and deletion requests are granted if required by law, with many listed cases where data must be kept. Incognito sessions are the one short-lived mode, expiring within 24 hours and not recoverable.
Trust & Transparency
Perplexity lists a SOC 2 Type 2 report and an ISO/IEC 27001:2022 certificate on its Trust Center, alongside a HIPAA gap assessment, PCI DSS documents and FedRAMP 20x Low materials. Its security page adds annual third-party penetration tests, a private bug bounty on Bugcrowd and a public vulnerability disclosure program. Independent assessments are listed, and that counts.
The limit is access. The Trust Center is built for business buyers, and the SOC 2 report sits behind a request-access form rather than being published. The auditor is not named and the period the report covers is not stated publicly, so a consumer cannot check what was examined or when. The attestation is real; it is addressed to procurement teams, not to the person typing questions into the free tier.
The documentation itself is a genuine strength. The help center articles on data collection, retention, incognito mode and training are short, dated, and specific about defaults and their limits, including the uncomfortable ones, such as the fact that opted-out training data cannot be withdrawn. The Privacy Notice states plainly that Perplexity does not sell personal data and does not send queries, prompts or conversation content to advertisers. It then says that cookies, pixels and server-to-server integrations are used to measure Perplexity’s own ad performance on partner sites, and that continuing to use the service without adjusting settings counts as consent to those technologies. Tracking for marketing measurement is therefore on until the user turns it off.
That disclosure sits next to the most serious question raised about the company. A class action filed on 31 March 2026 in federal court in San Francisco, first as Doe v. Perplexity and later under the plaintiff’s own name, Noel, named Perplexity AI, Google and Meta. The complaint alleged that tracking technology embedded in Perplexity’s code transmitted users’ chat data, email addresses, device information and IP addresses to Google and Meta without consent, including in incognito mode, and sought an injunction, damages and certification of a nationwide class of non-paying users from 7 December 2022 to 4 February 2026, plus a California subclass, across 14 counts. These were allegations, never findings. On 1 May 2026 the plaintiff withdrew the case voluntarily and without prejudice, before any defendant had answered, which means no court ruled on the claims and the plaintiff keeps the right to refile. A dismissal like that is not an acquittal and not an admission either. The case does not change any score on its own, but the gap between “we do not send conversation content to advertisers” and what the complaint said is exactly the kind of question a trust rating has to leave open until something answers it.
The second item concerns Comet, Perplexity’s separate agentic browser, not the chat assistant. Brave’s security team reported an indirect prompt-injection flaw on 25 July 2025: a page-summarisation feature passed untrusted web content to the model without separating it from the user’s own instructions, so a web page could issue commands. Perplexity shipped a fix on 27 July that retesting found incomplete; later testing on 13 August showed it appeared patched, and Brave published on 20 August 2025. Brave subsequently updated its post to say that further testing found Perplexity still had not fully mitigated that kind of attack, and that it had re-reported it. This is a vulnerability in a related product, not a breach of user data, and it is recorded that way here. It still bears on how far to rely on an agent that reads arbitrary web pages and acts on your behalf. Comet’s own incognito mode is described in the Privacy Notice with a direct caveat: Perplexity, and third parties such as the websites you visit, may still be able to track you.
Everything else is closed. The client apps, the server infrastructure and the routing between model providers are proprietary, so every privacy claim here rests on documentation and attestation rather than anything a third party can inspect. Jurisdiction is the United States: Perplexity AI, Inc. is privately held and headquartered in San Francisco, with VeraSafe appointed as its representative for users in the EU and UK, and certification under the EU-U.S. Data Privacy Framework and its UK extension. Data may be processed in the United States and other countries. The US sits inside the intelligence-sharing arrangement commonly called the Fourteen Eyes, and because Perplexity stores readable conversation history for signed-in users, a legal demand has something to reach.
Features
Search is the product, not an add-on. Every answer is built from live web results and comes back with inline citations, so a claim in the response can be traced to the page it came from. For research and fact-finding that is a more useful shape than a chat reply with no visible sources, and it is the main reason to use Perplexity at all.
Several model families sit behind it. At the time of this review the lineup included GPT-6.1 Sol, Gemini 3.8 Flash, Claude Sonnet 5.5, Kimi K3 and GLM 5.3 (both run on US-hosted infrastructure, per Perplexity), Grok 4.7 and NVIDIA Nemotron. On the free plan the model is chosen automatically; Pro and Max add a model picker. The lineup changes often enough that any list is a snapshot.
Around the core are Pro Search, Deep Research for longer multi-source reports, file upload (limited on Free, ten times the allowance on Pro, up to 50 files per project), image and video generation, document and app creation, memory, and Computer, an agent that carries out tasks rather than only answering. Max adds Model Council, the Brain research preview, early access to new products and more video generation. Comet extends the same assistant into a full browser on macOS, Windows, Android and iPhone.
The breadth is real and the citation-first design is well executed. The cost of that breadth is that the agentic parts, Computer and Comet, act on content and sites the user does not control, which is where the prompt-injection disclosure above becomes a practical concern rather than an abstract one.
Usability
Getting started takes nothing: open the site and ask. No sign-up, no installation, and the cited-answer format is readable without any explanation. Native apps cover macOS, Windows, iPhone and iPad, and Android.
Two things hold the score back. There is no Linux client, so Linux users are limited to the browser. And the product line has sprawled: the assistant app, the Comet browser, the Computer agent, projects and a credit system on paid plans now overlap, and it is not always obvious which surface a given task belongs in or which privacy statement covers it. Account deletion through a form rather than a settings button is a smaller friction point.
Price & Value
The free plan is useful for what most people use Perplexity for. Perplexity describes it as good for limited daily usage, with practically unlimited basic searches, search history, very limited Pro Searches, limited file uploads, and the model chosen for you; image generation and advanced models are not included. For quick cited lookups that is enough.
Pro costs $20 a month, or the equivalent of $17 a month billed annually, and adds Deep Research, the model picker, advanced models, image and video generation, larger upload limits, more memory, expanded Computer access and 4,000 bonus credits. Max costs $200 a month, or $167 a month billed annually, with the highest limits, frontier models, maximum Computer usage, 35,000 bonus credits and 10,000 monthly credits, early access and priority support. Education Pro is $10 a month with student verification. Enterprise Pro starts at $40 per seat per month and is outside what this review scores.
As with every mainstream product in this section, paying buys capability and nothing else. Free, Pro and Max share the same training default, the same storage model and the same tracking disclosures. The data handling that differs, with no training and a 7-day file retention, is available only on Enterprise plans bought by an organisation.
Pros and Cons
- Questions can be asked without an account; signing in is needed only to keep history
- Every answer is built from live web results with inline citations to its sources
- Several model families are available, with a model picker on Pro and Max
- Deep Research, file upload, image and video generation, and the Computer agent cover far more than basic search
- The AI training opt-out is a single toggle in account settings, not a support request
- Help center articles on training, retention and incognito are dated and state their own limits plainly
- A SOC 2 Type 2 report and an ISO/IEC 27001:2022 certificate are listed, alongside annual penetration tests and a bug bounty
- Perplexity states it does not sell personal data or send queries or conversation content to advertisers
- Incognito sessions expire within 24 hours and cannot be recovered
- The free plan offers practically unlimited basic searches, enough for everyday cited lookups
- AI training on Free, Pro and Max data is on by default, and the opt-out does not reach data collected before it was switched off
- Data already collected for training cannot be deleted or removed, by Perplexity's own statement
- Storage is server-side and readable by Perplexity, with no consumer-specific statement on encryption at rest
- Nothing in the documentation says the IP address is separated from the request, and location is inferred from it
- Cookies, pixels and server-to-server integrations measure Perplexity's own advertising, with consent assumed from continued use
- A class action alleging trackers sent chat data, emails and IP addresses to Google and Meta, including in incognito mode, was withdrawn without prejudice in May 2026 — no ruling either way, and refiling remains possible
- Brave reported a prompt-injection flaw in the Comet browser whose first fix was incomplete, and later said it was still not fully mitigated
- Comet's incognito mode does not stop tracking by Perplexity or by the websites you visit
- The SOC 2 report sits behind a request form, with no named auditor and no public report period
- Retention runs for as long as the account is active, and account deletion is requested through a form
- Paying for Pro or Max does not change the training default, storage model or tracking
- Closed source throughout, and no Linux client
Our Rating
Perplexity earns its Features and Usability scores honestly. Cited answers from the live web are a better format for research than unsourced chat replies, the model selection on paid plans is wide, and the product can be used with no account at all. The privacy architecture does not match that. Without an account your IP address still reaches the service with your question, and with one your history is stored where Perplexity can read it, retained for as long as the account exists, and used for training until you find the toggle, after which the earlier data stays in the training set regardless. Trust & Transparency lands in the middle: clear help documentation, a working opt-out and listed attestations on one side; a gated audit report, ad-measurement tracking on by default, an unanswered tracking allegation from a dropped lawsuit and an incompletely patched agent-browser flaw on the other.
The number is a baseline, not a warning and not a recommendation. Perplexity is rated as an answer engine on the same five criteria as everything else in this section, and the gap to the privacy-first entries is almost entirely Privacy Architecture. For quick factual lookups without signing in, it does what it promises and the free plan covers it. For anything you would not want stored, used for training or reachable by a legal demand, the account-holding version offers no structural protection, and the Enterprise terms that would change that are not sold to individuals.
- Privacy Architecture2.0/10
An account is optional, but nothing else in the architecture protects the user: no documentation says the IP address is separated from the request, storage is server-side and readable by the operator, and training on consumer chats is on by default with an opt-out that cannot reach data already collected
- Trust & Transparency4.0/10
A SOC 2 Type 2 report and an ISO 27001 certificate exist but are released through a request form; clear, dated help articles and a documented training opt-out count in its favour, while an unproven class-action claim that chat data reached ad platforms (dropped without prejudice in May 2026, refiling possible) and an agentic-browser flaw that was patched incompletely weigh against it
- Features8.5/10
Web search with inline citations is the core product rather than an add-on, with several model families to choose from on paid plans, file upload, Deep Research, image and video generation, and an agent platform on top
- Usability8.0/10
Works in a browser with no sign-up, with native apps for macOS, Windows, iOS and Android — held back by the absence of a Linux client and a product line that has sprawled into several overlapping surfaces
- Price & Value6.5/10
The free tier is useful for quick cited lookups, but Pro at $20/month and Max at $200/month buy capability only — the training default, storage model and tracking disclosures are identical on every consumer plan
Privacy Architecture 30% · Trust & Transparency 20% · Features 20% · Usability 20% · Price & Value 10%