Lumo AI
Lumo AI
Private AI chat app
Lumo AI homepage

Artificial Intelligence (AI) > Perplexity AI privacy policy

Perplexity AI privacy policy explained: What happens to your data?

Perplexity isn’t quite like a traditional search engine. It uses AI to interpret what you type, generate answers, and collect information about you. It may also process your data in ways you may not expect or feel comfortable with. Before you make it part of your everyday search routine, here’s what Perplexity’s privacy policy means for you and your personal information.

Perplexity AI privacy policy at a glance

This analysis is based on official sources including Perplexity’s privacy policy, help center documentation, and publicly disclosed information.

What does it collect?
How is data encrypted? 
How long is data kept?
Does it comply with GDPR and CCPA?
Does it read your chats?
Can you choose where your data is stored?
Is your data used to train AI?
Is your data subject to US surveillance?
What privacy controls does it offer?
Who else sees your data?
Does it show ads or sell your data?

How Perplexity handles your data

Perplexity uses your data to provide, personalize, and improve its services, creating an AI paper trail. Here’s what you should know:

Data collected by Perplexity

Contact information: Name, address, phone number, and email address. If you invite someone to Perplexity, it also collects their email address to send the invitation.

Account information: Name, username, email, password, and account credentials.

Service interaction information: Questions, prompts, uploaded or submitted content, AI outputs, collections, and pages you create.

Device and usage data: Device type, operating system, unique device identifiers, IP address, approximate location, browser type, logs, timestamps, clickstream data, marketing email interactions, and ad impressions.

Cookies and tracking technologies: Cookies, pixels, tags, and similar tools used for analytics, personalization, advertising, and measuring how you use the service.

Third-party information: Data from analytics providers, business partners, consumer marketing databases, data enrichment companies, and linked third-party platforms such as Google or Apple.

Synced email and calendar data: Contacts, email messages, email content, and calendar appointments if you connect Gmail, Google Calendar, or another email or calendar account.

Health information: Health data you voluntarily provide if you opt in to Perplexity Health, including information from linked health and wellness apps.

Communication data: Any other information you choose to include when contacting Perplexity or communicating through the service.

How long Perplexity stores your data

Why Perplexity monitors and reviews chats

How Perplexity uses your data

AI training

By default, Perplexity may use your search data on the Free, Pro, and Max plans to improve its AI models — unless you use Incognito Mode. AI data retention is enabled by default on these individual plans, but you can turn it off in account settings. Opting out only applies to anything going forward, as data collected before you disabled AI training cannot be deleted or removed.

Enterprise data is never used or retained for AI training, and neither is query information. Perplexity’s Sonar API has a zero-data retention policy, meaning it does not retain API prompt or response data, and does not use API customer data to train models.

Human access and review

Perplexity is not zero-access encrypted or end-to-end encrypted. Your searches, uploads, and Sessions are stored on Perplexity’s systems in a way the company can technically access.

Perplexity’s security documentation says customer data is stored in secure production environments, and engineers can receive temporary access to sensitive resources when necessary, such as for debugging.

Turning off AI data retention limits future model training, but it does not make your data invisible to Perplexity. The company can still process your searches, uploads, and Sessions to operate the service, provide support, improve products, maintain security, comply with legal obligations, and enforce its terms.

Sharing with third parties

Perplexity can share information with service providers, such as payment processors and customer support providers, or when required by law.

Some queries may also be processed by third-party AI model providers, including OpenAI (the maker of ChatGPT) and Anthropic (the maker of Claude). Agreements with those providers prohibit them from retaining Perplexity data or using it to train their own models.

For enterprise services, Perplexity says it reviews third-party vendors every year, with closer checks for vendors that handle more sensitive data or provide “more important” services.

Advertising and selling data

Perplexity does not sell your data. However, its privacy policy says it collects usage data through cookies, pixels, tags, and other tracking technologies, and may permit third parties to use that data for analytics, measurement, personalization, advertising, or marketing.

Plus, the company may receive information from consumer marketing databases or data brokers to better customize advertising and marketing.

Notably, Perplexity faces a proposed 2026 class-action lawsuit (new window)alleging that it shared users’ private conversations and sensitive data with Meta and Google for targeted advertising, including when they used Incognito Mode. 

Content ownership and user rights

Your questions, prompts, uploads, AI outputs, collections, and pages may contain personal information, depending on what you enter and how it is linked to your account.

If you make content public or share it with others, it may be stored, displayed, reproduced, published, used, or disclosed without your permission, and may or may not be attributed to you.

By using Perplexity, you grant it a broad license to use the content you submit. The company does not clearly assign ownership of AI-generated outputs to consumer users in the same way as some competing AI tools. 

The wider copyright picture around Perplexity is unsettled. Reuters (new window)reported that CNN sued Perplexity in May 2026, alleging unlawful distribution of copyrighted content, and noted that Perplexity also faces lawsuits from the New York Times, Reddit, and Dow Jones, among others. Perplexity disputes at least some of these claims, but the lawsuits show that ownership, reuse, and redistribution questions around AI search remain legally unresolved.

Perplexity’s encryption, compliance, and data residency

Data encryption

Perplexity states that all traffic is encrypted using SSL/TLS. Its enterprise security pages also describe separate AWS environments, Cloudflare DDoS and web application firewall protections, rate limiting, SSO, MFA, cloud monitoring, and 24/7 security monitoring.

However, Perplexity is not end-to-end or zero-access encrypted. The company retains the technical ability to access readable customer data when necessary, such as for debugging, and may disclose it when legally required. Its public consumer documentation does not clearly explain whether Sessions are encrypted at rest or how encryption keys are managed.

Regulatory compliance

Perplexity is committed to GDPR compliance and supports data subject rights, including access, rectification, erasure, restriction, objection, and portability. Standard self-serve actions, such as account deletion, can be handled directly in settings, while formal GDPR requests can be submitted through its privacy request process.

Perplexity’s enterprise security page says the company is SOC 2 Type II attested by independent auditors, GDPR-compliant, HIPAA-aligned, and PCI-compliant. Its API documentation also lists a SOC 2 Type II report, a 2025 HIPAA Gap Assessment, and a CAIQlite questionnaire in its Trust Center.

Perplexity data residency

Perplexity’s public documentation reviewed here does not show a storage-region choice for individual Free, Pro, or Max users. Enterprise customers get stronger privacy, security, retention, audit-log, SSO, SCIM, and admin controls, but Perplexity’s public materials describe these as enterprise controls rather than individual data residency options.

Because Perplexity is a US company, your data may be exposed to US legal demands. It may be shared with service providers or when required by law, and US law can require providers subject to US jurisdiction to disclose stored communications and customer records regardless of whether your data is located inside or outside the United States.

How to reduce Perplexity data collection

These steps can reduce how much of your data is retained or used for model improvement, although they do not make Perplexity zero-access encrypted.

Step 1

Turn off model training

Go to Account settings Preferences and switch off AI data retention. Once this setting is disabled, your new search data should no longer be used to train Perplexity’s AI models.

Note: This setting only applies going forward. Previously collected training data cannot be deleted or removed, and data may still be processed for service operation, legal compliance, and product improvement.

Step 2

Use Incognito Mode

Use Incognito Mode for searches you don’t want saved to your permanent History. All Incognito Threads expire within 24 hours and are not recoverable.

However, Incognito Mode does not prevent Perplexity from processing your queries to generate answers. A proposed 2026 class-action lawsuit also alleges that Perplexity shared Incognito search data with Meta and Google through tracking technologies, although the claim has not been proven.

Step 3

Delete Sessions and Projects

Go to your History, open the Options menu, and delete individual Sessions or all Sessions. Sessions are stored in History indefinitely, but you can delete individual or all Sessions at any time.

You can also delete Projects, Pages, or individual Sessions from the relevant Project or Page menu. Deletion cannot be undone.

Step 4

Delete uploaded files and images

Files and images are retained for 30 days by default, or seven days for Enterprise users. Files uploaded to Projects and personal or organization repositories remain until deleted.

To delete an uploaded file or image from a Session, you must delete the Session or response that last used the file.

Step 5:

Export your Perplexity data

Perplexity does not currently support self-serve access requests. To request a copy of the personal data Perplexity holds about you, you need to contact customer support or submit a formal GDPR request, depending on your region.

For individual Sessions, you can use the Export button. Exporting data gives you a copy of information but does not delete it from Perplexity.

Step 6:

Delete your Perplexity account

Open your Account details page and select My account. Scroll to the bottom of the page and click Learn more, then confirm the deletion request in the pop-up.

During this period, your account remains disabled and scheduled for erasure. If you sign in again using the same email before the 30 days are over, the deletion request is canceled. After 30 days, account deletion is irreversible.

Step 7

Submit a privacy request

You can request access, correction, deletion, restriction, objection, and data portability through Perplexity’s formal privacy request process. It usually responds within 30 days, but may extend the response period by up to two months for complex or high-volume requests.

Privacy rights vary by region. Some standard actions, such as deleting Sessions, Projects, files, or your account, should be handled through self-serve controls rather than the Data Privacy Form.

Perplexity makes privacy optional, not the default

Perplexity does offer privacy controls, but you must turn them on yourself — unless you’re on a Business plan. If that tradeoff doesn’t sit right with you, consider a Perplexity alternative that makes privacy the default. 

Switch to a private AI assistant

Lumo is designed for people who want an AI assistant that doesn’t treat the collection and reuse of their conversations as a necessary tradeoff just to get the benefits of AI.

Frequently asked questions about the Perplexity privacy policy

Can governments see my Perplexity data?
Can I completely delete my data from Perplexity?
Is Perplexity Incognito Mode private?

Learn more about AI