8 Total
0 High severity
6 Medium severity
2 Low severity
Summary

This document establishes Perplexity AI's data collection and use practices for its search and AI answer service. The policy authorizes collection of search queries, conversation history, device information, IP addresses, and account details, with provision for use of this data in AI model training and product improvement. Users in the EU and California are granted rights to request access, correction, or deletion of personal data through privacy@perplexity.ai.

Technical / Legal Breakdown

This document is Perplexity AI's Privacy Policy, governing the collection, use, storage, and sharing of personal data from users of the Perplexity AI search and answer platform, with an implicit legal basis in user consent and legitimate interest as articulated through its disclosed data practices. The policy states that Perplexity collects identifiers (name, email, IP address), device and usage data, query content (search inputs and conversation history), payment information, and data from third-party integrations, and the terms authorize use of this data for service improvement, product development, personalization, safety, and marketing communications. Notably, the policy permits Perplexity to use submitted query content and interaction data to train and improve its AI models, a practice that is functionally broad in scope given that user queries may contain sensitive personal or professional information entered in a search context where users may not anticipate model training use; the agreement asserts this right, though applicable law in certain jurisdictions may impose consent or opt-out requirements not fully addressed by the policy. The policy engages GDPR for EU/EEA users, CCPA/CPRA for California residents, and general FTC consumer protection frameworks, with Perplexity asserting standard data subject rights (access, deletion, correction, portability) but relying on a self-reported compliance posture without specifying the full technical and organizational measures supporting those claims. Compliance teams should note the policy's relatively limited specificity around data retention periods, AI training data governance, third-party sharing mechanisms, and cross-border data transfer safeguards, all of which create audit exposure under GDPR and CCPA enforcement frameworks.

Institutional Analysis

Institutional analysis available with Professional

Regulatory exposure by statute, material risk assessment, vendor due diligence action items, and enforcement precedent. Available on Professional.

Start Professional free trial

1 important change detected

2 versions captured · Last updated: May 2026

What changed Perplexity AI corrected a capitalization error in its privacy policy footer on May 18, 2026. The link text 'Linkedin' was changed to 'LinkedIn' to match standard branding. This is a formatting correction with no operational impact on privacy practices, data handling, or user rights.
Why this matters This change is a capitalization correction in the privacy policy footer and does not affect any substantive privacy practices, data collection, rights, or user obligations. The updated policy maintains the same operational terms as before.
View full change record →
Medium — 6 provisions
Low — 2 provisions

Monitoring

Perplexity AI has updated this document before.

Watcher includes same-day alerts, structured change summaries, and monitoring for up to 10 platforms.

Start Watcher free trial Or create a free account →

Professional Governance Intelligence

Need provision-level monitoring and regulatory mapping?

Professional includes governance timelines, compliance memos, audit-ready analysis, and full provision tracking.

Start Professional free trial

Cross-platform context

See how other platforms handle AI Model Training Use of Query Data and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured May 18, 2026 00:08 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000096
Version ID CA-V-002691
SHA-256 57e923c9fd9d9f2228aabfbaf9059b32021c8f2e8a0625bb6580e7284526d0f0
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 318+ platforms.

Create free account Compare plans