Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
Perplexity can change its privacy policy at any time and considers posting the update on its website to be sufficient notice, placing the responsibility on users to check for changes.
This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
Without a requirement for direct notification (such as email), users may not be aware that their data is now being collected or used in new ways unless they proactively revisit the policy page.
The updated Privacy Notice establishes more granular disclosure of data collection methods across multiple product areas. Perplexity now explicitly discloses that it collects and stores browsing history and settings in the Comet browser based on consent or legitimate interest, accesses email content through Email Assistant to analyze messages (while stating it does not train AI models on that content), and collects demographic data if users voluntarily upload it. The revised structure also clarifies that local browser data storage occurs on users' devices and that incognito mode does not fully prevent tracking by websites or Perplexity. You can review Comet privacy settings and controls as described in the updated policy.
View change record →Removal of boilerplate policy update notification language suggests either relocation to terms of service or de-prioritization of update transparency mechanisms.
View full change record →Perplexity may materially change how it handles your personal data, including query history and AI training use, and its policy treats a website update as sufficient notice, meaning you are responsible for checking for changes rather than receiving direct communication.
How other platforms handle this
If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.
When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.
Monitoring
Perplexity AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the effective date. You are advised to review this Privacy Policy periodically for any changes.Excerpt from Perplexity AI's Privacy Policy
(1) REGULATORY LANDSCAPE: GDPR Article 13 and 14 require that data subjects be informed of any changes to processing purposes in a timely manner, and passive website updates may not satisfy this requirement for material changes to data processing activities. CCPA does not mandate direct notification of policy changes but requires that the policy accurately reflect current practices at all times. (2) GOVERNANCE EXPOSURE: Low to Medium. For most routine updates, passive notification via website posting is a common industry practice. However, for material changes that expand data use (such as adding new AI training applications or new third-party sharing), passive notification alone may be insufficient under GDPR and could expose Perplexity to enforcement risk. (3) JURISDICTION FLAGS: EU/EEA users have the strongest grounds for challenging policy changes made without direct notification, particularly where those changes alter the lawful basis or scope of processing. (4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise customers should contractually require Perplexity to provide direct notification of material policy changes that affect the processing of employee or customer data, rather than relying on the standard website update mechanism. (5) COMPLIANCE CONSIDERATIONS: Legal teams should establish a monitoring process to track Perplexity policy updates and assess whether any changes trigger GDPR notification obligations, CCPA disclosure updates, or contract amendment requirements.
Regulatory citations, enforcement risk, and due diligence action items.
Ad personalization controls removed. Contact scanning added. Advertiser data partnerships quietly dropped. A timeline of every change.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
Without a requirement for direct notification (such as email), users may not be aware that their data is now being collected or used in new ways unless they proactively revisit the policy page.
Perplexity may materially change how it handles your personal data, including query history and AI training use, and its policy treats a website update as sufficient notice, meaning you are responsible for checking for changes rather than receiving direct communication.
ConductAtlas has identified this type of provision across 295 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.