Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes Perplexity to share user query content and conversation history with external AI model providers in order to generate responses. These third-party providers may process the submitted content under their own terms.
This analysis describes what Perplexity AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that sensitive user query content and conversation history are transmitted to third-party organizations beyond Perplexity, creating a data sharing chain that extends Perplexity's privacy obligations into downstream provider relationships. Compliance teams should assess whether adequate data processing agreements govern these transfers and whether the processing basis is sufficient under applicable law.
Interpretive note: The policy does not enumerate specific third-party AI model providers, making it difficult to assess the full scope of data sharing authorized by this provision.
The updated Privacy Notice establishes more granular disclosure of data collection methods across multiple product areas. Perplexity now explicitly discloses that it collects and stores browsing history and settings in the Comet browser based on consent or legitimate interest, accesses email content through Email Assistant to analyze messages (while stating it does not train AI models on that content), and collects demographic data if users voluntarily upload it. The revised structure also clarifies that local browser data storage occurs on users' devices and that incognito mode does not fully prevent tracking by websites or Perplexity. You can review Comet privacy settings and controls as described in the updated policy.
View change record →This is a newly disclosed high-severity practice of sharing query content and conversation history with third-party AI providers, which was not explicitly mentioned in the previous version.
View full change record →Under this clause, query content and conversation history submitted by users may be processed by third-party AI model providers, not solely by Perplexity. The specific identity and data handling practices of those third-party providers are not fully enumerated in the policy text reviewed.
How other platforms handle this
Third-party apps use data from Gemini consistent with their own privacy policies and terms.
if you are accessing and using Lime Services under a corporate account...you acknowledge and agree that Lime may share certain of your usage information with whomever provided you with access to the Lime Services
We will disclose personal information to companies that help us run our business to detect, prevent, or otherwise address fraud, deception, illegal activity, misuse of Adobe Services and Software, and security or technical issues.
Monitoring
Perplexity AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"We may share your information with third-party AI model providers to generate responses to your queries. These providers may process your queries and conversation history as part of providing their services.Excerpt from Perplexity AI's Privacy Policy
1) REGULATORY LANDSCAPE: This provision implicates GDPR Articles governing data controller and processor relationships and international data transfers, CCPA provisions on sharing personal information with service providers and third parties, and FTC Act standards on material disclosures to consumers. EU/EEA data transfers to third-party AI providers located outside the EEA require valid transfer mechanisms such as Standard Contractual Clauses. The enforcement authority in the EU is the lead supervisory authority under GDPR; the FTC has jurisdiction in the US. 2) GOVERNANCE EXPOSURE: High. The sharing of query content with third-party AI model providers creates complex data processing chain obligations. If the third-party providers use the data for their own model training or analytics, additional disclosure and consent obligations may arise. The policy does not enumerate specific third-party AI providers by name, limiting users' ability to assess downstream data handling. 3) JURISDICTION FLAGS: EU/EEA users face the highest exposure, as GDPR requires explicit lawful bases for data transfers to third countries and mandates data processing agreements with all processors. California users are protected by CCPA service provider restrictions. Healthcare or legal query content submitted by users could attract additional regulatory scrutiny in any jurisdiction. 4) CONTRACT AND VENDOR IMPLICATIONS: Procurement and legal teams should verify that data processing agreements with all third-party AI model providers are in place, covering purpose limitation, retention, security, and sub-processing restrictions. The policy's lack of named providers creates due diligence gaps for enterprise customers seeking to assess supply chain data risk. 5) COMPLIANCE CONSIDERATIONS: Compliance teams should maintain an updated list of third-party AI model providers, ensure DPAs or equivalent agreements are executed, and verify that transfer mechanisms are valid for cross-border flows. User-facing disclosures should be reviewed to confirm they satisfy GDPR transparency requirements regarding the identity of recipients.
Regulatory citations, enforcement risk, and due diligence action items.
ConductAtlas detected a major restructuring of Meta’s privacy policy that removed detailed consumer rights disclosures and relocated them to separate documents.
Your genetic data may be transferred to a new owner as a business asset. Here is what the Terms of Service actually say and what you can do right now.
Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.
This provision establishes that sensitive user query content and conversation history are transmitted to third-party organizations beyond Perplexity, creating a data sharing chain that extends Perplexity's privacy obligations into downstream provider relationships. Compliance teams should assess whether adequate data processing agreements govern these transfers and whether the processing basis is sufficient under applicable law.
Under this clause, query content and conversation history submitted by users may be processed by third-party AI model providers, not solely by Perplexity. The specific identity and data handling practices of those third-party providers are not fully enumerated in the policy text reviewed.
ConductAtlas has identified this type of provision across 294 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Perplexity AI.