Is Perplexity safe to use for business research? Consumer and Enterprise are governed very differently, and a 2026 lawsuit raised specific allegations about how its crawler behaves.
Plain-English risk rating: 3 of 5 (Consumer Perplexity) / 2 of 5 (Enterprise Perplexity)
Consumer Perplexity sits at 3 of 5, alongside the other consumer-tier AI products in this database. It was rated 4 of 5 until 3 September 2026, for two stated reasons: training-on-by-default, and a pending class action alleging that hidden trackers transmit full user conversation transcripts to Meta and Google even when users enable Perplexity's "Incognito" mode. The first reason is what every 3-of-5 consumer product here has. The second no longer holds: the case was voluntarily dismissed on 1 May 2026 without prejudice and before any defendant answered, so nothing was decided either way.
The allegation is unresolved, not answered, and the distinction matters. No court tested it and no independent researcher has confirmed or refuted it. If the tracker behaviour is as alleged, opting out of training would not stop it, because they are separate mechanisms. Treat the Incognito claim as an open question rather than a closed one. But an untested allegation in a withdrawn case is not what our rating scale means by pending material litigation, and we should not keep a company a band higher on the strength of one. Until this is resolved through litigation or independent technical disclosure, we recommend treating consumer Perplexity as higher-risk than ChatGPT, Claude, or Gemini consumer tiers.
Enterprise Perplexity (Enterprise Pro, Enterprise Max, Sonar API with ZDR) sits at 2 of 5 — comparable to Microsoft 365 Copilot. The Enterprise terms explicitly exclude training, the Sonar API supports Zero Data Retention, and Perplexity has achieved SOC 2 Type II certification. The Enterprise tier is in a different risk class than the consumer product.
Recommended for
- Sole proprietor: Use the Sonar API with ZDR if you can integrate it, OR opt out of training in consumer settings AND assume the tracker allegations are accurate (i.e., don't share anything you wouldn't share with Meta's ad targeting system). For most sole proprietors, ChatGPT, Claude, or Gemini consumer with opt-out are lower-risk alternatives for general search-and-summary use
- Small team (2-10 people): Enterprise Pro for shared-team usage; pricing is custom but generally competitive with ChatGPT Business / Claude Team
- Regulated industry: Enterprise Pro or Enterprise Max with a signed BAA (Perplexity supports BAAs for some enterprise customers, but not as a self-serve option — requires enterprise contracting). API with ZDR for developers
- The honest answer for most 1-10 employee businesses: Perplexity's search-grounding is genuinely better than ChatGPT or Claude for certain research tasks, but the consumer-tier risk profile is currently the worst in this database. If you specifically want Perplexity's search capability for a small business, the Enterprise tier is the right path. The Pro tier at $20/month for individual use is harder to recommend right now given the pending lawsuit
Data retention default
- Free, Pro, Max: Conversations retained while account is active. Deleted conversations retained for 30 days, then removed — we could NOT confirm this figure on 3 September 2026. Neither Perplexity's privacy policy (last updated 8 July 2026) nor its help centre states a retention period for deleted threads; the policy says only that data is kept "for only as long as necessary". The 30-day figure may come from an earlier policy version. Treat it as unverified rather than as a commitment.
- Enterprise Pro and Enterprise Max: Admin-configurable retention; data not used for training; integrates with org-level controls
- Sonar API (standard): Retention per API terms
- Sonar API (with ZDR): No data retention beyond what's needed to return the result
Training opt-out
Consumer tiers (Free, Pro, Max) — TRAINING IS ON BY DEFAULT. Same pattern as the other consumer AI products. Opt-out is at Account Settings → Preferences → AI data retention toggle → off.
Important quirks specific to Perplexity:
- Opt-out applies to logged-in sessions only. Unregistered/guest use is governed by separate analytics terms — not confirmed on 3 September 2026; Perplexity's help centre does not distinguish logged-in from logged-out use, so treat this as unverified.
- Opt-out applies only to future data. Data already used in training is not removed retroactively
- The opt-out toggle does not affect the third-party tracker behaviour alleged in the April 2026 lawsuit (if those allegations are accurate, opting out of training does not stop conversation transcripts from being shared with Meta and Google)
Enterprise tiers — TRAINING IS CONTRACTUALLY EXCLUDED BY DEFAULT. No user-side toggle needed. Enterprise data is never used for AI model training per the Enterprise Terms of Service.
Third-party AI providers: Perplexity uses third-party models (OpenAI, Anthropic) for some features. Perplexity's agreements with these providers prohibit those providers from using Perplexity data for their own model training. This is a contractual protection, not a technical one. We read Perplexity's statement to that effect on 22 May 2026 and re-read it on 29 August 2026: it still says agreements with providers “like OpenAI and Anthropic” prohibit using Perplexity data to train their models, and that data processed through Perplexity is not retained or used to further train external models. Note what it does and does not cover — it is about what THIRD PARTIES may do with your data, not about what Perplexity itself does, which is governed separately.
Zero Data Retention availability
- Sonar API: ZDR available; this is the most privacy-protective way to use Perplexity programmatically
- Enterprise Pro / Enterprise Max: Effectively achieves no-training and configurable retention, though not labelled "ZDR" in the same way as the API
- Consumer tiers: Not available
Plan tiers and pricing (as of early 2026)
| Tier | Price (USD) | Training on your data? | Suitable for |
|---|---|---|---|
| Free | $0 | Yes, unless opted out | Personal search; questionable given lawsuit |
| Pro | $20/month | Yes, unless opted out | Personal; questionable given lawsuit |
| Max | $200/month | Yes, unless opted out | Heavy individual use; same caveats |
| Enterprise Pro | Custom (typically $40-60/user/month range based on industry reports) | No — contractually excluded | Small to mid-size teams |
| Enterprise Max | Custom (higher tier) | No — contractually excluded | Larger organisations needing advanced controls |
| Sonar API | Pay-per-token | No, by default; ZDR available | Developers building applications |
Jurisdiction
- Primary processor: Perplexity AI, Inc., San Francisco, California, USA
- Cloud infrastructure: Primarily AWS
- Data processed in the United States by default. Enterprise customers may negotiate residency
- Subject to California privacy law (CCPA/CPRA) — directly relevant to the pending April 2026 lawsuit
Breach history (public incidents and allegations)
April 1, 2026 — Class-action lawsuit alleging hidden third-party trackers (VOLUNTARILY DISMISSED 1 MAY 2026)
Case: Noel v. Perplexity AI, Inc., Meta Platforms, Inc. and Google, LLC – 3:26-cv-02803-VC, US District Court for the Northern District of California, before Judge Vince Chhabria.
The 140-page complaint alleges that Perplexity embedded "undetectable" tracking software in its website that transmits full transcripts of user conversations to Meta and Google upon visiting the homepage. The complaint specifically alleges:
- Tracking software activates as soon as users log into Perplexity's homepage
- Full conversation transcripts (described as including sensitive content such as family finances, tax obligations, investment strategies, and health information) are transmitted to Meta and Google
- Data sharing persists even when users enable Perplexity's "Incognito" mode, which is explicitly marketed as a privacy feature
- Meta and Google then use this data for targeted advertising and resell it to additional third parties
- Behaviour alleged to violate California privacy laws including the state's "wiretapping" statute
The plaintiff is David Noel. The complaint was filed as John Doe, but Judge Chhabria DENIED the motion to proceed pseudonymously on 3 April 2026 and the plaintiff was named thereafter. He sought to represent a class of all affected Perplexity users.
Perplexity spokesperson Jesse Dwyer responded to Bloomberg: "We have not been served any lawsuit that matches this description, so we are unable to verify its existence or claims." Meta directed inquiries to its Facebook help page, noting that sharing sensitive information violates its policies. Google had not publicly responded as of April 1, 2026.
THE CASE WAS VOLUNTARILY DISMISSED ON 1 MAY 2026 AND TERMINATED ON 6 MAY 2026. Plaintiff’s counsel filed a notice under Rule 41(a)(1); the filing recorded that no defendant had served an answer or a motion for summary judgment. The dismissal was WITHOUT PREJUDICE, so the same claims may be refiled, and no court has tested the allegations either way. We are not aware of them having been refiled as at 2 September 2026.
Corrected 2 September 2026. Until today this profile described the case as unresolved and at an early procedural stage, named it Doe v. Perplexity, and said the plaintiff was proceeding as John Doe. All of that is wrong. The case ended on 1 May 2026, which is SIXTEEN DAYS BEFORE this profile’s own verification date of 22 May 2026, and we did not catch it – so we published an active class action against a named company for four months after it had been dropped. This is the error we would least want to make and we are recording it in full. Found by the first pass of the litigation-check register built the same day. Verified against the Justia docket for 3:26-cv-02803 and PPC Land’s report of the dismissal, both read 2 September 2026.
Rating moved 3 September 2026: Consumer Perplexity 4 of 5 to 3 of 5. The published scale defines Risk 4 as above-typical concerns – pending material litigation, recent policy regression, or a documented pattern of weak disclosure – and Risk 3 as industry-typical, training on by default for the consumer tier with opt-out available, some breach history but no pattern of cover-up or material misrepresentation. With the litigation withdrawn, the consumer tier matches the Risk 3 definition as written. Recorded rather than left implicit: this profile carried a rating one band harsher than its own stated reasoning supported, for four months, on a case that ended on 1 May 2026. Enterprise Perplexity is unchanged at 2 of 5.
Sources: Bloomberg (April 1, 2026); Insurance Journal; Claims Journal; Tom's Guide; Evermx case tracker; mlq.ai analysis
Documented Android app vulnerabilities (ongoing 2024-2026)
Independent security researchers have documented vulnerabilities in the Perplexity Android app related to session handling and credential storage. These have been progressively patched, but the pattern (multiple vulnerabilities surfacing in the mobile app over time) suggests that privacy and security may not be architected as deeply into the consumer mobile product as Perplexity's marketing implies. We are not aware of any public breach incident traceable to these vulnerabilities — but the existence of the vulnerabilities themselves is relevant to the risk picture.
Source: Anonyome research analysis (April 2026)
Note on infrastructure breaches: No public confirmed breach of Perplexity's core infrastructure (model serving, training pipeline, customer data stores) has been reported as of May 2026. The incidents above are application-layer and contractual/legal rather than infrastructure-level.
Note on the CEO's stated browser strategy: Perplexity's CEO has publicly discussed building a Perplexity-branded browser specifically to enable data collection "even outside the app." This is documented company strategy, not a breach or allegation, but it indicates a trajectory toward broader behavioural tracking. SMB owners using Perplexity should factor this into long-term vendor selection decisions — the privacy posture may continue to evolve in directions that reduce user control.
What this means in plain English for SMB owners
Three honest takeaways:
- The April 2026 lawsuit was DROPPED, not decided. The plaintiff voluntarily dismissed it on 1 May 2026 without prejudice, before any defendant answered, so nothing was proven either way and the claims can be refiled. That is not a clean bill of health, and it is not a finding against Perplexity either. Whether conversation transcripts reach Meta and Google, including in Incognito mode, remains untested by any court and unconfirmed by independent researchers. Treat consumer Perplexity accordingly: if you would not type something into a Facebook post, do not type it into consumer Perplexity.
- Enterprise Perplexity is a different product with substantially better defaults. If you want Perplexity's search-grounding capability for business use, the Enterprise tier with proper contracting is the right path. Do not use Pro for client work that you would not use a Meta product for.
- Perplexity's strength is search-grounded answers — that is genuinely better than ChatGPT or Claude for certain research tasks. For an SMB owner doing competitive research, market analysis, or technical research that needs recent web sources, Perplexity Enterprise is a legitimate choice. For general AI assistant work (drafting, brainstorming, analysis of your own content), ChatGPT Business or Claude Team are lower-risk choices.
Sources
- Perplexity Help Center: Third-party model providers training: https://www.perplexity.ai/help-center/en/articles/10354963-are-third-party-model-providers-training-on-my-data — read by us on 2026-05-22 and re-read on 2026-08-29. Perplexity refuses automated requests from our servers and the Internet Archive has never captured this page, so we check it by hand in an ordinary browser and keep a dated snapshot. The 29 August reading confirmed the statement is unchanged in substance. Separately, note that Perplexity's privacy policy — which we can read automatically — rules out training only on Email Assistant content; the broader third-party commitment lives solely on this page.
- Perplexity Security Hub: SOC 2 Type II announcement (April 2025)
- Anonyome: Perplexity AI data privacy analysis (April 2026)
- Cape: Perplexity AI Data Privacy Policy (April 2026)
- mePrism: Perplexity opt-out guide (2026)
- Spellbook: Is Perplexity Private for Lawyers (April 2026)
- Spellbook: Perplexity vs ChatGPT privacy comparison (April 2026)
- Paubox: Is Perplexity AI HIPAA compliant 2026 update (April 2026)
- Heydata: Perplexity AI data protection risks
- Bloomberg: Perplexity AI Machine Accused of Sharing Data With Meta, Google (2026-04-01)
- Claims Journal / Insurance Journal coverage of Doe v. Perplexity (2026-04-01/02)
- Tom's Guide: Perplexity 'incognito mode' lawsuit (2026)
- Evermx case tracker: Case 3:26-cv-02803, Northern District of California
- Modemguides: Perplexity AI lawsuit user data sharing analysis (April 2026)
Related on AI Leakage
- Compare all 29 AI tools in the risk directory — see how Perplexity stacks up against the rest, tier by tier.
- Take the 5-minute “Am I Leaking?” check — a personalised view of your business’s AI exposure.
- Check a prompt before you paste it — our free Data-Safe Prompt Rewriter.
- Shadow AI vs AI leakage — why even approved tools like Perplexity can leak data.
- Get plain-English AI Leakage Alerts — we email you when an AI tool you use changes its data policy or has an incident.
- Get the free AI Acceptable Use Policy template — a plain-English policy with the tool-by-tool risk guide built in.
