← All pages

1. What the document is: Perplexity's consumer Privacy Policy, covering the free and Pro tiers. It explicitly excludes the API/Enterprise Pro tier, which is covered by a separate DPA where Perplexity acts as Processor rather than Controller.

What this wiki found — complete, every page

AI trainingRoyalty-freeSublicensablePerpetual / irrevocableTransferableDerivative works

Presence facts, not verdicts — each flagged term links to its definition and the exact clause on this page. Absence of a badge means the term isn't currently flagged here, not that the page is risk-free.

Perplexity – Privacy Policy

Dataset: GenGA (Generative AI Governance Archive) — 11 AI services, 2025–present

GenGA (Generative AI Governance Archive) is this wiki’s Generative-AI dataset: raw policy snapshots captured by the Open Terms Archive genai-eu project across 11 GenAI providers (ChatGPT, Claude.ai, DeepSeek, Google Generative AI Services, Le Chat, Llama API, Meta AI, Microsoft Copilot, Perplexity, Qwen Chat, xAI). Unlike PGAv2, GenGA has no pre-tagged risk scores — all risk scoring and keyword tagging on these pages is LLM-assigned by direct reading, spanning 2025–present.

Note: This page contains documented policy clauses. Risk assessment is qualitative and context-dependent. For analysis of patterns across platforms, see:

Source: sources/GenGA/Perplexity/Privacy Policy/ (raw Markdown captures, Open Terms Archive genai-eu dataset — no pre-tagged JSONL exists for this source) Last updated: 2025-11-11 (only capture in this dataset; document’s own “Last updated: October 31, 2025”)

Note on methodology: No pre-computed risk_score/keyword fields exist for this source. Keyword tags and clause analysis on this page are LLM-assigned, using the same rubric/vocabulary as the PGAv2 pages plus new GenAI-specific tags (train AI/models, gdpr). Treat as first-pass analysis, not externally verified ground truth. This wiki’s risk-scoring system was retired project-wide on 2026-06-21 (see methodology.md §4) — no page, GenGA included, computes or displays a numeric risk score.


Overview

1. What the document is: Perplexity’s consumer Privacy Policy, covering the free and Pro tiers. It explicitly excludes the API/Enterprise Pro tier, which is covered by a separate DPA where Perplexity acts as Processor rather than Controller.

2. Input rights: AI training over “Service Interaction Information” (prompts, Output, generated collections/pages) is opt-out by default: “we may use any of the above information to provide you with and improve the Services (including our AI models),” with the opt-out described later — “You may opt out of information collection for AI (which would prohibit us from using your search information to improve our AI models) in your settings page.” A notable carve-out: synced third-party email/calendar content (“Email Service Information”) is excluded from training regardless of the opt-out setting — “we do not use or disclose Email Service Information to create, train, improve or fine-tune AI models.”

3. Output restrictions: If you make content or Output publicly available, “it may be stored, displayed, reproduced, published, or otherwise used or disclosed without your permission, and may or may not be attributed to you.”

4. Non-explicit predatory clauses: A broad “Deidentified Information” carve-out: Perplexity may deidentify or anonymize any collected information and then “use such Deidentified Information for any purpose.” This is a common catch-all, but notable — it also appears on other platforms in this dataset.

5. Regulatory references: GDPR — Perplexity uses the Prighter Group as its EEA/UK GDPR Article 27 representative, the same third-party representative-as-a-service vendor already documented for DeepSeek’s Privacy Policy elsewhere in this dataset. That’s now a confirmed 2-provider pattern, suggesting Prighter is a notable industry utility rather than a DeepSeek-specific arrangement. Perplexity also discloses certification under the EU-U.S. Data Privacy Framework (DPF) and its UK Extension — the first explicit DPF citation found in this dataset, a transatlantic-transfer mechanism distinct from Standard Contractual Clauses.

6. Regional variation: A dedicated “For EU and UK users” DPF-compliance section, Singapore-specific language describing the legal basis for processing job-applicant data, and a CCPA-driven “U.S. Residents” section (no sale or sharing of personal information, per CCPA definitions).

7. Key risk to users: Moderate. Opt-out-by-default training over prompts/Output is the standard-pattern risk in this dataset. The Email Service Information carve-out is a genuinely protective exception worth noting — it narrows what could otherwise be an unusually invasive third-party-account-sync data source.

Flagged Keywords & Risks (LLM-assigned)

Regulatory & Research Context

Perplexity was not among the providers studied by Davidson et al. (2026) or Pandit et al. (2026), but Pandit et al.’s observation that “all terms mentioned that inputs and outputs would also be used for other purposes beyond” the immediate service applies by analogy to this page’s train AI/models clause, which uses prompts and Output “to provide you with and improve the Services (including our AI models)” under an opt-out-by-default model. Edwards et al. (2025) note that privacy policies often “requir[e] reading comprehension abilities at university level,” a relevant lens for a document that buries a genuinely protective carve-out — that synced “Email Service Information” is never used “to create, train, improve or fine-tune AI models” regardless of the general opt-out setting — inside a much broader, less protective default-training disclosure.


Changes Summary

DateWhat changed
2025-11-11Baseline and only version captured in this dataset.

Version History

2025-11-11

Clause: train AI/models

In addition to the specific uses described above, we may use any of the above information to provide you with and improve the Services (including our AI models) and to maintain our business relationship… You may opt out of information collection for AI (which would prohibit us from using your search information to improve our AI models) in your settings page if you are logged into the Services.

Clause: Email Service Information carve-out (not separately concept-tagged — user-protective)

Notwithstanding anything else in this Privacy Policy, we only use and disclose Email Service Information to provide the Services or as otherwise required by applicable law, and we do not use or disclose Email Service Information to create, train, improve or fine-tune AI models.

Clause: gdpr

iuro Rechtsanwälte GmbH t/a Prighter and Prighter Ltd. (collectively, “Prighter Group”)… is our representative in the European Economic Area (“EEA”) for the purposes of the EU GDPR and the United Kingdom (“UK”) for the purposes of the UK GDPR.

We comply with the EU-U.S. Data Privacy Framework and the UK Extension to the EU-U.S. DPF as set forth by the U.S. Department of Commerce (collectively, the “DPF”) and have certified to the U.S. Department of Commerce that we adhere to the DPF Principles with regard to the processing of personal data received from the European Union and UK (and Gibraltar) in reliance on the DPF.