Consumer (websites, Comet browser & apps): No BAA published · Data used to improve services including AI models, with no opt-out described · Uploaded files deleted in seven days, but the session containing them is not
Enterprise Pro: No BAA published · Enterprise data never used to train, extended contractually to third-party providers · Admin-configurable session retention
| Consumer - websites, Comet browser & apps | Enterprise Pro | |
|---|---|---|
| HIPAA BAA | Not statedno Perplexity document reviewed offers a HIPAA Business Associate Agreement on any plan. The enterprise security page claims "HIPAA aligned safeguards," which is not a BAA | Not statedPerplexity claims "GDPR and HIPAA aligned safeguards" but publishes no BAA offer for Enterprise Pro or any other plan |
| Trains on your data | Yesdata is used to "Improve or create services and products, including our AI models," with no training opt-out described in the privacy notice. A carve-out exists only for Email Assistant: "We do not use the content of emails to create, train, improve, or fine-tune AI models" | No"Enterprise data is never used to train or fine-tune Perplexity's models, and our agreements with third-party AI providers prohibit them from training on your data" |
| Survives deletion | Yesuploaded files follow a seven-day deletion policy but "The session containing those files is not deleted unless you request it." Deletion requests may be refused where data is legally required, and "We may keep historical data in our backup files as permitted by law" | Admin-configurableEnterprise administrators set session retention windows in the admin control panel. Uploaded files follow a seven-day deletion policy, but the session containing them is not deleted unless requested |
| Deployer / admin log access | Not stated for consumer productsaudit logging is documented as an Enterprise admin feature | Yesaudit logging is available in the Enterprise admin control panel, alongside session retention, Incognito Mode enforcement and AI model/provider settings |
| Third-party attestation | SOC 2 Type 2 stated on the enterprise security page. ISO 27001 is not mentioned. Scope by plan not stated | SOC 2 Type 2 stated. ISO 27001 is not mentioned on the enterprise security page |
Enterprise Pro, which has the opposite training posture - the consumer privacy notice explicitly does not apply to Enterprise or API offerings. Also "HIPAA aligned safeguards," which is marketing language, not a BAA
"HIPAA aligned safeguards" being read as HIPAA coverage - no BAA is offered in any reviewed document. Also consumer Perplexity, which trains on user data and is governed by a different notice entirely
Vendor terms change without notice. This page reflects what Perplexity published as of September 2, 2026. Re-verified quarterly.
If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.
See how AVRA works →Want all 13 tools in one file?
Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.