Mostly no, not by default, and the reason is structural. Perplexity is an answer engine built for cited research on public sources, not a vault for client confidences. On Free, Pro, and Max, your queries can be used to improve its AI models unless you turn off the AI data retention setting. Perplexity also routes your query to third-party models and searches the public web, so a confidential fact you paste can leave your control fast. Enterprise Pro changes the contract posture with a no-train commitment and tighter retention. For privileged work, the plan and its written terms decide the answer, and ABA Formal Opinion 512 makes confirming them your duty. This is general information, not legal advice. Terms move, so confirm the current ones. Facts here were checked June 2026.
TL;DR
- Consumer Perplexity is not private by default. On Free, Pro, and Max, the AI data retention setting is on, so queries can be used to improve models unless you toggle it off.
- The opt-out is partial. Turning off AI data retention applies to future data. Anything already used may not be pulled back.
- It is a search product, not a chatbot. Perplexity routes your query to third-party models and pulls from the public web. That is a different exposure shape than a closed chat tool.
- Enterprise Pro is the business contract. Perplexity states Enterprise data is never used for training, offers zero data retention, and deletes files after seven days (Perplexity, checked June 2026).
- The API is separate. Perplexity's Sonar API runs a zero data retention policy, distinct from the consumer web product.
- ABA 512 sets the bar. Know how the tool handles data and, in general, get informed client consent before entering confidences. Boilerplate consent is not enough.
On Perplexity Free, Pro, and Max, what happens to your queries by default?

Why Perplexity is a different question than ChatGPT
Most "is this AI private" guides treat every tool the same. Perplexity is not the same, and the difference matters for a lawyer.
ChatGPT and Claude are mainly chat tools. You type, a model answers, and the data path is relatively contained. We cover those in is ChatGPT confidential for legal work and Claude for legal work. The plan-tier logic there still applies here, so we will not restate it.
Perplexity is an answer engine. It takes your question, searches the live web, and runs the results through a language model to write a cited answer. Two things follow. Your query travels to a third-party model. Your query also shapes a web search. Both widen the surface where a confidential fact can travel.
The structural wrinkle: your query goes places
Think of Perplexity as a discovery-layer tool, not an authority-layer one. A discovery-layer tool helps you find and frame public information. An authority-layer tool, like Westlaw or a closed legal AI suite, is where you do privileged work against a controlled corpus. Perplexity sits firmly in the first camp.
Here is why that classification decides the privacy question. When you paste a sensitive fact, the tool routes the text to a model provider. It also turns that text into a web search. So a privileged detail can become part of a public web query and part of a request to an external model host.
Perplexity states that its agreements with third-party providers prohibit those providers from training on your data. That is a real protection. It is also a promise about other companies' handling that you cannot audit directly.
The mistake is treating a discovery-layer tool as a place to hold a secret. You paste a client fact to get a fast cited answer, and the fact has already traveled. Use Perplexity for what it does well, which is research on public sources.
Free vs Pro vs Enterprise Pro: the split that decides everything
Perplexity's consumer plans and its business plan are different products with different data terms. Here it is plainly, with facts checked June 2026. Confirm the current terms yourself, because vendor policies change.
| Plan | Trains on your inputs (default) | Opt-out | Retention | Third-party model exposure | Built for privileged work? |
|---|---|---|---|---|---|
| Free | Can be used to improve models | AI data retention toggle (future data only) | Account-tied, user-deleted | Query routed to external models | No |
| Pro / Max | Can be used to improve models | AI data retention toggle (future data only) | Account-tied, user-deleted | Query routed to external models | No, paid does not equal private |
| Enterprise Pro | Not used for training (Perplexity, June 2026) | Zero data retention available | Files deleted after seven days; custom policies possible | Provider agreements bar training on your data | Closer, with the contract in place |
Two traps to flag. First, Pro and Max are still consumer plans, so the higher price does not buy a business data agreement. Second, the AI data retention toggle is a setting, not a signed no-train contract, and it only reaches future data. For client-confidential matters, that gap is the whole point.
For where inputs travel across any legal AI tool, see where your legal AI data actually goes.
The training default, concretely
Why does the default matter so much? Because if a tool can learn from your inputs, a confidence you pasted could in principle influence a later output to someone else. ABA Formal Opinion 512 names this concern directly. Lawyers should be aware that information put into a tool could improperly end up in a later output.
On Free, Pro, and Max, the AI data retention setting is on out of the box. Your queries can be used to improve Perplexity's models until you switch it off in account settings. The opt-out helps, but it covers future data, so it is weaker than a contractual no-train term.
This is also why a vendor's no-train claim is worth checking rather than trusting. We walk through how in we do not train on your data: how to verify it.
What Enterprise Pro changes, and what it does not
Enterprise Pro is the version with business data terms. Perplexity states that Enterprise data is never used to train its models. It offers a zero data retention option, deletes uploaded files after seven days, and holds SOC 2 Type II compliance (Perplexity, checked June 2026). Its Sonar API runs a separate zero data retention policy, so API prompts and responses are not stored.

That is a real shift in posture. It is contract terms written for an organization, not a click-through consumer agreement. What it does not do is remove your duty to read it. The firm still has to confirm the no-train clause, the retention schedule, and the subprocessor list. It also has to confirm that the third-party model providers are bound to match those terms. A no-train promise upstream means little if a downstream model host has different terms for the same data.
Confidentiality due-diligence checklist
Run this before Enterprise Pro touches a client matter. A no-train promise is the start, not the finish. Send these as written questions to Perplexity sales and keep the answers.
Questions to ask sales:
- Does zero data retention apply to every model call, including third-party providers, or only to first-party features?
- Which model providers see our queries, and are they named in a current subprocessor list?
- How long are prompts logged for abuse monitoring, and is that retention separate from the seven-day file deletion?
- Are web searches generated from our queries logged or shared anywhere?
- Can we set a custom retention policy, and what is the minimum seat count for it?
Contract clauses to request:
- A written no-train clause covering Perplexity and all downstream model providers.
- A defined retention and deletion term, with deletion on request and on termination.
- A subprocessor list with advance notice before any new provider is added.
- Breach notification within a stated window, plus SOC 2 Type II evidence on request.
- A use-limitation clause barring use beyond delivering the service. Watch for broad "to improve our products" carve-outs.
Beyond the no-train promise, confirm:
- Provider routing. A no-train promise upstream means little if a model host has different terms downstream.
- Abuse-monitoring logs. Many vendors retain prompts for safety review even under zero data retention. Get the period in writing.
- Logging scope. Confirm what metadata is kept, for how long, and who can access it.
To document client consent:
- Record which tool, which plan, and which data terms applied at the time of consent.
- Get specific, informed consent for the matter, not engagement-letter boilerplate, where confidences are involved.
- Note the date, the client contact, and the version of the data agreement you relied on.
Safe vs unsafe uses for lawyers
Perplexity earns its keep on public-source research. The line is whether the input carries client confidences. ABA Formal Opinion 512 requires you to understand the tool's data handling and, in general, to get informed client consent before entering confidences. Our ABA Formal Opinion 512 guide covers the full duty set, and several state bars have added their own guidance.
Reasonably safe on a consumer plan (no client confidences):
- Researching a public legal concept, doctrine, or general statute background with citations to chase down.
- Finding public secondary sources, news, or regulator pages on a topic.
- Summarizing a published court opinion or public filing you then verify at the source.
- Drafting generic, non-client language like a definition or a neutral explainer.
Unsafe unless terms and consent are confirmed:
- Pasting client names, deal terms, or matter facts into the search box.
- Entering privileged communications or anything under a confidentiality obligation.
- Uploading client documents, contracts, or sensitive files on a consumer plan.
- Treating a Pro or Max subscription as if it carried business data protections.
The reliable move is to anonymize. Strip identifiers and deal-specific details before you research, and keep the privileged work in a tool whose terms are written for client data. Note too that any cited answer needs verification at the primary source, since confidentiality and accuracy are separate problems.
The verdict
Perplexity is a discovery-layer tool. It is built for cited research on public sources, not for holding client confidences. On Free, Pro, and Max, the training default and the route to third-party models make it a poor place to paste privileged facts. That holds even with the opt-out on. Enterprise Pro changes the contract posture with a no-train commitment, zero data retention, and a defined deletion schedule. The firm must still verify those terms before relying on them, and should keep consumer-plan use to public, anonymized research. For the wider buyer's view, see our roundup of the best legal AI tools for in-house counsel.
If you want a tool whose terms start from the assumption that the data is privileged, that is the gap legal-specific software fills. Vaquill AI is a legal AI suite for in-house counsel. It takes a no-train stance on your matter data and gives source-linked answers over real US opinions and statutes. A legal tool is not magic. Its value here is that the confidentiality terms are written for client data instead of a general consumer audience.
FAQ
Is Perplexity AI private for legal work? Not on consumer plans by default. On Free, Pro, and Max, queries can be used to improve Perplexity's models unless you turn off the AI data retention setting. There is also no business data agreement on those plans. Enterprise Pro is built differently, with a no-train commitment and tighter retention. That makes it a closer fit for client data once you verify the terms.
Does Perplexity train on what I type? On Free, Pro, and Max the AI data retention setting is on by default. Your inputs can be used to improve models until you switch it off. The opt-out applies to future data. Enterprise Pro states it does not train on your data (checked June 2026). Confirm the current terms, since they change.
Is Perplexity Pro private enough for client data? Pro is a consumer plan, so the higher price does not buy a business data agreement. For client-confidential matters, Enterprise Pro with a written data agreement is the safer path. On Pro, anonymize or avoid pasting sensitive material.
Does Perplexity send my data to third-party AI models? Yes. Perplexity routes your query to third-party model providers to generate answers and searches the public web. Perplexity states its agreements bar those providers from training on your data, but the routing still widens where a confidential fact can travel. Keep client confidences out of the search box.
Is the AI data retention opt-out the same as a no-train guarantee? No. It is a setting that can change, and it only reaches future data, not data already used. A business plan with a written data agreement gives you a contractual no-train term you can point to. That is what privileged work calls for.
Does Perplexity comply with ABA Formal Opinion 512? The opinion applies to you, not to the tool. You must understand how Perplexity handles data, match the plan to the matter's sensitivity, and generally get informed client consent before entering confidences. Boilerplate consent in an engagement letter is not enough under the opinion.
What should I never paste into consumer Perplexity? Avoid client names, deal terms, privileged communications, and uploaded client files. The same goes for anything under a confidentiality obligation, unless you have confirmed the data terms and obtained any required consent. When in doubt, anonymize or use a tool built for legal data.
Is Perplexity's API the same as the web app for privacy? No. Perplexity's Sonar API runs a zero data retention policy, so it does not store prompts and responses sent through the API. The consumer web product is a separate question, with the AI data retention default described above.
Last updated: June 2026.
New legal AI guides, weekly.
Further Reading
Is Claude Private for Legal Work?
Read postIs Microsoft Copilot Private for Legal Work?
Read postIs Gemini Private? What It Means for Confidential and Legal Work
Read postJudges Use AI, Lawyers Get Sanctioned for It: The 2026 Double Standard
Read postCan AI Give Legal Advice?
Read postUS State Privacy Laws in 2026: The In-House Compliance Baseline
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.