
A class-action lawsuit filed on April 1, 2026, in federal court in San Francisco alleges that Perplexity AI embedded hidden tracking software into its search engine that transmits users’ private conversations to Meta and Google. These are allegations in an active, unresolved complaint, not adjudicated findings; the note below tracks which claims come from the complaint and which are independently confirmed. The plaintiff, a Utah man identified as John Doe, says he shared family financial information, tax details, and personal investment strategies with the chatbot. According to the complaint, those conversations were accessible to Meta and Google from the moment he logged in.
The case is Doe v. Perplexity AI Inc., 3:26-cv-02803, filed in the U.S. District Court for the Northern District of California. It names Perplexity, Meta, and Google as defendants and alleges violations of California privacy laws and federal and state fraud statutes.
Perplexity spokesperson Jesse Dwyer told Bloomberg: “We have not been served any lawsuit that matches this description, so we are unable to verify its existence or claims.” Meta pointed to a Facebook help page stating that it is against the company’s rules for advertisers to send sensitive information. Google did not immediately respond. None of the three defendants has confirmed the underlying tracking allegations; Perplexity’s stated position at the time of the Bloomberg report was that it could not even verify the suit existed.
What the Complaint Alleges Technically
The lawsuit describes a specific mechanism. According to the filing, as soon as users log into Perplexity’s home page, trackers download onto their devices. The complaint describes the tracking software as “undetectable” and says it was embedded directly into the search engine’s code. These trackers allegedly give Meta and Google access to conversations between the user and Perplexity’s AI search engine.
The complaint further alleges that the data collection continues even when users enable Perplexity’s “Incognito” mode. This is the core of the technical claim: a feature marketed as privacy-preserving allegedly did not prevent third-party data access. This claim, like the others in this section, comes from the complaint and has not been independently verified or tested in discovery as of this writing.
The distinction matters because AI search interfaces handle data differently than traditional web browsers. When a user types a query into a conventional search engine, the query itself is the data. When a user has a multi-turn conversation with an AI chatbot, the data includes not just queries but responses, follow-up questions, corrections, and the entire conversational context. A user asking Perplexity to help with tax planning generates far more sensitive data than someone typing “tax brackets 2026” into Google, if the complaint’s characterization of what gets captured is accurate.
If the allegations are accurate, the trackers transmitted this conversational data to Meta and Google for advertising targeting and resale to additional third parties. The complaint does not specify which tracking technologies were used (pixels, SDKs, or cookies), but the reference to code-level embedding suggests JavaScript-based tracker SDKs rather than simple cookie-based tracking. That inference is this publication’s reading of the complaint’s description, not a confirmed technical finding.
Why “Incognito” in an AI Product Is Not Browser Incognito
Browser incognito mode has a well-understood scope: it prevents the browser from saving history, cookies, and form data locally. It does not prevent the websites you visit from logging your activity server-side. Most users misunderstand this, but the technical boundary is clear.
Perplexity’s “Incognito” mode operates in a different context entirely. The product is not a browser. It is a conversational AI application that processes natural language queries, maintains session state, and generates personalized responses. When Perplexity offers an incognito mode, users reasonably expect that their conversations will not be stored, shared, or made available to third parties.
The lawsuit alleges that this expectation was violated at the infrastructure level. If third-party trackers fire on page load, before the user even begins a conversation, as the complaint claims, then the incognito toggle would be a UI element that controls Perplexity’s internal logging but does not affect data already flowing to external recipients. Whether that “if” holds is exactly what this lawsuit is meant to establish; the distinction between what the product tells you it does and what the underlying page instrumentation actually does is, at this stage, the plaintiff’s allegation rather than a settled fact.
This pattern is not unique to Perplexity as an allegation type. Meta’s own data practices with Ray-Ban smart glasses drew a similarly structured complaint about a gap between marketing claims and actual data flows. The difference here is that AI chatbot conversations, if the allegations are accurate, would contain far more granular personal information than camera footage. A single conversation about personal finances, health conditions, or legal questions creates a data profile that traditional web browsing patterns cannot match, assuming the alleged data flow exists as described.
The Legal Exposure Under California Privacy Law
California’s Consumer Privacy Act (CCPA) and its successor, the California Privacy Rights Act (CPRA), impose specific requirements on companies that collect and share personal information. Under CPRA, businesses must disclose the categories of personal information they sell or share for cross-context behavioral advertising. They must provide a clear opt-out mechanism. They must honor user requests to delete personal information.
The complaint alleges that Perplexity did none of these things with respect to the tracker-based data sharing. If conversational data constitutes “personal information” under CPRA (and multi-turn AI chat transcripts almost certainly qualify), and if the alleged tracking occurred as described, then sharing that data with Meta and Google without disclosure would represent a per-user violation. Both conditions remain to be established in this litigation.
CPRA provides for statutory damages of $100 to $750 per consumer per incident, or actual damages, whichever is greater. For a class action covering all Perplexity users in California, the aggregate exposure could be substantial if the class is certified and the allegations are proven. Perplexity crossed 1 billion monthly queries in Q1 2026 and closed a $400 million Series E at a $24 billion valuation, figures independently reported and not themselves in dispute.
Perplexity’s Growing Legal Pattern
This is not the first time Perplexity has faced litigation over data practices. Reddit accused Perplexity and three other companies of taking Reddit user content to train AI systems without permission, an allegation in its own separate proceeding. Multiple news organizations, including the New York Times, have raised similar allegations about Perplexity using published articles to generate answers without licensing agreements.
Amazon filed a separate lawsuit after Perplexity’s Comet agent placed orders on behalf of users without adequate authorization. Unlike the Doe complaint’s core tracking allegations, this one reached an actual judicial outcome: a judge ordered Perplexity Comet to stop accessing Amazon’s platform, which is a confirmed procedural fact rather than an unproven claim.
The pattern across these cases is consistent as a pattern of allegations and, in the Amazon matter, at least one adjudicated result: Perplexity has repeatedly been accused of building features that access or transmit data in ways that the data subjects did not expect or consent to. Each individual case may have limited legal significance on its own, and most remain unresolved allegations rather than established facts. Collectively, they describe a company whose product development velocity has repeatedly drawn scrutiny over its data governance practices, which is a fair characterization of the litigation pattern itself, independent of how any individual case is ultimately decided.
What This Means for the AI Search Market
Perplexity positioned itself as the privacy-conscious alternative to Google Search. Its marketing emphasized direct answers without the advertising machinery that funds Google’s search business. The “Incognito” feature reinforced this positioning. If the lawsuit’s allegations are proven, that positioning would not hold up; if they are not, the positioning stands as marketed. That is genuinely an open question at this stage, not a foregone conclusion either way.
The broader question is whether any AI search product can simultaneously serve advertising-supported business models and maintain the user trust required for conversational interfaces. Google Search works because users understand the implicit deal: free search in exchange for ad targeting. AI chatbots change the terms of that deal by asking users to share information they would never type into a search bar, a dynamic that holds regardless of how this specific case is resolved.
The Axios supply chain attack that hit npm the same day this lawsuit was filed drives home a related point: the trust infrastructure supporting AI tools is thinner than users assume. Users share tax information with chatbots, install npm packages that run arbitrary code, and enable AI agents to operate on their behalf, all with an implicit assumption that the systems work as described. When adversarial conditions reveal that assumption to be wrong, the consequences are proportional to the trust that was misplaced, whether the specific mechanism is a proven tracker or a different vulnerability entirely.
Whether Perplexity actually embedded trackers that transmitted conversations to Meta and Google is now a question for discovery, and remains unresolved as of this writing. What is already clear, independent of how this case resolves, is that the AI search market has not yet built the data governance infrastructure, or the independent verification mechanisms, that would let users and regulators confirm claims like these without waiting for litigation to surface them.
Updated 2026-08-18: added explicit framing distinguishing the complaint’s unproven allegations from independently confirmed facts (the Amazon/Comet judicial order, Perplexity’s reported valuation and query volume), since active-litigation claims should remain attributed to the complaint rather than presented as established.