Can Perplexity Access My Files After a Session Ends?

Sami Ullah Khan

September 12, 2026

Can Perplexity Access My Files After a Session Ends
  • πŸ—‚οΈ Standard session uploads are retained for 30 days for consumer users and seven days for Enterprise users unless they are deleted sooner.
  • πŸ“ Storage location changes the rule: Project and personal-repository files persist until deletion, while connector files continue to follow the connected service’s permissions and storage rules.
  • πŸ”„ Deleting a file from follow-up context is not the same as erasing earlier answers, because Perplexity says previously generated responses retain the context they already used.
  • ⏱️ Enterprise custom retention is measured from the session’s last activity, so a follow-up query can reset the retention clock.
  • πŸ” Retention and AI training are separate controls: Enterprise data is excluded from training, while Free, Pro, and Max users can opt out of AI data collection for future data.
  • βœ… For sensitive material, choose the storage surface first, keep sessions private, remove attachments when no longer needed, and treat Projects as persistent repositories rather than temporary chats.

Yes, Perplexity can still use an uploaded file after you stop chatting because ordinary session uploads are retained for 30 days and Enterprise session uploads for seven days, unless you delete them sooner. If you are asking, “can Perplexity access my uploaded files after the session ends?”, the key distinction is that closing a browser tab, leaving the app, ending your work for the day, and deleting a Perplexity session are not the same event.

I would treat the file’s storage location as the decisive privacy fact. A document attached to a one-off session follows a countdown. A document saved in a Project or personal repository is persistent until it is deleted. A document surfaced through a connector can remain governed by Google Drive, SharePoint, OneDrive, Box, or Dropbox permissions, while an imported Project copy follows Perplexity’s Project rules. That means the same PDF can have different retention and access behaviour depending on how it entered the product.

Perplexity’s Help Center now documents the core answer unusually clearly. Session files are retained for 30 days, or seven days for Enterprise users. After that period, the original file content is no longer available for follow-up questions, although previous answers can still carry context derived from the file. Deleting the session deletes its attached files. Files in Projects and personal repositories are retained until deleted.

This guide turns those separate rules into one retention map. It also separates four questions that are often blurred together: how long a file is stored, whether it remains usable in a later follow-up, who can see it, and whether account data can be used for AI training. Those are related privacy questions, but they are not interchangeable.

Can Perplexity Access My Uploaded Files After the Session Ends?

The practical answer is yes for a defined retention window, but “session ends” needs a precise meaning. Perplexity does not document a consumer session as ending merely because you close the tab or stop typing. For signed-in users, normal sessions remain in History until you delete them. The file attached to that session follows its own retention rule.

For ordinary consumer sessions, Perplexity says uploaded files and images are retained for 30 days. For Enterprise session attachments, the documented default is seven days. Once that file-retention period expires, Perplexity says the file contents are no longer accessible for follow-up questions. Earlier answers do not rewind themselves, however. If a previous answer already summarised a contract clause, extracted a number, or compared two uploaded documents, that generated text can remain in the conversation even after the source file stops being available.

That distinction produces a useful two-layer model:

1.  The source layer is the uploaded object itself. Its storage and accessibility are governed by the retention policy for the place where it lives.

2.  The conversation layer is the text Perplexity already generated from that source. Removing or expiring the source does not automatically remove every derivative statement already present in the session.

For users who regularly work with PDFs, spreadsheets, transcripts, or research papers, the mechanics of uploading files to Perplexity AI matter because a one-off attachment and a persistent research file are not the same privacy choice.

Perplexity also offers an immediate-deletion request route through support for files or images in a session, Project, or organisation. That is separate from normal self-service controls. The current web interface additionally allows a user to remove an uploaded item from follow-up context by clicking the file control and removing it, but Perplexity warns that previously generated responses retain the context they already used.

The safest interpretation is therefore not “the file disappears when I am done.” It is “the file follows the retention rule of its storage surface until it expires or I delete it, while prior answers may continue to reflect information already extracted from it.”

The Retention Map: Where the File Lives Changes the Rule

The most useful way to understand Perplexity file privacy is to stop thinking in terms of one universal upload bucket. The product has several storage surfaces, and each behaves differently.

File LocationTypical UseDefault RetentionWho Can Use or See ItImportant Caveat
Consumer session attachmentOne-off analysis or follow-up30 daysThe user, plus anyone given access through sharingEarlier responses can retain derived context after the file itself expires
Enterprise session attachmentOne-off team analysis7 daysThe user and authorised session participantsEnterprise admins can set custom session retention in eligible organisations
Project filePersistent project knowledgeUntil deletedProject members with appropriate permissionsImporting a connector file into a Project creates a copy governed by Project rules
Personal repository fileReusable private referenceUntil deletedThe user who added itShared sessions can expose responses that reference it, even when teammates cannot open the source file
Connector sourceSearch cloud content without treating every file as a local uploadUntil deleted from the connected cloud serviceDetermined by connected-service permissionsSource permissions still matter when Perplexity references the file
Incognito session attachmentShort-lived private sessionUp to 24 hours for the sessionThe user during the incognito sessionIncognito sessions are not stored in normal History and are not recoverable after expiry
Sonar API inputDeveloper API requestZero Data Retention for request contentGoverned by API controlsAPI privacy is a separate policy surface from the consumer and Enterprise interfaces

This is the first major information-gain point for privacy-conscious users: ask “where does this copy live now?” before asking “when does my chat end?” The location gives you the retention rule, the permission boundary, and often the available deletion control.

Closing the Chat Is Not a Deletion Event

A common mental model comes from disposable chat windows: when the conversation is over, the temporary material is assumed to be gone. Perplexity’s documented behaviour is different. Signed-in normal sessions are stored in History until the user deletes them, while the file attachment has a separate retention period.

That difference matters because three actions can look similar from the user’s point of view but have different privacy consequences. Closing the tab only ends your local viewing session. Leaving the app does not, by itself, delete account history. Deleting the Perplexity session is the action Perplexity says also deletes its attached files and images.

If a session appears to have vanished, that still does not always mean the same thing as deliberate deletion. Perplexity documents shorter-lived modes for logged-out and incognito use, and files or connectors can also be associated with temporary sessions. The practical recovery rules are different enough that our Perplexity search history recovery guide is a better troubleshooting path than assuming an attachment was deleted simply because the conversation is not visible where expected.

Enterprise retention adds another layer. Perplexity says custom session-retention policies are measured from the session’s last activity, not from its creation date. A follow-up query resets the clock. If an organisation sets a 30-day policy, for example, a session can remain within that window for longer than 30 calendar days from creation if users continue to interact with it. When the last activity falls outside the configured period, Perplexity says the session becomes inaccessible and is permanently deleted within seven days.

This produces a more accurate privacy vocabulary:

  • Closed means you stopped viewing the session.
  • Inactive means you stopped adding activity, but the session may still exist.
  • Expired means the applicable retention window has run out.
  • Deleted means a deletion control or policy removed the session or file under Perplexity’s documented process.

Users should not substitute one of those states for another. If a document contains client information, unreleased financials, private research, or personal records, closing the browser is not a deletion workflow.

Session Attachments Have a Countdown, but Projects Do Not

The cleanest dividing line in Perplexity’s current file model is temporary session context versus persistent knowledge storage. Session attachments are designed to support a conversation. Projects and personal repositories are designed to make files available beyond one conversation.

For consumer session uploads, the documented retention period is 30 days. For Enterprise session uploads, it is seven days. Perplexity’s general file-upload Help Center says a file that has passed its retention period is no longer accessible for follow-up questions. It does not say that the earlier generated answers are purged at the same moment. That is why a privacy review should consider both the file object and the text derived from it.

Projects are the opposite by design. Perplexity describes Projects as persistent workspaces that can contain conversations, files, instructions, tools, and accumulated context. Project files are retained until deleted. For Enterprise, the current technical limits make this persistence concrete: a Project can hold up to 2.5 GB of total storage, with no total file-count limit, subject to the aggregate size cap. Direct uploads can be up to 100 MB per file, while files imported through supported connectors into a Project are limited to 25 MB per file.

That makes our Perplexity Projects and Spaces guide relevant for privacy as well as organisation. A Project is useful precisely because it remembers the material you deliberately keep there. That same strength is a reason not to treat it as a temporary drop zone for a sensitive file you expect to disappear when one task is finished.

Enterprise personal repositories are persistent too. Perplexity currently documents up to 5,000 synchronised or uploaded personal-repository files for Enterprise Pro users and 10,000 for Enterprise Max users, with an additional total-persistent-file limit across Projects and personal repositories of 15,000 and 50,000 respectively. Those limits do not include session attachments.

The technical takeaway is simple: if you want the lowest persistence, use the storage surface designed for the shortest lifecycle and delete the session when the work is done. If you want reusable organisational context, use a Project, but manage it like a repository rather than a chat attachment.

Connectors and Imported Copies Create Two Data Lives

Connectors are where file privacy becomes less intuitive because a document can be visible to Perplexity without behaving like a conventional upload. Perplexity supports file workflows connected to services such as Google Drive, SharePoint, OneDrive, Box, and Dropbox. The source file continues to be controlled by the connected service’s permissions, while Perplexity can reference authorised content for search and answers.

The crucial distinction appears when a file is imported into a Project. Perplexity’s current Help Center explicitly says that moving or importing a file creates a copy with the destination’s rules. A Project copy follows Project permissions and retention. The connected source remains subject to the connected cloud service. One document can therefore have two policy lives: the source in the cloud system and the copy in Perplexity.

For Enterprise Projects, the limits reinforce that distinction. Direct uploads permit files up to 100 MB, while connector imports into a Project are capped at 25 MB per file. Project files imported from connected services can be searched by people who have access to the Project, but Perplexity says those users still need the relevant connected-app permissions to view the original file contents where that permission check applies.

This is a meaningful information-gain point because “I removed it from Drive” and “I removed it from the Project” are not necessarily equivalent actions once a copy has been created. Privacy reviews should ask whether a workflow merely referenced the source or created a persistent destination copy.

The same principle applies to browser context. Our practical Perplexity Comet guide separates page reading, contextual reasoning, and permissioned action because data exposed through a browser assistant is not identical to a file intentionally added to a persistent Project. Perplexity’s own Comet privacy documentation should be checked separately when browser history, open-tab context, or connected accounts are part of the task.

Deleting the Source File Does Not Erase Derived Context

Perplexity’s most important deletion caveat is buried in the difference between source material and generated output. On the web, users can remove an uploaded file from the context available to later follow-up questions. Perplexity says the file is then deleted as context for the follow-up, but all previously generated responses retain the context they already used.

That distinction matters whenever an answer has already extracted names, figures, clauses, summaries, or conclusions from the attachment.

Perplexity further says that if you want to delete the file from the session in this web workflow, you may need to delete the previous response that last used the file, while noting that only the last output can be deleted and earlier outputs cannot necessarily be removed individually. The broader self-service path is to delete the entire session, which Perplexity says deletes attached files and images. Users who need the step-by-step controls can follow our guide to delete Perplexity AI history, but the privacy principle is more important than the menu path: remove both the source and any conversation content that reproduces sensitive material.

A simple deletion sequence is more reliable than a single click:

1.  Check whether the file was used in any response that reproduces sensitive content.

2.  Remove the attachment from future context where that control is available.

3.  Delete the whole session if the conversation itself should not persist.

4.  If the file also lives in a Project or personal repository, delete that persistent copy separately.

5.  If the file came from a connector, confirm whether the source remains in the connected service and whether a Project copy was created.

6.  For urgent or exceptional removal, use Perplexity’s documented immediate-deletion request route.

The product’s own documentation supports the core distinction: deleting access to the source is not retroactive deletion of every answer the source helped generate.

Who Can Read the File Depends on Sharing and Permissions

Perplexity says uploaded files stay private and are used to customise responses unless the user shares a session. That default is reassuring, but the sharing state can change the privacy boundary instantly.

If a user makes a session public, Perplexity warns that anyone with the link can see an uploaded image or file that remains visible in the session. A thread can be made private again, but that does not reverse what someone may already have viewed or saved while the public link worked. Users who need to share conclusions without sharing attachments can export the conversation to PDF rather than exposing the live session with its files.

Project access is different. Projects are private by default, and access can be limited to invited members or, in Enterprise settings, an organisation scope. Files stored inside the Project inherit that collaboration model. The safest assumption is that adding a file to a collaborative Project means the file is part of that workspace’s knowledge boundary, not a private attachment known only to the uploader.

Personal repository files add another nuance. Perplexity’s Enterprise documentation says these files cannot be directly accessed by other team members unless the user brings them into shared sessions. Even then, other users may see answers that reference the files while still lacking permission to open the original content in the connected service. That creates a potential information-leak path through generated text even when source-file permissions are intact.

A research team can reduce this risk by applying the same evidence discipline described in our Perplexity research workflow guide: know which sources are in scope, keep sensitive collections separate, verify the sharing state before inviting collaborators, and avoid mixing confidential documents with public-source research in a thread that may later be shared.

The practical rule is straightforward: file privacy is partly a storage question and partly a permission question. Retention tells you how long the object exists. Sharing tells you who can reach it while it exists.

Retention, Training, and Third-Party Models Are Separate Questions

Retention is the storage timeline. For consumer session files, Perplexity documents 30 days. For Enterprise session files, it documents seven days by default. Projects and personal repositories persist until deletion.

Training is a different policy layer. Perplexity’s July 2026 data-collection guidance says Free, Pro, and Max users have AI Data Retention enabled by default and can turn the setting off in Account Settings under Preferences. The opt-out applies to data collected after the opt-out date. Perplexity also says previously collected training data cannot be removed from model training through that toggle.

The documentation does not state, with enough precision to justify a stronger claim, that every uploaded file byte on a consumer account is automatically placed into model training. It says some data may be used for AI training unless the user opts out. I therefore would not turn a general training policy into a specific unsupported statement about every PDF attachment. The safer conclusion is that consumer users who do not want their eligible activity used for model improvement should disable the AI data setting before uploading sensitive material.

Enterprise is clearer. Perplexity says Enterprise data is never used to train its models. It also describes Zero Data Retention and Zero Data Training agreements with third-party AI providers such as OpenAI and Anthropic for Enterprise use. Perplexity’s separate documentation on third-party model providers says those providers are contractually prohibited from training on Perplexity data.

For developers, Sonar API requests sit on a separate policy surface again. Perplexity documents Zero Data Retention for API request content, while retaining limited billing and operational metadata. That API rule should not be casually imported into assumptions about consumer web sessions, and the 30-day consumer file rule should not be imported into API architecture.

This is the second major information-gain principle: storage duration, model-training permission, and third-party processing are related but not interchangeable. Privacy reviews should record each one separately.

Incognito and Temporary Sessions Use Different Clocks

Incognito is useful when the goal is to avoid normal account History, but it should be understood on its own terms. Perplexity’s current Enterprise Security Hub says Incognito sessions, including attachments, are retained for 24 hours. During that period, the sessions cannot be shared and are not accessible through normal History. Separate Perplexity troubleshooting guidance likewise describes Incognito sessions as expiring within 24 hours and not recoverable after expiry.

That is a materially shorter lifecycle than a normal consumer session attachment’s 30-day window. It does not mean “nothing is processed” or “the file never exists on Perplexity systems.” It means the session uses an intentionally short retention window and is excluded from the normal history experience.

Logged-out use is different again. Perplexity documents a 14-day lifecycle for logged-out sessions in its session and missing-history guidance. A browser that was not signed into an account therefore should not be treated as equivalent to Incognito or to a signed-in session.

Files and connectors can also trigger what Perplexity describes as temporary sessions in some product flows. That can make a thread look as though it vanished from the expected History surface even when the cause is session type rather than a conventional user-initiated deletion.

For academics, journalists, and analysts working with unpublished material, our academic research privacy workflow is a useful complement because it treats AI synthesis as a discovery layer rather than the final evidence repository. The privacy equivalent is to use a short-lived session for bounded analysis, keep the authoritative source in an approved system, and save only the non-sensitive result you actually need.

There is still a limit to what Incognito solves. If an answer itself reproduces private information and the user copies or exports that answer elsewhere, the downstream copy is outside the Incognito retention boundary. Likewise, an organisation with compliance duties should use Enterprise retention, sharing, audit, and identity controls rather than relying on individual users to remember when Incognito is appropriate.

A Safer Upload Decision Framework for Sensitive Work

The best privacy decision happens before the upload. Once a document has been summarised, quoted, or shared, cleanup becomes more complex because the information may exist in both the source object and generated conversation text.

Sensitivity LevelExampleBetter Perplexity SurfaceWhyAfter the Task
PublicPublished report, public paper, press releaseNormal session or ProjectLittle confidentiality riskKeep or delete based on convenience
Internal, low sensitivityInternal procedure, non-confidential notesPrivate session or restricted ProjectLimits unnecessary exposureDelete when no longer useful; review sharing
Confidential businessPricing, unreleased roadmap, client documentEnterprise with organisation controls, shortest practical retentionStronger no-training policy and admin controlsDelete session and persistent copies; audit Project membership
Personal or regulatedHealth, identity, legal, HR, financial recordsUse only if organisational policy and legal basis explicitly allow itConsequences of disclosure can be highPrefer minimal data, strict retention, documented deletion
Highly sensitive or secretCredentials, cryptographic keys, merger data, privileged investigationsDo not upload to a general-purpose AI interface unless an approved security architecture explicitly permits itThe cost of an error exceeds the convenience benefitKeep in purpose-built controlled systems

I use a five-question gate for sensitive files:

1.  Do I need the entire file, or can I redact it to the minimum necessary evidence?

2.  Is this a one-off analysis, or do I genuinely need a persistent Project copy?

3.  Is the session private, and could anyone with a link or Project access see the attachment or derived answer?

4.  Is consumer AI data collection disabled where appropriate, or is the work occurring in an Enterprise environment with the documented no-training policy?

5.  What exact deletion step will I perform when the task is complete?

The broader Perplexity power-user workflow tips can improve productivity, but privacy requires an opposite instinct in one respect: provide enough context for the task, not every available document. Data minimisation is still a strong security control in AI workflows.

This framework is not legal advice. Its purpose is operational: match the storage surface to the sensitivity of the material, keep permissions narrow, and plan deletion before upload rather than after a privacy concern appears.

Pricing and Plan Controls That Matter for File Privacy

Price does not directly determine whether a file is private, but plan tier changes the controls, limits, and retention policy available around file use. Perplexity’s current plan documentation lists Pro at $20 per month or $200 per year, Max at $200 per month or $2,000 per year, Enterprise Pro at $40 per month or $400 per year per seat, and Enterprise Max at $325 per month or $3,250 per year per seat. Enterprise annual pages sometimes display rounded monthly equivalents when billed annually, so the annual total is the safer figure for exact comparison.

PlanCurrent Published PriceSession File RetentionDocumented File Controls Relevant HereAI Training Position
Free$030 daysFile uploads are available with tighter usage limits; general upload guidance sets a 40 MB file ceilingAI data setting is enabled by default; user can opt out for future data
Pro$20/month or $200/year30 daysExpanded paid access; consumer absolute upload quotas can vary by product documentationAI data setting is enabled by default; user can opt out for future data
Max$200/month or $2,000/year30 daysHighest consumer tier with expanded usage; do not assume Enterprise repository limits applyAI data setting is enabled by default; user can opt out for future data
Enterprise Pro$40/month or $400/year per seat7 days by default30 files per session upload, 50 MB each, up to 100 session-file uploads per week, 5,000 personal-repository filesEnterprise data is not used for training
Enterprise Max$325/month or $3,250/year per seat7 days by default30 files per session upload, 50 MB each, up to 1,000 session-file uploads per week, 10,000 personal-repository filesEnterprise data is not used for training

Enterprise Project limits are shared across Enterprise Pro and Max: 2.5 GB total storage per Project, no file-count limit within that aggregate cap, up to 100 MB per direct upload, and 25 MB per connector import. Total persistent-file limits are 15,000 per Enterprise Pro user and 50,000 per Enterprise Max user across personal repositories and Projects.

What Current AI Security Data Adds to the Risk Picture

File retention is a product-policy question, but the reason it matters is broader. Organisations are increasingly exposing internal data to generative AI systems faster than governance programmes are maturing.

EY surveyed 500 US technology business leaders in research published in March 2026. Forty-five per cent said their organisation had confirmed or suspected a sensitive-data leak tied to unauthorised third-party generative AI use, and 39 per cent reported confirmed or suspected intellectual-property leakage. James Brundage, EY Global and Americas Technology Sector Leader, captured the governance problem in four words: “adoption is outpacing oversight.” That is exactly why file lifecycle and access controls should be designed before an AI workflow becomes routine.

Ken Englund, EY Americas Technology Sector Growth Leader, recommended that organisations “standardize approved tools, strengthen monitoring and security controls.” The point is not to ban AI document analysis. It is to turn an individual upload habit into an approved data-flow decision with known retention, permission, and deletion rules.

Gartner made a related prediction in July 2026: by 2029, the majority of privacy incidents are expected to result from AI-generated inferences rather than direct data exposure. Gartner Vice President Analyst Bart Willemsen described “a fundamental shift underway from data exposure to insight exposure.” Perplexity’s own warning that prior answers can retain context after a file is removed is a small but concrete example of that shift. The sensitive object can disappear while the sensitive inference remains.

Browser-based AI increases that surface further. In a March 2026 CrowdStrike and Perplexity announcement, CrowdStrike Chief Business Officer Daniel Bernard said, “The browser is no longer just where people access information.” Perplexity Chief Business Officer Dmitry Shevelenko described Comet Enterprise as providing “secure, AI-native browsing out of the box.” Those statements are commercial, not independent security audits, but they illustrate where vendors themselves see the control point moving.

Our Editorial Verification Process

I built this article around primary Perplexity documentation current through 12 September 2026, then cross-checked the claims against independent 2026 security research and the current search results for the exact question. The core retention evidence came from Perplexity’s September 2 file-upload privacy page and Enterprise retention page, its September 8 Enterprise file-limits page, its July 16 data-collection guidance, current Project and connector documentation, Incognito guidance, and current pricing pages.

The top 10 ranking results for the query were reviewed before drafting. They were dominated by Perplexity Help Center pages, each solving one slice of the question: upload privacy, file mechanics, Enterprise retention, missing sessions, account security, collaborative workspaces, account deletion, file limits, session behaviour, and data collection. That search landscape was strong on individual facts but weak on one unified model of storage location, retention clock, sharing, derived context, training, connectors, and deletion. A ranking third-party guide also repeated the idea that closing or refreshing a chat clears temporary file storage, which conflicts with Perplexity’s current 30-day consumer session-file documentation. The structure here was therefore built as a retention-state map rather than copied from a source article’s section order.

The live Perplexity AI Magazine sitemap endpoints specified in the editorial brief were attempted through the available browsing layer but did not return parseable XML. To avoid inventing URLs, the eight internal links in this article were selected only from live indexed Perplexity AI Magazine pages and checked for topical relevance. Each appears once in a body section.

I did not represent account-interface behaviour as hands-on testing where it was not independently reproduced in a signed-in Perplexity account. When an exact consumer plan quota was not stably documented, the article states that uncertainty rather than synthesising a number. Quotations were limited to short passages from 2026 primary announcements or research publications and were checked against the named source.

This article was researched and drafted with AI assistance and reviewed by the Sami Ullah Khan editorial desk at Perplexity AI Magazine. All data, citations, pricing figures, and named quotes have been independently verified against primary sources before publication.

Conclusion

Perplexity can continue to hold and use a session upload after you stop actively chatting, but the exact answer depends on the storage surface. For ordinary consumer sessions, the current documented retention period is 30 days. Enterprise session files default to seven days. Project files and personal-repository files are persistent until deletion, while connector sources continue to follow the connected service’s permissions and can create separately governed copies when imported into Projects.

The most important privacy insight is that file retention is not the same as conversation retention, sharing, or AI training. Closing a browser tab is not deletion. Removing a file from follow-up context does not erase an earlier answer that already contains information from it. A public session can widen access regardless of the underlying retention clock. Consumer training controls and Enterprise no-training commitments sit on a separate policy layer.

Perplexity’s documentation is clearer in September 2026 than many third-party summaries suggest, but open questions remain. Consumer upload quotas can change, product terminology continues to evolve, and new AI surfaces such as browser agents create additional context flows that require their own privacy review. The durable approach is to classify the document first, choose the least persistent suitable surface, keep sharing narrow, and plan deletion as part of the workflow rather than as an afterthought.

FAQs

Can Perplexity Access My Uploaded Files After the Session Ends?

Yes. Perplexity says ordinary session uploads are retained for 30 days and Enterprise session uploads for seven days unless deleted sooner. After the retention period, the original file content is no longer available for follow-up questions, although earlier answers can retain context derived from it. Perplexity’s “Security and Privacy with File Uploads” Help Center page is the primary source for this rule.

Does Closing Perplexity Delete My Uploaded File?

No. Closing a tab or app is not the same as deleting a session. Signed-in normal sessions can remain in History, while their attachments follow the applicable file-retention rule. Perplexity says deleting the session deletes files and images attached to it.

How Long Does Perplexity Keep Uploaded Files?

Perplexity currently documents 30 days for ordinary session files and seven days for Enterprise session files. Files stored in Projects and personal repositories are retained until deleted. Incognito sessions use a shorter 24-hour lifecycle.

Are Files in Perplexity Projects Deleted After 30 Days?

No. Perplexity says Project files are retained until deleted. The 30-day rule applies to ordinary session attachments, not persistent Project storage. Enterprise Projects currently have a 2.5 GB aggregate storage limit per Project, with different per-file limits for direct uploads and connector imports.

Does Deleting a File Remove What Perplexity Already Learned From It?

Not necessarily. Perplexity says removing an uploaded file from follow-up context does not change previously generated responses, which retain the context they already used. If an earlier answer reproduces sensitive content, deleting the source file alone may not remove that text from the conversation.

Does Perplexity Use Uploaded Files to Train AI Models?

Perplexity says some consumer data may be used for AI training unless Free, Pro, or Max users opt out through the AI Data Retention setting. Its public documentation does not justify claiming that every uploaded file is automatically used for training. Enterprise data is explicitly excluded from AI training.

Can Other People See a File I Upload to Perplexity?

Files are private by default, according to Perplexity, but sharing changes the boundary. If a session is public, anyone with the link may be able to see an uploaded file or image visible in that session. Project access is controlled by Project membership and organisation permissions.

Is Incognito Better for Sensitive File Uploads?

Incognito reduces persistence because Perplexity documents a 24-hour session lifecycle and excludes Incognito sessions from normal History. It is not a substitute for organisational approval, legal review, data minimisation, or Enterprise security controls when documents are confidential or regulated.

References

Perplexity Support. (2026, September 2). Security and Privacy with File Uploads. Perplexity Help Center.

Perplexity Support. (2026, September 2). Data Retention for Enterprise. Perplexity Help Center.

Morales, E. (2026, September 8). Enterprise file limits. Perplexity Help Center.

Perplexity Support. (2026, July 16). Data Collection at Perplexity. Perplexity Help Center.

Perplexity AI. (2026, July 8). Privacy Notice. Perplexity.

EY. (2026, March 4). Autonomous AI adoption is outpacing governance, increasing enterprise risk. EY Newsroom.

Perplexity AI. (2026). Pricing: Plans for Individuals and Enterprise. Perplexity.

CrowdStrike. (2026, March 11). CrowdStrike and Perplexity partner to secure the AI browser. CrowdStrike.

Gartner. (2026, July 30). Gartner predicts the majority of privacy incidents will result from AI-generated inferences by 2029. Gartner.

Stay Ahead of AI

Get the latest AI news delivered to your inbox.

We don’t spam! Read our privacy policy for more info.