Someone on r/perplexity_ai asked last week whether Comet was safe to keep open while logged into their bank. The thread split into “Perplexity is reputable, chill” and “are you actually insane.” Neither side answered the question.

The question “is the Comet AI browser safe” has a real answer. It’s just not yes or no. It comes down to what leaves your machine, where it goes, and whether you understand the deal you’re making each time you click Search.

What Comet does with your tab

Comet is Perplexity’s browser. The pitch is that it can answer questions about the page you’re on, summarize what you’re reading, and run multi-step tasks across your tabs. To do any of that, it has to know what’s in those tabs, and that information has to live somewhere the LLM can reach it.

It lives on Perplexity’s servers. Your page DOM, the URLs you’re visiting, the text you’ve selected, sometimes the form fields you’ve focused, all of it gets bundled and shipped upstream so the model can reason about it. This isn’t sneaky. It’s just how a cloud-routed browser agent works.

The same architecture powers most of the other big AI browsers. Dia does it. Arc Search did it. ChatGPT’s Atlas does a slightly different version of it. The model is always somewhere else, the page is always on your machine, and something has to bridge the two. That bridge is a network call.

What can actually go wrong

A few specific things, in rough order of likelihood.

Session tokens and partial auth state can leak through page content. Plenty of sites embed CSRF tokens, signed URLs, or OAuth state directly in rendered HTML, and if the assistant scrapes the DOM and ships it upstream, that material is sitting in Perplexity’s request logs for however long their retention policy says it is.

Prompt injection becomes a much wider attack. A hostile webpage (a comment thread, a calendar invite, a shared doc that links to another poisoned doc) can hide instructions that tell the agent to do something on your behalf, and because the agent has full browsing permissions across your logged-in tabs, the blast radius is basically every site you’re authenticated to. Simon Willison’s “lethal trifecta” framing fits exactly here: untrusted content, sensitive data, external communication.

Form values get hoovered up. If you ask Comet to help with a form, the values it sees are values it sends. Salary fields. Medical intake. Half-written Slack drafts. Whatever’s on screen is fair game.

And then the boring one. Perplexity is a company. Companies get breached, change ToS, get acquired, pivot. The data you trusted them with in 2026 is governed by whatever policy exists in 2028, which is governed by whoever owns the company then.

The fix isn’t more trust. It’s less surface area.

You don’t make this safer by hoping Perplexity is careful. You make it safer by not sending them the data at all.

A different architecture exists

Run the agent inside the browser the user already controls, in the tab they’re already authenticated to, using the session that’s already loaded. The page doesn’t need to be uploaded to a third party because the agent is already inside the page.

This is the local browser model, and it’s a real architectural alternative, not a marketing position. Dassi is one of these. It’s a Chrome extension that lives in the side panel, reads the active tab locally, and only sends data to the LLM provider you’ve explicitly chosen. With BYOK or your existing ChatGPT subscription, the round trip is browser to your LLM and back. Perplexity isn’t in the loop, and neither is any other middleman.

That doesn’t make it perfectly safe. The LLM provider you picked still sees what you send. Prompt injection still exists in some form. But the supply chain is shorter, the data flow is auditable, and you’re picking who you trust instead of having it picked for you.

So is Comet safe

For browsing news, reading articles, doing research on public pages? Probably fine. The blast radius is narrow and the data isn’t sensitive.

For anything inside an authenticated session, like banking portals, health records, internal company tools, an email inbox that holds your password resets, the answer changes. Not because Perplexity is sketchy. Because you’re routing your most private context through a third party that didn’t need to be in the path.

Pick the architecture that matches the task. A cloud browser is a fine tool for some jobs. It’s a strange choice for the ones where your tab is the source of truth and the data isn’t yours to share.