09.25.26 · The Cape Team

Comet Browser Privacy and Security Features: Strengths, Limitations, and Risks

Comet Browser is an AI-powered browser that delivers a unique, agentic browsing experience. Its primary goal is to automate tasks that users may find repetitive or time-consuming when browsing the web, such as comparing products across tabs, conducting cross-site research, and managing digital workflows, including scheduling meetings and unsubscribing from spam.

Because Comet Browser is built around AI-first browsing and workflow automation, privacy and security naturally become key considerations. Does the browser offer sufficient protection, or have convenience and AI functionality overshadowed this aspect?

This guide examines the Comet Browser's privacy and security features, explores how user data is handled, and discusses potential privacy and security risks to consider before switching.

What Is Comet Browser?

Comet Browser is Perplexity’s AI-native, Chromium-based browser, described as an AI assistant rather than a conventional web browser. It relies on Perplexity as its default search engine but aims to fundamentally change how users search and interact with the web. Instead of typing a query and receiving a list of organic search results, the Comet Assistant can help users:

  • Navigate websites
  • Summarize content, even across multiple tabs
  • Manage and automate tasks such as sending emails and creating calendar events

The browser introduces the concept of agentic browsing. It essentially minimizes manual interaction with the web by allowing users to delegate tasks to an AI assistant. For example, instead of manually comparing products across multiple websites, you can instruct Comet to “compare prices for X item across different shopping platforms,” and it will research the relevant websites and present the results.

The key difference between traditional AI assistants and Comet Browser is that most AI tools generate responses based on user prompts, whereas Comet actively interacts with browser content. It can navigate existing tabs, open new ones, refine searches, click links, and complete more complex tasks such as researching a topic or summarizing information from multiple sources. Users can also interact with the assistant through voice commands instead of typing.

Comet Browser also integrates with Gmail and Google Calendar. When granted permission, it can reply to emails, automatically unsubscribe from spam, and organize your calendar based on information in your inbox. Since features like this one allow Comet to access more browsing context and information than traditional browsers, its privacy and security model becomes particularly important.

Comet Browser User Data Handling

Perplexity describes Comet Browser’s privacy model as private by design. , all data is primarily stored locally to support an optimized browsing experience. The information Comet may collect includes three broad categories of data:

  1. Technical data, including crash logs, information, and IP address, primarily used for diagnostic and troubleshooting purposes
  2. Browsing data, including URLs, cookies, and site permissions, which help power AI features and browsing recommendations
  3. Extension and add-on data, such as passwords, payment methods, and profile information, which can be imported and stored locally in your Comet profile only with your permission

Because Comet Browser relies on the Perplexity search engine, information entered into the search bar may be . The developer states that browser data is only transmitted when “a personal search is asked to Comet.” To answer these requests, Comet may access information from your open tabs and browsing history when relevant to the task.

Similarly, Comet’s AI capabilities rely on contextual awareness. With the necessary permissions granted, Comet can access information from services such as Gmail and Google Calendar to complete tasks like drafting email replies, organizing your schedule, or managing other AI-assisted workflows. The browsing data used to power these features can be managed through Comet’s privacy settings.

While acknowledging that user data is collected and processed to provide AI capabilities in accordance with the Comet Browser privacy policy, Perplexity states that it does not sell personal data to third parties.

Comet Browser Privacy and Security Settings

Since Comet Browser relies heavily on agentic browsing and AI-powered workflows, privacy and security settings play a key role in controlling how user data is accessed and processed.

The following sections outline the primary privacy and security settings currently available in Comet Browser and explain how they help protect your data while reducing unnecessary exposure.

Perplexity Comet Browser Privacy Features

Comet Browser’s “privacy by design” approach is grounded in several key privacy features, outlined in the table below:

Privacy Feature

What It Entails

Local data storage

  • Sensitive data, such as browsing and search history, cookies, signed-in sessions, cached files, autofill data, and download history, is stored locally on your device unless you choose to sync it with your Perplexity account
  • Diagnostic data used for troubleshooting is stripped of personal identifiers, can’t be traced back to you, and can be disabled via Settings > Privacy and security > Help improve Comet

Limited retention and access to sensitive data

  • AI requests that rely on page content, browsing history, or open tabs are retained for no more than 30 days, after which they’re automatically erased
  • Comet only accesses browsing history, open tabs, emails, or calendars when those permissions are explicitly granted

Permission-based AI access

  • Before Comet performs an automation or advanced AI task for the first time, it requests your permission, where you can choose either Allow this time only, Always allow, or Don’t allow
  • The data accessible by Comet Assistant can be controlled via Settings > Privacy and security > Comet Assistant, where you can choose to Disable Comet Assistant entirely or Block Assistant on specific websites

Privacy Snapshot widget

  • The all-in-one privacy widget provides quick access to key privacy controls directly from the homepage
  • The centralized dashboard allows you to review and manage AI Assistant and site permissions, data settings, and built-in features such as Adblock

Adblock

  • Comet’s built-in Adblock blocks advertisements and tracking scripts by default, helping reduce behavioral tracking and limiting the amount of browsing data available to advertisers
  • You can review blocking statistics, add trusted websites to the exceptions list, and manage preferences through Settings > Privacy > Blocking

Perplexity Comet Browser Security Features

In addition to privacy controls, Comet relies on several to defend against common online threats, such as phishing attempts and malicious websites. The table below summarizes the core security-related protections:

Security Feature

What It Entails

Malware defense

  • Comet prevents pages from loading if they’re identified as known malicious websites, malware-hosting domains, or phishing sites
  • The browser relies on regularly updated lists to identify and block malicious destinations

Autofill security

  • Autofill is only available on trusted (whitelisted) domains
  • It never activates on mismatched or suspicious websites, helping reduce credential theft

Password manager

  • Comet can’t export or read saved passwords without your explicit permission
  • Password decryption takes place locally and only after your identity is verified via Touch ID, Face ID, or Windows Hello

Incognito mode

  • automatically blocks third-party cookies unless you explicitly allow them
  • Extensions are also disabled by default unless you manually enable them, reducing the attack surface created by unnecessary or potentially malicious add-ons

Site permission controls

  • Comet lets users control website access to sensitive resources such as the camera, microphone, location, and notifications
  • You can review, grant, deny, or revoke permissions at any time to prevent unauthorized access through Settings > Privacy and Security > Site Settings

Comet Browser Privacy and Security Concerns

Comet Browser’s transparent data collection and retention practices, along with privacy and security controls, may make it a compelling alternative to mainstream browsers. Still, the amount of data required to power its AI-driven capabilities may raise privacy and security concerns not present in traditional browsers.

Researchers at LayerX recently known as CometJacking, which specifically targets AI browsers. According to the researchers, attackers can embed hidden prompt-injection instructions in a phishing email or a seemingly legitimate web page via a link to extract user information.

With a single click, these instructions may manipulate the AI agent into accessing sensitive information from connected services, such as email and calendar, and revealing user data that the browser is permitted to access.

In this scenario, limited data retention offers little protection, as information can be extracted during the active browsing session. Instead of performing a standard web search, the AI assistant may be redirected to tap into its memory and reveal saved user information to attackers.

The possibility of malicious code redirecting or controlling the AI browser introduces an entirely new attack surface that did not exist with traditional browsers. At the same time, existing threats, such as network-level risks and large-scale carrier breaches, remain just as relevant.

1

Bonus: Explore the best in this guide.

Is Comet Browser Private Enough?

With modern browsing solutions, such as AI browsers, entering the picture, the online security landscape faces new, more sophisticated threats. Still, the core vulnerabilities of online browsing don’t disappear—quite the contrary, they continue to grow more elaborate.

While adopting secure browsing habits and employing all available browser protections play a crucial role in limiting tracking and data collection, they remain completely independent of one of the most significant attack surfaces: mobile carriers.

The China-state-linked campaign, which silently siphoned sensitive user information, including call logs and geolocation data, continues to have repercussions through 2026. This massive telecommunications hack is still not fully understood by experts and government officials, while users of major carriers such as remain compromised.

Even if you minimize data collection at the browser level, big telcos still gather an enormous amount of data that remains vulnerable to breaches, leaks, and internal compromises.

Switching to a privacy-centered mobile carrier such as ensures you address this critical concern by eliminating the blind trust traditionally placed in outdated network infrastructure.

Cape Makes Security the Standard: Here’s How

Cape is America’s privacy-first mobile carrier, providing premium, unlimited, and nationwide call, text, and data. Unlike other providers, our service is built from the ground up with privacy and security at its core.

Mainstream carriers track you and store your data, often without your consent. Cape takes a different path—we collect the absolute minimum amount of information to provide you with service.

Any information we do collect is retained for the minimum amount of time possible. Most carriers store call data records (CDRs) for years, sometimes indefinitely. Cape stores yours for just 24 hours, and we have a commitment to never sell your data.

Cape service includes security features that no other carrier offers:

  • : During onboarding, we don’t ask for your name, Social Security number, or address. We only collect what’s necessary to provide you with service, and we retain it for the minimum amount of time possible.
  • Every SIM card has an International Mobile Subscriber ID (IMSI), a unique identifier which your device uses to register with cellular networks. Most carriers assign a fixed IMSI that stays the same for the life of your account, making it easy for your carrier, advertisers, and bad actors to identify and track your device over time. Cape breaks that pattern by allowing subscribers to automatically rotate their IMSI every 24 hours, so you appear as a different subscriber every day, making it much more difficult for anyone to follow or track your movements.
  • : Your phone number is a target for data brokers and scammers. Retailers, websites, apps—everyone is routinely asking you to share your number with them, which exposes you to a variety of risks. Many turn to VoIP numbers to use as secondary lines, which can be helpful, but cost extra, don’t work with 2FA, and aren’t encrypted. Cape provides subscribers with two free additional SMS/MMS lines that are middle-to-end encrypted. With secondary numbers, you can reserve your primary number for communicating with your close friends and family, and use the other for anything from shopping and signing up for discounts, to receiving secure OTPs.
  • : Call and text records reveal a lot about you, from who your closest relationships are to when and where communication took place. With traditional carriers, your call and text metadata doesn’t just disappear; it’s retained, analyzed, and folded into a lasting customer profile. At Cape, we’re built to forget and delete these records after just one day.
  • : A SIM swap happens when an attacker convinces your carrier to transfer your number to their device, allowing them to receive your calls and texts, trigger password resets, and gain access to your accounts. Cape protects against SIM swaps by removing humans entirely from the loop. During sign-up, you receive a 24-word phrase that generates a private key tied to your number. This phrase is the only way to move your number to a new device or carrier. No one, not even Cape, can transfer your number without your phrase, giving you full control over your number.
  • : Traditional cellular networks were designed for interoperability, not security. Outdated and legacy network protocols like SS7 have vulnerabilities that allow attackers to hack in and track your location, intercept your calls and texts, and steal sensitive information. Cape’s Network Lock uses a proprietary signaling proxy to verify that your device’s physical location matches the network it’s trying to attach to. If anything looks suspicious, like a mismatched location, we block the connection.
  • : Voicemails can reveal more than you think, from personal messages to authentication codes, yet most voicemail systems are outdated and unencrypted. Cape encrypts your voicemails so that only you can access them.
  • : While you’re traveling abroad, your phone connects to local telecom providers to provide you with connectivity. But not all networks are secure, and not all governments treat privacy the same. Cape routes your traffic through our U.S.-based mobile core. Our Secure Global Roaming gives you the convenience of international data roaming without exposing your identity or communications. You get up to 15GB per month of international roaming included in your plan.

These features are made possible because we’re a “Heavy” Mobile Virtual Network Operator (MVNO).

Other MVNOs (such as Mint Mobile, Cricket, etc.) simply ride on top of the mobile core, SIMs, and physical infrastructure of their underlying MNO partner. At Cape, we actually own our own mobile core and provision our own SIMs.

This gives us control over how accounts are authenticated, what data we do and don’t collect, how long we retain it for, as well as the ability to build proprietary features like Identifier Rotation. No other carrier on the market has this capability.

Reclaim Your Privacy: Switch to Cape Today

Ready to ditch traditional telcos and switch to a privacy-first mobile carrier? Visit to sign up.

Thanks to our partnership with Proton, you can also take your privacy a step further and for only $1 for the first six months.

Share it

Signup Callout

Switch to Cape,
America's privacy-first mobile carrier.

Protect yourself with premium, secure cell service.

Sign up now