Q16 Frontier Watch

AI App Privacy Ratings

Every consumer AI app traced through the model behind it. Each carries two scores from 0 (worst) to 10 (best): an App score — the privacy the app’s own policy gives you — and a Model score — the privacy of the AI provider running underneath. Your data gets whichever is weaker; that lower number is the overall rating. Read the full methodology →

The finding: across this cohort, the App score is almost always the lower number. The frontier-model backends behind these apps (OpenAI, Anthropic, Azure) are more privacy-protective than the apps riding on them — compare the two columns on any card below. Your privacy isn’t being lost to the AI model underneath. It’s being lost at the app on top.
Runs on:AllOpenAIAnthropicGooglexAIMoonshot AIPerplexity
1
3.5overall
Manus
agent
App 3.5 · Model 9.0
 
Policy-basedMinors 2.0
Trace the chain — App → Host → Provider
app3.5Manus — app policyPolicy-basedsets the score
provider9.0Anthropic (direct API)Policy-based
2
3.4overall
Replit
coding
App 3.4 · Model 9.0
 
Policy-based
Trace the chain — App → Host → Provider
app3.4Replit — app policyPolicy-basedsets the score
provider9.0Anthropic (direct API)Policy-based
3
2.2overall
Notion AI
productivity
App 2.2 · Model 9.0
 
Policy-based
Trace the chain — App → Host → Provider
app2.2Notion AI — app policyPolicy-basedsets the score
provider9.0Anthropic (direct API)Policy-based
4
1.7overall
Perplexity
search
App 1.7 · Model own
5 model choices
Policy-based
Trace the chains — 5 model backends

This app lets you choose which model runs underneath. The App score stays the same whichever you pick — each choice below shows the Model score for that backend. The overall rating uses the default configuration. Switching models can never lift an app above its own App score, though a weak model can pull it lower.

Perplexity → GPT-5Model 8.3
app1.7Perplexity — app policyPolicy-basedsets the score
provider8.3OpenAI (direct API)Policy-based
Perplexity → Sonar (own model)Model owndefault
app1.7Perplexity — app policyPolicy-basedsets the score
Perplexity → Claude (Opus/Sonnet)Model 9.0
app1.7Perplexity — app policyPolicy-basedsets the score
provider9.0Anthropic (direct API)Policy-based
Perplexity → Gemini ProModel 6.7
app1.7Perplexity — app policyPolicy-basedsets the score
provider6.7Google (direct API)Policy-based
Perplexity → Grok 4Model 7.6
app1.7Perplexity — app policyPolicy-basedsets the score
provider7.6xAI (direct API)Policy-based
5
1.6overall
Comet
browser / agent
App 1.6 · Model 8.4
6 model choices
Policy-basedMinors 0.0
Trace the chains — 6 model backends

This app lets you choose which model runs underneath. The App score stays the same whichever you pick — each choice below shows the Model score for that backend. The overall rating uses the default configuration. Switching models can never lift an app above its own App score, though a weak model can pull it lower.

Comet → Sonar (Perplexity's own)Model 8.4default
app1.6Comet — app policyPolicy-basedsets the score
provider8.4Perplexity (direct API)Policy-based
Comet → Claude (Opus 4.6 / Sonnet 4.6)Model 9.0
app1.6Comet — app policyPolicy-basedsets the score
provider9.0Anthropic (direct API)Policy-based
Comet → GPT-5.4Model 8.3
app1.6Comet — app policyPolicy-basedsets the score
provider8.3OpenAI (direct API)Policy-based
Comet → Gemini 3.1 ProModel 6.7
app1.6Comet — app policyPolicy-basedsets the score
provider6.7Google (direct API)Policy-based
Comet → Grok 4Model 7.6
app1.6Comet — app policyPolicy-basedsets the score
provider7.6xAI (direct API)Policy-based
Comet → Kimi K2.5Model 1.3
app1.6Comet — app policyPolicy-based
provider1.3Moonshot AI (direct API)Policy-basedsets the score

Minors is a separate 0–10 read of how well an app protects under-18 users (age verification, parental controls, minors’-data handling). It is reported alongside the privacy score, not folded into it. How it’s scored →

Verification: Verified = backed by a contract/DPA · Policy-based = from a published policy · Inferred = deduced where the policy is silent · Unverified = not yet assessed. The label reflects confidence in the number, not the number itself.