An AI browser is not a search engine that only sees what you type. It is a Chromium browser with an assistant wired into every tab, and while that assistant is active it can read the actual page in front of you: the article, the logged-in dashboard, the form you are halfway through filling out. Some of these tools also ship an agent mode that goes further, clicking links and filling in fields on your behalf. ChatGPT Atlas and Perplexity Comet are the two products most people mean when they say AI browser, and they make a useful pair to examine, because one of them no longer exists as a standalone browser and the other is still live and adding features. Both cases are worth understanding, because the underlying question does not go away when a product does: once an assistant can see a page, what happens to what it sees.
ChatGPT Atlas stopped working as a standalone browser on August 9, 2026. Its agentic browsing features did not disappear. They moved into the ChatGPT desktop app and a ChatGPT Chrome extension, so the privacy questions Atlas raised are still relevant to whatever replaced it.
What 'The Assistant Can See The Page' Actually Means
There are two distinct modes worth separating before anything else, because they carry different privacy weight. The first is passive: the assistant reads the current page as text and answers questions or summarizes it, the way a browser sidebar has worked since AI browsers first shipped. The second is agent mode: the assistant reads the page, decides on an action, clicks or types, then reads the result and repeats, working through a task with the same access a logged-in person would have. Passive mode sees one page at a time, on request. Agent mode can move across several pages and logged-in sessions in a row, without you clicking anything yourself. Both modes require the same starting fact: the content of the page has to leave your screen and reach the assistant in some form before it can do anything with it. Where that content goes, and what happens to it afterward, differs by product, and that is the part worth checking rather than assuming.
What ChatGPT Atlas Could See, and Where That Capability Lives Now
OpenAI launched Atlas on October 21, 2025, as a Chromium-based browser available only on macOS, with ChatGPT built into a sidebar that could read the open page. Its two standout features were Browser Memories, an opt-in setting that let ChatGPT recall details from pages you had previously visited, and Agent Mode, which carried out multi-step tasks such as filling forms and navigating between sites.
OpenAI's own documentation, corroborated independently, described specific handling for that browsing content: web content gets summarized on OpenAI's servers, the original page content is deleted immediately after that summary is produced, and the privacy-filtered summary itself is deleted within seven days. Browser Memories, the opt-in feature that persists across sessions, were retained for up to 30 days for safety monitoring before automatic deletion, with filters designed to strip identifiers such as government IDs, bank account numbers, and login credentials before anything was stored.
On model training, the default ran the other way from what many assumed: OpenAI did not use browsing content to train its models unless a person opted in, and that toggle was off by default. Business and Enterprise accounts had their browsing content excluded from training regardless of that setting. Atlas also had an Incognito mode: browsing done there was not linked to a ChatGPT account and was not added to browsing history, though signed-out chats were still retained separately for 30 days for abuse detection, a caveat easy to miss if you assumed incognito meant nothing was kept at all.
The Tainted Memories Finding
In October 2025, the security firm LayerX disclosed a technique it called Tainted Memories, a cross-site request forgery style attack in which a person tricked into visiting a malicious page could have hidden instructions written into their persistent ChatGPT memory without realizing it, instructions that could then carry forward into later sessions and other devices. OpenAI's response was direct: the company said it had been unable to reproduce the reported CSRF attack and had seen no evidence of real-world exploitation. Both claims are worth holding at once. A named security firm published a specific attack chain, and OpenAI specifically disputed being able to reproduce it. Neither side's account resolves the other.
Atlas itself did not survive long enough for that dispute to fully play out in public. OpenAI shut it down on August 9, 2026, 292 days after launch. Applications CEO Fidji Simo had reportedly told her team to cut back on what she called side quests, the same directive that led OpenAI to shut down its Sora video app earlier in 2026, and OpenAI framed the browser itself as, in its own words, a feature, not the destination. The capability did not vanish. Page-context question answering and summarizing moved into a ChatGPT Chrome extension, website login and file-download handling moved into the ChatGPT desktop app, and the agent that completes multi-step tasks now runs on a remote browser on OpenAI's own servers rather than as a downloadable app on yours. Practically, that means the privacy questions this section covers did not close when Atlas did. The same category of page access now sits inside whichever ChatGPT surface a person already has open.
What Perplexity Comet Can See Right Now
Comet, also Chromium-based, has been free across Windows, macOS, iOS, and Android since its platform rollout completed in early 2026. Its default design leans local: an independent review of Comet's data practices found that ordinary browsing data, the pages you visit as you visit them, is stored on your own device rather than sent to Perplexity's servers by default. What does leave the device is narrower but specific: information you type into the assistant directly, and, when you ask the assistant to do something with a task in progress, the currently open tab plus whatever browsing history is relevant to completing that task. Comet also collects standard technical telemetry, device and operating system details, crash reports, and IP address, and if sync is turned on, it can carry saved passwords, bookmarks, payment methods, and location to your account as well.
That description of what gets sent, by default, on request, was tested directly by Shivan Kaul Sahib, Brave's own VP of Privacy and Security, working independently. He found that Comet sent every URL he visited to Perplexity's servers through an autosuggest network call, carrying the visited address in a parameter named source_tab_url, and that this kept happening even after he switched off every privacy toggle available in Comet's settings and disabled the Comet Assistant entirely. No opt-out existed for it at the time, and he verified the behavior across multiple versions of the browser using direct network traffic inspection. The gap between what a product's settings claim to control and what its network traffic actually shows is exactly the kind of thing a published privacy policy will not tell you on its own.
On training, Perplexity's own stated default runs opposite to Atlas's: search and assistant query data feeds Perplexity's model training by default across its Free, Pro, and Max plans, with an AI data retention toggle in account settings available to opt out, though switching it off only stops future data from being used and does not retroactively remove data already folded into a trained model. A July 2, 2026 rewrite of Perplexity's privacy notice dropped the earlier written description of that opt-out, along with a previously stated 30-day account-deletion window and a commitment to notify users of material policy changes, according to an independent line-by-line comparison of the old and new text, even though the underlying toggle reportedly still functions inside the product. The same rewrite expanded the categories of data the policy describes collecting, including through Comet, voice, and health information tied to features that use it. None of that is presented here as proof the toggle stopped working. It is a documented change in what the company commits to in writing, which is a different thing worth knowing on its own.
Perplexity has also built a specific tool for checking this rather than digging through settings menus: Privacy Snapshot, a homepage widget launched November 3, 2025, that shows a breakdown of what Comet has collected, lets a person block the assistant from specific websites or turn it off entirely, and auto-deletes personal search queries after 30 days.
CometJacking and the Prompt Injection Findings
Brave's security team disclosed the more serious finding. Working independently in the summer of 2025, researchers found that hidden instructions embedded in an ordinary webpage, invisible white-on-white text or text buried in an HTML comment, could redirect what Comet did next without the user asking for any of it. Their proof-of-concept had Comet pull the logged-in user's account email, trigger an account recovery flow, read the resulting one-time passcode out of an open Gmail tab, and post both out to Reddit, a full account-takeover chain built entirely from words hidden on a page the user simply asked the assistant to summarize. Brave's own framing of the severity is blunt: "the AI operates with the user's full privileges across authenticated sessions," which means standard web protections like same-origin policy do nothing once an agent already has legitimate permission to act on your behalf. Brave disclosed the vulnerability to Perplexity in late July 2025, and after testing Perplexity's fix, published the full details publicly on August 20, 2025. A follow-up Brave post in October 2025 documented a further class of injection hidden inside screenshots the assistant reads rather than in visible page text, evidence that the underlying issue is architectural rather than a single patched bug.
Separately, researchers at LayerX described a related technique they named CometJacking, in which a single crafted URL, with no hidden instructions needed on the destination page itself, was enough to pull sensitive account data out of an active Comet session. Coverage of the finding reported that Perplexity characterized it as having no meaningful security impact, an assessment that sits at odds with how directly the technique targeted logged-in account data.
Atlas-Era Data Handling vs. Comet Today
| What You're Checking | ChatGPT Atlas (now inside the ChatGPT app and extension) | Perplexity Comet |
|---|---|---|
| Standalone browser status | Discontinued August 9, 2026; capability moved into the ChatGPT desktop app and Chrome extension | Active, free across Windows, macOS, iOS, and Android |
| How page content is handled by default | Summarized on OpenAI's servers; original content deleted right after summarizing | Stored locally by default; open tab and relevant browsing history sent to Perplexity's servers when the Assistant runs a task |
| Opt-in memory across sessions | Browser Memories, opt-in, retained up to 30 days for safety monitoring | Personal Search history tied to your account; independent testing found some URLs sent even with related toggles switched off |
| Used to train the underlying model by default | No, off by default; requires opting in, and Business/Enterprise content is excluded regardless | Yes, by default, through Personal Search query data, unless the AI data retention toggle is switched off in settings |
| Per-site exclusion control for sensitive pages | No dedicated per-site exclusion list; an Incognito mode is available instead | Yes: block the Assistant on specific sites, or disable it site-wide, under Settings, Privacy and Security |
| Disclosed security finding | LayerX's Tainted Memories CSRF claim (October 2025), which OpenAI disputed reproducing | Brave's indirect prompt-injection disclosure (2025) and LayerX's CometJacking finding |
What To Check Before Turning On Agent Mode
The specifics above point to a short, practical checklist rather than a single verdict, because the two products default to opposite settings on the question that matters most.
- Find the model-training toggle and check which way it defaults. Comet's Personal Search data trains Perplexity's models by default, with an opt-out in account settings; a ChatGPT browsing surface trains only if you opt in, since that default runs the other way.
- Exclude sensitive sites explicitly rather than trusting a general safety filter. Comet lets you block the Assistant on specific websites or disable it site-wide under Settings, Privacy and Security, and banking, health, and email accounts are the obvious candidates.
- Confirm what incognito or private mode actually keeps. Comet's private mode blocks third-party cookies and disables extensions by default and does not collect browsing data in that state; on the ChatGPT side, Incognito keeps browsing out of your account history, though signed-out sessions are still retained separately for 30 days for abuse detection.
- Assume any open tab the assistant can see is a tab it can read from, and potentially act on in agent mode. Close tabs you would not want considered before invoking an agent-mode task, rather than trusting it to ignore them.
- Treat the disclosed prompt-injection findings as a standing limitation of how these agents work, not a bug that got fixed and closed. Keep agent mode away from logged-in banking, health, and email sessions until a task genuinely requires it, and watch what it does while it runs instead of leaving it unattended.
Where MemX Fits
MemX (memx.app) is a different kind of tool built on a different privacy shape than either of these browsers. An AI browser, by design, sees whatever you browse while it is active, every page, by default, because that is what makes it useful as a browser. MemX only sees what you deliberately choose to save into it: a note, a document, a conversation you pick to store, not a running log of everything you have looked at today. That is a narrower, more passive kind of tool, and this is not a claim that MemX replaces an AI browser or does the same job better. It is a different job. What MemX does store is private by architecture: per-user isolation, encryption at rest backed by customer-managed keys, and on-device processing where the platform supports it, so that memory is not merged into a shared pool the way default-on training data can be. The distinction that matters here is not which product is safer in the abstract. It is that one of these tools watches by default and one of them only remembers what you point it at, and knowing which kind of tool you are using is most of what this whole checklist is about.
01Is ChatGPT Atlas still available?
No. OpenAI shut down Atlas as a standalone browser on August 9, 2026, 292 days after its October 2025 launch. Its features were redistributed: page-context question answering and summarizing moved into a ChatGPT Chrome extension, website login and file downloads moved into the ChatGPT desktop app, and multi-step agent tasks now run on a remote browser on OpenAI's own servers.
02Does Perplexity Comet send my browsing data to its servers?
By default, ordinary browsing data is stored locally on your device. What gets sent includes queries typed directly into the Assistant and, when a task is running, the current tab plus relevant browsing history. Independent testing by a security researcher also found that Comet sent every visited URL to Perplexity's servers through an autosuggest call, even with privacy toggles switched off, so the documented default and the observed network behavior are not identical.
03Does Comet or ChatGPT's browsing use my data to train their AI models?
The two run in opposite directions by default. Perplexity uses Personal Search and assistant query data to train its models by default, with an opt-out toggle in account settings. ChatGPT's browsing-derived content is not used for training unless a person opts in, and Business and Enterprise accounts are excluded from training regardless of that setting.
04What is the CometJacking or prompt injection risk with AI browsers?
Prompt injection means hidden instructions on a webpage, invisible text, an HTML comment, or text inside an image, get read by the AI agent as if they were commands from the user. Brave's security team demonstrated this against Comet in 2025, showing it could be used to extract a user's account email and a one-time passcode and exfiltrate both, and LayerX separately described a related technique called CometJacking. It is considered an unsolved, architectural limitation rather than a single patched bug.
05How do I stop an AI browser from acting on sensitive sites like my bank?
In Comet, go to Settings, Privacy and Security, and use the controls there to block the Assistant on specific websites or disable it entirely; Privacy Snapshot on the homepage offers the same controls in one place. For a ChatGPT browsing surface, keep sensitive sessions in Incognito mode, and avoid invoking agent-mode tasks while logged into banking, health, or email accounts.
