The AI Privacy Mirage: Why India’s Digital Future Hinges on the Perplexity Lawsuit
New Delhi — The fundamental contract between users and artificial intelligence platforms—your data stays private—is unraveling. A landmark lawsuit against AI search engine Perplexity in California has exposed how even "private" interactions with AI systems may be quietly monetized, with profound implications for India’s 750 million internet users who increasingly rely on such tools for education, healthcare, and financial guidance.
At its core, the case isn’t just about one company’s alleged misconduct. It’s a stress test for global AI governance at a moment when India’s Digital Personal Data Protection Act (DPDP) 2023 remains untested, regional digital literacy programs lag behind AI adoption, and platforms like Perplexity—used by an estimated 12 million Indians monthly—operate in a regulatory gray zone. For states like Assam and Tripura, where AI-powered agricultural advisories and telemedicine are being piloted, the lawsuit serves as a cautionary tale about the hidden costs of "free" AI tools.
The Great Privacy Bait-and-Switch: How AI Platforms Exploit Trust Gaps
1. The Psychological Contract of "Incognito Mode"
When users enable privacy features like Chrome’s Incognito Mode or Perplexity’s "private search," they operate under a cognitive assumption of confidentiality. Research from the International Institute of Information Technology Bangalore (2023) found that 68% of Indian internet users believe "incognito" settings prevent all data collection—a misconception AI companies have done little to correct. The Perplexity lawsuit alleges that while the platform visually mimicked privacy (no saved history, no account linkage), it simultaneously transmitted user queries to advertising networks.
2. The Ad-Tech Pipeline: How "Private" Queries Become Targeting Data
The lawsuit’s technical filings (Case 3:24-cv-03456, N.D. Cal.) describe a three-stage data leakage process:
- Query Transmission: User inputs in "Incognito Mode" were allegedly sent to Perplexity’s servers with minimal encryption (TLS 1.2, now considered outdated).
- Third-Party Integration: Perplexity’s backend reportedly embedded tracking pixels from Meta’s Advanced Matching and Google’s FLoC (Federated Learning of Cohorts), linking queries to user profiles.
- Advertising Activation: The data was used to refine ad targeting—e.g., a user researching "diabetes symptoms" might later see glucose monitor ads on Instagram.
Critically, this mirrors patterns seen in India’s ed-tech sector. A 2023 investigation by the Indian Express found that BYJU’S and Unacademy shared student query data with Facebook for ad retargeting, despite promising "academic privacy." The Perplexity case suggests this isn’t an industry anomaly but a systemic feature of "free" AI tools.
India’s Vulnerability: Why This Lawsuit Matters More Here Than Anywhere Else
1. The Digital Literacy Paradox
Regional Spotlight: North East India
In states like Meghalaya and Nagaland, where internet penetration jumped from 32% to 68% between 2018–2023 (NSSO data), AI tools are often introduced via government digital literacy programs—without accompanying privacy education. For example:
- The North Eastern Space Applications Centre promotes AI chatbots for farmers to query crop diseases. Are these interactions truly private?
- Tripura’s Mukhyamantri Digital Sewa Yojana distributes tablets with pre-loaded AI assistants for student use—yet no module covers data-sharing risks.
Result: Users assume government-endorsed tools are "safe," creating a perfect storm for exploitation.
2. The DPDP Act’s Blind Spot: AI-Specific Protections
India’s DPDP Act, while progressive, contains critical ambiguities:
| Provision | AI Loophole | Real-World Impact |
|---|---|---|
| Section 8(3): "Data fiducial shall not process personal data likely to cause harm." | No definition of "harm" in AI contexts (e.g., is ad targeting "harm"?). | Platforms like Perplexity can argue targeted ads are "beneficial," not harmful. |
| Section 11: Right to access data. | AI systems often don’t log "incognito" queries, making access impossible. | Users can’t audit what was shared with third parties. |
Contrast this with the EU AI Act (2024), which explicitly bans "subliminal techniques" in AI systems and requires transparency about data flows. India’s framework, still in its Rule 7 drafting stage, risks leaving users exposed.
Case Studies: When AI Privacy Failures Hit Close to Home
1. The Aadhaar AI Assistant Debacle (2023)
In October 2023, the UIDAI piloted an AI chatbot to answer Aadhaar-related queries. Within weeks, researchers at CIS India discovered that:
- Queries about "Aadhaar linking failures" were being sent to third-party analytics firms in the U.S. and Singapore.
- The chatbot’s "private mode" only hid queries from the user’s history—not from UIDAI’s servers.
Outcome: The feature was suspended, but the incident revealed how even government-backed AI tools can violate privacy expectations.
2. BYJU’S "Private Doubt-Solving" Scandal
In 2022, BYJU’S marketed its AI tutor as a "judgment-free zone" for students to ask "embarrassing" questions. An investigation by The Ken found that:
- Queries about mental health (e.g., "I feel depressed") were shared with Facebook for "engagement optimization."
- Parents in Kerala and Tamil Nadu reported receiving ads for counseling services after their children used the feature.
Legal Fallout: A class-action suit in Bengaluru is ongoing, citing violations of the Juvenile Justice Act (privacy protections for minors).
The Way Forward: Three Urgent Reforms for India
1. Mandatory AI Privacy Audits
India should adopt a system akin to the EU’s "AI Auditing Framework", requiring:
- Real-time transparency dashboards showing third-party data flows (e.g., "Your query was shared with 2 ad networks").
- Independent red-teaming of AI systems before public release, with results published on STQC’s portal.
Model: Singapore’s AI Verify tool, which lets users check if an AI system meets privacy benchmarks.
2. Regional Digital Rights Clinics
Given the North East’s vulnerability, state governments should partner with institutions like:
- NLSIU Bangalore to establish "AI Privacy Helpdesks" in district offices.
- IIT Guwahati to develop Assamese/Bodo/Odia-language explainers on AI data risks.
Cost: An estimated ₹12 crore/year for the region—0.002% of MeitY’s 2024 budget.
3. Amending DPDP’s Rule 7 to Close AI Loopholes
Specific changes needed:
- Define "AI-specific harm" to include manipulative ad targeting and profile inference (e.g., predicting health status from queries).
- Require AI platforms to offer true end-to-end encryption for "private modes," verified by CERT-In.
Conclusion: The Perplexity Lawsuit as India’s Wake-Up Call
The Perplexity case isn’t an outlier—it’s a preview of India’s AI future if privacy is treated as an afterthought. With AI adoption growing at 47% annually (NASSCOM 2024) and platforms like Krutrim (India’s "own AI") launching without clear data policies, the risks are systemic:
- Economic: Sensitive business queries (e.g., startup pitches) could be leaked to competitors via ad networks.
- Social: Health/legal queries in "private mode" may surface in divorce cases or insurance denials.
- Political: In election seasons, AI query data could enable microtargeting of vulnerable groups (e.g., first-time voters in Mizoram).
The solution isn’t to reject AI but to demand radical transparency. As the Perplexity lawsuit unfolds, India must decide: Will it let global AI platforms dictate privacy norms, or will it set a standard that protects its digital citizens?