Perplexity's new Mac feature keeps your secrets on the laptop. I spent a week looking for the seam.
Hybrid Compute splits a single task between a cloud model and a smaller one running on your Mac, so sensitive files never leave the machine. The idea is good. The handoff is where it gets interesting.

Image: Apple M1 by Henriok / Wikimedia Commons, CC0 1.0 (public domain)
For a week I let Perplexity's new Hybrid Compute run errands that touched my actual files — a folder of invoices, a messy export of contacts, a draft with two names in it I would not want on anyone's server. The pitch is that the sensitive parts never leave my Mac. By Thursday I believed the pitch. I also knew exactly where it gets awkward, and it is not where the marketing thinks.
Here is the setup, because the whole feature lives in the setup. Perplexity's Computer agent normally does its thinking in the cloud, on a frontier model — the reasoning, the planning, the web search. Hybrid Compute adds a second brain that runs locally on Apple silicon. When a step in a task brushes up against something private — a name, an email, an account number, a file marked confidential — an on-device classifier flags it, and Perplexity asks whether you want to keep that slice on the Mac, mask it, or send it up to the cloud anyway. The cloud does the hard part. The laptop does the part you would rather not hand over.
It launched on September 1 for Pro, Max, and Enterprise subscribers, in the Perplexity Mac app, on Apple silicon running macOS 15 or later. The floor is 24GB of unified memory; Perplexity recommends 32GB. You pick a local model from three at launch: Google's Gemma E4B, Qwen3.6 in a 35-billion-parameter configuration, and a version of that Qwen model Perplexity fine-tuned itself. Generation on the local model does not cost you tokens. Hold onto that last detail, because it changes the math more than the privacy story does.
The good part, first, because it earns it
The classifier is the thing that makes this more than a checkbox. Most privacy features are a switch you flip once and forget, which means they protect you right up until the moment you are busy and paste the wrong thing. This one watches the actual content moving through a task and interrupts. When I pointed the agent at a folder and asked it to pull totals out of a stack of invoices, it stopped on the ones with a client's full name and bank details and asked, in effect: this looks private, do you want me to keep it here? That is the right question at the right moment, and it is a genuinely different posture from an assistant that quietly ships everything to a data center and lets you read the privacy policy afterward.
Perplexity says the classifier runs entirely on the device, inspecting content before anything is transmitted, and that it trained the thing through its Secure Intelligence Institute and open-sourced it. I cannot audit that claim from my kitchen table, and you should treat any ‘it never leaves your machine' promise as a thing to verify rather than a thing to feel good about. But the behavior I could see matched the claim: when I kept a step local, the network went quiet, and the answer still came back. Slower, plainer, but back.
Most privacy features are a switch you flip once and forget. This one watches the content moving through a task and interrupts at the exact moment you would otherwise paste the wrong thing.
There is also a nice bit of plumbing that took me a day to appreciate: the Mac does not have to be the device you start on. I kicked off a task from my phone, and because my Mac was awake and running Perplexity, the sensitive steps executed there, against my local files, while I was nowhere near the keyboard. When it works, it feels less like an app and more like your laptop quietly acting as your own private server. That is a genuinely new shape for a consumer AI tool, and I did not expect to like it as much as I did.
The seam is the handoff
Now the part the demo skips. The whole design rests on a handoff — cloud brain does the reasoning, local brain does the sensitive touch — and a handoff is exactly where these systems get human, in the bad sense. A frontier model in the cloud and a 35-billion-parameter model on your laptop are not the same instrument. One can hold a complicated multi-step plan in its head; the other is competent but literal, the way a smart intern is competent but literal. When a task crossed the line into local territory and stayed there for a few steps, I could feel the drop. The reasoning got shallower. It followed instructions more than it understood them.
Most of the time that is fine, because the sensitive step is usually small — redact this, total that, rewrite this line without the name. But a few times the private data was not a footnote to the task; it was the task. Reconciling a contact list where every row is personal means the local model is doing the heavy lifting on the hard part, and that is precisely the configuration Hybrid Compute is worst at. The cloud model, the good one, is standing on the other side of a wall it is not allowed to see over. You end up choosing between a smart model that sees your data and a less-smart model that protects it, which is an honest tradeoff, but it is a tradeoff, and no amount of clever routing dissolves it.
The masking option is the interesting middle path, and also the one I trusted least. Handing the cloud a version of your data with the names swapped out sounds ideal — full-strength reasoning, no exposure. In practice, masking well is hard. Strip too little and you have not protected anything; strip too much and the cloud model is now reasoning about a document full of holes and guessing at what the holes meant. It worked cleanly on structured stuff, like a spreadsheet where a column is obviously an email address. It got shakier on free text, where the sensitive thing is tangled into the meaning of the sentence. I would not lean on masking for anything where being wrong actually costs you.
The hardware asks a real question of you
The 24GB floor is not a suggestion, and the 32GB recommendation is closer to the truth. A 35-billion-parameter model living in unified memory alongside everything else your Mac is doing is a real tenant. On a machine near the minimum, keeping a local model warm means it is holding memory your other apps want, and you feel it — not in the AI, but in everything around it. This is a feature that quietly assumes you bought, or will buy, a fairly serious Mac. If you are on a 16GB machine, this is not for you yet, and no update is going to argue with the physics of how much model fits in how much memory.
The cost angle is the one I did not expect to matter and did. Local generation does not spend tokens. If you are a heavy user, that is not a privacy nicety — it is a bill. Offloading the grunt work of a long task onto your own silicon means the pricey frontier model only gets called for the parts that need it, and over a week of real use I could see how that adds up for someone running the agent all day. Perplexity is, in effect, letting you pay for some of your inference in electricity and RAM instead of subscription credits. Whether that is a good deal depends entirely on how much you use it and how much Mac you already own.
So who is it for
After a week, my read is narrow and specific, which is usually the honest kind:
- Buy in if you have a 32GB-or-more Apple silicon Mac and you regularly ask an AI to touch files you genuinely would not paste into a public chatbot — client records, financials, anything under a confidentiality obligation. This is the first mainstream tool that treats that instinct as a feature instead of a warning label.
- Buy in if you are a heavy Computer user and the token savings from offloading local work are real money to you. The privacy is the headline; the economics may be the reason you keep it.
- Wait if you are on a 16GB Mac or anything without Apple silicon. The requirements are load-bearing, not marketing, and the experience below them is not the experience being sold.
- Wait if your work with the agent is mostly casual and cloud-safe anyway. If nothing you do would embarrass you on a server, you are paying a complexity tax — the prompts, the choices, the slower local steps — for a protection you do not need.
Here is the plain verdict. Hybrid Compute is the first time a consumer AI tool has taken the on-device privacy pitch and actually shipped the awkward, expensive machinery it requires, instead of gesturing at it. The classifier is smart, the local fallback is real, and the phone-to-Mac handoff points at something genuinely new. It also cannot repeal the tradeoff at its center: the model that protects your data is not the model that is best at using it, and every task that lives in the sensitive lane pays for the protection in capability. That is not a flaw Perplexity can patch. It is the deal. The feature's real achievement is making the deal visible, and letting you take it one step at a time instead of all at once. On my subscriptions ledger, this one stays — which, for a privacy feature I went in expecting to cancel by Friday, is the highest grade I give.
References
- Engadget — Perplexity's Hybrid Compute splits sensitive tasks between cloud and local AI
- 9to5Mac — Perplexity launches privacy-minded 'hybrid compute' AI feature for Mac
- MacStories — Perplexity introduces Hybrid Compute to keep sensitive data local
- The New Stack — Your Mac is now part of Perplexity's AI infrastructure
- Perplexity — Hybrid Compute on Mac (product hub)


