Zero Data Retention: What It Means When You Choose an AI Tool

Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Zero Data Retention: What It Means When You Choose an AI Tool.
Coding Liquids tutorial cover featuring Sagnik Bhattacharya for Zero Data Retention: What It Means When You Choose an AI Tool.

Zero data retention (ZDR) means the AI model provider deletes your prompts and its replies once the response is returned, keeping no conversation copy and no abuse-monitoring log. It's an approved arrangement on API and enterprise contracts, not a setting on a $20 plan, and it binds the model provider only, not the app built on top of it.

The label has two catches in 2026. Providers keep exceptions: Anthropic still stores its safety-classifier results under ZDR, and since 9 June 2026 it keeps prompts and outputs on its most capable "covered" models for 30 days even for ZDR customers, with a by-application route back added in September. And an app vendor that has ZDR with its model supplier can still keep every transcript in its own database.

Follow me on Instagram@sagnikteaches

What a zero-retention arrangement actually switches off

Start with what normally happens when software sends text to a model provider's API, which is how most AI features inside business apps work. Three kinds of copy can be created:

Connect on LinkedInSagnik Bhattacharya
  • Abuse-monitoring logs. The provider keeps prompts and responses for a limited time so its safety systems can spot misuse. On OpenAI's API that is up to 30 days by default. Anthropic's privacy pages say API inputs and outputs are deleted from its back end within 30 days, with exceptions such as policy violations.
  • Application state. Some features store data because the feature needs it: saved conversation threads, uploaded files, search indexes built from your documents. These last until they are deleted.
  • Training data. Not on business APIs by default. OpenAI says API data hasn't been used for training since 1 March 2023 unless a customer opts in, and Anthropic says it has never trained on enterprise data without explicit permission.

ZDR removes the first kind and restricts the second. On OpenAI's platform, approved customers have their content excluded from abuse-monitoring logs, and the store option on the main text endpoints is always treated as off. Endpoints that exist to hold state, such as stored conversations, assistants, threads and vector stores, aren't ZDR-eligible and can still keep data even when ZDR is on. The before-and-after in an automation's request looks like this:

Subscribe on YouTube@codingliquids
Before (default):
  { "model": "gpt-6-luna",
    "store": true,
    "input": "Summarise this service report: ..." }

After (ZDR approved for the project):
  { "model": "gpt-6-luna",
    "store": false,
    "input": "Summarise this service report: ..." }
  # Under ZDR OpenAI treats store as false even if a
  # developer leaves it set to true.

That single flag is why a developer's word matters as much as a sales page. A tool can hold a genuine ZDR approval and still route some requests through a feature that keeps state. OpenAI's data controls guide lists which endpoints are eligible, and it's worth asking any vendor to name the ones it uses.

Five privacy labels that get mistaken for zero retention

Vendor pages mix several different promises, and only one of them means "nothing kept". This table separates them.

Label you'll seeWhat it really meansWhere it usually appears
"We don't train on your data"Content isn't used to improve models. It can still be stored for weeks, or indefinitely as chat history.Business plans of ChatGPT, Claude, Copilot and Gemini in Workspace; OpenAI's API by default
Temporary or incognito chatHidden from your history, but kept briefly for safety: ChatGPT may keep a temporary chat for up to 30 days, Gemini's temporary chats up to 72 hours.Chat apps, including free plans
Custom retention periodAn admin decides how long chats persist. Claude Enterprise's minimum is 30 days; ChatGPT Enterprise policies can be indefinite or time-bound.Enterprise chat plans
Data residencyWhere data is stored, not how long it's kept.Business and enterprise plans
Zero data retentionThe provider stores no inputs or outputs after responding, with stated exceptions.API and enterprise contracts, after approval

The mix-up that happens most often is the second row. An illustrative cleaning company owner switches on ChatGPT's temporary chat before pasting in a list of clients' door codes, believing that means "never stored". OpenAI's retention page says a temporary chat may be kept for up to 30 days for safety purposes. The honest version of the belief is "not in my history, but on OpenAI's systems for up to a month", which is a different decision about door codes. The better fix is that door codes never go into a chat tool at all, and the tutorial on stopping AI tools from training on your business data covers the settings that sit alongside that habit.

A sixth label is new this year: customer-held safety logs. OpenAI's Private Safety Processing and Anthropic's Enterprise Frontier Safeguards both let large customers keep monitoring data in their own cloud storage rather than the provider's. They matter to banks and hospitals more than to a ten-person firm, but you may see them quoted in vendor security pages.

Where OpenAI, Anthropic and Google draw the lines

OpenAI

ZDR and a lighter option called Modified Abuse Monitoring are, in OpenAI's words, "subject to prior approval by OpenAI and acceptance of additional requirements", and you ask through its sales team. Once approved, a Data Retention tab appears in the organisation's data controls, where ZDR can be set for the whole organisation or project by project. OpenAI also reserves the right to make particular models ineligible for particular customers, with written notice in advance. Inside ChatGPT itself, the controls you'll meet are retention policies on Enterprise workspaces and temporary chat for individuals, not ZDR.

Anthropic

ZDR covers the Claude API and Claude Code on Enterprise plans, reviewed organisation by organisation. Even then Anthropic keeps its safety-classifier results to enforce its usage policy, and customers can confirm ZDR under the Data retention period entry in their privacy controls. The bigger change is the covered-models rule: since 9 June 2026, prompts and outputs on Mythos-class models, which include Claude Fable 5 and 5.1, are kept for 30 days for safety work on every platform that offers them, as Anthropic's covered-models retention page explains. Other Claude models are unaffected. After pushback, Anthropic announced Enterprise Frontier Safeguards on 1 September 2026: monitoring data held in the customer's own cloud storage, rolling out in phases, with eligible customers given ZDR on Fable 5 and 5.1 in the meantime. It isn't automatic: eligibility is decided customer by customer.

Google

On Google Cloud's AI platform, zero retention is something you assemble rather than receive. Google's documentation lists the steps: request an exception from prompt logging for abuse monitoring if you're in scope, leave request-and-response logging off, set store to false on the Interactions API (it defaults to true), and avoid Grounding with Google Search, which keeps logs with no way to switch them off. It also warns that zero retention may not be possible with some advanced features.

Microsoft sits slightly apart. It says Microsoft 365 Copilot services have opted out of the abuse monitoring, including human review, that its Azure platform otherwise offers. Copilot still keeps your prompts and responses as activity history inside your tenant, so it isn't ZDR, but Microsoft staff aren't reviewing flagged prompts as part of abuse monitoring.

Two phone-answering quotes for an HVAC installer, compared

This is where the label gets tested. An illustrative HVAC installer with six engineers and two office staff takes about 400 calls a month, most of them breakdowns and service bookings. It shortlists two AI receptionist services at similar monthly prices.

  • Vendor A advertises "zero data retention with our AI provider". Asked in writing, it confirms that it records every call and keeps recordings and transcripts in its own system for 12 months.
  • Vendor B has no ZDR. Its model provider keeps abuse-monitoring logs for up to 30 days, and B keeps transcripts for 30 days by default, with call recording switched off unless the customer turns it on.

Now count what sits on someone else's servers at any one time once each service has been running a year:

Copies heldVendor A (ZDR label)Vendor B (no ZDR)
At the app vendor4,800 recordings + 4,800 transcripts (400 x 12)About 400 transcripts (one month)
At the model providerNoneUp to about 400 in 30-day safety logs
TotalAbout 9,600 itemsAbout 800 items

Vendor B, without the label, holds roughly a twelfth of what Vendor A does. The ZDR claim was true and nearly irrelevant, because the app layer was where the data piled up. The installer chose B, got the 30-day transcript setting confirmed in writing, and asked to be told before B changed model provider. If you're weighing these services on cost as well, what an AI receptionist costs a trades business sets out the pricing models.

Questions that show what a ZDR claim covers

When a vendor mentions zero retention, these questions turn the claim into something you can check:

  1. Which model provider is the agreement with, and does it cover every model you use for our account?
  2. Are any of those models on the provider's list of exceptions, such as Anthropic's covered models?
  3. Which endpoints or features do you call? Do any of them store conversations, files or search indexes?
  4. What do you store yourselves, for how long, and can we shorten it?
  5. Do you use web search or grounding features that keep their own logs?
  6. Can you show the provider's confirmation, such as a screenshot of the retention setting or the relevant contract clause?

A typical first answer, illustrative but very familiar: "We have a zero-data-retention agreement with our AI partner, so your data is never stored." Put it against the list and it answers half of question 1. "Never stored" is also untrue on its face if the product shows you past conversations. A good follow-up is short: "Thanks. Which provider and models does that cover, and how long do you keep transcripts on your side?" A vendor that knows its own architecture replies with specifics. One that doesn't will often come back with more adjectives.

What you give up when nothing is kept

Zero retention isn't free, even when it costs nothing extra. The provider can't hold conversation state for you, so the software has to manage history itself. Features built on stored data, such as file search over uploaded documents, may be unavailable. And when something goes wrong, there is no provider-side record to look at.

That last point catches people out. An illustrative landscaper's quoting automation sends each site-visit note to a model and emails the client a draft price. After a week of odd quotes, including a lawn job priced at ten times the usual rate, nobody can see what the model returned because the automation logged nothing and the provider kept nothing. The fix was a short, redacted log on the business's own side:

Before (no log):
  [nothing recorded]

After (own log, kept 14 days, names stripped):
  2026-09-18 10:42  job=Q-2291  model=gpt-6-luna
  input_words=184  output="Lawn renovation, 450 m2 ... total 6,750"
  flag=price_above_3x_median  sent=no (held for review)

With ZDR at the provider, your own logs become the only record. Keep them short-lived, strip names, and treat them with the same care you wanted from the vendor. The build-side costs of automations like this are covered in what the ChatGPT API costs for a business automation.

How a model upgrade can quietly end zero retention

ZDR is tied to models and settings, and both change. The June 2026 covered-models rule is the clearest example: a vendor that moved its product to Claude Fable 5 for better answers also moved its customers' prompts into a 30-day retention window, whatever its sales page still said. OpenAI's terms allow a similar change for specific models, with advance notice to the approved customer, and that customer is usually the vendor rather than you.

So put a re-check in the calendar rather than trusting a one-off answer:

  • Ask vendors to tell you in writing before they change model provider or model family, and put that in the order form if they'll agree to it.
  • Every six months, re-send questions 1, 2 and 4 from the list above. It takes five minutes, and the answers change more often than you'd expect.
  • If you run your own API automations, look at the retention entry in the provider's console after every model change. Anthropic shows it as the Data retention period in privacy controls; OpenAI shows approved controls on its Data Retention tab.
  • Anthropic's June change applied to its most capable class of models, so new top-tier releases are the ones to check first when a vendor announces an upgrade.

Does a small business need ZDR at all?

Most don't. For the common jobs, such as drafting emails, summarising notes or answering routine enquiries, a business plan that doesn't train on your content, a short retention setting and a firm rule about what never goes in will protect you more than a contract clause you'd struggle to verify. ZDR starts to earn its place in three situations:

  • You are building your own automation on an API and it handles sensitive client material at volume.
  • A client contract requires that subprocessors keep no copies.
  • Your sector's rules restrict who may hold the data at all, even briefly.

A quick sum shows where the effort belongs. An illustrative roofing contractor sends about 150 insurance-claim reports a month through an API automation, each around 3,000 tokens of input and 800 tokens of output (roughly 2,250 and 600 words), so about 450,000 input and 120,000 output tokens a month. On Claude Sonnet 5 at $2 per million input tokens and $10 per million output tokens, that is about $0.90 plus $1.20, so around $2.10 a month; on Claude Opus 5.5 at $4 and $20 it's about $4.20. The model bill is trivial either way. The retention question isn't: if the contractor picked a covered Fable-class model, around 150 reports would sit in Anthropic's 30-day safety store at any time, whereas a non-covered model under an approved ZDR agreement would leave no prompts or outputs on file. Model choice is a privacy decision as well as a cost one.

Before signing anything, a locksmith choosing a booking chatbot might fill in a one-page check like this (illustrative answers):

ZERO-RETENTION CHECK: booking chatbot           Date: [date]

Model provider named?               Yes - named in DPA annex
Models used for our account?        Two; neither on exception lists
ZDR confirmed in writing?           Yes - contract clause 7.3
Features that store data?           Conversation history (vendor side)
Vendor keeps transcripts for:       90 days, can set 30
Web search or grounding used?       No
Customer data we will never enter:  key codes, alarm codes,
                                    "away until" dates
Decision:                           Proceed, set 30 days,
                                    review in 6 months

The last three lines do most of the work. Whatever the contract says, a locksmith's key and alarm codes never go into the chatbot, and a 30-day transcript setting limits what any breach could expose. The ZDR clause is a useful extra, not the foundation. For the wider picture of what each tool stores and where, see where your data is stored when you use AI tools.

Further reads

Sources: OpenAI API guide (Data controls in the OpenAI platform) and help pages on chat and file retention; Anthropic privacy pages (Data retention practices for Covered Models; zero data retention agreements; organisation data retention; custom retention for Enterprise); Anthropic announcement of Enterprise Frontier Safeguards (1 Sep 2026); Google Cloud documentation on zero data retention; Microsoft Learn (Data, Privacy, and Security for Microsoft Copilot). Checked September 2026.

Not sure what your AI vendors actually keep?

On a 1:1 call we'll go through the tools and automations you use, work out what each one stores and for how long, and decide whether zero retention is worth pursuing or a simpler setting does the job.

Book a 1:1 call with me