---
title: What is zero data retention AI?
description: Zero data retention AI means the model provider keeps no prompts or outputs after a response. See what ZDR covers, its exceptions, and how to check it.
canonical: https://privatesuperintelligence.si/guides/zero-data-retention-ai/
last-updated: 2026-10-07
---

# What is zero data retention AI?

Zero data retention (ZDR) AI is an arrangement in which the model provider does not store your prompts or the model's responses at rest once the response is returned to you. Providers offer it to approved business customers, and it changes how abuse monitoring, stored conversation state, and some tools behave. ZDR governs the provider's model endpoint, so files, logs, and apps around that endpoint need their own controls.

Box CEO Aaron Levie argued on X in August 2026 that ZDR drove a large share of enterprise AI adoption, because it simplified the compliance review companies run on subprocessors that handle their data. He added that many companies have internal governance rules that permit ZDR models and nothing else.

## What zero data retention covers and what it does not

Each provider defines ZDR in its own terms, but the published documentation lines up on several points.

| Covered in most ZDR terms | Outside most ZDR terms |
| --- | --- |
| Prompts and outputs on eligible inference endpoints (for example, Anthropic's Messages API, OpenAI's Responses and Chat Completions APIs) | Stateful features that store data by design: files, batch jobs, vector stores, assistants and threads, fine-tuning |
| Exclusion from the provider's standard abuse monitoring logs | Content flagged by automated safety systems, or data held under a legal requirement |
| Short-lived in-memory processing, such as prompt caching, that does not write content to durable storage | Consumer chat apps and some web consoles and playgrounds |
| A training restriction (separate from ZDR, but published by each provider listed below) | Third-party tools, websites, and integrations your application calls |

Anthropic states that even with ZDR in place, it may retain inputs and outputs for up to two years if automated trust and safety systems flag a chat or session, and may retain data where the law requires it. OpenAI notes that its default abuse monitoring logs are kept for up to 30 days, unless longer retention is required by law, and that ZDR removes customer content from those logs.

## How major providers offer zero data retention

| Provider | How to get it | Notable exceptions |
| --- | --- | --- |
| OpenAI API | Approval from OpenAI; contact the sales team. Modified Abuse Monitoring is a second, related option | Not eligible: Assistants, Threads, Vector Stores, Conversations, Agents, Fine-tuning, Files, Batches, Evals, and Realtime sessions. Under ZDR, the `store` parameter is treated as false |
| Anthropic Claude API | Request through Anthropic sales. Enabled per organization, and each new organization needs its own enablement | Not covered: Claude Console, Managed Agents, consumer plans, Batch processing (29-day retention), Files API, code execution (container data up to 30 days), and some newer models that require 30-day retention |
| Amazon Bedrock | Set `data_retention_mode` to `none` at the account or project level in each Region; enforce it with IAM or Service Control Policies | Models that require retention for safety become unavailable under `none`. ZDR on those models is evaluated per account and per model; for Claude models, Anthropic manages eligibility |
| Google Gemini Enterprise Agent Platform (previously Vertex AI) | Request an exception for abuse-monitoring prompt logging, leave request-response logging off, and set `store = false` on the Interactions API | Grounding with Google Search keeps query logs for up to three days, and Grounding with Google Maps keeps data for 30 days; neither can be disabled. Deep Research keeps session data for seven days |
| Microsoft Foundry (Azure OpenAI) | Apply for modified abuse monitoring under Limited Access eligibility criteria; verify with the `ContentLogging` attribute set to false | The Responses API, Assistants threads, stored completions, files, and batch jobs store data in your Azure tenant until you delete it. Automated abuse review still runs |

Two details deserve attention. Amazon Bedrock models are deployed in AWS-owned accounts that model providers cannot access, so the providers never see your prompts or completions. Google keeps Gemini inputs and outputs in an in-memory cache with a 24-hour TTL by default; Google says this cache does not violate zero data retention, and a project administrator can disable it.

## What retention means beyond the model

A ZDR contract with your model provider says nothing about the rest of your AI system. Retention happens at every hop where data lands.

- **Application logs.** Your own servers, observability tools, and error trackers often capture full prompts and responses. Google's request-response logging, for example, writes them to a BigQuery table if you turn it on.
- **Vector stores and indexes.** Retrieval systems keep embeddings and source chunks of your documents for as long as the index exists. OpenAI lists vector stores as ineligible for ZDR.
- **Files and conversation state.** Uploaded files, threads, and stored responses persist until you delete them or they expire.
- **Backups.** Database snapshots and disaster-recovery copies can hold data long after the live record is gone.
- **Connected apps.** Email, calendar, CRM, and document integrations keep their own copies under their own policies. Anthropic's documentation states that data processed by third-party integrations falls outside its ZDR arrangement.
- **Agents that browse and act.** An agent that searches the web, runs code, or calls external tools sends fragments of your request to each service it touches. Anthropic's code execution keeps container data for up to 30 days, and Google's Search grounding keeps query logs for up to three days.

## A checklist for buyers

Use these questions when you evaluate any vendor that claims zero data retention.

1. Which endpoints and features does the ZDR agreement name, and which does it exclude?
2. Does the vendor hold ZDR with every model provider it routes to, including fallback models?
3. What happens to content flagged by safety systems, and for how long is it kept?
4. Can you verify the setting yourself, through a console attribute, an API, or a policy you control?
5. Where do application logs, traces, and analytics events go, and what do they contain?
6. How long do vector stores, file stores, and backups keep your data, and who can delete it?
7. Which third-party tools and connected apps can the system call, and what are their retention terms?
8. Is your data excluded from training at every layer, in writing?
9. Does a newer or more capable model change the terms? Some current models on Anthropic and Bedrock require 30-day retention.

## ZDR is one layer of privacy

Zero data retention at the model is a strong control, and it protects one layer. A complete answer to "where does my data live" covers retention, communication, access, inference, storage, and deployment together. That is the idea behind [private superintelligence](/what-is-private-superintelligence/): privacy designed across the full stack, so the concierge, its memory, and its tools follow the same rules as the model.

Private SuperIntelligence from Mitosis Labs is an AI concierge for enterprises, family offices, and private clients, built on six privacy layers: retention and deletion, communication, access and actions, model inference, data storage, and deployment. The provider retains nothing and trains on nothing. Intake is limited, and the current intake is fully subscribed; you can [register interest](/#waitlist) for the next one.

## Frequently asked questions

### What is zero data retention in AI?

Zero data retention means the AI provider does not store your prompts or the model's outputs at rest after it returns a response. It applies to eligible endpoints and features, and providers grant it to approved business customers.

### Does zero data retention mean nothing is ever stored?

No. Providers may keep content flagged by safety systems or data the law requires them to hold, and stateful features such as files, batch jobs, and vector stores sit outside ZDR. Anthropic, for example, may keep flagged inputs and outputs for up to two years.

### How do I get ZDR from OpenAI or Anthropic?

Both require approval. OpenAI directs customers to its sales team, and Anthropic enables ZDR per organization through its account team.

### Is ZDR the same as not training on my data?

The two are separate commitments. OpenAI, Anthropic, Microsoft, and Google each state that they do not train models on business API data without permission, while ZDR addresses whether the content is stored at all.

### Can an AI agent have zero data retention?

An agent can use a ZDR model, but its memory, tool calls, browsing, and connected apps each keep data under their own terms. Anthropic lists its Managed Agents as outside ZDR because session transcripts persist until you delete them.


## Related guides

- [Is ChatGPT safe for confidential information?](/guides/is-chatgpt-safe-for-confidential-information/)
- [How to keep company data private when using AI](/guides/keep-company-data-private-with-ai/)
- [Private AI for family offices](/guides/private-ai-for-family-offices/)
- [Private AI vs public AI](/guides/private-ai-vs-public-ai/)
- [What is private superintelligence?](/what-is-private-superintelligence/)

## Sources

- [Data controls in the OpenAI platform (OpenAI)](https://developers.openai.com/api/docs/guides/your-data)
- [API and data retention (Anthropic)](https://platform.claude.com/docs/en/manage-claude/api-and-data-retention)
- [Data retention (Amazon Web Services, Amazon Bedrock User Guide)](https://docs.aws.amazon.com/bedrock/latest/userguide/data-retention.html)
- [Data protection (Amazon Web Services, Amazon Bedrock User Guide)](https://docs.aws.amazon.com/bedrock/latest/userguide/data-protection.html)
- [Gemini Enterprise Agent Platform and zero data retention (Google Cloud)](https://docs.cloud.google.com/vertex-ai/generative-ai/docs/vertex-ai-zero-data-retention)
- [Data, privacy, and security for Foundry Models sold by Azure (Microsoft Learn)](https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy)
- [Foundry Models sold by Azure abuse monitoring (Microsoft Learn)](https://learn.microsoft.com/en-us/azure/ai-foundry/openai/concepts/abuse-monitoring)
- [Aaron Levie on ZDR and AI adoption (X)](https://x.com/levie/status/2091909170308296950)
