Every prompt your employees send to an AI model is a disclosure. It may contain customer records, source code, deal terms, health information, or privileged legal analysis, and the moment it leaves your network, a new question attaches to it: how long does the model provider keep it, who can access it, and what happens if a regulator, litigant, or attacker comes looking? Zero data retention, often shortened to ZDR, has emerged as the gold-standard answer to that question, and it is rapidly becoming a line item in vendor security reviews, DPA negotiations, and AI governance frameworks. This guide explains what zero data retention actually means, how the major AI providers implement it, and how to build a defensible zero data retention framework inside a broader privacy program.
A note before the vendor sections: retention terms in the AI market change faster than almost any other category of vendor policy, and providers frequently distinguish between consumer products, standard API tiers, and negotiated enterprise agreements. Treat the descriptions below as a map of how these programs are structured, and verify the current terms and eligibility requirements directly with each provider before relying on them in a compliance assessment.
If you need help with guardrails and AI Governance as well as data privacy measures Captain Compliance is the solution for organizations large to small figuring out how to responsibly handle the convergence AI and data.
Zero Data Retention AI: What It Means and Why It Matters
Zero data retention is a contractual and technical commitment that an AI provider will not store the content of your prompts and the model’s outputs after the request is processed. Inputs are held in memory only as long as needed to generate a response, then discarded. Nothing is written to persistent logs, nothing is available to provider employees after the fact, and nothing accumulates in a store that could later be breached, subpoenaed, or repurposed for training.
ZDR is distinct from two commitments it is often confused with:
- No-training commitments promise your data will not be used to improve the model, but the provider may still retain prompts for 30 days or longer for abuse monitoring, debugging, or legal compliance
- Data residency commitments control where data is stored, not whether it is stored at all
The distinction stopped being academic in 2025, when a federal magistrate judge in the New York Times copyright litigation ordered OpenAI to preserve output logs that would ordinarily have been deleted, including conversations users had deleted themselves. Customers on true zero data retention endpoints were carved out of that preservation obligation for a simple reason: there was nothing to preserve. That episode taught enterprise counsel a lesson that now drives procurement, which is that data a vendor never stores cannot be swept into someone else’s lawsuit, breached in someone else’s incident, or produced in someone else’s investigation.
The regulatory logic points the same direction. GDPR’s storage limitation principle in Article 5(1)(e) requires that personal data be kept no longer than necessary. The CPRA obligates businesses to disclose retention periods for each category of personal information at collection and prohibits keeping data longer than reasonably necessary. Italy’s data protection authority fined OpenAI 15 million euros in late 2024 in a case that turned substantially on transparency and legal basis for data handling in ChatGPT. Minimizing what your AI vendors retain is the cleanest way to shrink all of those exposures at once.
Zero Data Retention OpenAI Policy
OpenAI’s retention architecture differs sharply across its product lines, which is exactly why the phrase “we use OpenAI” tells a compliance team almost nothing.
For the API platform, OpenAI’s standard practice has been to retain API inputs and outputs for up to 30 days for abuse and misuse monitoring, then delete them, with business data not used for training by default. Zero data retention is available as a negotiated arrangement for qualifying customers on eligible endpoints, under which prompts and completions are not persisted at all. ZDR eligibility typically involves a trust and safety review, applies to specific endpoints rather than the entire platform, and can be incompatible with features that inherently require storage, such as file uploads, assistants-style threads, or batch processing. Enterprises handling regulated data should get the ZDR designation, the covered endpoints, and the excluded features in writing in the services agreement.
Zero Data Retention for ChatGPT
ChatGPT is a different animal from the API. The consumer product retains conversation history by default, and even deleted conversations have historically persisted for a wind-down period. Consumer chats may be used to improve models unless the user opts out, and temporary chat modes still involve short-term retention for safety purposes. ChatGPT Enterprise, Business, and Edu tiers commit that customer content is not used for training and give workspace admins retention controls, but admin-configurable retention is not the same thing as zero retention. The compliance takeaway is blunt: employees pasting sensitive data into a personal ChatGPT account are creating a retained, potentially discoverable record outside your control, which is why unsanctioned AI use belongs in every data inventory and acceptable use policy.
Zero Data Retention Anthropic Policy
Anthropic’s enterprise posture follows a similar two-track structure. Commercial API customers’ inputs and outputs are not used to train models by default, and standard API retention runs on a limited deletion cycle, with Anthropic offering zero data retention agreements to qualifying enterprise customers through its sales organization. Under a ZDR arrangement, prompts and outputs from covered API traffic are not persisted after processing, subject to carve-outs that customers should scrutinize, such as trust and safety flags, features that require storage to function, and any separately stored operational metadata.
Zero Data Retention for Claude
On the consumer side, Claude’s retention terms shifted notably in late 2025, when Anthropic began asking consumer users to choose whether their chats could be used for model training, with materially longer retention for users who opt in. Claude for Work and API-based deployments sit under the commercial terms rather than the consumer ones. As with OpenAI, the same brand name spans very different retention realities, so governance teams should document which Claude surface each business unit actually uses, because “Claude” via a personal account, “Claude” via an enterprise workspace, and “Claude” via a ZDR API agreement are three different risk profiles wearing one name.
Zero Data Retention Gemini Policy
Google splits Gemini across consumer apps, the Gemini Developer API, and Vertex AI, and retention differs across all three. In the consumer Gemini apps, conversations are retained and human review is possible, and Google has disclosed that even with activity settings turned off, recent conversations may be held for a short operational window. The Gemini Developer API historically distinguished free and paid tiers, with free-tier content eligible for product improvement and paid-tier content excluded from training. Vertex AI is where Google’s enterprise commitments live: customer data is not used to train foundation models without permission, and customers can configure deployments to disable prompt caching and data logging, which is the closest practical equivalent to a zero data retention configuration in the Google ecosystem. Enterprises should confirm in their Google Cloud agreements which retention and caching settings are active, because the defaults are not uniformly the most protective option.
Zero Data Retention OpenRouter Policy
OpenRouter illustrates a problem that will define the next phase of AI vendor management: intermediaries. OpenRouter is a routing layer that sends your prompts to dozens of underlying model providers through one API. That convenience multiplies your retention analysis, because your data’s fate depends on both the router’s own logging practices and the policies of whichever downstream provider served the request.
OpenRouter addresses this with provider routing controls, including settings that restrict requests to endpoints whose operators have zero data retention or no-logging policies, alongside its own controls over prompt logging on the platform. Used correctly, that lets teams enforce a ZDR-only posture across many models at once. Used carelessly, an aggregator becomes an invisible subprocessor chain. Three diligence questions apply to OpenRouter and every similar gateway:
- What does the intermediary itself log and retain, including metadata, and can prompt logging be disabled at the account or organization level?
- How does it verify and enforce the downstream providers’ retention claims, and what happens to a request if no ZDR-eligible provider is available?
- Do your DPA and subprocessor disclosures actually reflect the full chain of entities that may touch the data?
Zero Data Retention Framework
Buying ZDR terms from vendors is only half the job. A zero data retention framework is the internal governance structure that makes those terms real, provable, and audit-ready. A workable framework has six components:
- AI data flow inventory. Map every AI tool in use, sanctioned or not, and record what data categories flow into it, which product tier and account type is involved, and where outputs land. Shadow AI discovered through network and browser telemetry belongs in this inventory, not outside it.
- Classification-based routing. Define which data classes may only be processed through ZDR-covered channels. Regulated data such as PHI, cardholder data, children’s data, and privileged material should be technically blocked from non-ZDR endpoints, not merely discouraged by policy.
- Contractual architecture. For each provider, capture the retention commitment in the DPA or services agreement, including covered endpoints, safety carve-outs, metadata handling, subprocessors, and audit or attestation rights. A marketing page describing ZDR is not a contract term.
- Retention schedule integration. Fold AI processing into your existing records retention schedule so that CPRA retention disclosures, GDPR Article 30 records, and privacy policy statements accurately describe AI vendor retention. A privacy policy that is silent about AI processing while your stack sends data to four model providers is itself a compliance gap.
- Verification and monitoring. Periodically confirm configurations are still what you contracted for: logging toggles, caching settings, tier assignments, and router policies drift as teams adopt new features. Treat each provider policy update as a change-management event.
- Governance alignment. Slot the framework into your AI governance program under NIST AI RMF’s Govern and Map functions and, where applicable, EU AI Act obligations around data governance and documentation. Zero data retention answers the storage limitation question, but purpose limitation, transparency, and human oversight still need their own controls.
Where Data Privacy, AI Governance, and ZDR Converge
Zero data retention sits at the intersection of two disciplines that are merging fast. From the privacy side, it operationalizes data minimization and storage limitation, the principles regulators cite most often when AI processing goes wrong. From the governance side, it is a concrete, testable control that boards and auditors can verify, unlike aspirational AI principles. It also changes litigation posture: retention you never had cannot become a preservation dispute, a breach notification event, or a wrongful collection allegation about data kept beyond its disclosed purpose.
The connective tissue between those disciplines is knowing what you collect and where it goes, and that is where most organizations still fail. You cannot route sensitive data to ZDR endpoints if you do not know which forms, chat widgets, and internal tools are capturing it in the first place.
Captain Compliance helps organizations build that foundation: continuous website and data flow scanning that surfaces where personal information is actually collected, consent management that gates collection before it happens, dynamic privacy policies that keep your retention disclosures synchronized with your real practices, and DSAR workflows that can honor deletion rights across your vendor stack. If your team is drafting AI governance policies or negotiating ZDR terms with model providers, talk to Captain Compliance about grounding that program in an accurate picture of your data, because zero retention only protects the data you know you are sending.