Zero data retention (ZDR) is an arrangement under which an AI model provider keeps no copy of your prompts or the model’s outputs once a request completes, including in the abuse-monitoring logs most providers hold by default. It is usually approved account by account, covers only eligible endpoints and features, and still lets the provider retain flagged content or data under a legal hold.
Key takeaways
- 01 Without ZDR, providers keep prompts and outputs for a while: up to 30 days of abuse-monitoring logs on the OpenAI API, deletion within 30 days by default at Anthropic, and up to 90 days for flagged prompts on Google Cloud.
- 02 ZDR is granted rather than switched on at OpenAI and Anthropic, approved through a Limited Access process for Azure’s modified abuse monitoring, set as a retention mode on Amazon Bedrock, and requested as an exception on Google Cloud.
- 03 Stateful features sit outside it: files, batches, assistants and threads, vector stores, code execution containers and connectors to third-party tools keep data by design.
- 04 Every provider keeps exceptions for flagged content and legal obligations. The 2025 preservation order in the New York Times case against OpenAI did not reach API customers on ZDR.
- 05 ZDR limits what the provider stores. It does nothing about your own logs, vector stores and tool calls, and the prompt still leaves your network to be processed.
Free 35-page PDF
Enterprise AI Agent Procurement & RFP Guide 2026
RFP questions, scoring model and vendor red flags.
Zero data retention, defined
Zero data retention describes what happens after inference. The provider processes the request in memory, returns the response and keeps no copy of the prompt or the output at rest: none in application storage, none in abuse-monitoring logs and none in a review queue. OpenRouter states it in one line: ZDR means a provider will not store your data for any period of time.
Three nearby ideas get confused with it. No training is a separate promise: OpenAI, Anthropic, Microsoft and Google all say business API data is not used for training by default, yet each may still store it for a time, and OpenRouter notes that some providers retain data they do not train on. Data residency controls where data is processed or stored, not whether it is kept. In-memory caching is generally treated as compatible with ZDR: Google says the in-memory cache its Gemini models use, which expires after 24 hours, does not violate zero data retention, and OpenRouter takes the same position on implicit caching.
What providers keep when ZDR is off
Default retention is what most teams actually run on, so start there. On the OpenAI API, abuse-monitoring logs are generated for all API usage and kept for up to 30 days, and stateful endpoints keep application state until it is deleted. Anthropic deletes commercial inputs and outputs within 30 days by default, but keeps them for up to two years, and trust and safety classification scores for up to seven, if a conversation is flagged (verified October 2026).
On Google Cloud, prompts can be logged for up to 90 days when safety classifiers detect suspicious activity. That applies to customers under the Google Cloud Platform Terms of Service; customers with a Google Cloud Master Agreement are exempt by default. Models Google designates as Advanced AI, which include Anthropic’s Claude Fable and Claude Mythos models, have every prompt and response logged for up to 30 days. Microsoft’s Azure OpenAI documentation describes an abuse-monitoring store in the customer’s geography that holds flagged prompts and completions for human review, while stateful features such as the Responses API, Assistants threads and stored completions keep data in your resource until you delete it.
Amazon Bedrock starts from the opposite default: it does not store model inputs or outputs. Specific models are carved out. Bedrock keeps classifier-flagged traffic for some OpenAI models for up to 30 days, and all traffic for Claude Fable 5 and 5.1 for up to 30 days with possible human review by AWS; that data stays with AWS and is not shared with the model provider.
How to get zero data retention from each provider
OpenAI. Zero Data Retention and the lighter Modified Abuse Monitoring both need prior approval from OpenAI, arranged through its sales team. Both keep customer content out of abuse-monitoring logs, and ZDR also forces the Responses API store parameter to false. Endpoints that hold state, including Assistants, Threads, Conversations, vector stores, Files, fine-tuning and Batch, are not eligible.
Anthropic. ZDR is requested through Anthropic’s sales team and enabled per organization, so a new organization needs it switched on separately. It covers the Messages and Token Counting APIs for eligible features, Claude Code used with commercial API keys, and Claude Platform on AWS. The feature table marks the Files API, batch processing (29-day retention), code execution, the MCP connector, Agent Skills and Managed Agents as not eligible, and the Claude Fable and Claude Mythos models require 30-day retention unless Anthropic authorizes otherwise.
Azure OpenAI in Microsoft Foundry. Microsoft calls its control modified abuse monitoring. Customers who meet additional Limited Access eligibility criteria apply through a form. Once approved, prompts and completions are no longer stored for abuse review and human review stops, although automated review still runs at request time. You can confirm the change, because the resource’s capabilities then show ContentLogging set to false.
Amazon Bedrock. Retention is a per-Region mode set at account or project level. Mode none means nothing is written to durable storage or shared with the model provider, and requests to models that require retention are then blocked. A service control policy can stop anyone in the organization from choosing another mode. ZDR access to models that require retention is evaluated per account and per model, and for Claude models Anthropic manages eligibility.
Google Cloud (Vertex AI, now documented as Gemini Enterprise Agent Platform). Google lists the steps on its zero data retention page, updated on 1 October 2026: request an exception from abuse-monitoring prompt logging, leave request-response logging off, set store to false on the Interactions API, where it defaults to true, and do not enable Live API session resumption. Grounding with Google Search keeps logs for up to three days and Grounding with Google Maps keeps data for 30 days, with no way to turn either off, so Google points ZDR customers to Web Grounding for Enterprise instead.
OpenRouter. The router itself does not retain prompts unless you opt in to prompt logging. You can restrict routing to ZDR endpoints for the whole account in its privacy settings, or per request with "zdr": true in the provider preferences, and it publishes the eligible endpoints through its API. Where a provider’s policy is unclear, OpenRouter assumes the endpoint retains data.
What zero data retention does not cover
Flagged and illegal content. Anthropic may keep inputs and outputs for up to two years if its trust and safety systems flag them, even under ZDR. OpenAI keeps an image flagged as potential child sexual abuse material for manual review even when ZDR or Modified Abuse Monitoring is on, and Bedrock may store and review an input it detects as apparent CSAM.
Legal holds. A court can override any deletion schedule. In 2025 a preservation order in the New York Times lawsuit required OpenAI to keep consumer ChatGPT and API content, deleted chats included. ChatGPT Enterprise and Edu fell outside the order, and API customers using zero data retention endpoints were not affected. OpenAI reports that the obligation ended on 26 September 2025, while limited April to September 2025 data remains under legal hold.
Stateful features and outside tools. Files, batches, threads, vector stores, code containers and managed agent sessions exist to keep data, so they sit outside ZDR at every provider that lists them. Anything an agent sends to a third-party service, such as a remote MCP server or another integration, falls under that service’s own retention terms.
Your own side of the request. ZDR says nothing about the application logs, traces, vector databases, prompt caches and observability tools you run, and the prompt still crosses your network boundary to be processed. A request that never leaves your infrastructure needs no ZDR agreement at all.
A zero data retention checklist for procurement
1. Get it in the contract. A settings screenshot is not an agreement. Confirm which organizations, projects, Regions and models the arrangement covers.
2. Map excluded features. Get the provider’s list of ineligible endpoints and features and check your application against it, including files, batches, assistants or threads, code execution and connectors.
3. Ask what is kept regardless. Flagged content, legal holds, safety classification scores and feedback submissions each have their own retention period.
4. Verify it technically. Where the provider allows, check the setting itself: ContentLogging false on Azure, the Bedrock data_retention mode, or store false on every Responses or Interactions call.
5. Check the models. Some new models require retention and refuse requests from a ZDR configuration, so a model upgrade can quietly change your position.
6. List every third party in the path. Routers, gateways, observability vendors and MCP servers each need their own retention terms.
7. Set your own retention. Once the provider keeps nothing, the logs and traces you keep are the only copy, and your policy decides how long they live.
Zero Data Retention by Provider (Verified October 2026)
Default retention, how to obtain zero data retention, and what stays outside it, taken from each provider’s own documentation in October 2026.
| Provider | Without ZDR | How ZDR is obtained | Not covered or still kept |
|---|---|---|---|
| OpenAI API | Abuse-monitoring logs up to 30 days; stateful endpoints keep data until deleted | Prior approval through OpenAI sales (ZDR or Modified Abuse Monitoring) | Assistants, Threads, Conversations, vector stores, Files, fine-tuning, Batch; images flagged as CSAM |
| Anthropic API | Inputs and outputs deleted within 30 days; flagged content up to 2 years | Request through Anthropic sales; enabled per organization | Files API, batches, code execution, MCP connector, Agent Skills, Managed Agents, Console; Fable and Mythos models need 30-day retention |
| Azure OpenAI (Microsoft Foundry) | Flagged content stored in your geography for human review; stateful features store data in your resource | Limited Access application for modified abuse monitoring | Automated review still runs; Responses, Assistants threads and stored completions keep data |
| Amazon Bedrock | No storage of inputs or outputs by default | Retention mode none per Region; enforce with a service control policy | Models that require retention: Claude Fable 5 and 5.1 (all traffic, up to 30 days); flagged traffic for some OpenAI models |
| Google Cloud (Vertex AI) | Flagged prompts up to 90 days; Advanced AI models log all traffic up to 30 days | Abuse-monitoring exception request; leave optional storage features off | Grounding with Google Search (3 days) and Google Maps (30 days); Interactions API stores by default |
| OpenRouter | Prompts not retained unless you opt in to logging; each provider’s policy applies | Account-wide ZDR setting, or "zdr": true per request | Routes only to endpoints it classifies as ZDR; unclear policies are treated as retaining |
From concept to a governed, on-premise reality
Zero data retention is a promise about a third party’s storage, and running models on your own infrastructure takes the third party out of the request. In an on-premises or air-gapped VDF AI deployment the production data plane has no required path to third-party model APIs, network egress can be disabled, and prompts, documents, embeddings, model outputs and audit logs stay in your environment, as the trust center sets out. Retention then follows your own policy, with configurable retention and deletion for indexes, logs and source connectors.
Many organizations still allow some external models for low-risk work. VDF AI Chat lets commercial APIs such as OpenAI, Anthropic and Azure OpenAI be enabled per agent where policy allows, and those calls fall under that provider’s retention terms, including any ZDR agreement you hold. VDF AI Router decides which requests may leave, with allow and deny lists, regulated domains that only consider explicitly approved models, and an air-gap mode that restricts routing to local models.
Frequently asked questions
What does zero data retention mean?
Zero data retention means an AI provider processes your request and keeps no copy of the prompt or the response afterwards, including in the logs it would normally hold for abuse monitoring. It is usually an approved arrangement rather than a default, it covers only the endpoints and features the provider lists as eligible, and providers keep exceptions for flagged content and legal obligations. It limits storage at the provider; the data is still sent outside your network to be processed.
Does OpenAI offer zero data retention?
Yes, for approved API customers. OpenAI offers Zero Data Retention and a lighter Modified Abuse Monitoring option, both subject to prior approval and additional requirements and arranged through its sales team. Without them, API abuse-monitoring logs are kept for up to 30 days. Stateful endpoints such as Assistants, Threads, Conversations, vector stores, Files, fine-tuning and Batch are not eligible, and ChatGPT workspaces follow their own retention settings rather than API ZDR.
Does Anthropic offer zero data retention for Claude?
Yes. Anthropic offers ZDR for the Claude API through its sales team, enabled per organization. It covers the Messages and Token Counting APIs for eligible features, Claude Code used with commercial API keys, and Claude Platform on AWS. The Files API, batch processing, code execution, the MCP connector and Managed Agents are excluded, as are the Console and the consumer, Teams and Enterprise apps. Claude Fable and Claude Mythos models require 30-day retention unless Anthropic authorizes otherwise.
Does Amazon Bedrock store prompts?
Not by default. AWS documents that Bedrock does not store model inputs or outputs, and that model providers have no access to Bedrock logs or to customer prompts and completions. Some models are exceptions: Claude Fable 5 and 5.1 traffic is kept for up to 30 days for abuse detection, as is flagged traffic for some OpenAI models. Setting the retention mode to none blocks models that require retention, so nothing is written to durable storage.
Is zero data retention the same as not training on my data?
No. A no-training commitment says the provider will not use your data to improve its models, while zero data retention says it will not store the data at all. Business API terms at OpenAI, Anthropic, Microsoft and Google already exclude training by default, yet each still stores some data for a period unless ZDR or an equivalent is in place. OpenRouter makes the distinction explicit: some providers do not train on data but still retain it, for example to scan for abuse.
Does zero data retention protect data from legal holds?
Largely, because data that is never stored cannot be preserved. When a 2025 court order in the New York Times case required OpenAI to keep consumer ChatGPT and API content, API customers using zero data retention endpoints were not affected, and neither were ChatGPT Enterprise or Edu. That obligation ended on 26 September 2025. Providers still reserve the right to retain data where the law requires it, so ZDR reduces legal-hold exposure without removing it.
Put these concepts to work on infrastructure you control.
VDF AI runs governed agents, private retrieval, and model routing inside your own cloud, data center, or air-gapped network — or start free in our managed cloud today. Book a walkthrough mapped to your stack.