Zero data retention means an AI provider doesn't store your prompts or the model's responses once a request completes. As of August 2026, OpenAI, Anthropic, Google and Microsoft all offer a version of it. None of them switch it on by default, each works through a different mechanism, and Anthropic's most capable models are excluded from it outright. Here's what each provider actually gives you, and what you give up in return.
Key Takeaways
- No major AI provider ships zero data retention by default. Getting it takes a contract, an application, or manual configuration, depending on the vendor.
- Anthropic's Covered Models policy, in effect since 9 June 2026, retains prompts and outputs for 30 days on every platform where those models run, and zero data retention is not available for them, including in Claude Enterprise, AWS Bedrock, Google Cloud and Microsoft Foundry.
- OpenAI restated its zero data retention commitment for eligible API customers on 19 August 2026 and previewed Private Safety Processing, with a technical white paper promised for September.
- Google's Vertex path is a checklist rather than a switch. Context caching runs by default with a 24-hour window, so skipping that step leaves you holding retention you didn't ask for.
- Microsoft's nearest equivalent, modified abuse monitoring, is open only to Enterprise Agreement customers and granted per Azure subscription, not per tenant.
What zero data retention actually means
Zero data retention (ZDR) is a commitment that prompts and outputs aren't persisted after the API returns a response. That's narrower than most buyers assume, and it gets confused with three other controls that sound similar and protect against different things.
A no-training policy is a different lever
Every provider on this list already commits not to train on paid enterprise data. Training policy governs what happens to your data later. Retention governs whether it sits on their disks at all. You can have a watertight no-training clause and 30 days of stored prompts at the same time.
Data residency answers a different question
Residency tells you which country your data sits in. Retention tells you whether it sits anywhere. Plenty of buyers hold EU residency and 30-day retention together without realising it. We've covered how to pick AI tools on residency grounds separately, and the two evaluations shouldn't be merged.
Confidential computing is the thing people actually mean
This is the distinction worth internalising before you write anything into policy. Zero data retention means the provider doesn't keep your content. It does not mean the provider can't see it while processing. If your threat model includes the provider's own infrastructure during inference, retention policy doesn't address that. Confidential computing does, and almost nobody sells it yet.
The three shapes of "zero"
The mechanism matters more than the label, because the mechanisms fail differently.
Anthropic sells you a contract. You go through sales, it's enabled per organisation, and every enablement action is audit-logged. A new organisation under the same account doesn't inherit it, and Enterprise admins can't switch it on themselves.
Microsoft has you file an application. Modified abuse monitoring is requested through the Azure OpenAI Limited Access programme with your Subscription ID and Tenant ID, and it's granted per subscription. Approval for one subscription doesn't cover the others in your tenant. You also need an Enterprise Agreement or MCA-E, so pay-as-you-go accounts convert first.
Google hands you a checklist. On Vertex you set store=false, disable context caching, and request an abuse-monitoring exception through a form. Three separate actions, and only the first is obvious. Context caching is enabled by default and holds inputs for up to 24 hours in the data centre that served the request.
That last one is the difference that matters. The Anthropic and Microsoft arrangements fail closed: without the contract or the approval, you know you haven't got zero retention. The Google configuration fails open. Miss the caching step and you'll believe you have it while running a 24-hour cache, and nothing in the API will tell you.
The comparison at a glance
| Dimension | OpenAI | Claude (Anthropic) | Gemini (Google) | Copilot (Microsoft) |
|---|---|---|---|---|
| Formal ZDR | Yes, API only, per endpoint | Yes, contractual, per organisation | Yes, as a configuration checklist | Yes, as modified abuse monitoring |
| How you get it | Sales approval plus additional terms | Sales, not self-serve | Set store=false, disable caching, request abuse-monitoring exception | Limited Access application per Azure subscription |
| Eligibility gate | Prior approval, criteria unpublished | Sales qualification | Not publicly documented for the Developer API | Enterprise Agreement or MCA-E only |
| Default retention | 30 days for abuse monitoring | Covered Models: 30 days on every platform | Vertex advanced tier 30 days; standard services up to 90 days if flagged; paid Developer API 55 days, configurable to 7 | Azure OpenAI 30 days; M365 Copilot follows your Purview policy |
| Training on your data | No since March 2023, unless you opt in | No for API, Team, Enterprise. Opt-out on Free, Pro, Max | No on Vertex, paid API, Workspace. Yes on the free AI Studio tier | No across M365 Copilot, Azure OpenAI, Copilot Business and Enterprise |
| Breaks under ZDR | Assistants, Files, fine-tuning, Batches, Evals, background mode, hosted containers | Batches, Files API, code execution, MCP connectors, Agent Skills | Context caching, grounding with Search or Maps, Live API session resumption | Not documented; stateful features almost certainly persist |
| Retention despite ZDR | Not published | Up to 2 years if flagged by trust and safety | Not published | Automated classification continues, storage stated as none |
| Data residency | Multiple regions including EU and UK | US or global only on the first-party API | Regional and multi-region endpoints, Assured Workloads | EU Data Boundary, Advanced Data Residency, Multi-Geo |
OpenAI: per endpoint, after approval
OpenAI's zero data retention is an API platform control, granted per endpoint after sales approval. It isn't a ChatGPT Enterprise feature. Non-ZDR API traffic generates abuse-monitoring logs retained up to 30 days, and API data hasn't been used for training by default since March 2023.
The per-endpoint design is where buyers get caught. Chat completions, responses, embeddings, images, audio and moderations are covered. Assistants, Conversations, Files, fine-tuning, Batches, Evals, background mode and hosted containers are not, and the documentation says plainly that excluded capabilities may still store application state even with ZDR enabled. So ZDR is a property of the call you make, not of your organisation. Your HIPAA BAA scope is bounded by that same endpoint list, which is the most concrete downstream consequence of the design.
On 19 August 2026 OpenAI published Offering Zero Data Retention for frontier models and previewed Private Safety Processing, which runs safety monitoring across related interactions without giving OpenAI personnel access to the underlying content. Customer content either stays on customer-controlled infrastructure or is encrypted with keys the customer holds. It's a preview, tested with early customers, with broader rollout and a technical white paper promised for September. Eligibility criteria weren't published.
One episode belongs in any serious evaluation. During the New York Times copyright litigation, a May 2025 preservation order required OpenAI to retain output logs that would otherwise have been deleted. API customers without a zero data retention agreement were covered by that order. ZDR customers were not. The going-forward preservation duty was terminated in October 2025, but the lesson holds: a vendor's deletion policy is only as durable as the next court order, and a ZDR agreement was the thing that kept customer logs out of a litigation hold.
Claude: the strictest programme, with its best models carved out
Anthropic runs a formal, contractual zero data retention programme, and it publishes more detail about what breaks under it than anyone else. Under a ZDR arrangement, Anthropic doesn't store customer prompts or responses at rest after the response is returned.
Then comes the exclusion that reframes the whole comparison. Anthropic's Covered Models policy, effective 9 June 2026, requires 30-day retention of prompts and outputs for its most capable models on every platform where they're offered. Zero data retention isn't available in workspaces, Claude Enterprise organisations, or third-party platforms where Covered Models run, and existing enterprise ZDR commitments don't extend to them. Axios summarised the week's positioning in one headline: OpenAI previewing a zero-retention safety system while Anthropic requires data logs. If your evaluation assumed the safety-forward vendor would also be the retention-strict one, that assumption now points the wrong way.
Some feature detail that's better documented here than anywhere else. Prompt caching stays ZDR-eligible, which surprises people: the cache holds key-value representations and hashes in memory for the cache lifetime, then discards them. Citations are eligible too. Batch processing, the Files API, code execution and MCP connectors are not, and using them is a decision to step outside your ZDR arrangement for that data rather than an error the API blocks.
Two things worth knowing that vendor comparison pages skip. Flagged content can be retained for up to 2 years even under ZDR, and Anthropic is the only one of the four publishing a number for that. And its Compliance API doesn't capture sessions where ZDR is in effect, which means buying zero retention costs you part of your own forensic trail. That tension exists at every vendor. Anthropic is the only one that writes it down.
On residency, the first-party API offers US-only or global, with no EU inference option, and US-only inference carries a 1.1x price premium. On Bedrock and Google Cloud the cloud provider is the data processor rather than Anthropic, which changes who your data processing agreement is actually with.
Mid-evaluation and the vendor answers aren't lining up?
Run the free AI adoption scorecard →Book 20 minutesNo sales script. If we're not the right fit, we'll say so in the first five.
Gemini: three surfaces, three different answers
Google's story depends entirely on which surface you're using, and the gap between them is the widest of any vendor here.
The free AI Studio tier is the one to watch. Google's terms state that content submitted to the unpaid services is used to provide, improve and develop Google products and machine learning technologies, and that human reviewers may read, annotate and process API input and output. Google disconnects the data from your account and project first, and the terms warn directly against submitting sensitive or confidential information. If anyone in your organisation is prototyping on a free API key, that's your finding for the week. There's a regional carve-out: users in the EEA, Switzerland and the UK get the paid data terms even on free usage.
The paid Developer API is a different product. Google doesn't use paid prompts or responses to improve its products, and logs are retained for a default 55 days, configurable down to 7, 14 or 28. A project-level zero data retention path is documented, though the docs don't say how to request it, and developer forum threads asking have gone unanswered.
Vertex, now being rebranded towards Gemini Enterprise Agent Platform, is where the enterprise commitments live. Google won't train on your data without permission, and zero retention is achievable through the checklist described above. The abuse-monitoring behaviour splits in a way worth checking against your model choice: advanced models log all prompts and responses for up to 30 days, while standard generative services log only when safety classifiers flag something, then hold it up to 90 days in your selected region. Workspace Gemini sits under your existing Workspace agreement and stays inside the user trust boundary.
Copilot: four products wearing one name
Treating Copilot as a single product is the most common mistake in this category, and we've written a fuller platform comparison if that's the decision on your desk.
Microsoft 365 Copilot processes data inside your tenant boundary, and prompts, responses and Graph-accessed data are never used to train the underlying models. Prompt and response pairs are stored as Teams messages in the user's mailbox and follow your Purview retention policies, so the retention answer is whatever you've configured rather than a vendor default. One detail for anyone writing deletion SLAs: even a one-day retention policy can take up to 16 days to purge permanently, because content passes through the SubstrateHolds folder and stays discoverable in eDiscovery until it clears.
Copilot Chat runs under the same enterprise data protection commitments, with prompts and responses logged in Exchange for audit and eDiscovery.
Azure OpenAI Service is the surface with a genuine ZDR analogue. The default is 30-day abuse-monitoring retention, stored in Microsoft's environment, inaccessible to OpenAI, and never used for training. Human reviewers can only reach content that's already been flagged, through Secure Access Workstations with just-in-time approval. Modified abuse monitoring removes human review and stops storage of prompts and completions entirely. It's the application-gated path described earlier.
GitHub Copilot Business and Enterprise don't train on your code. Retention splits by surface: prompts and suggestions aren't retained for IDE code completions, but on github.com chat, mobile and CLI they're held for 28 days, with engagement data kept 2 years. Free, Pro and Pro+ tiers do feed training unless the user opts out.
Microsoft's sovereignty position is the strongest of the four. IL4, IL5 and IL6 availability plus the EU Data Boundary is a combination the others don't match. Its IP indemnity is also the most conditional, requiring you to implement every mitigation named in the product documentation to keep coverage.
What zero data retention costs you
Nobody markets this part, and it's where your security review should spend its time.
You lose stateful features. Across every vendor, the excluded list has the same shape: batch processing, file storage, code execution, hosted containers, agent frameworks. Anything that has to remember something between calls is, by definition, retention. If your architecture depends on those, ZDR is an architectural decision rather than a contract clause.
You may lose part of your own audit trail. Anthropic states that its Compliance API doesn't capture ZDR sessions. Put the same question to Google and Microsoft in writing, because neither documents an answer. A compliance team that requires full session forensics and zero provider retention is asking for two things that partly contradict each other.
Flagged content survives anyway. Every provider retains content flagged by safety systems, and legal holds override deletion policy at all four. "Zero" describes the normal path, not the exception path.
Caching needs checking, not assuming. Anthropic's prompt caching is ZDR-compatible. Google's context caching isn't, and it runs by default. Same word, opposite answer.
The ten questions to put in your RFP
These separate a real commitment from a marketing page. Send them to all four vendors, and pair them with our enterprise AI procurement guide for the rest of the evaluation.
- Is zero data retention available for the specific model we intend to use, or are your most capable models excluded?
- Is it granted per account, per organisation, per subscription, or per endpoint?
- Which API features stop working, or silently fall outside the arrangement, once it's enabled?
- What's the retention period for content flagged by your safety systems, expressed as a number?
- Does enabling zero retention reduce the audit and compliance data available to us?
- Which entity is the data processor if we consume your model through a cloud marketplace?
- What happened to customer data under your most recent litigation hold or preservation order?
- Can you contractually commit to the retention behaviour, or is it a documentation statement you can revise?
- What's the notice period before you change retention policy for a model we're already running in production?
- Is any caching enabled by default that we'd need to disable separately?
The question that changes answers is number 8. A policy page can be edited. A contract can't. If a vendor will only point you at documentation, price that difference into your risk assessment.
The line worth keeping
Retention policy is now a model selection criterion, not a legal review step that happens after the technical evaluation. Anthropic's Covered Models decision proved a vendor can ship its best model with retention that can't be switched off, and that the commitment you signed for one model doesn't automatically travel to the next one.
Which makes the practical move a small one. Before your next model upgrade goes to production, have whoever owns the vendor relationship confirm in writing that the retention terms you negotiated still apply to the specific model version you're deploying. That's a five-line email, and it's the gap most teams won't find until an auditor does.
Frequently asked questions
What is zero data retention in AI?
Zero data retention means an AI provider doesn't store your prompts or the model's responses after the request completes. It's distinct from a commitment not to train on your data, and distinct from data residency. It also doesn't stop the provider from processing your content during inference.
Which AI models offer zero data retention in 2026?
OpenAI offers it for eligible API endpoints, Anthropic offers it contractually per organisation, Google offers it on Vertex through configuration, and Microsoft offers it for Azure OpenAI as modified abuse monitoring. None are enabled by default, and Anthropic's Covered Models are excluded entirely.
Does ChatGPT Enterprise have zero data retention?
Zero data retention is an OpenAI API platform control applied per endpoint, and there's no evidence it extends to ChatGPT Enterprise conversation data. Enterprise workspaces instead use admin-configured retention with a 90-day minimum. Confirm this with OpenAI directly rather than relying on secondary sources.
Why can't I get zero data retention on Claude's best models?
Anthropic's Covered Models policy, effective 9 June 2026, requires 30-day retention of prompts and outputs for its most capable models to support its safety work. It applies on every platform where those models run, including Claude Enterprise, AWS Bedrock, Google Cloud and Microsoft Foundry, and existing ZDR agreements don't extend to them.
Is Gemini safe for confidential business data?
It depends on the surface. Vertex AI and paid Gemini API usage carry enterprise commitments including no training on your data. The free AI Studio tier does not: Google's terms state that content is used to improve its products and that human reviewers may read it, with a carve-out for EEA, Swiss and UK users.
How do I get zero data retention on Azure OpenAI?
Apply for modified abuse monitoring through the Azure OpenAI Limited Access programme, supplying your Azure Subscription ID and Tenant ID. You need an Enterprise Agreement or MCA-E, and approval is granted per subscription, so each subscription needs its own application.
Does zero data retention mean the provider can't see my data?
No. Zero data retention means content isn't kept after processing. The provider's systems still handle it during inference. Preventing the provider from seeing content during processing requires confidential computing, which is a different technology and not widely available.
What breaks when I enable zero data retention?
Typically batch processing, file storage APIs, code execution environments, and agent or assistant frameworks, since anything holding state between calls is retention by definition. Caching varies: Anthropic's prompt caching stays compatible, while Google's context caching runs by default with a 24-hour window and must be disabled separately.
We sit in the passenger seat for this exact decision
We're We Call Shotgun, a founder-led AI consulting and training boutique working across the UK and France. We help companies choose the AI platform that fits their risk position, then get their teams actually using it. 1,500+ professionals trained, 50+ companies, 4.98/5 average rating. UK engagements from £3,500.
Run the Free AI Adoption Scorecard Book a Free 20-Minute CallSources and further reading
- OpenAI, "Offering Zero Data Retention for frontier models" — the 19 August 2026 announcement and the Private Safety Processing preview.
- OpenAI, "Data controls in the OpenAI platform" — ZDR-eligible endpoints and the 30-day abuse-monitoring default.
- Axios, "OpenAI previews zero-retention safety system as Anthropic requires data logs" — 19 August 2026.
- Anthropic, "Covered Models" — the 30-day retention requirement and platform scope.
- Anthropic, "API and data retention" — ZDR mechanics, the 2-year flagged-content window, and the Compliance API exclusion.
- Google, "Vertex AI zero data retention" — the store=false, caching and abuse-monitoring checklist.
- Google, "Gemini API additional terms of service" — unpaid vs paid data handling and the EEA/UK carve-out.
- Microsoft, "Azure OpenAI abuse monitoring" — the 30-day default and the modified abuse monitoring programme.
- Microsoft, "Retention policies for Copilot" — mailbox storage and the purge timeline.
- GitHub, "Copilot Business" — the no-training commitment for Business and Enterprise.
- Engadget, on the termination of the NYT preservation order — October 2025, with the ZDR customer exemption.