What is zero data retention in AI APIs?
Zero data retention (ZDR) is a contract-level setting under which an AI provider processes your API requests and keeps nothing afterwards - no prompts, no outputs, no abuse-monitoring copy. By default OpenAI keeps API logs for up to 30 days; ZDR removes that copy for approved customers on eligible endpoints. It is about storage, not about training, which API data is already excluded from.
What happens to your data by default
When a company sends a support ticket or a contract clause to a model through an API, two questions matter: is the text used to train the model, and is a copy kept. At OpenAI the first answer is no unless you opt in; API data is not used for training. The second answer is yes: abuse-monitoring logs are generated for API use and kept for up to 30 days, so the text exists on the provider's side for a month.
Zero data retention changes the second answer. Under ZDR the content of a request is excluded from those logs - it is processed and then gone. It is granted on request after OpenAI's approval, on additional terms, and only for specific endpoints: the ordinary completions and responses calls, embeddings, transcription and a few others. In September 2026 OpenAI extended it to its most capable models, which had been the gap that pushed regulated customers towards older ones.
What ZDR does not cover
It is not encryption, not data residency and not a legal opinion. Stateful features keep state regardless: the assistants, threads and conversations endpoints hold what you put in them until you delete it, ZDR or not, and a feature that stores files to search them stores files. A model with ZDR still saw the data while answering, so a provider's own security still matters, and your side of the pipeline - your logs, your vendor's logs, the CRM the answer lands in - is untouched by the setting.
Other providers offer comparable options on enterprise terms, under different names and with different exclusions. The names change faster than this page will, so treat every claim of "no retention" as a question to answer from the current policy and the signed agreement, not from a sales deck.
Four things to check before you rely on it
First, eligibility: ZDR is not switched on by opening an account; confirm in writing which organisation, which tier and which endpoints it covers. Second, features: list what your integration actually calls - a pipeline that uses file search or a stored conversation is not covered end to end even when the chat calls are. Third, your own retention: a no-retention model behind an application that logs every prompt to a database has moved the problem, not removed it.
Fourth, whether you needed it. Most of the workflows that were blocked - ticket triage, call summaries, CRM enrichment - handle customer data that is already in three of your systems. ZDR lets a compliance team say yes to a fourth without a redaction layer, which is a real simplification; it does not replace a data-processing agreement or the minimisation a regulator expects. Where the data is sensitive enough, the right answer may still be to redact before sending, and that is a design decision, not a setting.
Related questions
- Is zero data retention the same as opting out of training?
- No. API data is excluded from training by default at OpenAI; that is a separate policy. ZDR is about whether a copy of the request is kept at all after it is processed - the 30-day abuse-monitoring log.
- Does ZDR mean the provider never sees my data?
- The model processes the text, so the provider's systems see it while answering. ZDR means nothing is kept afterwards. Security of the processing itself is a different question, answered by the provider's certifications and your agreement.
- Do we need ZDR for GDPR?
- The regulation does not name it. It asks for a lawful basis, a processing agreement and data minimisation; ZDR helps with the last of those and shortens the answer to "where is this data now". Whether it is required for a given workflow is a question for your counsel, not for a settings page.
- Does ZDR apply to ChatGPT?
- ZDR is an API control. ChatGPT's business tiers have their own retention settings and admin controls, decided separately; a company using both has two policies to read.
Related
Free AI Diagnostic
The free diagnostic maps which of your processes touch customer data and which model, with which controls, each one can run on.
Start the free diagnosticStarts immediately in the browser.
- Fee
- Free
- Length
- 15 minutes
You keep the ranked list of candidates either way.