What Is Zero Data Retention? ZDR in AI Explained
Zero data retention is a contractual setting where an AI provider processes your prompt, returns the output, and keeps no copy of either once the request completes.
Zero data retention is a contractual setting where an AI provider processes your prompt, returns the output, and keeps no copy of either once the request completes. Nothing is written to the provider's storage, nothing sits in a 30-day abuse-review buffer, and there is no log for a support engineer to pull up later. It is the strictest of the standard data handling tiers, and it is also the one most often confused with two weaker promises that sound identical in a sales call.
The three promises people mix up
Most AI vendor data terms combine three separate commitments. They are frequently presented as one bullet point, and they are not the same thing.
Promise | What it means | What it does not mean |
|---|---|---|
No training on your data | Your inputs are excluded from model training runs | Your data is not stored |
Limited retention | Data is stored for a fixed window, often 30 days, then deleted | Nobody can read it during that window |
Zero data retention | Nothing is written to persistent storage at all | The provider has no metadata about your account |
The middle row is the default at most providers, and it exists for a reason: the retention window is what powers abuse detection, incident investigation and support. Turning it off removes those capabilities along with the storage.
That last column matters. Even under ZDR, providers still keep account-level metadata such as request counts, token usage and billing records. Zero retention applies to content, not to the fact that you made a request.
Why providers resist turning it on
If retention is the risk, why is ZDR not the default? Because abuse detection needs history. Spotting that one account is methodically probing for a jailbreak, or that a set of requests is assembling something harmful across dozens of separate sessions, requires comparing traffic over a rolling window. With nothing retained, each request looks isolated and unremarkable.
So providers trade it deliberately. ZDR is usually gated behind an enterprise agreement, a stated use case, and sometimes a compliance justification, because the provider is accepting a real reduction in its own ability to catch misuse on your account.
This is why the industry has started trying to have both. Anthropic's Enterprise Frontier Safeguards, announced on 1 September 2026, keeps the rolling detection window but stores it in the customer's own cloud, with alerts routed to the customer's team rather than the vendor's. The mechanism is worth understanding even if you will never qualify for it, because it shows where the constraint actually sits.
When you genuinely need it
ZDR is worth the friction in a narrow set of cases:
You process regulated data (health records, financial account details, legal privilege) and your compliance framework forbids third-party storage outright.
A customer contract passes a no-subprocessor-storage obligation down to you, and you have to honour it.
You operate in a jurisdiction where the data residency rules make a US-stored buffer a problem regardless of encryption.
It is not worth the friction because it feels safer. ZDR costs you support quality: when something goes wrong, neither you nor the provider can look at the request that caused it. Teams that switch it on without planning for that discover it during their first production incident.
What to do instead if you cannot get it
Most small teams will not qualify for a ZDR agreement, and that is usually fine. The controls that matter more at that scale are the ones on your side of the boundary.
Redact before you send. The cheapest retention policy is not transmitting the field in the first place. Strip account numbers, full names and identifiers at the application layer before the API call.
Set your own log retention deliberately. Your application logs are frequently a bigger exposure than the provider's, and they are entirely under your control. Our guide on how long to keep AI chat logs covers picking a defensible window.
Read the actual data processing terms, not the marketing page. The GDPR compliance checklist for AI vendors lists which documents contain the real commitments.
Know the default. If you have never checked, what happens to your prompts after you send them walks through the standard path.
How to verify a ZDR claim
Ask three questions in writing. A vendor that can answer all three has probably implemented it; one that answers only the first is describing a training policy.
Is content written to persistent storage at any point, including transient caches and queues?
What metadata is retained, and for how long?
If our account is flagged for abuse, what data exists to investigate with, and who can see it?
The third question is the one that reveals whether ZDR is real, because a genuine zero retention setup has an uncomfortable answer to it, and vendors who have thought it through will tell you so directly. For broader context on where this fits among the other things that can go wrong, see our overview of AI risks for builders.
Retention policy is only half of the privacy picture. Confidential computing addresses who can see data while it is being processed, which a retention policy does not.
FAQ
Does zero data retention mean the AI provider has no record of me at all?
No. Account metadata, usage counts and billing records still exist. ZDR covers the content of your requests and responses, not the fact that requests happened.
Is zero data retention the same as not training on my data?
No. Excluding your data from training runs is a separate, weaker commitment. A provider can honestly say it never trains on your inputs while still storing them for 30 days.
Can I get zero data retention on a normal paid plan?
Usually not. It is typically an enterprise-tier agreement requiring a stated use case, because the provider gives up its own abuse detection on your account to grant it.
Does ZDR make my AI usage GDPR compliant?
Not by itself. It removes one processing concern, but you still need a lawful basis, a data processing agreement with the provider, and appropriate controls on your own side.
How did this land?
About the author

Senior Editor, AI & Product
Cecilia leads the Swarmz editorial desk. She has spent a decade turning complex AI and product topics into writing people actually finish, and she owns the blog's quality bar.


