← All articles

LLM API Data Privacy and Retention Policies Across Providers: What Happens to Your Prompts After You Hit Send

A cross-provider reference comparing how OpenAI, Anthropic, Google, DeepSeek, and DashScope handle your API prompts and responses. We mapped default retention windows, zero-data-retention options, training opt-out mechanisms, compliance certifications, and data processing agreements — so you can make an informed procurement decision without reading six different privacy policies.

· TheRouter

Every enterprise AI procurement conversation eventually arrives at the same question: what happens to our prompts and responses after the API call completes?

The answer varies dramatically across providers. Some delete API traffic within 7 days. Others retain it for 30 days. Some offer zero-data-retention agreements. And at least one major provider has never published a clear retention window for API traffic at all.

We reviewed the published privacy policies, data processing agreements, and enterprise documentation for the five providers we route most traffic through. This reference captures what we found as of August 2026.

The Quick Reference Table

ProviderDefault API RetentionTrains on API Data?ZDR Available?Key Compliance
OpenAI30 daysNoYes (org-level opt-in)SOC 2, HIPAA BAA available
Anthropic7 daysNoYes (enterprise agreement)SOC 2, HIPAA BAA available
Google (Gemini API)Varies by planNo (paid plans)Yes (paid plans)SOC 2, ISO 27001, HIPAA BAA
DeepSeekNot publishedNot explicitly committedNoLimited public documentation
DashScopeNot publishedNo (explicit commitment)Not documentedSOC 2, AES-256 encryption

OpenAI: 30-Day Default, ZDR for Enterprise

OpenAI's enterprise privacy page commits that data submitted through the API is not used to train models. This covers the API, ChatGPT Enterprise, and ChatGPT Team. Consumer ChatGPT (free and Plus) operates under different terms.

The default retention window for API inputs and outputs is 30 days for abuse monitoring. After that window, the data is deleted unless legal obligations require longer retention.

OpenAI offers zero data retention (ZDR) for eligible customers. Under ZDR, prompts and outputs are not stored after the request completes. The store parameter is forced to false even if your code sets it to true. ZDR covers /v1/chat/completions, /v1/responses, /v1/embeddings, /v1/audio/transcriptions, /v1/audio/translations, /v1/moderations, and other endpoints listed in OpenAI's data controls documentation.

ZDR is not self-serve. Your account team must enable it at the organization or project level.

One caveat worth noting: the 2025 New York Times copyright litigation required OpenAI to retain certain output data under a court preservation order. API customers with ZDR agreements, ChatGPT Enterprise, and ChatGPT Edu were excluded from that order. OpenAI stated that the going-forward retention obligation ended on September 26, 2025.

Sources: OpenAI Data Controls (retrieved 2026-08-12), OpenAI Enterprise Privacy (retrieved 2026-08-12)

Anthropic: 7-Day Default, Strictest Published Baseline

Anthropic reduced its API log retention from 30 days to 7 days in September 2025. API inputs and outputs are automatically deleted after 7 days. They are never used for model training.

Organizations that need longer retention for auditing can opt in to a 30-day window through their Data Processing Addendum. But the default is the shortest published baseline among the major providers.

For enterprise API customers, Anthropic offers a zero data retention agreement where inputs and outputs are not stored at all beyond abuse screening. One important note: Anthropic still retains User Safety classifier results even under ZDR to enforce usage policy.

Commercial products (Claude for Work, Enterprise, Edu, Gov) are explicitly excluded from consumer training policies. The August 2025 consumer opt-in training toggle does not apply to API or commercial customers.

Anthropic offers HIPAA-eligible services with a BAA for qualifying healthcare customers. Under the BAA, certain features like web search are disabled.

Sources: Anthropic API and Data Retention (retrieved 2026-08-12), Anthropic Privacy Center (retrieved 2026-08-12), Anthropic Training Policy (retrieved 2026-08-12)

Google Gemini: Plan-Dependent, ZDR for Paid Tiers

Google's data handling for Gemini varies significantly by plan and access path.

Gemini Developer API (free tier): Google may use prompts and responses to improve products and train models. Content can be reviewed by human reviewers. Not suitable for sensitive or production workloads.

Gemini Developer API (paid plan): Google commits to not using prompts and responses for model training. Zero data retention applies by default for paid plan users, meaning inputs and outputs are not stored after processing.

Vertex AI: Google Cloud's enterprise terms apply. Customer data is not used for model training. Data residency controls, VPC Service Controls, and CMEK (Customer-Managed Encryption Keys) are available. Vertex AI supports HIPAA, SOC 2, and ISO 27001.

The split between free and paid tiers is the sharpest of any provider. If you are evaluating Gemini for anything beyond prototyping, the paid tier distinction matters.

Sources: Google Gemini API ZDR documentation (referenced 2026-08-12), Gemini API Terms (referenced 2026-08-12)

DeepSeek: Open Weights, Opaque Data Practices

DeepSeek occupies an unusual position. Its V4 models offer exceptional price-performance, and the open-weight releases (V3, R1) let you self-host. But the hosted API's data practices are the least transparent among major providers.

DeepSeek's privacy policy states that it collects "text input, voice input, prompt, uploaded files, photos, feedback, chat history, or other content." The policy does not publish a specific retention window for API traffic. There is no public statement equivalent to OpenAI's "not used for training" or Anthropic's "deleted after 7 days."

DeepSeek has not published a Data Processing Agreement template, a BAA for HIPAA, or ZDR options.

For teams that need DeepSeek-class performance with stronger data governance, self-hosting the open-weight models is the most practical path. DeepSeek V4 weights are available on Hugging Face, and providers like SiliconFlow offer hosted inference with their own privacy terms.

Sources: DeepSeek Privacy Policy (retrieved 2026-08-12), DeepSeek API Documentation (retrieved 2026-08-12)

DashScope (Alibaba Cloud Model Studio): No Training, SOC 2 Certified

Alibaba Cloud's privacy notice for Model Studio makes one commitment clearly: "Alibaba Cloud strictly protects your data privacy and will never use your data for model training."

All data transmitted during API calls is encrypted with AES-256. DashScope holds SOC 2 certification with an unqualified opinion covering Security, Availability, and Confidentiality.

What DashScope has not published is a specific retention window for API inputs and outputs. The privacy notice defers to the Alibaba Cloud International Website Product Terms of Service for detailed data handling terms.

DashScope does not publicly offer a ZDR agreement or HIPAA BAA, though enterprise Alibaba Cloud customers can negotiate custom data processing terms through their account team.

Sources: DashScope Privacy Notice (retrieved 2026-08-12), Alibaba Cloud Compliance Repository (retrieved 2026-08-12)

Decision Tree: Picking the Right Provider for Your Data Sensitivity

If you need HIPAA compliance: OpenAI (with BAA), Anthropic (with BAA), or Google Vertex AI. DashScope and DeepSeek do not currently offer HIPAA-eligible services for international customers.

If you need zero data retention: OpenAI ZDR (request via account team), Anthropic ZDR (enterprise agreement), or Google Gemini paid tier / Vertex AI.

If you need the shortest default retention: Anthropic at 7 days, followed by OpenAI at 30 days.

If you need a no-training guarantee and work primarily in China: DashScope provides an explicit no-training commitment with SOC 2 certification.

If cost is the primary constraint and data sensitivity is low: DeepSeek's API offers the best price-performance, but plan for the data governance gap. Consider self-hosting the open-weight models if your compliance requirements demand it.

How a Unified Gateway Simplifies Data Governance

When you route traffic through multiple LLM providers directly, each provider relationship is a separate data processing agreement, a separate compliance review, and a separate audit surface.

OpenAI-compatible means a provider exposes a chat-completions endpoint whose request and response shape matches the OpenAI API contract closely enough that an unmodified OpenAI SDK call works against it after swapping three values: API key, base URL, and model name. The minimum surface in practice is POST /v1/chat/completions with messages, model, and an OpenAI-shaped streaming response.

A unified gateway like TheRouter consolidates the vendor management surface. Your application code talks to one endpoint. Your compliance team reviews one set of routing rules. When a provider's data practices change, you update one routing configuration instead of patching every service that calls that provider directly.

This does not eliminate the underlying provider policies. Your data still reaches the provider you route to. But it reduces the operational surface from N vendor relationships to one gateway plus N provider agreements, and it gives you a single point to enforce fallback routing if a provider's data practices change in ways your organization cannot accept.

What We Did Not Cover

This reference focuses on API data retention and training policies. We did not cover:

  • Fine-tuning data retention, which has separate and longer retention semantics at every provider
  • Stored Completions / Assistants API data, which you explicitly opt into and which has its own lifecycle
  • Consumer product policies (ChatGPT free, Claude free, Gemini free consumer app), which operate under different and generally less restrictive terms
  • Data residency (where your data is processed geographically), which we plan to cover in a separate reference

Sources and Retrieval Dates

All policy claims in this reference were verified against the linked sources on August 12, 2026. LLM API privacy policies change. Verify against the current published policy before making procurement decisions.

ProviderSourceRetrieved
OpenAIData Controls, Enterprise Privacy2026-08-12
AnthropicAPI and Data Retention, Privacy Center2026-08-12
GoogleGemini API ZDR, Gemini API Terms2026-08-12
DeepSeekPrivacy Policy, API Docs2026-08-12
DashScopePrivacy Notice, Compliance Repository2026-08-12
Help & contact