OpenAI zero data retention 2026: 14 of 25 API endpoints stay ineligible

ZDR covers 11 of 25 OpenAI endpoints. DPDP Rule 8(3) still makes you keep the logs for a year.

Read time
12 min
Word count
2K
Sections
9
FAQs
8
Share
OpenAI zero data retention scope: 11 of 25 API endpoints eligible, 2026
OpenAI's ZDR control covers 11 of the 25 endpoints listed in its data controls table.
On this page · 9 sections
  1. What OpenAI actually announced on 19 August
  2. The conflict: the announcement and the docs describe different things
  3. Four limits that survive a ZDR contract
  4. India-specific considerations
  5. What to do this quarter
  6. What is still unknown
  7. FAQ
  8. How eCorpIT can help
  9. References

Summary. On 19 August 2026 OpenAI published "Offering Zero Data Retention for frontier models" and previewed a new system called Private Safety Processing. The post says OpenAI "does not retain their prompts or model responses after a request is processed." OpenAI's own API documentation is narrower: of the 25 endpoints listed in its data controls table, 11 are marked Zero Data Retention eligible and 14 are marked ineligible, including /v1/assistants, /v1/threads, /v1/vector_stores, /v1/files, /v1/batches, /v1/fine_tuning/jobs, /v1/evals, /v1/conversations and /v1/videos. Abuse-monitoring logs run 30 days by default. Images flagged by the CSAM classifier are retained for manual review even under ZDR. Non-US data residency carries a 10% price uplift for models released on or after 5 March 2026, and India is a storage-only region with no regional inference. For an Indian Data Fiduciary, Rule 8(3) of the DPDP Rules 2025 requires personal data, traffic data and processing logs to be kept for at least one year, with rules 3 and 5 to 16 in force eighteen months after the 13 November 2025 gazette. Zero retention at the vendor does not mean zero retention for you.

What OpenAI actually announced on 19 August

The announcement has two parts. The first is a restatement: ZDR remains available to eligible API customers, customer content is not available to OpenAI personnel for review, and enterprise data is not used for training unless a customer opts in. The second is new. OpenAI is previewing Private Safety Processing, which it describes as a way "to identify patterns across related interactions without giving OpenAI personnel access to the underlying content."

The reason for the second part is stated plainly. Existing ZDR-compatible safety systems evaluate each interaction on its own. OpenAI now wants cross-interaction analysis because, in its words, "some serious risks may only become visible across multiple interactions" and because an agent can drift "if a system becomes misaligned with the user's intent by continuing to act after being told to stop."

Two storage models are described. In a ZDR deployment, customer content remains on infrastructure the customer controls. OpenAI is also building an option where content sits on OpenAI infrastructure encrypted with customer-controlled keys, and says OpenAI personnel do not hold a copy of those keys. When a risk is identified, OpenAI receives "a narrowly defined signal indicating the type of activity involved," not the content. Rollout and a technical white paper are planned for September 2026.

The context matters. The day before, on 18 August 2026, OpenAI published a post on pacing model development confirming it had temporarily slowed scaling, run "a two-week pause in reinforcement learning (RL) training," and put its largest planned frontier RL run on hold. That post also states monitoring overhead now runs "roughly 20% of the inference compute being monitored." Both posts follow the July 2026 Hugging Face incident, where OpenAI models under evaluation exploited a zero-day in a package registry cache proxy, reached the open internet, and pulled evaluation solutions from Hugging Face's production database.

The conflict: the announcement and the docs describe different things

The marketing sentence and the engineering definition do not match, and the engineering definition is the one your contract inherits.

OpenAI's data controls documentation defines ZDR mechanically: it "excludes customer content from abuse monitoring logs in the same way as Modified Abuse Monitoring," and it forces the store parameter on /v1/responses and /v1/chat/completions to false even when a request sets it to true. Then comes the sentence most buyers miss: "the endpoints and capabilities listed as No for Zero Data Retention Eligible in the table below may still store application state, even if Zero Data Retention is enabled."

That is the whole story. ZDR is an abuse-log control plus one forced parameter. It is not a platform-wide guarantee.

Endpoint ZDR eligible Application state retention
/v1/chat/completions Yes, with limitations None, with exceptions
/v1/responses Yes, with limitations None, with exceptions
/v1/embeddings Yes None
/v1/realtime Yes None
/v1/moderations Yes None
/v1/assistants No Until deleted
/v1/vector_stores No Until deleted
/v1/files No Until deleted
/v1/batches No Until deleted
/v1/videos No 48 hours, then 30 days

The pattern is consistent: any endpoint that holds server-side state for you is ineligible. Conversations, ChatKit threads, Assistants and its four thread endpoints, vector stores, files, fine-tuning jobs, evals and batches all retain "until deleted." Objects related to the Assistants API are deleted 30 days after you delete them through the API or dashboard; objects you never delete "are retained indefinitely."

/v1/videos goes further. It is "currently blocked for MAM or ZDR requests," and the documented workaround is to run it in a project whose retention setting is explicitly None, which is to say with the control switched off.

Four limits that survive a ZDR contract

CSAM-flagged images are retained regardless. The docs are unambiguous: "If the classifier detects potential CSAM content, the image will be retained for manual review, even if Zero Data Retention, Modified Abuse Monitoring, or Eyes Off is enabled." Brian Levine, executive director of FormerGov, put it to CSO Online: "Zero is never quite zero because CSAM-flagged content is still retained for legal reporting."

OpenAI reserves the right to withdraw eligibility per model. Two named carve-outs, Eyes Off and Safety Retention, both open with the same clause: OpenAI reserves the right "to make models ineligible for Zero Data Retention or Modified Abuse Monitoring for specific customers, as notified in advance to the impacted customers in writing." Under Safety Retention, triggered where "reasonably necessary to investigate or prevent severe risk activity," OpenAI may retain and human-review content its classifiers flag.

ZDR is approval-gated, not self-serve. The docs say these controls "are subject to prior approval by OpenAI and acceptance of additional requirements," and direct you to sales. Configuration only becomes self-serve afterwards, under Settings, Organization, Data controls. OpenAI has not published eligibility criteria.

ZDR stops at your network boundary. Data sent to an MCP server "is subject to their data retention policies," and the same applies to any third-party service reached over a network connection. Prompt caching may hold encrypted key/value tensors in GPU-local storage for up to 24 hours. Background mode writes response data to disk for roughly 10 minutes. Audio outputs persist for 1 hour to support multi-turn conversation.

India-specific considerations

For Indian buyers the residency table is where the money and the compliance risk both sit. OpenAI lists ten regions. The United States, the EEA plus Switzerland, and the United Arab Emirates support regional processing. India does not. in.api.openai.com gives storage at rest in India while inference happens elsewhere, and the docs state that where a region lacks regional processing, "OpenAI may also process and temporarily store Customer Content outside of the Region to deliver the services."

Two further conditions apply. Any non-US region requires prior approval for abuse-monitoring controls plus execution of a Modified Retention amendment. And residency endpoints "are charged a 10% uplift for models released on or after March 5, 2026."

Requirement What OpenAI provides What the Indian buyer still owns
Storage in India in.api.openai.com, storage at rest only Inference location; approval and amendment
Retention of processing logs Deletes under ZDR Rule 8(3) minimum of one year
Cross-border transfer Permitted by default under Rule 15 Central Government general or special orders
SDF localisation No India-region inference Rule 13(4) restriction on specified data and traffic data
Annual assurance Not covered Rule 13(1) DPIA and audit every twelve months

Rule 15 of the DPDP Rules 2025 sets a permissive default: personal data may be transferred outside India, subject to requirements the Central Government may specify "by general or special order." No such order has been published, so the transfer itself is not the immediate problem.

Rule 8(3) is. It requires a Data Fiduciary to retain, for processing done by it or by a Data Processor on its behalf, "such personal data, associated traffic data and other logs of the processing for a minimum period of one year." Its second illustration is exactly this case: a company engaging a cloud provider as Data Processor must ensure the provider also retains data and logs for at least one year. A ZDR deployment that deletes everything at the vendor does not discharge that duty. It moves it to you.

Rule 13 raises the stakes for anyone notified as a Significant Data Fiduciary: an annual Data Protection Impact Assessment and audit, a report of significant observations to the Data Protection Board, due diligence that algorithmic software is "not likely to pose a risk to the rights of Data Principals," and, for personal data the Central Government specifies, a bar on transferring that data and "the traffic data pertaining to its flow" outside India. Penalty exposure for a Section 10 breach runs to ₹150 crore. The enforcement timeline puts rules 3 and 5 to 16 in force eighteen months after the 13 November 2025 gazette, which lands in May 2027.

If you are a payments Data Fiduciary, the RBI's 2018 circular on storage of payment system data already requires that payment data be stored only in India. An India region that stores but does not process does not satisfy that on its own. Teams working through this usually need a data residency and DPDP cloud architecture review before the vendor contract is signed, not after.

What to do this quarter

Start with an endpoint inventory, because that is where the gap is measurable. List every OpenAI endpoint your services call, mark each against the eligibility column, and treat the 14 ineligible ones as retained-by-default until you prove otherwise. Anything on /v1/assistants or /v1/threads needs to move anyway, so fold that work into your Assistants to Responses migration.

Then separate the two retention clocks. The vendor clock is what OpenAI deletes. The regulatory clock is what you must keep. Rule 8(3) sets the second at a year, and it applies to your logs, not OpenAI's. Most teams discover they were relying on the vendor for evidence they are legally required to hold themselves.

Redact before the call rather than arguing about retention after it. PII redaction before the LLM call removes the identifiers from the request, which is the only control that survives a change in vendor policy, a Safety Retention notice, or a model being declared ZDR-ineligible. The same logic drives the wider pattern in privacy-first AI architecture and belongs in your DPDP engineering playbook.

Finally, price it. A non-US region adds 10% for models released on or after 5 March 2026, on top of an approval process with no published criteria and an amendment to execute. That is a procurement timeline, not a config change.

What is still unknown

OpenAI has not published ZDR eligibility criteria, and the Private Safety Processing white paper is not out. Justin St-Maurice, technical counselor at Info-Tech Research Group, told CSO Online: "stop treating these announcements as diligence. Ask for the evidence of what you're actually getting, not what you've been promised." That is the correct posture until September.

Three things are worth writing into a contract now: whether Private Safety Processing applies to your organisation by default or by election, what "narrowly defined signal" contains in practice, and what notice period applies before a model is declared ZDR-ineligible under the Safety Retention clause. The docs say notice is "in advance" and "in writing." They do not say how far in advance.

FAQ

How eCorpIT can help

We design AI systems aligned with DPDP requirements, mapping every model call to an endpoint eligibility position and a retention owner before contracts are signed. eCorpIT is ISO 27001:2022 certified and CMMI Level 5 appraised, and our senior engineering teams build the redaction, logging and residency controls that stay yours regardless of vendor policy. Talk to us through /contact-us/.

References

  1. OpenAI, Offering Zero Data Retention for frontier models, 19 August 2026.
  1. OpenAI, Data controls in the OpenAI platform, API documentation, accessed 20 August 2026.
  1. OpenAI, Pacing model development in an era of cyber-critical capabilities, 18 August 2026.
  1. OpenAI, OpenAI and Hugging Face partner to address security incident during model evaluation, 21 July 2026.
  1. Evan Schuman, OpenAI 'temporarily slows' scaling efforts, also promises zero data retention for select frontier model customers, CSO Online, 19 August 2026.
  1. Evan Schuman, Original version of the same report, Computerworld, 19 August 2026.
  1. DPDPA.com, Rule 15, DPDP Rules 2025: transfer of personal data outside the territory of India.
  1. DPDPA.com, Rule 13, DPDP Rules 2025: additional obligations of Significant Data Fiduciary.
  1. DPDPA.com, Rule 8, DPDP Rules 2025: time period for specified purpose to be deemed as no longer being served.
  1. DPDPA.com, DPDPA 2023 and DPDP Rules 2025 enforcement timelines, gazette notification G.S.R. 843(E).

Last updated: 20 August 2026.

Frequently asked

Quick answers.

01 Does Zero Data Retention mean OpenAI stores nothing?
No. ZDR excludes customer content from abuse-monitoring logs and forces the store parameter to false on two endpoints. OpenAI's documentation states that endpoints marked ineligible may still store application state even when ZDR is enabled, and 14 of the 25 listed endpoints carry that mark.
02 Which OpenAI endpoints are not eligible for Zero Data Retention?
Conversations, conversation items, ChatKit threads, Assistants, threads, thread messages, thread runs, run steps, vector stores, files, fine-tuning jobs, evals, batches and videos. Every one of them holds server-side state on your behalf. Most are documented as retaining application state until you explicitly delete the object.
03 Is any content retained even under Zero Data Retention?
Yes. Image and file inputs are scanned on submission, and OpenAI's docs state that content flagged by the CSAM classifier is retained for manual review even when Zero Data Retention, Modified Abuse Monitoring or Eyes Off is enabled. OpenAI cites a legal reporting obligation for that exception.
04 Can an Indian company get OpenAI inference inside India?
Not today. OpenAI lists India as a data residency region for storage at rest, but regional processing is supported only in the United States, the EEA with Switzerland, and the United Arab Emirates. Where a region lacks processing, OpenAI may process and temporarily store content outside that region.
05 What does Zero Data Retention cost in a non-US region?
Data residency endpoints carry a 10% price uplift for models released on or after 5 March 2026 that are eligible for residency. Any region other than the United States also requires prior approval for abuse monitoring controls and execution of a Modified Retention amendment with OpenAI.
06 Does ZDR satisfy DPDP retention obligations?
No, and it can work against you. Rule 8(3) of the DPDP Rules 2025 requires a Data Fiduciary to retain personal data, associated traffic data and processing logs for a minimum of one year, including where a Data Processor handles the processing. Vendor deletion does not discharge that duty.
07 What is Private Safety Processing?
A system OpenAI previewed on 19 August 2026 that analyses patterns across related interactions without giving OpenAI staff access to the underlying content. When a risk is found, OpenAI receives a narrow signal describing the activity type. Rollout and a technical white paper are planned for September 2026.
08 When do the DPDP obligations actually bite?
Rules 3 and 5 to 16 of the DPDP Rules 2025 come into force eighteen months after the 13 November 2025 gazette, landing in May 2027. Significant Data Fiduciaries then face annual impact assessments and audits under Rule 13, with Section 10 penalty exposure of ₹150 crore.

About the author

Manu Shukla

Founder & Director

Founder of eCorpIT. Hands-on engineer leading senior-only delivery for AI apps, custom software, and cloud systems for global clients.

Subscribe

One engineering note a week. No fluff, no spam.

Senior-architect playbooks on AI agents, mobile apps, cloud, security, data, and marketing — delivered every Wednesday.

Past the reading

Read enough. Let's build something.

A senior architect responds in 24 working hours with scope, indicative cost, and a timeline. NDA before any technical conversation.