Woman using a laptop in a server room, showcasing modern technology and work environment.

Photo by Christina Morillo on Pexels

For API users, OpenAI and Anthropic generally start from limited retention measured in weeks, with zero data retention available only for eligible customers, models, or endpoints. Google requires a sharper product distinction: Gemini API terms and Vertex AI controls differ, so “Google retention” cannot be reduced to one number.

In 1999, NASA lost the Mars Climate Orbiter after one engineering team used imperial units while another expected metric units. The spacecraft reached Mars, but the mismatch sent it dangerously close to the planet and the mission ended. NASA documented the failure in its Mars Climate Orbiter Mishap Investigation Board Phase I Report.

The lesson was larger than unit conversion. Two groups used familiar words and interfaces while carrying different assumptions about what those interfaces meant.

AI data policies create the same class of risk. “Not used for training,” “deleted after 30 days,” and “zero data retention” describe different controls. Treating them as interchangeable can turn a procurement checkbox into a production data incident.

The comparison procurement teams actually need

OpenAI’s API policy has typically allowed abuse-monitoring logs containing prompts and responses to be retained for up to 30 days. Approved customers can request Modified Abuse Monitoring or Zero Data Retention, but support varies by endpoint and feature. Some capabilities may store application state because the product cannot work without it.

That last distinction matters. A zero-retention setting for model inputs does not automatically erase files, conversation objects, vector stores, batches, or other stateful resources created by the customer. Teams need to check both the model’s logging behavior and every API object used around it.

Anthropic’s commercial API terms have also generally used a retention window of up to 30 days for inputs and outputs, subject to exceptions such as policy enforcement, legal obligations, or customer feedback. Anthropic offers zero data retention arrangements for eligible API customers, including access tied to particular commercial agreements and supported configurations.

Google is harder to compare because developers can reach Gemini models through different services. The Gemini API, often used through Google AI Studio, and Gemini on Vertex AI sit under different terms and administrative controls. Paid and unpaid use may also receive different treatment, particularly around whether submitted content can help improve Google products.

For a company handling customer records, source code, legal documents, or support transcripts, “we use Gemini” is therefore incomplete. The useful question is: which Google service, under which billing state, contract, region, model, and logging configuration?

Policies also change. Before approving a deployment, verify the current provider documentation and signed terms rather than relying on a comparison article, including this one.

Zero retention has boundaries

Zero data retention sounds absolute. Operationally, it is usually a scoped promise.

The scope may depend on the account rather than the API key. It may cover prompts and outputs while excluding stored resources. It may apply to one endpoint and fail when a developer adds file search, asynchronous processing, caching, or a third-party observability tool.

The rest of the request path matters too. An application can use a provider’s zero-retention configuration while copying every prompt into its own logs. An API gateway may record request bodies. An error tracker may capture a full payload when a call fails. A support agent may paste the same data into a ticket.

This is why a vendor’s retention setting should sit inside a data-flow review. Our guide to safely launching an Anthropic API support agent covers the adjacent controls that a provider policy cannot supply, including tool permissions and testing.

Build the comparison around evidence

Start with the data, not the model leaderboard. List what the application sends: public text, employee messages, customer identifiers, health information, payment data, source code, uploaded files, and retrieved documents. Remove fields the model does not need.

Then record the applicable control for each provider:

  • The exact service, model, endpoint, and account tier.
  • The default retention period for prompts, outputs, files, and stored objects.
  • Whether content is used for model improvement.
  • The eligibility and approval status for zero retention.
  • Features that are incompatible with the required setting.
  • Policy-enforcement and legal exceptions.
  • Deletion behavior for resources created through the API.
  • Logging performed by your own application and vendors.

Ask for evidence that can survive a security review: current documentation, account-level confirmation, contractual terms, configuration screenshots, and a dated test. A sales email saying “your data is private” cannot answer those questions.

Also separate retention from training. A provider may promise not to train on API data while retaining content temporarily for abuse detection. Conversely, deletion from one operational system does not prove immediate removal from every backup or legally required record. The words describe separate stages in the data lifecycle.

Test the deployed path before approval

Run a controlled request containing a harmless marker, then trace it through the application, gateway, provider configuration, monitoring tools, storage objects, and deletion workflow. Repeat the test when the team changes models or enables a new feature.

The Mars Climate Orbiter failed because a critical assumption crossed an interface without being verified. API buyers face a smaller-stakes version of that problem whenever one team says “zero retention” and another hears “nothing is stored anywhere.”

Put the exact meaning in the architecture record. Name the endpoint. Record the exception. Date the evidence. Then require a fresh review before any developer adds files, caching, background jobs, retrieval, or prompt logging.

Comments

No comments yet.