Zero Data Retention Defined
Zero data retention (ZDR) is an agreement or setting under which an AI model provider does not store the prompts and outputs sent through its API once a response is generated. ZDR limits who can access customer data, keeps it out of model training, and is a common enterprise requirement for AI vendors.
When a company uses an AI agent for customer service, customer messages travel from the company's systems to the AI vendor, and often from that vendor to a model provider. Security and legal teams want to know what happens to that data at every step. Zero data retention is one of the clearest answers a vendor can give.
What is zero data retention?
Zero data retention is a data-handling commitment in which an AI model provider processes a request and does not store its content afterward. The prompt (for example, a customer's question plus the context sent with it) and the model's output are used to produce the response and are not kept in logs, databases, or training datasets.
By default, many AI APIs keep request data for a limited period, commonly around 30 days, to monitor for abuse. Under a ZDR agreement, that retention is turned off for eligible services. ZDR usually comes with a separate but related commitment: the provider does not use the customer's data to train or improve its models.
ZDR covers the model provider's handling of data. It does not mean the AI vendor keeps nothing. A customer service platform still stores conversation history so that agents and customers can see it, under its own retention and deletion policies.
Why zero data retention matters
- Smaller attack surface: data that is never stored cannot be exposed in a breach at the model provider
- No training on customer data: customer conversations do not end up shaping a model other companies use
- Easier compliance: data minimization is a core principle of GDPR, and ZDR helps show that personal data is not held longer than needed
- Faster security reviews: enterprise buyers, especially in financial services, healthcare, and the public sector, often ask about ZDR in vendor questionnaires
How zero data retention works
- The request is sent: the AI vendor sends the prompt to the model provider over an encrypted connection.
- The model processes it in memory: the provider generates a response without writing the prompt or output to persistent storage.
- The response is returned to the vendor, which delivers the answer to the customer.
- Nothing is kept by the provider: the request content is discarded once the response is generated.
- Contracts back it up: ZDR is set out in the data processing agreement between the vendor and the provider, alongside restrictions on training.
For example, a bank evaluating an AI agent asks, "Will our customers' account questions be stored by your model provider?" A vendor with ZDR in place can answer no, point to the contractual terms, and describe what it stores itself and for how long.
Questions to ask AI vendors about data retention
- Which model providers process our data, and do all of them operate under ZDR?
- Is our data used to train any models, yours or a provider's? Can we opt out?
- What conversation data do you store, where, and for how long?
- How do deletion requests work, and how quickly is data removed?
- Which certifications cover these controls, such as SOC 2 Type II, ISO 27001, or ISO 42001?
How Fin handles data retention
Third-party AI providers used by the Fin AI Engine are contractually restricted from using customer data for model training and operate under zero data retention policies, so data is not stored once an output has been generated. Fin can use anonymized data for fine-tuning its own models, and customers can opt out at any time. More detail is on the trust and reliability page.
Frequently asked questions
Does zero data retention mean no data is stored anywhere?
No. ZDR usually applies to the model provider. The software vendor still stores conversation records for the product to work, governed by its own retention and deletion policies.
Is zero data retention required by GDPR?
Not directly. GDPR requires data minimization and storage limits, not ZDR specifically. ZDR is one practical way to meet those principles when using third-party AI models.