Blog

AI data retention in 2026: ChatGPT, Claude, and Gemini

AI data retention windows now run from zero to five years. The window that applies depends on the vendor, the product tier, the endpoint, and whether the user opted in. ChatGPT, Claude, and Gemini all rewrote their rules between 2025 and 2026, and Anthropic did it twice. Every one of them stores the prompts your employees send and the outputs their models return.

Your organization remains responsible for governing that data even when it is retained by an AI vendor. A single prompt pasted into a personal Claude account can sit in a five-year retention window, while the same content sent through an API with zero data retention (ZDR) leaves little behind beyond safety metadata.

This article takes each vendor in turn, using the same three tiers for all of them, then compares the results side by side. It closes with the exceptions that outlast every published window, the gap personal accounts open in enterprise coverage, and what to log on your own side.

Key takeaways

  • Retention depends heavily on the product tier and endpoint. Consumer services often permit training and longer storage, while enterprise and API offerings generally provide stricter controls.
  • Anthropic’s 2025 and 2026 changes add distinct trade-offs, including five-year retention for consumer training opt-ins and mandatory 30-day storage for Covered Models, even for customers with zero data retention agreements.
  • OpenAI and Google apply different exceptions across APIs, temporary chats, grounded search, abuse monitoring, and legal holds, so vendor-level comparisons alone are insufficient.
  • Effective governance pairs workload-to-tier mapping with enterprise visibility and enterprise-side audit records, since the vendor’s retention window and your own governance evidence are separate problems.

What an AI data retention policy covers across consumer, enterprise, and API tiers

An AI data retention policy covers how long a vendor stores prompts and outputs, who can access them, and when they are deleted. It also governs secondary use, including whether conversations feed model training and how long abuse-monitoring copies persist. Each of those answers can change from one tier to the next.

Consumer plans typically carry permissive training defaults, while enterprise and API tiers usually exclude customer data from training. Features like grounded search or uploaded files often run on separate schedules. Exceptions such as flagged content or litigation holds can extend retention beyond the advertised window.

Those exceptions shape what a regulator can audit, and they can also make retention exceptions an enterprise governance concern. The three vendor sections that follow use the same three tiers, so each vendor answers the same three questions. What happens by default on consumer plans, what changes at the enterprise tier, and what an API contract can and cannot remove.

Anthropic data retention across Claude and the Anthropic API

Anthropic revised its rules twice in short order: consumer training opt-ins landed in October 2025, and a mandatory 30-day window for Covered Models followed in June 2026. Both sit on top of an unchanged commercial baseline. The consumer change is the one that moved retention the furthest, while the Covered Model rule is the one that reaches even customers who negotiated retention away.

Consumer tiers: Claude Free, Pro, and Max

Consumer users now decide their own retention window. Since October 8, 2025, Claude Free, Pro, and Max users must choose whether their chats can train future models. Users who opt in accept a five-year retention period for that data. Users who opt out keep the 30-day standard.

Enterprise tiers: Claude for Work and Enterprise

The consumer change does not reach enterprise agreements. Anthropic’s exemptions cover Claude for Work, Team, Enterprise, Education, the API, and third-party cloud deployments, so none of those tiers face the five-year window. Enterprise customers can also configure custom retention periods, subject to a 30-day minimum.

API tiers, zero data retention, and Covered Models

The API baseline is 30 days with no training, and one carve-out survives even a zero-retention contract. Inputs and outputs follow a 30-day deletion policy, and Anthropic’s Commercial Terms bar training on customer content submitted through the Services. 

Approved API customers can negotiate zero data retention, though Anthropic still retains safety classifier results. Content flagged for Usage Policy violations is kept up to two years even under a ZDR or HIPAA arrangement, and the commercial retention policy holds trust and safety classification scores for up to seven years.

Covered Models carry their own floor. The policy applies on every platform where these models are offered, including Amazon Bedrock and Google Cloud. Under the Covered Model safeguards, the data is not used for training, human access is logged, and deletion usually follows after 30 days. ZDR customers can enable Covered Model access in a designated workspace while other workspaces stay at zero retention. Access to the newest models costs zero retention in whichever workspace runs them. 

OpenAI data retention across ChatGPT and the OpenAI API

OpenAI structures retention by tier and endpoint rather than by product surface. The training default flips between consumer and business plans, and the zero-retention option comes with a list of endpoints it does not cover.

Consumer tiers: ChatGPT Free and Plus

Consumer conversations train models unless the user intervenes. Free and Plus chats feed training by default, and opting out is a per-user action rather than an organizational setting. Temporary Chats carry a caveat too, since the Temporary Chat policy notes that OpenAI may still retain a copy for up to 30 days for safety purposes.

Enterprise tiers: Business, Enterprise, and Edu

Business plans reverse the consumer default. OpenAI’s enterprise privacy policy excludes Business, Enterprise, Edu, and API data from training by default, which makes tier selection the single highest-leverage retention decision an administrator makes.

API tiers and zero data retention

The API default is 30 days, and zero retention is available but conditional. API inputs and outputs may be retained up to 30 days for abuse monitoring. Zero data retention requires a qualifying use case and sales approval, and it is unavailable for several excluded API endpoints, such as /v1/conversations, /v1/conversations/items, /v1/chatkit/threads, and /v1/assistants. An application built on those endpoints cannot be brought under a ZDR agreement by contract alone.

Google data retention across the Gemini app, Workspace, and the Gemini API

Google structures retention by product surface, so the same underlying model carries different rules depending on where a user reaches it. The consumer app is the most permissive surface of the three vendors covered here, and the API adds a feature-level schedule that cannot be switched off.

Consumer tiers: the Gemini app

Consumer retention here is measured in months and years rather than days. The consumer Gemini app retains activity for an 18-month default and uses it to train models. Chats sampled for human review are kept up to three years, disconnected from the account, even after deletion.

Enterprise tiers: Gemini in Google Workspace

Workspace submissions sit outside both training and human review. Admins set Workspace retention settings ranging from 90 days to indefinite for Gemini in Workspace apps, which means the enterprise, rather than Google, decides how long the record lives.

API tiers and zero data retention

The API splits by billing tier, and grounding runs on its own clock. The free tier holds data for an abuse monitoring window of 55 days and uses it for product improvement. The paid tier makes that window configurable up to 55 days and excludes training. The paid tier also applies 30-day grounding retention to Grounding with Google Search prompts, with no option to disable it, and paid API ZDR is available by request.

How the three retention policies compare

Read across the tiers rather than down the vendors. The consumer row is where the three diverge most, while their enterprise and API rows converge on a similar 30-day, no-training posture with different exceptions attached.

AnthropicOpenAIGoogle
Consumer default30 days, or up to 5 years with a training opt-inTrains by default unless the user opts out18 months, used for training
Enterprise defaultConfigurable, 30-day minimumExcluded from training90 days to indefinite, admin-set
API default30 days, no trainingUp to 30 days for abuse monitoring55 days free tier; configurable on paid
ZDR availableYes, for approved API customersYes, with a qualifying use caseYes, on the paid API by request
Carve-out to watchCovered Models keep a 30-day floorSeveral endpoints are excludedGrounding storage cannot be disabled

The pattern across the row for enterprise and API tiers is convergence on paper and divergence in the fine print. Every vendor will contract away routine retention, and every vendor keeps something back.

Why the published window is not the last word

A published deletion date holds only until an exception overrides it, and three categories of exception apply in some form at all three vendors. None show up in a tier comparison, so a vendor-level answer to “how long is our data kept” tends to be wrong in exactly the cases that matter most: 

  • Safety and abuse copies. Content flagged by a classifier follows a separate, longer schedule than ordinary conversation data. Anthropic’s flagged-content window runs to years while its standard window runs to days, and a zero-retention agreement generally does not reach this category.
  • Feature-level schedules. Capabilities layered on top of a model frequently retain data on their own clock, as Google’s non-disableable grounding storage shows. Auditing a vendor at the tier level misses these entirely, because they attach to the feature rather than the plan.
  • Legal holds and preservation orders. A court can compel a vendor to keep data its own policy would have deleted. A May 2025 preservation order in the New York Times litigation required OpenAI to preserve consumer and API output logs. ChatGPT Enterprise, Edu, and ZDR API customers sat outside it.

That last case is the clearest evidence that tier selection is a control rather than a formality. The preservation obligation ended on September 26, 2025, but for the months it ran, which tier a workload sat on decided whether deleted conversations were actually gone.

How personal accounts fall outside every enterprise retention setting

Every protection described above attaches to a plan the organization holds, so an employee working from a personal login sits outside all of them. These protections follow the contract, not the person, and much enterprise AI activity happens off-contract. 69% of organizations suspect or have evidence that employees are using prohibited public GenAI tools. 

Those interactions run under consumer terms, with permissive training defaults, multi-year retention windows, and no enterprise data processing agreement. Unreleased campaign copy pasted into a personal account sits in a consumer retention window, and an employee relations summary pasted into the same account sits there too. The retention period may not have been reviewed or approved by marketing, HR, or legal.

Since August 2, 2026, deployers of high-risk AI systems face a six-month logging requirement under the EU AI Act. An enterprise has little or no log evidence for interactions it never observed.

Turning retention policy sprawl into provable AI control

Sprawl turns into control once the mapping between workloads and retention tiers is written down, and into provable control once you hold records of your own. Vendor policies will keep changing, so run the same review each time: 

  1. Discover and inventory AI tools, account types, and endpoints. Classify the workloads that use them. Classify the workloads that use them.
  2. Map workloads to approved retention tiers. Isolate ZDR workloads from endpoints with mandatory retention.
  3. Define enterprise log-retention periods. Schedule periodic vendor-policy reviews to keep the mapping current.

Approached this way, retention policy changes stop being one-off fire drills and become routine control updates tied to a known inventory. Each vendor revision maps to a specific workload group, so security, legal, and compliance teams can adjust settings quickly. When regulators or internal reviewers ask how AI data is handled, the audit evidence is already there.

Schedule a demo to see how WitnessAI helps enterprises discover AI usage, gain visibility across vendors, models, and account types, and build consistent AI governance regardless of retention policy differences.

FAQs about AI data retention across ChatGPT, Claude, and Gemini