Cloudflare Workers AI API zero data retention: terms and exceptions
ZDR 3.0 (f) · B
Short answer
No training and no service-improvement use of Customer Content without consent. Docs do not state a prompt-log deletion window. R2, KV, Durable Objects, and Vectorize persist content by design. Inference-payload logging is unspecified.
Scope and evidence
| Provider | Cloudflare |
|---|---|
| Service | Workers AI API |
| Lane | API default |
| Origin | |
| License | open-weight |
| Hosting | Self-host |
| Score | ZDR 3.0 (f) · B No-training. No training, but retention unbounded or unspecified |
| Evidence | Public documentation reviewed (B: published documentation) |
| Source-review date | 2026-08-25 |
Other lanes for Cloudflare
Structured breakdown
- Default posture
- No training and no service-improvement use of Customer Content without consent. Docs do not state a prompt-log deletion window.
- Exceptions and carve-outs
- R2, KV, Durable Objects, and Vectorize persist content by design. Inference-payload logging is unspecified.
Approval and setup path
Approval and setup path not yet reviewed.
Flags on this record
- f
- stateful-feature carve-outs (files, batch, threads, caching, grounding)
Practical questions for your agreement
- Does your signed agreement cover this exact service, model set, and feature path?
- Which retention, logging, and human-review exceptions still apply after any ZDR election?
- What configuration evidence (flags, project settings, store defaults) confirms the posture you expect?
- Do your customer commitments match what the reviewed evidence supports?
Does your agreement cover this deployment?
We can review the relevant terms, feature choices, and customer commitments, then help your team identify what to clarify or negotiate.
Sources
Trust and security
- Trust Hub cloudflare.com
- Compliance cloudflare.com
Posture ledger
seeded
ZDR 3.0 (f) · B
Seeded from published documentation.
Full key on the scale. Method notes on methodology. Notation is always ZDR 1.0 (s,f,r) · A.