OpenAI first-party API, default zero data retention: terms and exceptions
ZDR 2.0 (f,h) · B
Short answer
Abuse logs incl. content <=30d; Responses API stores state 30d (store defaults true); no training. Stateful endpoints retained until deleted; assistants objects indefinitely.
Scope and evidence
| Provider | OpenAI |
|---|---|
| Service | first-party API, default |
| Lane | API default |
| Origin | |
| License | proprietary |
| Hosting | Provider-hosted |
| Score | ZDR 2.0 (f,h) · B Bounded retention. Content retained a defined window (<=90d) for abuse monitoring, possibly human-reviewed, then deleted |
| Evidence | Public documentation reviewed (B: published documentation) |
| Source-review date | 2026-08-24 (registry) |
Other lanes for OpenAI
Structured breakdown
- Default posture
- abuse logs incl. content <=30d; Responses API stores state 30d (store defaults true); no training
- Exceptions and carve-outs
- stateful endpoints retained until deleted; assistants objects indefinitely
Approval and setup path
sales-gated approval; tiers: Modified Abuse Monitoring, ZDR
Flags on this record
- f
- stateful-feature carve-outs (files, batch, threads, caching, grounding)
- h
- human review possible
Practical questions for your agreement
- Does your signed agreement cover this exact service, model set, and feature path?
- Which retention, logging, and human-review exceptions still apply after any ZDR election?
- What configuration evidence (flags, project settings, store defaults) confirms the posture you expect?
- Do your customer commitments match what the reviewed evidence supports?
Does your agreement cover this deployment?
We can review the relevant terms, feature choices, and customer commitments, then help your team identify what to clarify or negotiate.
Sources
Trust and security
- Trust Portal trust.openai.com
- Security openai.com
Posture ledger
seeded
ZDR 2.0 (f,h) · B
Seeded from published documentation.
Full key on the scale. Method notes on methodology. Notation is always ZDR 1.0 (s,f,r) · A.