xAI first-party API, default zero data retention: terms and exceptions

ZDR 2.0 · B

Short answer

30d encrypted storage of content unless the ZDR toggle is on. Audit event logs continue under both postures.

Scope and evidence

ProviderxAI
Servicefirst-party API, default
LaneAPI default
OriginUnited StatesUS United States
Licenseproprietary
HostingProvider-hosted
Score ZDR 2.0 · B Bounded retention. Content retained a defined window (<=90d) for abuse monitoring, possibly human-reviewed, then deleted
EvidencePublic documentation reviewed (B: published documentation)
Source-review date2026-08-25

Other lanes for xAI

Structured breakdown

Default posture
30d encrypted storage of content unless the ZDR toggle is on.
Exceptions and carve-outs
audit event logs continue under both postures

Approval and setup path

self-serve ZDR toggle; confirmed via x-zero-data-retention header

Flags on this record

No exception flags on this record.

Practical questions for your agreement

  • Does your signed agreement cover this exact service, model set, and feature path?
  • Which retention, logging, and human-review exceptions still apply after any ZDR election?
  • What configuration evidence (flags, project settings, store defaults) confirms the posture you expect?
  • Do your customer commitments match what the reviewed evidence supports?

Does your agreement cover this deployment?

We can review the relevant terms, feature choices, and customer commitments, then help your team identify what to clarify or negotiate.

Speak to a ZDR expert about xAI

Sources

  1. https://docs.x.ai/developers/faq/security

Trust and security

Posture ledger

seeded

ZDR 2.0 · B

Seeded from published documentation.

Full key on the scale. Method notes on methodology. Notation is always ZDR 1.0 (s,f,r) · A.