What OpenAI announced
OpenAI published an update on August 19 describing its commitment to Zero Data Retention for eligible API customers. Under ZDR, the company says prompts and responses are not retained after a request is processed and are unavailable to OpenAI personnel for review.
The company also reiterated that enterprise data is not used to train models unless the customer opts in. These statements address two different questions: whether content is retained for operational purposes and whether it is used for model training.
Private Safety Processing
OpenAI describes Private Safety Processing as a preview designed to identify harmful patterns across interactions without giving personnel access to the underlying customer content. The architecture attempts to reduce the privacy tradeoff that can arise when abuse monitoring depends on storing readable requests.
A preview should be evaluated as an evolving control. Customers need documentation for eligible models and endpoints, failure behavior, legal terms, audit evidence and any circumstances in which metadata or content may still be processed differently.
ZDR is a scoped setting, not a slogan
Teams should confirm that every feature in a workflow is compatible with ZDR. File storage, asynchronous jobs, assistants, logs or third-party integrations can have different retention behavior from a synchronous model request.
Create a data-flow diagram that follows content from the user's device through gateways, observability tools, model providers and downstream storage. A zero-retention setting at one layer cannot erase copies written by another.
Customer responsibilities remain
Send only the data required for the task, redact unnecessary identifiers and enforce role-based access to prompts and outputs. Where sensitive data is unavoidable, define an approved purpose, retention rule and deletion process before the workflow launches.
Operational logs should record request identifiers, configuration and performance without duplicating sensitive content. This lets teams investigate failures while reducing the amount of raw information available to attackers or internal misuse.
Questions for procurement and security review
Ask which endpoints qualify, how eligibility is approved, what metadata persists, where processing occurs and what independent assurance is available. Document the exact configuration tested rather than relying on a general product statement.
The announcement is meaningful because it pushes privacy controls closer to model execution. Its real value will depend on transparent scope, reliable enforcement and whether customers integrate it into a broader program of minimization, access control and accountable review.
Sources & further reading
Social-media activity is treated as a signal of attention, not proof. Product claims are attributed to the linked publisher or announcement.