Zero Data Retention (ZDR) Explained — Three Catch Points

Glossary #7. When we added the Amazon Bedrock data-handling note to China AI on September 25, 2026, readers asked the obvious follow-up: “It says ZDR — so my data is never stored, right?” The answer is no. This page takes ZDR (zero data retention) and ZOA (zero operator access) out of that vendor-specific context and treats them as shared industry vocabulary. Sources are vendor documentation only. We also list the published exception lists of models that require retention.

ZDR (zero data retention) means “we don’t store it.” But it is “not stored by default” — not “always on.”

AWS writes it plainly: “uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs.” The two words “by default” carry the whole argument. Three things trip people up: ① some models sit on an exception list that requires retention, ② a guarantee needs an explicit setting, and ③ “not stored”, “operators can’t see it” and “not used for training” are three different promises.

● Last updated:  |  Policy: we publish only what we verified verbatim in vendor documentation. No “it is generally understood that” here

Remember three words: default, exception, explicit

Almost all ZDR confusion collapses into these three words. You do not need to memorise the long version.

① Default

Normally it is not stored. That is the default data security model. Assuming “everything is always stored” leads to over-engineering in the other direction.

② Exception

Some models must be retained. For abuse detection, some models are kept for up to 30 days. The scope differs by model — from classifier-flagged traffic only (Bedrock’s OpenAI models) to all traffic with possible human review by AWS (the Claude Fable 5 models).

③ Explicit

If you need a guarantee, you state it. “It’s the default” is not a guarantee; a configuration value or a contract term is.

📝 An analogy (not a technical definition)

The same reason evacuation drills use short mottos: if it is not short enough to recall, it will not be used under pressure. “Default, exception, explicit” plays that role here. A motto is a memory aid, not a definition. In an actual contract, the wording in the vendor’s documentation governs.

Figure: ZDR governs step ③, storage

What ZDR and ZOA each cover A three-step diagram: send input, process it, store it. ZOA covers the processing step, meaning no operators can see the content. ZDR covers the storage step, meaning nothing is stored by default. Not using data for training is a separate clause. ① Send Prompts and files are sent to the provider This part is your action ② Process The model runs inference ZOA covers this step No operator can see it ③ Store Does it stay on disk? ZDR covers this step Not stored by default A separate clause: “not used for training” “Not stored” = ZDR. “Operators cannot see it” = ZOA. “Not used for training” = a training-use limit. Three separate promises; one does not imply another. Exception: some models are retained up to 30 days for abuse detection; the scope differs by model

← Scroll horizontally on narrow screens

Created by LLM Data Hub. A conceptual map of three terms, not a description of any provider’s implementation.

The most common mix-up: three separate promises

ZDR = zero data retention

about storage

Request and response data is not retained at rest. AWS verbatim: “by default, Amazon Bedrock does not store model inputs or outputs.” Data obviously still passes through memory while the request is processed.

ZOA = zero operator access

about visibility

No human operator at the provider can access the content. AWS verbatim: “no operators of the service can access model input or output.” This is a different axis from storage. And even under ZDR, automated safety checks keep running — Anthropic states it “still retains User Safety classifier results.”

“Not used for training”

about training use

Your data is not used to train or improve the models. This is often the API default and is independent of ZDR. AWS: “will not use any inputs to or outputs from Amazon Bedrock to train …”. Google: “Google won’t use your data to train or fine-tune any AI/ML models without your prior permission or instruction.” Training exclusion frequently applies even without ZDR — which is exactly why the two get conflated.

💡 Why does retention happen at all?

The reason is almost always abuse detection. Attacks that are invisible one request at a time (distributed jailbreak attempts, coordinated misuse) can only be found by comparing requests over a window of time. Hence the carve-out: retention for safety only, for a limited period. That carve-out is what a retention-required model is — a model the provider keeps outside ZDR so that abuse detection can run. What is retained differs by model: flagged traffic only, or all traffic, and in one Bedrock case with possible human review. The published lists are below.

Five providers: default vs. gated changes everything

“ZDR” can mean you get it with no action (default) or you must be approved (gated). The table below uses only the wording in each vendor’s own documentation.

ProviderDefault retentionHow you get ZDRWhat it does not cover (stated officially)
Amazon Bedrock Documented as “by default … does not store” (ZOA/ZDR data security model) The default. For a guarantee, set the retention mode to none explicitly (account level or project level, per Region). The default for new accounts is inherit, which defers to a broader scope Retention-required models (exception list below). Customers eligible for Enterprise Frontier Safeguards get ZDR only through December 31, 2026
OpenAI Abuse-monitoring logs up to 30 days. The Responses API also keeps application state for 30 days by default (store defaults to true) Gated. Only customers approved for Zero Data Retention or Modified Abuse Monitoring (not the default) Coverage varies by endpoint. With ZDR enabled, store is always treated as false even if a request sets it to true
Anthropic Conversation content is not retained by default (official wording); the exception is Covered Models, which require 30-day retention. No training on your data by default On request, per organisation (via your account representative). Official wording: “ZDR is available on request” — there is no self-serve toggle Claude Console (including playground), Claude Teams and Claude Enterprise chat interfaces, Claude for Excel, Claude Managed Agents (transcripts persist until deleted), and Covered Models. Even under ZDR, safety classifier results are retained
Google Cloud
(Gemini)
Prompts and responses are logged for a limited period for abuse detection on paid services Customer action required. Official wording: “To achieve zero data retention, customers must take specific actions” — ① opt out of abuse-monitoring logging ② disable data caching ③ set store=false explicitly Grounding with Google Search and Maps: official docs state there is no way to disable the storage. For the Gemini Developer API, Google says workloads needing guaranteed ZDR should use Vertex AI
Microsoft Foundry
(Azure OpenAI)
For abuse monitoring, a sample of flagged prompts and completions may be retained in a store used for human review Gated (approval for modified abuse monitoring). Official wording: “If the customer has been approved for modified abuse monitoring … the data storage and human review process described above is not performed” Even after approval, automated review continues: “However, automated review may still be conducted.” Stateful features such as Files, vector stores and Stored Completions are stored separately by design

※ Sources are the official documents listed at the bottom. The “does not cover” column is our summary of enumerated exclusions — always read the original.

The exception lists: models that require retention

This is the core of the page. ZDR is decided not only by your contract but per model. Some models are excluded from ZDR and retained for abuse detection — and both the reason and the scope (flagged traffic only vs. all traffic, with or without possible human review) differ from model to model.

ProviderModels requiring retentionWhat actually happens
Amazon
Bedrock
OpenAI: GPT-6 Astra, GPT-5.4, GPT-5.5, GPT-5.6 Sol / Terra / Luna, Daybreak Red: GPT-5.6 Cyber, Daybreak Blue: GPT-5.6 Sol
Anthropic: Claude Fable 5 and Claude Fable 5.1
For the OpenAI models, only classifier-flagged traffic is retained for up to 30 days (eligible customers may request full ZDR via their AWS account team).
For Claude Fable 5 and 5.1, all traffic is retained up to 30 days, and flagged traffic is subject to possible human review by AWS (the aws_review mode is required)
Anthropic
(direct / other clouds)
Covered Models: Claude Fable 5.1, Mythos 5.1, Fable 5, Mythos 5 Verbatim: “These models require 30-day data retention and are not available under ZDR unless expressly authorized by Anthropic.” You enable retention only for the workspace that needs those models; your other workspaces keep ZDR

📌 Models not on the exception list as of September 27, 2026

We fetched the Bedrock abuse-detection page the same day and read the full list. Kimi K3 and MiMo-V2.6 are not on it — meaning Bedrock imposes no retention requirement for them. But the list grows. New frontier models get added, so check the official page once before signing and once after onboarding.

Practical checks: six common questions

If a model is advertised as “ZDR-compatible”, is my data not stored?
No. “Compatible” usually means the option exists, not that it is on by default. OpenAI, Anthropic and Microsoft are gated or on request; Google requires customer action. Check both the setting and the contract.
If nothing is stored, does that mean no one can read it?
Different promise. Not stored = ZDR; operators cannot access it = ZOA. ZDR is about not writing to durable storage; it does not by itself prohibit access during processing. Verify both.
Is “not used for training” stronger than ZDR?
They are not comparable — they protect different things. One limits training use, the other limits retention. On most APIs the training exclusion is already the default, while retention is governed separately.
Which models become unavailable if I enable ZDR?
Only the retention-required models on the exception list. On Anthropic you enable retention only for the workspace that needs a Covered Model, leaving other workspaces on ZDR. On Bedrock it shows up as none being insufficient for those models, where aws_review is required.
ZDR is on, yet someone says data is still retained. Why?
Three usual causes. ① Stateful features — stored responses, Files API, vector stores, agent session transcripts are retained by design. ② Caching — Google keeps in-memory cached data for 24 hours and states this “does not violate zero data retention.” ③ Safety classifier results — Anthropic states these are retained. Treat ZDR as covering the retention done for abuse monitoring, not every byte in the system.
Can a setting silently fail to apply?
Yes. Retention settings are per Region and per account, with inherit as the default for new accounts on Bedrock. Using an API key in another Region, or adding a project, puts you outside the scope you configured. Send one real request after onboarding, and again after any configuration change.

Sources (all verified September 27, 2026)

Related: Glossary index · China AI (Bedrock data handling note) · Harness (#3) · What benchmarks are (#5) · Who operates the benchmarks (#6) · The four data requirements (#8) · ZOA (#9) · No-training (#10) · Data residency (#11) · Prompt cache (#2)

⚠️ Limits of this page

  • Everything here reflects vendor documentation as of September 27, 2026. Retention policies and exception lists change without notice.
  • The three-word summary and the “does not cover” column are our editorial framing, not a vendor taxonomy. Base contractual decisions on the original wording.
  • This page is not legal or compliance advice. Consult a professional for regulatory decisions.
  • We are not affiliated with any provider.