Training, storage, deletion, safety review, administrator access, and zero data retention are separate controls. A provider can promise not to train on business data while still keeping abuse-monitoring logs. Deleting a chat can start a backend deletion clock without erasing a file stored elsewhere. A zero-data-retention agreement can cover an eligible request path while a stateful API feature, connector, or remote tool creates another retention boundary.

That is why “Does Claude or OpenAI keep my data?” is the wrong first question. Start with the product, account type, model, endpoint, enabled features, and exceptions.

Six paths, six different answers

RouteTraining ruleOrdinary storage and deletionSafety, legal, and access boundaryZDR reality
Claude consumer plans and consumer-authenticated Claude CodeModel improvement is controlled in privacy settings. If enabled, Anthropic may keep de-identified chats or coding sessions in training pipelines for up to five years.Chats remain until you delete them; they disappear from history immediately and backend deletion follows within 30 days.Flagged inputs and outputs may remain up to two years, classifier scores up to seven years, and feedback data five years. Legal and Usage Policy exceptions apply.Consumer surfaces use standard retention, not a ZDR contract.
Anthropic commercial and API accessCommercial inputs and outputs are not used for model training by default unless the customer opts in or agrees otherwise.API inputs and outputs normally clear from Anthropic’s backend within 30 days. Saved conversations, Files API data, and other persistent features can last longer; approved agreements can differ.Usage Policy and legal exceptions apply. Managed products also sit under organization controls.Approved ZDR can apply to configured workspaces and routes, subject to model and feature rules.
Fable 5 and Mythos 5 Covered ModelsThe Covered Model policy changes retention, not the ordinary training promise.Prompts and completions have a 30-day minimum across every platform where the models are offered. Anthropic’s detailed policy says automatic deletion follows after 30 days except safety investigations and legal requirements.Automated review is standard; controlled human review can follow a safety flag. The rule follows the model across Anthropic and supported clouds.Unavailable wherever Covered Models are accessible. A separate workspace or another approved model is required for ZDR.
ChatGPT consumer and Temporary ChatConsumer users control whether chats help improve models.Normal chats remain until deletion; deletion schedules removal within 30 days. Archiving does not delete. Temporary Chats can still remain for up to 30 days.Security and legal obligations can extend retention. Files can have lifecycles independent of the chat.Temporary Chat is a consumer privacy mode, not an API ZDR agreement.
OpenAI business and API accessChatGPT business products and API data are not used for training by default.Default API abuse-monitoring logs can include prompts and responses for up to 30 days. Application state depends on the endpoint and feature.Law, protection from harm, approved-customer safety controls, managed-account administrators, and third-party tools create additional boundaries.ZDR and Modified Abuse Monitoring require approval. They do not make every endpoint, model, or feature stateless.
Locally run open-weight modelThe hosted model provider is removed from the inference path.Retention is controlled by your runtime and infrastructure.Local UIs, RAG databases, shell history, traces, telemetry, backups, cloud hosts, actions, and remote integrations can still keep prompts or outputs.“Local” is only genuinely local when inference, storage, logging, backups, and tools stay inside the environment.

Anthropic says consumer Free, Pro, and Max users—including consumer accounts using Claude Code—are “unaffected” by the Covered Model update because those surfaces already retain inputs and outputs under standard consumer rules. The material change is for commercial routes that previously used ZDR.

Anthropic: ordinary retention and the Covered Model override

For consumer Claude, deleting a conversation removes it from visible history immediately and Anthropic says backend deletion follows within 30 days. That deletion clock should not be confused with training retention. If the user enables model improvement, Anthropic may retain de-identified chats or coding sessions for up to five years in training pipelines. Incognito chats are excluded from training.

Safety and feedback are separate again. Anthropic says inputs and outputs flagged by automated trust-and-safety systems may be retained for up to two years, related classifier scores for up to seven years, and feedback submissions for five years. Legal requirements, dispute resolution, and Usage Policy enforcement can extend ordinary handling.

Commercial API traffic has a different baseline. Anthropic says it automatically deletes API inputs and outputs from its backend within 30 days, except when a customer uses a longer-lived feature such as Files, has an approved different agreement such as ZDR, or safety or law requires longer retention. Claude for Work and Enterprise products can keep saved conversations to provide product history until users or administrators delete them.

Fable 5 and Mythos 5 override an expected no-retention configuration. Anthropic’s Covered Models list says prompts and completions are retained for at least 30 days, ZDR is unavailable wherever a Covered Model can be accessed, and safety investigations or legal requirements can extend retention. The detailed Covered Model retention policy describes automated safety assessment by default, a controlled and logged path for human review after a flag, and automatic deletion after 30 days unless an exception applies.

The practical rule is simple: if Fable or Mythos is a requirement, accept the 30-day minimum and its exceptions or route the workload to another approved model.

Do not collapse “30-day minimum” into “kept forever.” The minimum expresses Anthropic’s model-wide safety window. The detailed policy describes deletion after that window, with safety and legal exceptions.

OpenAI: product, endpoint, and feature decide the result

OpenAI says consumer ChatGPT chats stay in an account until deletion. Deletion removes the chat from the account immediately and schedules permanent deletion within 30 days, subject to de-identification and security or legal exceptions. Archiving only hides a chat; it does not start deletion. Temporary Chat avoids saved history, but OpenAI can still retain it for up to 30 days.

Files are a common trap. OpenAI’s current retention guidance says files stored in the ChatGPT Library are managed separately, so deleting the conversation that introduced a file does not necessarily delete the Library copy. Project and custom-GPT files can persist until the parent object is deleted. Enterprise file expiry and backup windows can also differ from conversation retention.

For business products and the API, “not trained on by default” is not “never stored.” OpenAI says API abuse-monitoring logs may contain customer prompts, responses, and derived classifier metadata for up to 30 days by default, unless law or protection from harm requires longer. Application state is a second store whose lifetime depends on the API route.

Three API examples

OpenAI routePractical retention implication
/v1/chat/completionsZDR eligible and forces store=false. Ordinary use has up to 30-day abuse logs, with narrower audio-output, prompt-cache, image, and file exceptions.
/v1/responsesZDR forces store=false. Without ZDR, response state is retained for at least 30 days by default or with store=true; background mode, audio, caching, containers, files, remote MCP, and other third parties have separate lifecycles.
Conversations, ChatKit threads, and Assistants objectsZDR-ineligible. Conversations and ChatKit state can persist until explicitly deleted. Assistants-family objects persist until deletion and OpenAI documents a 30-day removal window after deletion for those objects.

The governing lesson is: ZDR excludes customer content from specified logging and storage paths; it does not turn every API feature into a stateless request.

Safety retention is not one universal model class

The current OpenAI data-controls guide describes two notice-based controls for customers already approved for ZDR or Modified Abuse Monitoring:

  • Anthropic Covered Models: a named public model list with mandatory model-wide retention across customers and platforms.
  • OpenAI Eyes Off: OpenAI may make a model ineligible for ZDR or MAM for a specific customer with advance written notice. Retained customer content is excluded from human review unless law requires it.
  • OpenAI Safety Retention: OpenAI may make a model ineligible for a specific customer when reasonably necessary to investigate or prevent severe-risk activity, again with advance written notice. Classifier-flagged content may then be retained and human-reviewed when necessary.

Both providers preserve safety-related exceptions to expected no-retention configurations. Their scope, notice, human-review rules, and universality differ. Anthropic publishes a model-wide class. OpenAI documents customer-specific controls. This article found no current primary source designating a named public OpenAI model as a direct Fable/Mythos equivalent.

OpenAI’s October 22, 2025 retention update says its earlier obligation to retain new consumer ChatGPT and non-ZDR API content indefinitely ended on September 26, 2025, after which forward-looking standard retention resumed. OpenAI said a limited body of historical April–September 2025 data remained preserved. Its later litigation chronology separately describes de-identification and tightly controlled access to data made available under court procedures. That history is an example of legal duties overriding ordinary deletion—not evidence that current traffic remains under a blanket indefinite hold, that no NYT-related preservation remains, or that the later court-access data is necessarily a separate dataset.

Your organization and tools create more retention boundaries

On a managed ChatGPT account, OpenAI says an administrator may be able to access, export, audit, retain, or delete prompts, files, outputs, history, and usage metadata, depending on workspace configuration and law. Anthropic’s managed products similarly place saved history and privacy controls inside organization settings and agreements. A provider-level promise cannot override your employer’s workspace policy.

Actions, connectors, web search, observability vendors, remote MCP servers, cloud drives, and hosted sandboxes can all receive data after the model request. Their policies are separate. OpenAI explicitly notes that data sent to a remote MCP server follows that third party’s retention policy. The same architectural warning applies regardless of provider: map the complete data path, not only the model endpoint.

What “local” removes—and what it does not

A locally run open-weight model removes the hosted model provider from the inference path. That can be the cleanest route when data cannot leave an environment. It does not automatically remove retention.

Check the local chat UI, RAG/vector database, prompt history, debug logs, traces, crash reporting, telemetry, filesystem snapshots, backups, shared GPU host, and every remote tool. If Ollama runs locally but the UI syncs chats to a cloud account, or the agent calls a remote search or MCP service, the workflow has crossed another boundary.

Routing checklist

  • Ordinary personal use: disable training if desired, distinguish archive from delete, and understand the provider’s deletion timing and exceptions.
  • Confidential code or documents: use an approved commercial route and verify feature-level retention, organization controls, files, tools, and logs.
  • ZDR requirement: confirm organization approval, project configuration, endpoint eligibility, model eligibility, and tool or file exceptions.
  • Fable or Mythos requirement: accept the 30-day minimum and safety/legal exceptions, or use another approved model.
  • Data cannot leave the environment: use a fully local open-weight deployment with local-only inference, logging, RAG, backups, telemetry, and integrations.

This is a technical explainer, not legal advice. Contracts, DPAs, BAAs, workspace settings, and legal obligations can produce a different answer for a specific organization.

Primary sources

Archive status: exact Wayback lookups and save attempts were run on July 26, 2026. Nine sources have replayable captures. The current ChatGPT chat/file-retention URL remained archive-pending after exact, protocol-variant, fallback, and save attempts; its canonical live page remains the current authority.


Verified July 26, 2026. Provider policies, endpoint eligibility, account controls, and legal obligations can change independently.