Wire flash
TechOpenAI and Anthropic escalate data privacy war: zero retention vs customer-managed storage
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
In a rapidly escalating privacy war between Silicon Valley AI giants, OpenAI announced on August 19 a 'zero data retention' policy for enterprise customers, promising not to store any prompts or model outputs. The move directly challenged Anthropic's June policy requiring 30-day data retention for its top-tier models. Within 24 hours, Anthropic relented, offering a new option: data can be stored on the customer's own cloud infrastructure, though the 30-day retention period remains. Anthropic's Claude Code head Boris Cherny confirmed the company will retain no data under the new plan, set for autumn rollout. The core technical dispute centers on safety monitoring: detecting complex attacks like Best-of-N jailbreaks requires analyzing patterns across multiple requests, which necessitates temporary data storage. OpenAI's solution processes data on customer infrastructure and only sends anonymized alerts, while Anthropic shifts custody to customers. The article notes these enterprise protections do not extend to consumer tiers, where data may still be used for training with default opt-in settings.
Source report
A fierce privacy battle has erupted between the two leading AI companies in Silicon Valley, with major policy shifts unfolding in just 48 hours.
OpenAI Strikes First: Zero Data Retention
On August 19, OpenAI made a bold move by announcing "zero data retention" — a commitment that once a task is completed, neither the user's prompts nor the model's responses will be stored.
This announcement directly targeted a policy Anthropic had introduced just two months earlier for its enterprise clients: to access the company's most powerful models, customers were required to surrender their data for 30 days.
Anthropic Responds: Data Stays, But on Your Cloud
The very next day, Anthropic softened its stance. While data would still be retained for 30 days, it could now be stored on the customer's own cloud infrastructure.
Boris Cherny, the creator of Claude Code, clarified the company's position:
"Customers can own and control their data. Anthropic will retain nothing. A new solution is coming this fall."
The phrase "retain nothing" echoed OpenAI's promise from the day before — but the two companies mean very different things by it.
The 48-Hour Blitz: Key Events
| Date | Event | |------|-------| | June 9 | Anthropic's new policy takes effect: enterprise clients using Fable 5 and Mythos 5 models must accept 30-day data retention | | August 19 | OpenAI announces Private Safety Processing, promising zero data retention | | August 20 | Anthropic offers customers the option to store data on their own cloud |
OpenAI's strategy was clear: capture enterprise clients frustrated with Anthropic's data retention policy. Meanwhile, Anthropic — facing significant pushback from over 100 clients, including Salesforce — had been developing an alternative. OpenAI's move simply forced it out early.
Why Anthropic Insists on 30-Day Retention
Anthropic's rationale for data retention is security. Some attacks are invisible when examining a single request.
Example: Best-of-N Jailbreak
- The same prompt is modified into hundreds of subtle variations
- All variations are sent simultaneously, hoping one bypasses defenses
- Each individual request appears perfectly normal
- Only when analyzed collectively does the malicious intent become clear
Larger-scale threats, such as data extortion, never reveal themselves in a single conversation. They require safety classifiers to "zoom out" and analyze patterns across numerous requests.
To enable this broader analysis, data must be temporarily stored in a location where it can be examined collectively — not processed in isolation.
Anthropic did specify that this policy targets organizations that previously had zero data retention configured but wanted access to Covered Models. It also outlined detailed protective measures. Nevertheless, the policy backed many large clients into a corner.
What Actually Changed: Custody, Not Retention
According to sources familiar with the matter, the 30-day retention period remains unchanged. What changed is where the data is stored.
The key difference:
| Storage Location | Control | |-----------------|---------| | Anthropic's servers | Encryption keys, access logs, and permissions are managed by Anthropic. Customers must trust their promises. | | Customer's own cloud | Encryption keys belong to the customer. Access is tracked through the customer's own audit system. If something goes wrong, the customer can investigate independently. |
While this may seem like a small step, for corporate compliance departments, it is a non-negotiable requirement.
OpenAI's Approach: Send the Algorithm to the Data
OpenAI offers a fundamentally different solution: instead of moving data to the algorithm, the algorithm goes to the data.
Private Safety Processing works in three steps:
- Storage Options:
- Original content stays on the customer's own infrastructure, OR
- Stored in OpenAI-provided storage, encrypted with the customer's key — a key OpenAI cannot access
- Cross-Session Analysis:
- Automated systems analyze multiple related interactions horizontally to identify risk patterns
- This solves the same problem Anthropic's 30-day retention was designed to address
- Narrow Alerting:
- When a risk is detected, OpenAI receives only a narrow signal: the type of activity and its severity
- The underlying prompts and responses remain invisible to OpenAI, even when flagged
Customer Control:
- Alerts can be reviewed within the customer's own system
- Customers decide whether to share relevant content for appeals, clarification, or abuse investigations
This system is currently in early customer testing, with a planned September launch. A technical white paper will be released at that time.
Retention ≠ Training: A Distinction That Only Applies to Enterprise
When users hear "your data is retained for 30 days," many assume their conversations are being used for model training. Here's how each company handles this:
| Company | Enterprise Policy | Consumer Policy | |---------|------------------|-----------------| | Anthropic | Retained prompts/outputs are used for safety work, not training | Consumer data may be used for training | | OpenAI | Enterprise data is not used for training unless customers opt in | Consumer training toggle is on by default |
The purpose of retention is abuse detection, not model training. These are separate technical and data governance pathways.
However, this distinction applies only to enterprise clients.
Anthropic's Consumer Policy
Anthropic's official page states that consumer plans require no configuration changes because inputs and outputs are already retained by default.
Consumer data can be used for training in three scenarios:
- You allow it in settings — The default toggle was changed in August 2025 to be opt-out (pre-checked "on"), drawing criticism as a "dark pattern"
- Your conversation is flagged for safety review — This bypasses your toggle setting entirely
- You participate in programs like Trusted Tester
Timeframes for consumer data:
- If you allow training: anonymized chat logs can remain in the training pipeline for up to 5 years
- If a conversation violates usage policies: your inputs and AI responses are stored for 2 years, and risk scores for 7 years
OpenAI's Consumer Policy
- The training toggle is on by default — users must manually turn it off
- Turning it off only stops training: conversations remain stored unless deleted
- Deleted conversations take 30 days to be fully purged
The Core Agreement — and the Core Disagreement
Both companies agree on one fundamental point: complex attacks are only visible across multiple requests, making security monitoring non-negotiable.
The disagreement is about what that monitoring costs:
| Company | What "Zero Retention" Means | |---------|----------------------------| | OpenAI | OpenAI retains nothing and requires nothing from you. If something goes wrong, it receives only an alert. | | Anthropic | Anthropic retains nothing, but you must retain it. The 30-day obligation remains — only the custodian changes from Anthropic to you. |
A New Factor in AI Selection
The landscape has shifted. Choosing an AI provider now involves more than benchmarks, cost-performance ratios, and context windows.
You must also ask:
- Where is my data stored?
- Who can access it?
- How long is it kept?
References:
- OpenAI: Offering Zero Data Retention for Frontier Models
- Anthropic Privacy: Is My Data Used for Model Training?
Editor: Yuan Yu
Source
新智元Neutral / independent
Part of this Story
OpenAI and Anthropic Compete on Zero Data Retention for Enterprise AI Clients