← Back to library
Tighten operationsSecurityOpen4 min read

AI Vendors Are Now Competing on How Little of Your Data They Keep: The 10-Minute Retention Check

OpenAI just previewed misuse monitoring that retains none of your data, weeks after Anthropic moved to 30-day retention on its top models. Retention is now a feature vendors compete on. Run this 10-minute check before your next renewal.


What happened. On August 19, OpenAI previewed a system it calls Private Safety Processing: automated misuse monitoring built to work without retaining customer data or exposing it to staff. It runs alongside zero-data-retention options, is being tested with a small group of early customers, and a wider rollout with a technical white paper is planned for September. The context that makes it matter: earlier this summer, Anthropic began requiring 30-day data retention on its most capable models. The two biggest AI vendors are now openly competing on how little of your data they hold. (TechCrunch, Security Boulevard)

Why an operator should care. For two years, "what happens to the stuff I paste in" was buried in help-center pages that changed quietly. Now retention is a headline feature, which means two things. First, you have leverage: vendors want to win on privacy, so the good settings and tiers exist and are worth asking for. Second, whatever you verified in the spring may be stale, because policies moved twice this summer alone.

The move: a 10-minute retention check.

  1. List every AI tool that touches business data. Chat tools, meeting notetakers, and the AI features inside your CRM and email count.
  2. Look up each one's current policy. Search its help center for "data retention" and write down two things: how long they keep your content, and who can see it. If you can't find a clear answer in five minutes, that is your answer.
  3. Note which plan tier gets you zero or short retention. It is often the business tier you should be on anyway.
  4. Add one question to every AI vendor renewal or sales call: "What do you keep, for how long, and who can see it?" Vendors are now competing to answer that well. Make them.

Caution. A good retention policy is a seatbelt. Keep truly sensitive data (client financials, health info, credentials) in a private/business AI workspace regardless of what any vendor promises.

Example outputwhat you get back

Retention Check: 6 tools, 40 minutes total

Zero or short retention confirmed (3)

  • Chat assistant, business tier: zero retention available on the $60/user plan. Currently on the $25 individual plan, which trains on inputs by default. Upgrade cost for 4 seats: $1,680/yr.
  • CRM's built-in AI: 30 days, vendor staff access for abuse review only. Acceptable.
  • Email drafting add-on: no retention beyond the session. Documented clearly.

Problems (3)

  • Meeting notetaker: transcripts stored indefinitely by default. Support pages list no deletion window. Renewal is October 14.
  • Document summarizer used by the office manager: help center returns nothing for "retention." Five minutes, no answer.
  • Bookkeeping AI feature: 18-month retention, unclear staff access. This one touches client financials.

Flagged: the notetaker and the bookkeeping tool see client financials under indefinite or 18-month storage.