Independent/Reader-funded/Infrastructure, not tokens
DeAINEWS

AI you control — open models, private inference, and the networks that run them.

Provider Policy & Trust

7 Zero-Retention AI APIs for Sensitive Workloads (2026)

Seven LLM APIs publish zero-retention or no-training policies for sensitive data. Learn what each actually promises and the one contract clause that matters.

DeAI is powered by Morpheus (mor.org). We cover competing providers on the same terms — see our methodology.

7 Zero-Retention AI APIs for Sensitive Workloads (2026) Illustration: DeAI
7 Zero-Retention AI APIs for Sensitive Workloads (2026) Illustration: DeAI

If you're looking for an AI API with no data retention, the realistic shortlist is seven providers: OpenAI, Anthropic, Azure OpenAI, Amazon Bedrock, Google Vertex AI, Together AI, and Fireworks AI. The number that matters is 0: zero days of stored prompts. Only a signed contract, not a marketing page, makes that number enforceable.

Key takeaways

  • Seven hosted LLM APIs publish no-training-by-default policies, but true zero retention usually requires an approval process or an enterprise tier; it is rarely the default.
  • "Won't train on your data" and "won't retain your data" are two different promises. Most providers keep limited abuse-monitoring logs (roughly 30 days in several published policies, as of 2026-08-20) unless you get that window waived.
  • One signature decides HIPAA eligibility: without a Business Associate Agreement (BAA), a zero-retention API is still a non-starter for PHI.
  • Zero providers' retention claims are externally verifiable. Treat "we don't store your prompts" as a policy statement and anchor it in a contract, a DPA, and audit scope.

What does "zero data retention" actually mean?

Teams shopping for a private AI API routinely conflate four separate commitments. Untangling them is the whole game:

  1. No training. The provider won't use your prompts or completions to improve its models. Every provider on this list publishes some version of this for API traffic.
  2. No retention. The provider deletes (or never writes) prompt and completion content after the response is served. This is the "zero retention" claim, and it usually sits behind an approval process, an enterprise tier, or a specific endpoint configuration.
  3. Abuse-monitoring logs. Most providers carve out an exception: content may be held briefly for trust-and-safety or abuse-prevention purposes. Several published policies describe a window of roughly 30 days (as of 2026-08-20); the whole point of a zero-retention agreement is collapsing that window to nothing.
  4. Transient processing. Your prompt always exists in the provider's memory while the response is generated. "Zero retention" says nothing about this; it is a promise about storage afterward.

That last point is why DeAI's provider-trust methodology scores retention and privacy absence-claims ("operators can't see your prompts," "zero logs") as policy statements, not verified facts. You cannot audit a provider's disk from the outside. You can only move the claim from a web page into a contract.

Which providers offer zero-retention APIs?

The matrix below summarizes each provider's published posture as of 2026-08-20. Terms change; confirm on the provider's current legal and documentation pages before signing anything.

ProviderTrains on your data?Default retention (published policy)Path to zero retentionBAA for HIPAA?
OpenAI APINo (per policy)Limited abuse-monitoring windowZDR approval for eligible orgs/endpointsYes, for eligible customers
Anthropic APINo (per commercial terms)Limited trust-and-safety retentionEnterprise arrangementsYes, for eligible customers
Azure OpenAINoAbuse-monitoring storage unless modified"Modified abuse monitoring" approvalYes (Microsoft BAA)
Amazon BedrockNo (docs: content not stored or used)No provider-side content storage by default; you control your own loggingDefault posture + keep your own invocation logging offYes (HIPAA-eligible service)
Google Vertex AINo (without permission)Limited caching/abuse logging per docsEnterprise data-governance controls, residency optionsYes (Google Cloud BAA)
Together AITier-dependent (per terms)Varies by product tierEnterprise / dedicated zero-retention termsEnterprise; confirm
Fireworks AINo (per policy)Limited operational logs per policyEnterprise zero-retention termsEnterprise; confirm

Does the OpenAI API retain your prompts?

OpenAI's API terms state that customer inputs and outputs are not used for training. Its published policy describes a limited retention window for abuse monitoring, with a zero-data-retention (ZDR) option available to qualifying organizations on eligible endpoints after a review process. Practically: default API traffic is "no training, short retention," and ZDR is something you apply for, not something you toggle on.

Is Anthropic's API zero-retention?

Anthropic's commercial terms commit to not training on customer content, with limited retention for trust-and-safety purposes described in its policies. Stricter arrangements are an enterprise conversation. Anthropic also operates a public trust center where you can review certifications and subprocessors before procurement.

Is Azure OpenAI the enterprise HIPAA default?

Azure OpenAI is frequently the first shortlist entry for regulated workloads, for structural reasons rather than model quality: it sits inside Microsoft's compliance stack, Microsoft signs a BAA, and its documented "modified abuse monitoring" path lets approved customers remove prompt and completion storage entirely. If your organization already runs on Azure with a BAA in place, the marginal paperwork is small.

How does Amazon Bedrock handle prompt data?

AWS's Bedrock documentation states that prompts and responses are not stored by the service to improve models, and that content logging (such as model invocation logging) is something you configure into your account, so the retention decision is largely yours to make and audit. Bedrock is a HIPAA-eligible service under the AWS BAA.

What does Google Vertex AI promise?

Google's Vertex AI data-governance documentation commits to not using customer data to train foundation models without permission, and the platform offers data-residency controls, customer-managed encryption keys, and a BAA under Google Cloud's HIPAA commitments. The zero-retention story is assembled from platform controls rather than a single switch.

Do independent inference clouds offer zero retention?

Together AI and Fireworks AI both serve popular open-weight models (Llama, Qwen, DeepSeek, and peers) behind OpenAI-compatible endpoints, and both publish no-training commitments with enterprise zero-retention or dedicated-deployment options. Terms vary by tier, so the operative question is what lands in your order form, not what the pricing page implies. These are the common picks when you want open-weight models without operating GPUs yourself.

What about decentralized marketplaces?

A different trust model exists alongside hosted APIs. Morpheus, a decentralized inference marketplace, routes prompts to independent operators rather than to one provider's servers, so there is no single corporate retention policy to negotiate. That removes the central-logging question but moves verification to routing behavior and operator incentives, and any absence-of-logging claim is still a policy statement wherever your data lands. Evaluate it on the same criteria as the seven providers above: what is promised, by whom, and what is it anchored to.

Is a zero-retention API enough for HIPAA?

No. HIPAA doesn't care about a retention marketing claim; it cares about a Business Associate Agreement. A provider can promise zero retention and still be unusable for PHI if it won't sign a BAA. Conversely, a signed BAA with a 30-day abuse log can be perfectly workable, because the BAA is what makes the handling lawful. The cloud platforms (Azure OpenAI, Bedrock, Vertex AI) are the common choices here precisely because BAAs are standard paperwork for them. Beyond the BAA, your own obligations remain: access controls, audit logging on your side, and minimum-necessary data in each prompt. HHS's covered-entity guidance is the right starting point if this is new territory.

What makes an LLM API GDPR-compliant?

Nothing, by itself. No API is "GDPR certified," and compliance is shared. Your checklist as a controller: an Article 28 data-processing agreement with the provider, a lawful transfer mechanism (typically SCCs) if prompts leave the EEA, data-residency options where your risk assessment demands them, and a credible answer on erasure. That is exactly where retention policy matters, because you cannot honor a deletion request for data sitting in a vendor's abuse log. A zero-retention contract simplifies the erasure story considerably. Run a DPIA before sending personal data to any of these APIs.

How do you verify a zero-retention claim before sending confidential data?

Since you can't inspect a provider's disks, verification is a procurement discipline:

  1. Get retention terms in the contract or DPA, not the marketing page. If sales won't paper it, the policy doesn't exist for you.
  2. Ask for the abuse-monitoring window in writing, and request the waiver or ZDR addendum explicitly.
  3. Check audit scope. Does the SOC 2 or ISO 27001 report actually cover the API product you're calling?
  4. Review the subprocessor list. Your prompt may touch more entities than the logo on the docs.
  5. Minimize client-side. Redact PII, strip identifiers, and route through a gateway you control.
  6. Prefer private networking (VPC endpoints, Private Link) so prompts don't traverse the public internet.
  7. Canary-test. Send unique marker strings and exercise your DPA rights to see what the provider can produce.

DeAI maintains a retention-policy matrix tracking each provider's current terms, and the provider-trust methodology scores exactly these claims: unverifiable absence-claims count as policy statements until they're anchored in contract.

FAQ

Which AI APIs offer zero data retention?

As of August 2026, seven major providers publish zero-retention or no-training policies: OpenAI, Anthropic, Azure OpenAI, Amazon Bedrock, Google Vertex AI, Together AI, and Fireworks AI. True zero retention usually requires approval or an enterprise tier. Get it in writing.

Is there a HIPAA-compliant AI API?

Several providers sign BAAs, including Azure OpenAI, Amazon Bedrock, and Google Vertex AI, so their APIs can be used with PHI inside a compliant setup. Zero retention alone isn't enough: HIPAA requires a signed BAA plus your own administrative and technical safeguards.

What makes an LLM API GDPR compliant?

No API is "GDPR certified." Compliance is shared: you need an Article 28 data-processing agreement, a lawful transfer mechanism (e.g., SCCs) for non-EU processing, data-residency options where required, and a plan for erasure requests that covers provider-side logs.

Can I send confidential data to an AI API?

Yes, if the contract covers no training plus zero or minimal retention, and you minimize what you send (redaction, PII scrubbing). If the provider won't put retention terms in writing, move the workload to a private deployment or a self-hosted open-weight model.

Does zero retention mean the provider never sees my prompt?

No. Your prompt is processed in the provider's systems to generate a response. Zero retention is a policy about what is stored afterward. It is a contractual promise you cannot verify from outside, so treat absence-claims as policy statements.

Questions

Which AI APIs offer zero data retention?
As of August 2026, seven major providers publish zero-retention or no-training policies: OpenAI, Anthropic, Azure OpenAI, Amazon Bedrock, Google Vertex AI, Together AI, and Fireworks AI. True zero retention usually requires approval or an enterprise tier — get it in writing.
Is there a HIPAA-compliant AI API?
Several providers sign BAAs — including Azure OpenAI, Amazon Bedrock, and Google Vertex AI — making their APIs usable with PHI inside a compliant setup. Zero retention alone isn't enough: HIPAA requires a signed BAA plus your own administrative and technical safeguards.
What makes an LLM API GDPR compliant?
No API is 'GDPR certified.' Compliance is shared: you need an Article 28 data-processing agreement, a lawful transfer mechanism (e.g., SCCs) for non-EU processing, data-residency options where required, and a plan for erasure requests that covers provider-side logs.
Can I send confidential data to an AI API?
Yes, if the contract covers no training plus zero or minimal retention, and you minimize what you send (redaction, PII scrubbing). If the provider won't put retention terms in writing, move the workload to a private deployment or a self-hosted open-weight model.
Does zero retention mean the provider never sees my prompt?
No. Your prompt is processed in the provider's systems to generate a response. Zero retention is a policy about what is stored afterward — a contractual promise you cannot verify from outside, so treat absence-claims as policy statements.

Sources

  1. OpenAI Enterprise Privacy — OpenAI
  2. Anthropic Commercial Terms of Service — Anthropic
  3. Data, privacy, and security for Azure OpenAI Service — Microsoft Learn
  4. Data protection in Amazon Bedrock — AWS Documentation
  5. Data governance and generative AI — Google Cloud
  6. Together AI Privacy Policy — Together AI
  7. Fireworks AI — Fireworks AI
  8. HIPAA for Covered Entities — U.S. Department of Health & Human Services
  9. GDPR.eu — Complete guide to GDPR compliance — GDPR.eu

About DeAI

DeAI is an independent publication covering open-weight AI models, private inference, and decentralized infrastructure — the tools for running AI you actually control. We test providers on price, privacy, and refusal behavior and publish the numbers, not the vibes. DeAI is powered by Morpheus (mor.org), a decentralized inference marketplace, and covers it on the same terms as every other provider.

Powered by Morpheus and StrandCMS

Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider — we rank it wherever the data lands. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more about the Morpheus Inference API →

Sponsor disclosure — not editorial

Powered by Morpheus and StrandCMS. Morpheus is a decentralized inference marketplace, covered on the same terms as every other provider. StrandCMS is the open-source, agent-first framework this site is built on.

Learn more →