Claude API Data Retention: ZDR, Training & Commercial Terms
What Anthropic keeps when you use the Claude API: no-training default, 30-day retention, ZDR eligibility, and the commercial terms in plain English.
What Anthropic Keeps When You Use the Claude API: The Verdict
The Claude API's data story is short and mostly reassuring โ which is exactly why it's worth writing down precisely, because the version people half-remember is out of date. No training on your data by default. Thirty-day retention, automatically deleted. Real zero-retention available on request. And one June 2026 exception, for Anthropic's newest models, that most summaries haven't caught up with.
The direct answer: Anthropic does not train models on Claude API inputs or outputs by default โ its Commercial Terms of Service (effective June 17, 2025) state that "Anthropic may not train models on Customer Content from Services." API inputs and outputs are automatically deleted within 30 days. Qualified organizations can sign a Zero Data Retention (ZDR) agreement, under which prompts and responses are not stored at rest after the response returns. The exception: under the Covered Models policy effective June 9, 2026, Claude Fable 5 and Claude Mythos 5 require 30-day retention on every platform, and are not available under ZDR. Every claim on this page was verified against Anthropic's live documentation on August 5, 2026.
| Surface | Trains on your data? | Default retention | Zero retention? |
|---|---|---|---|
| Claude API (standard models) | No, by default | 30 days, auto-deleted | Yes โ ZDR by approval, per organization |
| Claude API โ Fable 5 / Mythos 5 | No, by default | 30 days, required (since June 9, 2026) | No โ excluded from ZDR |
| Claude for Team / Enterprise (chat) | No, by default | Retained while active; deleted chats purged within 30 days; Enterprise custom retention (30-day minimum) | Chat interfaces: no. Claude Code via Enterprise: yes |
| Amazon Bedrock | No | Not stored by default (Fable 5: 30 days + required Anthropic sharing) | Bedrock's own zero-retention model; full ZDR via AWS account team |
| Google Cloud (formerly Vertex AI) | Not without permission | Abuse logs: all Claude prompts kept up to 30 days | Anthropic's ZDR doesn't apply โ Google is the processor |
| Microsoft Foundry | Anthropic is an independent processor | No published retention window | Not documented |
| Claude Pro/Max (consumer, for contrast) | Yes, unless toggled off | Up to 5 years (training on) / 30 days (off) | No |
The rest of this page unpacks each row with Anthropic's own wording and dates: the Commercial Terms, the 30-day window and its exceptions, ZDR mechanics, the Covered Models rule, the cloud-provider paths, HIPAA, and what the API does โ and doesn't โ offer for audio. If your question is about Claude Code specifically, start with our Claude Code safety review; if it's about a personal Pro or Max subscription, the consumer side lives in our Claude Pro and Max privacy explainer.
Key Takeaway
The Claude API does not train on your data by default (Commercial Terms, effective June 17, 2025) and deletes inputs and outputs within 30 days. ZDR is available by approval. The June 9, 2026 Covered Models policy is the exception: Fable 5 and Mythos 5 require 30-day retention on every platform and are excluded from ZDR.
The No-Training Default: What the Commercial Terms Actually Say
The training question has a one-line answer in the contract. Anthropic's Commercial Terms of Service, effective June 17, 2025, state in the Customer Content section: "Anthropic may not train models on Customer Content from Services." The same section settles ownership: "Anthropic agrees that Customer (a) retains all rights to its Inputs, and (b) owns its Outputs." Data handling runs through the Anthropic Data Processing Addendum, incorporated into the Terms by reference.
Three scope notes worth having straight before a vendor review:
- Who the Commercial Terms govern. They cover "Customer's use of Anthropic API keys and any other Anthropic offerings that references these Terms," and explicitly exclude consumer use โ claude.ai accounts run under the separate Consumer Terms. Anthropic's privacy center groups the API, Console, and Team & Enterprise plans together as "Commercial Customers," and its training-policy article states the default plainly: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models."
- The one opt-in exception. The Development Partner Program lets an organization admin explicitly share Claude Code input and output tokens from the first-party API with Anthropic โ stored up to two years. It is off unless an admin turns it on, doesn't extend to other API traffic, and organizations under ZDR agreements aren't eligible.
- Feedback is its own channel. Explicitly submitted feedback (thumbs ratings, bug reports) is retained for 5 years โ a separate, voluntary path that doesn't change the no-training default for ordinary traffic.
The pattern to hold onto: on the commercial side, the sensitive defaults are set correctly and the deviations are things a human in your organization must actively choose.
The 30-Day Window โ and the Exceptions That Outlive It
The 30-day window is the retention fact people come to verify, and it holds: per Anthropic's retention documentation (updated July 1, 2026), "For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation." Anthropic's developer docs add the same point from the other direction: conversation content is not retained beyond that window by default.
Four documented exceptions change the math, and they're worth quoting precisely because they're what a security review will ask about:
- Stateful services you control. Anything with longer retention by design โ the Files API is Anthropic's own example, and the Batch API holds results up to 29 days.
- ZDR agreements. Shorter than 30 days: nothing stored at rest after the response returns (next section).
- Usage Policy enforcement. If automated trust-and-safety systems flag content as violating the Usage Policy, Anthropic "retain[s] inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years."
- Legal requirements. The standard carve-out for compliance with law.
Plus the voluntary one: feedback submissions are kept 5 years. If you're comparing this against the consumer side โ where allowing model training extends retention to up to 5 years in de-identified form โ the commercial 30-day default is the materially shorter window, and it doesn't depend on a toggle being set correctly. That asymmetry is the core of the two-tier framework that runs through every Claude privacy question.
Zero Data Retention: What It Is, Who Gets It, How to Ask
Zero Data Retention is Anthropic's strictest arrangement, and its definition is one sentence in the developer documentation: "Under a ZDR arrangement, Anthropic does not store customer prompts or responses at rest after the API response is returned." Getting it is a sales conversation, not a checkbox: you contact the Anthropic sales team, approval is required, and ZDR is enabled per organization โ a second org needs its own enablement.
What it covers, per Anthropic's ZDR scope article (dated June 9, 2026): eligible Anthropic APIs, Anthropic products that use your Commercial organization API key โ including Claude Code accessed via the API โ and Claude Code on Enterprise plans. What it doesn't:
- The Team and Enterprise chat interfaces are not ZDR-eligible; Claude Code through Enterprise is the documented exception.
- Stateful features sit outside it by nature: the Files API, Batch API results (up to 29 days), code execution, and the Console/Workbench.
- Safety enforcement continues. Anthropic "still retains User Safety classifier results in order to enforce our Usage Policy," and flagged content can be kept up to 2 years even under ZDR.
- Anthropic's newest models. Fable 5 and Mythos 5 are not available under ZDR at all โ the next section explains why.
One operational note from the Claude Code side: enabling ZDR also switches off the product surfaces that depend on server-side storage โ Claude Code on the web, desktop cloud sessions, the /feedback command, and Remote Control. Zero retention means the convenience features that require retention go with it; our Claude Code privacy settings guide covers the same trade from the configuration side.
The June 2026 Covered Models Rule: Fable 5 and Mythos 5

The newest fact on this page is the one that changes previously correct answers. Effective June 9, 2026, Anthropic's Covered Models policy requires 30-day retention for its Mythos-class models โ Claude Fable 5 and Claude Mythos 5: "Prompts submitted to, and outputs generated by, covered models are retained for 30 days to support our safety work, on every platform where these models are offered."
What that means in practice:
- ZDR does not cover these models. Anthropic's docs are direct: "These models require 30-day data retention and are not available under ZDR." Organizations with ZDR agreements can enable 30-day retention on a specific workspace to use them there, keeping ZDR everywhere else.
- The rule follows the models across clouds. On Amazon Bedrock, "inputs and outputs will be retained for up to 30 days" for Fable 5, and AWS states that using it requires opting in to sharing retained traffic with Anthropic for abuse detection. Google's documentation carries the same requirement for Fable 5 and Mythos 5 on its platform.
- Access to the retained data is constrained. Per Anthropic: "By default, no Anthropic personnel can read your retained conversations. Human review can occur only through a controlled access path," and the data deletes automatically after 30 days unless flagged or legally held.
If your organization's data posture was designed around "zero retention, everywhere, always," this is the fact to socialize before someone flips a model picker to Fable 5: with these two models, 30 days of retention is the price of access, on every platform. Standard models โ Opus, Sonnet, Haiku โ keep the regular rules above.
Info
Covered Models in one line: since June 9, 2026, Claude Fable 5 and Claude Mythos 5 carry mandatory 30-day retention on every platform, are excluded from ZDR, and on Bedrock and Google Cloud require sharing retained traffic with Anthropic for safety review.
Bedrock, Google Cloud, and Foundry: Who Holds Your Data on Each Path
Same Claude models, four legal arrangements โ and the question that decides between them is who acts as your data processor. Anthropic's own docs draw the line: its ZDR and HIPAA arrangements "apply to the Claude API, where Anthropic is the data processor. On Bedrock and Google Cloud, the cloud provider is the data processor."
- Amazon Bedrock runs what AWS calls a zero-data-retention security model: "by default, Amazon Bedrock does not store model inputs or outputs," and model providers โ Anthropic included โ "don't have access to Amazon Bedrock logs or to customer prompts and completions." Bedrock now exposes explicit retention modes configurable at the account and project level, and eligible customers can request full ZDR through their AWS account team. The exception is Fable 5, which carries the Covered Models rule: up to 30 days retention plus required sharing with Anthropic.
- Google Cloud (the platform formerly named Vertex AI) states: "Google won't use your data to train or fine-tune any AI/ML models without your prior permission or instruction." The nuance is abuse monitoring: Google's standard tier logs only classifier-flagged prompts for up to 90 days, with an exception form to opt out โ but Claude models are designated "Advanced AI," where all prompts and responses are logged for up to 30 days. Request-response logging beyond that is off by default.
- Microsoft Foundry is the different one: per Microsoft's documentation (June 23, 2026), "Anthropic is the seller and operator of Claude models in Microsoft Foundry and acts as an independent data processor for prompts and outputs." Depending on the hosting option, data "might be processed outside of Azure including outside of your selected Azure region." Flagged content can be reviewed by Anthropic trust-and-safety personnel on an exceptions-only basis. Microsoft's page publishes no retention duration โ treat that as an open question for your Microsoft or Anthropic contact, not as zero.
- Claude Platform on AWS follows the same retention policy as the first-party API, with ZDR available on request.
The takeaway for a procurement decision: if your requirement is "our cloud provider is the only processor," Bedrock or Google Cloud is the shape that matches. If your requirement is "a signed agreement with Anthropic that nothing is stored," that's the first-party API with ZDR. The two postures are not interchangeable, and neither is strictly stronger โ they put different names on the processing agreement.
Is the Claude API HIPAA Compliant? Anthropic's Posture, Documented
Anthropic offers a Business Associate Agreement, and the scope is specific. Per its BAA documentation: "Anthropic provides a BAA covering our HIPAA-ready services, such as use of our first-party API or Enterprise plans." The mechanics, all from Anthropic's own pages:
- Enterprise plans: a Primary Owner can accept the BAA directly in organization settings under "Data and privacy" when activating HIPAA readiness.
- First-party API: the organization's Primary Owner signs the BAA and enables HIPAA readiness through Anthropic โ the developer docs describe an execution path directly from the Claude Console for eligible organizations.
- HIPAA readiness replaces ZDR for this purpose: "If your organization handles PHI, HIPAA readiness is the arrangement to use; you do not also need ZDR."
- What the BAA excludes: it covers only the accepting organization, and excludes the Workbench, Claude Console, Claude Cowork, and features in beta. It is not available on Amazon Bedrock, Google Cloud, Claude Platform on AWS, or Microsoft Foundry โ on Bedrock and Google Cloud, healthcare arrangements run through AWS's or Google's own agreements instead.
- Covered Models interact badly with the BAA for Claude Code: Anthropic notes Claude Code is covered under the BAA only when ZDR is enabled โ and since Fable 5 and Mythos 5 aren't available under ZDR, those models can't be used that way.
On the certification ledger, Anthropic's privacy center (March 16, 2026) lists a HIPAA-ready configuration with BAA availability, ISO 27001:2022, ISO/IEC 42001:2023, and SOC 2 Type I and Type II. Everything in this section describes Anthropic's posture as documented โ whether a given deployment satisfies your obligations is a determination for your compliance team, made in writing, before PHI flows anywhere.
Audio and Speech-to-Text on the Claude API: What Exists and What Doesn't
A recurring point of confusion, settled by the model documentation: the Claude API does not accept audio. Anthropic's models overview states that current Claude models "support text and image input, text output" โ there is no audio content type in the Messages API and no transcription endpoint anywhere in the platform docs as of August 5, 2026.
The documented pattern for voice-driven workflows โ the one Anthropic's own cookbook uses โ is a two-step pipeline: a separate speech-to-text layer transcribes the audio, then the text goes to Claude. Anthropic's cookbook example wires up Deepgram for the transcription step. The consumer Claude apps do ship a voice mode (a beta feature across plans on mobile, desktop, and web), and Anthropic's mobile-dictation privacy note is worth knowing: audio recordings are deleted after transcription and voice is not used for model training. But those are product features of the apps โ nothing about them is exposed through the API.
For anyone building or using a dictate-into-Claude workflow, the practical consequence: the transcription layer is a separate vendor decision with its own retention question. Everything this page establishes about Anthropic covers the text after it arrives. Who heard the audio, where it was processed, and whether it was stored is decided entirely by the speech-to-text tool you put in front of Claude โ which is the half of the pipeline most data reviews forget to include.
Voibe: Zero Retention as the Default, Not the Enterprise Upgrade
Reading Anthropic's ZDR docs back to back with this section makes the contrast plain: on the API, zero retention is a sales conversation โ approval-based, per-organization, contract-gated, and now with two models excluded from it entirely. That's a reasonable posture for a frontier-model vendor with safety obligations. It's also precisely the thing Voibe โ the dictation app we build โ inverts for the voice layer: zero retention is the default architecture, for every user, on every plan.
Voibe is the speech-to-text half of the dictate-into-Claude pipeline from the previous section. Two modes, one promise:
- On-device (Apple Silicon Macs): Whisper runs locally โ audio never leaves the Mac at all. No retention window exists because no server ever receives anything.
- Private zero-retention cloud (Windows and Intel Macs): open-source models only, audio never stored, never sold, never used to train AI โ and that's the standard behavior, not a negotiated agreement.
For developers dictating prompts into Claude, Claude Code, or Cursor, Voibe's Developer Mode resolves file and folder names as you speak, and Smart Formatting cleans fillers without paraphrasing. Dictation runs at roughly 5x typing speed, which is what makes voice worth it for long, context-heavy prompts. Pricing is $7.50/month, $59/year, or $149 lifetime.
The boundary, stated plainly: Voibe covers who hears your voice; Anthropic's terms cover what happens to your text. Choose the API path with the retention posture your data needs โ this page's tables are for that โ and pair it with a voice layer that doesn't add a second retention policy on top. Setup for the voice side is in our dictation for AI prompting guide.
Tip
Try Voibe for Free: download at getvoibe.com โ no account, no credit card. On-device mode requires an Apple Silicon Mac (M1 or newer); Windows and Intel Macs use the private zero-retention cloud.
Claude Privacy, Page by Page
This page covers the commercial side โ API, Team, Enterprise, and the cloud paths. The rest of the cluster:
- Is Claude Code safe? โ the full safety review of the CLI: consumer-vs-commercial defaults, the terms-update history, and the deployment decision tree.
- The session transcript prompt โ the shared-transcript path and its own 6-month clock, separate from both the 30-day API window and the 5-year
/feedbackretention. - Claude Code privacy settings โ every env var, flag, and toggle, copy-paste ready, plus how to delete sessions.
- Claude Pro and Max privacy โ the consumer plans: the 5-year window, the training toggle, incognito chats, and deletion.
- Is Claude safe? โ the claude.ai consumer product, including the ChatGPT comparison.
- AI Tool Privacy Tracker โ the continuously updated reference across Claude, ChatGPT, Gemini, Cursor, Copilot, and the dictation tools.
- Cloud AI privacy โ the wider architecture question: what any cloud AI provider can and cannot promise.
Frequently Asked Questions
Does Anthropic train models on Claude API data?
How long does Anthropic retain Claude API inputs and outputs?
What is Zero Data Retention and how do I get it for the Claude API?
Does zero data retention apply on Amazon Bedrock or Google Cloud?
Why do Claude Fable 5 and Mythos 5 require 30-day data retention?
Does Claude for Teams or Enterprise have zero data retention?
Is the Claude API HIPAA compliant?
Can the Claude API transcribe audio or accept voice input?
What happens to Claude API content flagged by safety systems?
Do the Commercial Terms cover Claude Code?
Ready to type 5x faster?
Voibe is the fastest, most private dictation app for Mac and Windows. Try it today.
- On-device or private cloud
- Free to try
- No subscription
- Mac + Windows
- 90+ languages
Prefer to go Pro? Save 20% on any plan with code VOIBE20 View pricing โ
Related Articles
Is Claude Safe? Privacy, Data Retention & Security Review (2026)
Claude is safe for everyday use once one toggle is checked. What Anthropic collects, how long chats are kept, and how Claude compares with ChatGPT on privacy.
Is DictaFlow Safe? Its Own Privacy Policy Answers That
DictaFlow's cloud step runs through OpenAI and NVIDIA, and its privacy policy says the $69 plan is not for medical dictation. Here is the full data path.
I Tested 7 DictaFlow Alternatives โ Here's the One I Trust with Sensitive Work
DictaFlow markets itself for clinical notes and legal drafts, so I tested seven alternatives and read every privacy page. Here's the one I'd trust with a patient's name โ and the one you actually need a signed BAA for.

