Loading prices...
All news

Where the data you send to AI is stored, and for how long

17:00 · 10.10.2026
0

Your message leaves the device and lands on the provider's servers. Three clocks start there rather than one: the conversation you can see, a safety copy you cannot, and a training set your text may or may not enter. Deleting the first does nothing to the other two.

“Even if you opt-out, we will use Inputs and Outputs for model improvement when: (i) your conversations are flagged for safety review”

— Anthropic, Политика конфиденциальности

The thirty-day floor

OpenAI removes deleted conversations from its systems within 30 days, unless a legal or security obligation requires longer. Temporary chats disappear on the same schedule without you doing anything. API inputs and outputs are kept up to 30 days for abuse monitoring, and zero retention exists as an exception that needs a qualifying use case and sales approval, and does not cover several endpoints.

The delete button starts a month-long countdown, and a legal hold pauses it.

The default flips depending on which door you use

Free and Plus conversations feed model training unless the user turns it off. Business, Enterprise, Edu and API data is excluded from training by default.

Same company, same model, opposite defaults. The difference is the contract rather than the technology, and the door where the default protects you is the one that costs money.

Flagged conversations follow different rules

Anthropic's privacy policy states that opting out of training does not cover everything. Flagged content is separated from the user ID, with re-identification available «to enforce our Terms of Service or Usage Policy with the responsible user if necessary».

The same policy permits sharing personal data with law enforcement on a good-faith belief that disclosure is reasonably necessary to prevent serious harm to any person or to property. On 6 October we covered a Florida case where that pipeline ran end to end: safety systems flagged a user's own words, a reviewer escalated, and police made an arrest.

What this means for anything sensitive

AI data retention has a floor and no published ceiling. Treat 30 days as the floor, because legal obligations extend it and no provider publishes a maximum.

Keep credentials, private keys, a wallet seed phrase and client data out of a consumer chat window. The text sits on someone else's server inside a retention window, inside a safety pipeline, and inside whatever a court later asks for.

Use the enterprise or API door for work material. It costs more and the default is the one you want. The same logic now applies to consumer AI agents, which hold credentials and drive a browser on a machine you do not administer.

And read the provider's own policy rather than its marketing page. Both documents come from the same company, and only one of them is binding.

Informational material, not legal advice. Retention terms are the providers' own published figures and change without notice.

Published: 17:00 · 10.10.2026
Maks

Author

Maks

Trading man

I've been interested in the cryptocurrency market for a long time, am a trader, and write articles and news about my experience and crypto in simple terms.

Comments (0)

No comments yet — be the first!

The market talks all day. We write when it says something

Short, and it tells you why it came