Skip to main content

Icy Tales

The Fine Print Problem: Inside OpenAI’s Enterprise Data Retention Confusion

Joshita
By
21 Min Read

Post Author

A Swedish developer named Herman posted a question to OpenAI’s developer forum1 in June of 2025. His company builds on the API. His customers are in the European Union. And he had just read a blog post that made his stomach drop. OpenAI, the post said, was now retaining “all ChatGPT logs” indefinitely, including data that should have been deleted after thirty days. Herman’s company had compliance obligations. His customers would have compliance problems if their data sat on a server past the promised window. He asked the forum a simple question. What now?

The Fine Print Problem: Inside OpenAI's Enterprise Data Retention Confusion 2

Nobody gave him a clean answer. One commenter suggested Azure. Another offered a half-built Python script to auto-delete files, warning that “you cannot trust generalistic programs to delete stuff” and that Herman would need a separate system entirely. A third pointed him toward OpenAI’s2 newly announced European data residency option, which promised in-region processing with zero data retention, meaning model requests and responses are not stored at rest on OpenAI’s servers. Herman checked. His account couldn’t select a region. The thread ended there, unresolved, the way most of these threads do.

I’ve spent the past several weeks reading OpenAI’s privacy documentation, court filings, developer forum threads, and the public statements of the company’s leadership, and Herman’s confusion turns out to be the rule rather than the exception. OpenAI has built one of the most detailed enterprise privacy pages in the industry. It has SOC 2 certifications, a trust portal, HIPAA business associate agreements, and a public commitment that customer data is not used for training by default. And yet, ask a working developer, a compliance officer, or a general counsel what actually happens to their company’s prompts after they hit send, and you’ll get a shrug, a guess, or a call to sales that never quite resolves. The retention story at OpenAI isn’t one policy. It’s a stack of them, layered by product tier, contract type, legal jurisdiction, and now, a federal court order that upended the whole premise for months.

The Promise on the Page

Start with what OpenAI3 says, because the company says a lot. Its enterprise privacy page, last updated in January, opens with three commitments: ownership, control, and security. Enterprise customers are told plainly that they own and control their data, that OpenAI does not train on it by default, and that customers can decide how long it is retained. For the API specifically, the FAQ states that OpenAI may securely retain inputs and outputs for up to 30 days to identify abuse, after which they are removed from OpenAI’s systems unless the company is legally required to keep them. Zero data retention, or ZDR, is available for eligible endpoints. It sounds tidy. A number, a window, an opt-out.

The Fine Print Problem: Inside OpenAI's Enterprise Data Retention Confusion 3

Except the tidiness dissolves the moment you look at how many different products live under the “enterprise” umbrella. ChatGPT Enterprise, ChatGPT Business, ChatGPT for Healthcare, ChatGPT Edu, ChatGPT for Teachers, and the API Platform each carry their own retention language, their own audit hooks, and their own carve-outs. According to a comparison published by Meetily4, a company that tracks LLM privacy policies across vendors for its own compliance purposes, the default API posture is training-free with a short abuse-monitoring window, but ZDR itself isn’t a self-serve toggle. Eligibility depends on the endpoint and requires your account team to switch it on. That single fact, that a company can’t simply flip a setting and trust it, is the seed of most of the confusion that follows.

Ask around and you’ll find that ZDR feels less like a feature and more like a favor. A Medium5 write-up on the policy lays out the mechanics well. ZDR is not a default setting for any OpenAI service. It is primarily built for business and enterprise customers, and it requires those customers to specifically request it and be approved. The standard API tier retains inputs and outputs for up to thirty days regardless of what a customer wants. Consumer ChatGPT retains conversations by default to improve the models, and turning off chat history is a separate, weaker control that has nothing to do with a formal ZDR agreement.

That approval gate matters more than it should. A March 2026 post from a small EU company on OpenAI’s6 own developer forum describes a request process so opaque that the poster had to submit the same contact form four times.

In my case, I had to fill out the contact form four times. Three times, the Submit button was simply grayed out and I could not proceed. On the fourth attempt, I finally reached the confirmation screen saying the request would be processed, but I received no confirmation email and no case number.

Three of those attempts left the submit button grayed out with no explanation. The company needed a clear answer before it could adopt the tools for internal code repositories, since no storage outside Europe was a hard requirement for their own customers. Even on the fourth try, when the form finally went through, there was no confirmation email and no case number. The poster asked OpenAI to simply say no if the answer was no, rather than leaving companies to guess. As of this writing, nobody from OpenAI has replied in that thread.

One could argue that the problem isn’t OpenAI’s retention policy in the abstract. It’s that the policy reads like a settled fact on the marketing page and behaves like a negotiation everywhere else. A promise you can point to in a sales deck is not the same thing as a promise you can point to in a signed addendum, and enterprise buyers, she said, are only slowly learning the difference.

Then a Judge Got Involved

Here is where the story stops being a documentation problem and becomes something closer to a structural one. In May of 2025, Magistrate Judge Ona T. Wang, overseeing the consolidated copyright litigation between The New York Times and OpenAI, ordered OpenAI to preserve and segregate all ChatGPT output log data that would otherwise have been deleted, including chats users had explicitly deleted and temporary chats users assumed were never stored at all. The order came out of the Times’ argument that deleted or temporary chats might be exactly where users tried to route around the paper’s paywall, and that this behavior could support the newspaper’s copyright claims.

OpenAI did not go quietly. CEO Sam Altman called the demand a crazy overreach and said he expected the company to win. In a podcast appearance covered by Barchart7, Altman argued that a newspaper that claims to value privacy shouldn’t be the one asking an AI company to compromise it, and said he hoped the fight would force a broader societal reckoning with what privacy means in the AI era. The company’s Chief Information Security Officer, Dane Stuckey, went further in a public statement reported by Fox News8, writing that the company treats user data as among the most sensitive information in your digital life and that this responsibility was, in his words, being tested.

The Times pushed back hard on OpenAI’s framing. A spokesperson told Malay Mail9 that OpenAI’s public statements purposely misled its own users and omitted key facts, and insisted no ChatGPT user’s privacy was actually at risk, since the court had ordered a sample of chats that OpenAI itself would anonymize under a legal protective order. Judge Wang’s own order noted that user privacy would be protected through what she called exhaustive de-identification.

Both sides had a point, and both sides had an incentive to overstate it. That tension is worth sitting with for a second, because it’s the whole article in miniature. OpenAI’s public identity depends on being the privacy-conscious choice for enterprises weighing whether to trust it with sensitive workflows. The Times’ case depends on proving that ChatGPT users, in aggregate, behaved in ways that implicate the newspaper’s copyrighted material. Neither side is lying, exactly. They’re both describing the same pile of data from the angle that serves them.

The Retention Order that Wouldn’t Die

By October of 2025, OpenAI had partly won its fight. According to a detailed timeline compiled by legal newsletter Terms.Law10, OpenAI reported that its obligation to retain all consumer content indefinitely under the original order ended on September 26, 2025, after months of what the outlet called extraordinary retention. Mashable11 reported that Judge Wang released OpenAI from the requirement to preserve all output log data going forward, though the company still had to retain logs tied to accounts the Times had specifically flagged. Some noted that OpenAI would finally stop saving most users’ deleted and temporary chats, ending a fight that had run since May. Anyone who had assumed their deleted chat was actually deleted during that four-month window was, as a factual matter, wrong.

But the story didn’t end with the preservation order lifting. It escalated. In November, Judge Wang ordered OpenAI to produce 20 million de-identified ChatGPT logs to the Times and other news plaintiffs. OpenAI fought that too, calling it a fishing expedition, and lost again. District Judge Sidney Stein affirmed the order in January 2026. Legal analysis from Jones Walker LLP12 frames the ruling as a preview of how courts will treat user-privacy claims whenever an AI company’s data practices collide with copyright liability. The plaintiffs had originally wanted 120 million logs. OpenAI proposed 20 million as a ceiling, and the plaintiffs agreed to that number, only for OpenAI to later try narrowing what within that sample it would actually hand over. The court said no to that maneuver too. The company doesn’t get to pick its own greatest hits.

The Fine Print Problem: Inside OpenAI's Enterprise Data Retention Confusion 4

Enterprise customers, notably, sat outside this entire fight. OpenAI’s13 clarified that ChatGPT Enterprise was excluded from the preservation order from the start, and that business customers with a Zero Data Retention agreement were not impacted at all, since OpenAI never retained their prompts or answers in the first place. That’s a genuinely meaningful distinction, and I don’t want to bury it under the drama of the lawsuit. But it also means the entire episode functioned as a two-year natural experiment in what “enterprise” actually buys you. If you had ZDR, you were untouched. If you had ChatGPT Enterprise, you were carved out by definition, not by a contract you’d personally negotiated. If you were a consumer, a Team subscriber, or an API customer without a ZDR agreement, your data got swept up regardless of what OpenAI’s own retention page told you to expect.

What “Enterprise” Doesn’t Mean

This is the part that I think gets lost in most coverage of the lawsuit, which tends to frame it purely as a copyright story with a privacy subplot. The retention fight exposed something structural about how OpenAI, and honestly the entire industry, sells trust. A comparison published by Decagon14, a company that builds on top of multiple model providers, notes that ZDR requires a negotiated enterprise agreement in every case and is never available on standard pay-as-you-go plans, whether you’re talking about OpenAI, Anthropic, or Google’s Vertex AI. That’s the industry norm now, not an OpenAI quirk. But OpenAI’s marketing language doesn’t always make that gate obvious. The word “enterprise” appears on five separate product tiers, each with different retention defaults, different admin controls, and different legal exposure, and a buyer has to read deep into FAQ accordions to figure out which tier actually insulates them from a scenario like the one the Times lawsuit created.

A security-focused piece on DEV Community15 put it bluntly: most enterprise-grade providers offer ZDR-eligible endpoints, but they aren’t the default, and standard accounts often carry a thirty-day retention window that the author calls a nightmare for companies handling financial, health, or trade secret data, since a breach within that window is still a breach. I’d add a related point that doesn’t get said often enough. A retention promise is a policy choice right up until a court decides it isn’t. OpenAI’s ZDR customers were safe from the Times order because ZDR is architected so there’s nothing to preserve, not because a judge respected OpenAI’s terms of service. That’s an important distinction for anyone weighing whether a contractual promise of deletion will hold up against a subpoena, a regulator, or a plaintiff’s discovery request. Architecture beats policy. A company that never stores your data can’t be ordered to hand it over. A company that stores it and promises to delete it later can absolutely be ordered to keep it, no matter what the sales page says.

Herman’s original question, the one that opened this piece, points at a second layer of the ambiguity that rarely makes it into US coverage of the lawsuit. European companies operate under GDPR, which imposes real obligations about where personal data lives and how long it’s kept. OpenAI16 does offer a Data Processing Addendum for customers who need to formalize GDPR compliance, and it introduced European data residency options that promise in-region, zero-retention processing for participating projects. But as Herman discovered, and as the EU company posting on the forum in March 2026 discovered independently, actually enrolling in these programs is its own obstacle course. Region selection wasn’t available on Herman’s account. The ZDR contact form silently failed for the EU poster three times running. These aren’t edge cases dug up by hostile critics. They’re first-party accounts, posted on OpenAI’s own community forum, by people trying in good faith to use the product the way OpenAI’s documentation says it can be used.

The Fine Print Problem: Inside OpenAI's Enterprise Data Retention Confusion 5

One forum reply to that EU thread took a more fatalistic view, arguing that individual users paste sensitive information into ChatGPT constantly without a second thought, while companies agonize over ZDR paperwork and data residency, and suggested the gap between perceived risk and actual behavior is hard to ignore. There’s something to that. Plenty of individual professionals treat ChatGPT like a diary, a legal advisor, and a first draft partner all at once, with none of the scrutiny their employer’s procurement team applies to the same tool. But I don’t think that observation lets OpenAI off the hook. If anything it cuts the other way. A company whose own retention rules are hard enough to parse that its enterprise customers can’t get a straight answer is not well positioned to expect casual users to make informed choices either.

Where this Leaves the Rest of Us

I keep coming back to a phrase from Anthropic’s own retention policy, referenced in a piece from Digital Applied17 comparing the two companies. Anthropic states that flagged or legally required content may be kept beyond the standard window in what it calls rare cases, without publishing a numeric ceiling, while outside reporting has pegged the real-world figure at up to two years for flagged material. The piece’s broader point stands regardless of which company you’re evaluating: most coverage treats a policy statement and a legal outcome as two separate facts, when they’re really the same fact observed at two different points in time. OpenAI’s enterprise privacy page is accurate the day you read it. It stops being reliable the moment a federal judge, a regulator, or a plaintiff’s attorney decides the underlying data is relevant to something bigger than your contract with OpenAI.

None of this makes OpenAI uniquely dishonest. The company genuinely does offer stronger controls than most of its competitors offered even two years ago, and its enterprise tier held up structurally throughout a lawsuit that would have been a five-alarm crisis for a less carefully engineered product. But the gap between “we don’t retain your data” and “we can’t be forced to hand over data we never had” is the whole story here, and it’s a gap that most buyers, and honestly most journalists covering this beat, still talk about as if it were the same sentence. It isn’t. One is a promise. The other is a design decision. Only one of them survives contact with a courtroom.

Sources

  1. OpenAI, community.openai.com/. Accessed 6 Oct. 2026. ↩︎
  2. OpenAI, openai.com/index/introducing-data-residency-in-europe/. Accessed 6 Oct. 2026. ↩︎
  3. OpenAI, openai.com/enterprise-privacy/. Accessed 5 Oct. 2026. ↩︎
  4. “OpenAI Data Retention Policy 2026 – Does OpenAI Train on Your API Data?” Meetily, 11 May 2026, meetily.ai/llm-privacy/openai. Accessed 5 Oct. 2026. ↩︎
  5. Medium, medium.com/@jeffkessie50/openais-zero-data-retention-policy-916ff04a3599. Accessed 5 Oct. 2026. ↩︎
  6. “Zero Data Retention request path is too unclear and frustrating for small EU companies” OpenAI Developer Community, 18 Mar. 2026, community.openai.com/t/zero-data-retention-request-path-is-too-unclear-and-frustrating-for-small-eu-companies/1377052. Accessed 5 Oct. 2026. ↩︎
  7. Barchart, www.barchart.com/story/news/32985620/crazy-overreach-openais-sam-altman-blasts-nyts-request-to-store-chatgpt-records-says-privacy-is-really-important. Accessed 6 Oct. 2026. ↩︎
  8. Wulfsohn, Joseph. “OpenAI accuses NY Times of wanting to invade millions of users’ privacy in paper’s lawsuit against tech giant” 12 Nov. 2025, www-ak-ms.foxnews.com/media/openai-accuses-ny-times-wanting-invade-millions-users-privacy-papers-lawsuit-against-tech-giant.print. Accessed 6 Oct. 2026. ↩︎
  9. 13 Nov. 2025, malaymail.com/news/tech-gadgets/2025/11/13/openai-resists-court-order-to-release-more-than-20-million-chatgpt-logs-in-new-york-times-case/198188. Accessed 6 Oct. 2026. ↩︎
  10. “OpenAI Court Case: Can Your ChatGPT Logs Be Subpoenaed? 20M Chats Ordered” Terms.Law, 12 Nov. 2025, www.terms.law/2025/11/12/openai-v-new-york-times-stopped-being-just-a-copyright-case-the-moment-the-court-turned-to-your-chatgpt-logs/. Accessed 6 Oct. 2026. ↩︎
  11. Townsend, Chance. “Judge lifts order requiring OpenAI to preserve ChatGPT logs” Mashable, 12 Oct. 2025, mashable.com/article/openai-court-ordered-chat-gpt-preservation-no-longer-required. Accessed 6 Oct. 2026. ↩︎
  12. “OpenAI Loses Privacy Gambit: 20 Million ChatGPT Logs Likely Headed to Copyright Plaintiffs” Jones Walker LLP, 6 Jan. 2026, www.joneswalker.com/en/insights/blogs/ai-law-blog/openai-loses-privacy-gambit-20-million-chatgpt-logs-likely-headed-to-copyright-p.html?id=102lzo9. Accessed 6 Oct. 2026. ↩︎
  13. OpenAI, openai.com/index/response-to-nyt-data-demands/. Accessed 6 Oct. 2026. ↩︎
  14. “What is Zero Data Retention AI? Definition & Vendor Guide” Decagon, decagon.ai/glossary/what-is-zero-data-retention-ai. Accessed 6 Oct. 2026. ↩︎
  15. Pignati, Alessandro. “Is Your AI Agent Leaking Secrets? Why Zero Data Retention is the New Standard for Enterprise Trust” DEV Community, 31 Mar. 2026, dev.to/alessandro_pignati/is-your-ai-agent-leaking-secrets-why-zero-data-retention-is-the-new-standard-for-enterprise-trust-3c3a. Accessed 6 Oct. 2026. ↩︎
  16. OpenAI, openai.com/enterprise-privacy/. Accessed 6 Oct. 2026. ↩︎
  17. Team, Digital Applied. “Fable 5’s 30-Day Retention: The End of Zero Retention?” 2 July 2026, www.digitalapplied.com/blog/fable-5-30-day-data-retention-zdr-enterprise-2026. Accessed 6 Oct. 2026. ↩︎

Stay Connected

Share This Article
Follow:

An avid reader of all kinds of literature, Joshita has written on various fascinating topics across many sites. She wishes to travel worldwide and complete her long and exciting bucket list.

Education and Experience

  • MA (English)
  • Specialization in English Language & English Literature

Certifications/Qualifications

  • MA in English
  • BA in English (Honours)
  • Certificate in Editing and Publishing

Skills

  • Content Writing
  • Creative Writing
  • Computer and Information Technology Application
  • Editing
  • Proficient in Multiple Languages
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *