OpenAI previews Private Safety Processing to keep zero data retention
OpenAI is previewing Private Safety Processing, an automated system built to spot misuse that spreads across several conversations without breaking the zero data retention promise it makes to eligible API customers. The company set it out on August 19 in a post titled Offering Zero Data Retention for frontier models. Zero Data Retention, or ZDR, is the standing promise that OpenAI doesn’t keep prompts or model responses once a request has been processed.
The mechanism is the interesting part. Existing ZDR-compatible safety systems assess each interaction on its own, which means a pattern assembled across separate sessions never gets read as one thing. Private Safety Processing extends those automated checks across related interactions, and OpenAI says its personnel don’t get access to the underlying content even when something is flagged. What reaches the company instead is a “narrowly defined signal indicating the type of activity involved”.
Aleah Houze, Head of Product Policy at OpenAI, gave reporters a worked example in a briefing reported by Axios. Someone might ask about a weakness in a company’s software in one conversation, then ask about remote access or what security tools can detect in another. Neither question looks alarming by itself, but together they read differently.
We’re seeing with more capable frontier models that often risks are emerging not just by looking at one single prompt and response pair, but when you look over time at multiple interactions.
Aleah Houze, Head of Product Policy at OpenAI, via Axios
The Anthropic policy this answers
That same reasoning is what led Anthropic to the opposite decision, which is why this preview reads as a rebuttal. Anthropic’s policy page for covered models says prompts and outputs from those models are retained for 30 days to support safety work, on every platform where they’re offered. It covers Mythos-class models and future models with similar capabilities, and Anthropic’s page says it went into effect on June 9, 2026. Anthropic says no personnel can read retained conversations by default, and that human review happens only through a controlled access path with a small set of approved reviewers.
| OpenAI | Anthropic | |
|---|---|---|
| Retention on the models at issue | None under ZDR | 30 days for covered models |
| Where content sits | Infrastructure the customer controls, or OpenAI storage encrypted with customer-held keys | Every platform where covered models are offered |
| Human review of content | Personnel don’t receive access, even when flagged | Controlled access path, small set of approved reviewers, tamper-proof log |
| Who it applies to | Eligible enterprise and API customers | Organizations with ZDR workspaces using covered models |
The competitive read is hard to miss. TechCrunch framed the preview as OpenAI seeking to one-up Anthropic, whose retention policy it reports has aggravated some customers. There’s money behind the needling. TechCrunch cites reporting that Anthropic’s annualized revenue run rate is now $65 billion, the figure the company gave investors in July.
What OpenAI hasn’t shown yet
Even so, the preview is a claim rather than a proof. OpenAI hasn’t published any technical account of how patterns get assembled across sessions without a person seeing content. The option to store content on OpenAI infrastructure under customer-held keys is described as still being developed, not shipped. The post quotes Sunil Agrawal, chief information security officer at Glean, on why the no-training commitment matters, but it doesn’t name which customers are running the test.
The scope is also narrower than the framing suggests. Axios reports the system is built for eligible enterprise and API customers, not for people on OpenAI’s paid consumer ChatGPT plans. ZDR controls don’t apply to Free, Plus, Go and Pro users, and Axios says their existing data settings are unchanged.
September is the date to hold OpenAI to. That’s when it plans to start rolling Private Safety Processing out and publish a technical white paper. That paper is the thing worth reading, because it’s where the cross-session detection either survives scrutiny or doesn’t. It lands while the company is slowing its own model work, having paused some model training work over cyber risk the day before.
Get the daily rundown
One email each weekday with the AI news that matters, every claim linked to its primary source.
Free, one email each weekday, unsubscribe in one click. We never sell or share your address.
