Skip to content

Docs · OpenAI · Reference

OpenAI API data controls for regulated firms

For it, security, compliance, developers.

Short answer

OpenAI says data sent to its API is not used to train models unless you opt in. API inputs and outputs can be kept for up to 30 days in abuse monitoring logs. Zero Data Retention and Modified Abuse Monitoring remove content from those logs, but they need OpenAI's approval. Data residency is set per project and also requires approval.

The defaults

  • Training: OpenAI states that API data has not been used to train its models since March 1, 2023, unless the customer opts in.
  • Abuse monitoring: OpenAI keeps abuse monitoring logs for API use for up to 30 days, longer if the law requires it.
  • Stored objects: features that store content on purpose, such as stored responses, files and vector stores, keep it until you delete it or it expires.

Controls you can request

ControlWhat it doesHow to get it
Zero Data Retention (ZDR)Excludes customer content from abuse monitoring logs on eligible endpoints and turns off storing responsesApply through OpenAI sales; requires approval
Modified Abuse MonitoringExcludes customer content from abuse monitoring logs across API endpointsApply through OpenAI sales; requires approval
Data residencyStores data, and in some regions processes it, in a chosen region such as the US, Europe or the UKSet per project after approval

Once approved, these are set under the organization's data controls, for the whole organization or per project.

A setup we recommend for regulated firms

  • A separate OpenAI project per application, so keys, limits and data settings are scoped.
  • API keys in a secrets manager or the CRM's protected settings, never in code or workflow text.
  • No client identifiers sent unless the use case needs them; mask account numbers and tax IDs first.
  • Your own log of prompts and outputs where the output becomes a record, kept in a system your firm controls.

ChatGPT is different

ChatGPT Business, Enterprise and Edu are covered by OpenAI's business terms, with workspace controls for retention and connectors. The API settings above don't apply to ChatGPT workspaces; review each product's terms on its own.

Official documentation

Frequently asked questions

Does OpenAI train on data sent through the API?

OpenAI states that data sent to the API is not used to train or improve its models unless you explicitly opt in, a policy in place since March 1, 2023.

How do we get Zero Data Retention from OpenAI?

Contact OpenAI's sales team to check eligibility. ZDR needs OpenAI's prior approval, and once approved it is turned on in the organization's data controls.

Salesforce, HubSpot, Anthropic and OpenAI change their products often. Check the official documentation before you rely on a specific setting, limit or price.

Last reviewed October 9, 2026 by the Vantage Point team. Browse all docs