Zero Data Retention
Zero data retention (ZDR) is an operational security policy in which a service provider processes user inputs and model outputs in temporary memory, then discards that content as soon as the request is complete. Enterprises handling sensitive information use ZDR to reduce privacy and security risk, but the promise only holds when the vendor and every model provider or sub-processor follows the same rule.
Zero Data Retention Must Cover the Full Data Chain
During an AI conversation, a customer’s prompt may pass through the browser, the support vendor, routing or monitoring services, and the model provider before the response returns. Zero data retention does not mean the content was never processed, because each service must read enough of the request to perform its part.

The weakest retention term across the vendor and its sub-processors sets the real answer, even when every other link retains nothing.
The promise means that no covered party keeps the conversation content after processing ends, but every party that receives that content must make the same commitment. A vendor’s policy cannot close a gap in its model provider’s terms, and a model provider’s agreement cannot control copies stored by the vendor.
What Zero Data Retention Does Not Automatically Cover
A zero-retention label is incomplete until the written terms name the data, products, and exceptions it covers. Buyers should separate four records that marketing pages often place under one promise.
- Conversation content includes prompts, responses, attachments, and tool results, although the exact list must appear in the agreement.
- Operational metadata may include account identifiers, timestamps, token counts, model names, or latency, which can remain even when message content does not.
- Logs, caches, and backups may follow separate retention windows, especially when a service keeps records for security, abuse prevention, billing, or legal duties.
- Customer-controlled copies remain wherever the customer exports, saves, or sends them, including a CRM, help desk, analytics tool, or downloaded file.
“No training on your data” is also a different promise, because a provider can exclude content from model training while keeping it for a limited security or debugging period. Likewise, content used to ground an AI answer may be stored as a knowledge source under terms that differ from the rules for conversation content.
How to Verify a Zero-Retention Promise
A legal or security reviewer should ask for evidence that follows the same path as the data, rather than relying on one sentence from a marketing page.
- Map every processor. List the vendor, model provider, optional model routes, monitoring tools, and any other service that can receive conversation content.
- Read the controlling documents. Check the DPA, service order, product terms, and sub-processor terms for covered data, endpoints, retention windows, exceptions, and deletion timing.
- Check how the promise works. Ask whether logging, caching, human review, backups, and debugging are disabled by default or require a separate account setting or contract.
A security audit can support the review by showing that stated controls operate, but it does not replace a contract that defines what “zero” covers.
Wonderchat names every sub-processor that touches conversation data, including the model provider. Its GDPR information and public sub-processor list give reviewers a starting point, but they do not establish that Wonderchat operates zero data retention.
Frequently Asked Questions
What is zero data retention?
Zero data retention means covered conversation content is processed to produce a response and is not stored afterward by the vendor or any covered model provider.
Does zero data retention mean nothing is logged?
Not always. An agreement may stop the storage of prompts and responses while allowing limited metadata, billing records, security signals, or legally required records. The contract should name each exception.
How do you verify a vendor’s retention policy?
Map every service that receives content, then compare the vendor’s DPA and product terms with each sub-processor’s terms. Confirm covered data, retention windows, exceptions, settings, and deletion rules in writing.
Related Terms
- Grounding
- Data Residency
- PII Redaction
- Data Processing Agreement