AI DevelopmentDecision guide9 min readPublished September 8, 2026

Which AI Agent Features Fall Outside Zero Data Retention

Compare 31 agent features across Anthropic, OpenAI, Google and AWS, with dated sources for retention, ZDR eligibility, contract scope and deletion.

DA
Digital Applied Team
Research and practical implementation
PublishedSeptember 8, 2026
EvidencePrimary documentation

A model can support a zero-data-retention arrangement while the agent feature around it stores sessions, files or memories. The purchase decision therefore belongs at the feature level. Start with the workflow you intend to run, identify every place it creates persistent state, and check each against the applicable provider arrangement.

This census records 31 feature and delivery-surface combinations across Anthropic, OpenAI, Google and AWS. It separates what provider documentation states from what remains unknown. It is a procurement reference, not a legal opinion or a certification that any deployment meets its obligations.

Key takeaways
  1. 01
    A provider label is too broad.Messages, files, hosted sessions and tools can have different eligibility.
  2. 02
    State and abuse monitoring differ.Disabling response storage does not establish that every copy or log disappears.
  3. 03
    Deletion may require several operations.Session history, uploaded files and derived memories can have separate lifecycles.
  4. 04
    Unknown is a useful result.Ask the provider for a feature-specific answer instead of inferring it from a nearby service.

01Practical decisionRetention and eligibility by feature

ZDR means zero data retention under the provider’s defined arrangement. BAA means a HIPAA business associate agreement; DPA means a data processing agreement, with Google’s CDPA label retained where documented. Eligibility does not establish that your organization has executed the required agreement.

Read the contract and deletion fields separately even where they share a column. “Conditional” requires the applicable account, model and feature settings. “Unknown” means the inspected source does not establish the field; it does not mean the provider has no agreement or deletion mechanism. Source letters resolve directly to provider pages.

Provider documentation linked in every cell, read September 9, 2026. This sample is not an exhaustive product inventory or a vendor ranking.
Provider / featureZDR eligibilityRetention windowContract and deletion path
Anthropic / Messages Source · Sep 9, 2026Conditional A · Sep 9, 2026No conversation-content storage by default; exceptions below A · Sep 9, 2026Contract: HIPAA eligible; DPA unknown A · Sep 9, 2026
Delete: Unknown A · Sep 9, 2026
Anthropic / Files Source · Sep 9, 2026No A · Sep 9, 2026Until deletion or configured expiry A · Sep 9, 2026Contract: BAA no; DPA unknown A · Sep 9, 2026
Delete: Separate file deletion M · Sep 9, 2026
Anthropic / Batch Source · Sep 9, 2026No A · Sep 9, 202629 days A · Sep 9, 2026Contract: BAA no; DPA unknown A · Sep 9, 2026
Delete: Account representative A · Sep 9, 2026
Anthropic / Web search, no dynamic filtering Source · Sep 9, 2026Conditional A · Sep 9, 2026Response handling A · Sep 9, 2026Contract: HIPAA eligible; DPA unknown A · Sep 9, 2026
Delete: Unknown A · Sep 9, 2026
Anthropic / Web fetch, no dynamic filtering Source · Sep 9, 2026Conditional A · Sep 9, 2026Response handling; publisher policies separate A · Sep 9, 2026Contract: BAA no; DPA unknown A · Sep 9, 2026
Delete: Unknown A · Sep 9, 2026
Anthropic / MCP connector Source · Sep 9, 2026No A · Sep 9, 2026Standard policy A · Sep 9, 2026Contract: BAA no; DPA unknown A · Sep 9, 2026
Delete: Account representative A · Sep 9, 2026
Anthropic / MCP tunnels Source · Sep 9, 2026No A · Sep 9, 2026Unknown T · Sep 9, 2026Contract: BAA no; DPA unknown A · Sep 9, 2026
Delete: Archive tunnel; remove local credentials; data erasure unknown T · Sep 9, 2026
Anthropic / Managed Agents sessions Source · Sep 9, 2026No M · Sep 9, 2026Stored session history/state/output M · Sep 9, 2026Contract: BAA no; DPA unknown M · Sep 9, 2026
Delete: Delete session; uploaded files separately M · Sep 9, 2026
Anthropic / Scheduled deployments Source · Sep 9, 2026No: Managed Agents sub-feature A · Sep 9, 2026Session data persists; run-record TTL unknown A · Sep 9, 2026S · Sep 9, 2026Contract: BAA no; DPA unknown A · Sep 9, 2026
Delete: Archive stops schedule; delete sessions/files separately; record erasure unknown S · Sep 9, 2026M · Sep 9, 2026
OpenAI API / Chat Completions Source · Sep 9, 2026Conditional O · Sep 9, 2026No ordinary state; abuse logs up to 30 days by default; exceptions apply O · Sep 9, 2026Contract: BAA conditional; DPA unknown H · Sep 9, 2026
Delete: Unknown O · Sep 9, 2026
OpenAI API / Responses foreground Source · Sep 9, 2026Conditional; store=false under ZDR O · Sep 9, 2026Default stored response ≥30 days O · Sep 9, 2026Contract: BAA conditional; DPA unknown H · Sep 9, 2026
Delete: Unknown in inspected page O · Sep 9, 2026
OpenAI API / Responses background Source · Sep 9, 2026Permitted from ZDR projects; temporary storage B · Sep 9, 2026Roughly 10 minutes with store=false B · Sep 9, 2026Contract: Responses BAA conditional; DPA unknown H · Sep 9, 2026
Delete: Automatic after temporary polling period B · Sep 9, 2026
OpenAI API / Conversations Source · Sep 9, 2026No O · Sep 9, 2026Until deletion O · Sep 9, 2026Contract: Unknown H · Sep 9, 2026
Delete: Deletion required; exact operation not checked O · Sep 9, 2026
OpenAI API / Files Source · Sep 9, 2026No O · Sep 9, 2026Until deletion/expiry O · Sep 9, 2026Contract: BAA conditional; DPA unknown H · Sep 9, 2026
Delete: API/dashboard; expires_after O · Sep 9, 2026
OpenAI API / Batch Source · Sep 9, 2026No O · Sep 9, 2026Until deletion O · Sep 9, 2026Contract: BAA conditional; DPA unknown H · Sep 9, 2026
Delete: Unknown in inspected page O · Sep 9, 2026
OpenAI API / Live web search Source · Sep 9, 2026Tool-specific classification unknown O · Sep 9, 2026Tool-specific window unknown O · Sep 9, 2026Contract: BAA no; DPA unknown O · Sep 9, 2026
Delete: Unknown O · Sep 9, 2026
OpenAI API / Cache-only web search Source · Sep 9, 2026ZDR setup required for BAA path O · Sep 9, 2026Tool-specific window unknown O · Sep 9, 2026Contract: BAA conditional; DPA unknown O · Sep 9, 2026
Delete: Unknown O · Sep 9, 2026
OpenAI API / Remote MCP Source · Sep 9, 2026Third-party boundary O · Sep 9, 2026MCP operator policy O · Sep 9, 2026Contract: Third-party agreement unknown O · Sep 9, 2026
Delete: MCP operator; exact path unknown O · Sep 9, 2026
OpenAI / Codex cloud Source · Sep 9, 2026Unknown C · Sep 9, 2026Unknown numeric window C · Sep 9, 2026Contract: BAA no; DPA unknown H · Sep 9, 2026
Delete: Unknown C · Sep 9, 2026
Google Cloud / Plain model inference Source · Sep 9, 2026Conditional configuration and model G · Sep 9, 2026Abuse/Advanced AI exceptions; inspect contract G · Sep 9, 2026Contract: CDPA referenced; BAA unknown G · Sep 9, 2026
Delete: Unknown G · Sep 9, 2026
Google Cloud / Search grounding Source · Sep 9, 2026No for this feature G · Sep 9, 2026Derived query/context logs ≤3 days G · Sep 9, 2026Contract: CDPA referenced; BAA unknown G · Sep 9, 2026
Delete: Logging cannot be disabled G · Sep 9, 2026
Google Cloud / Maps grounding Source · Sep 9, 2026No for this feature G · Sep 9, 2026Prompts/context/output 30 days G · Sep 9, 2026Contract: CDPA referenced; BAA unknown G · Sep 9, 2026
Delete: Logging cannot be disabled G · Sep 9, 2026
Google Cloud / Live session resumption Source · Sep 9, 2026Disable resumption for ZDR G · Sep 9, 2026Cached inputs/outputs ≤24 hours G · Sep 9, 2026Contract: CDPA referenced; BAA unknown G · Sep 9, 2026
Delete: Exact deletion operation unknown G · Sep 9, 2026
Google Cloud / Managed Agents preview Source · Sep 9, 2026Unknown; confidential-data use prohibited V · Sep 9, 2026Unknown numeric window V · Sep 9, 2026Contract: Pre-GA restrictions; BAA/DPA unknown V · Sep 9, 2026
Delete: Project deletion documented; individual record erasure unknown V · Sep 9, 2026
Gemini Developer API / Stored interactions (paid) Source · Sep 9, 2026Unknown program eligibility; stored state I · Sep 9, 202655 days; configurable 7/14/28/55 I · Sep 9, 2026Contract: BAA/DPA unknown I · Sep 9, 2026
Delete: interactions.delete or AI Studio; expiry I · Sep 9, 2026
Gemini Developer API / Stateless interactions Source · Sep 9, 2026Unknown program eligibility; store=false supported I · Sep 9, 2026Interaction storage disabled; other retention unknown I · Sep 9, 2026Contract: BAA/DPA unknown I · Sep 9, 2026
Delete: No stored interaction; other deletion unknown I · Sep 9, 2026
Gemini Developer API / Background interactions Source · Sep 9, 2026store=false incompatible I · Sep 9, 2026Stored interactions follow tier policy I · Sep 9, 2026Contract: BAA/DPA unknown I · Sep 9, 2026
Delete: interactions.delete or AI Studio; expiry I · Sep 9, 2026
Gemini Developer API / Files Source · Sep 9, 2026Unknown program eligibility; file storage required F · Sep 9, 202648 hours F · Sep 9, 2026Contract: BAA/DPA unknown F · Sep 9, 2026
Delete: files.delete or automatic expiry F · Sep 9, 2026
AWS AgentCore / Runtime sessions Source · Sep 9, 2026Unknown D · Sep 9, 2026Data window unknown; microVM lifetime is separate R · Sep 9, 2026Contract: Service HIPAA eligible; BAA/DPA terms unknown K · Sep 9, 2026
Delete: Timeout terminates instance; session can resume R · Sep 9, 2026
AWS AgentCore / Short-term memory Source · Sep 9, 2026Unknown program eligibility; persistent events W · Sep 9, 2026Configured event retention ≤365 days W · Sep 9, 2026Contract: Service HIPAA eligible; BAA/DPA terms unknown K · Sep 9, 2026
Delete: DeleteEvent; derived long-term memory survives E · Sep 9, 2026
AWS AgentCore / Long-term memory Source · Sep 9, 2026Unknown D · Sep 9, 2026Unknown numeric window W · Sep 9, 2026Contract: Service HIPAA eligible; BAA/DPA terms unknown K · Sep 9, 2026
Delete: DeleteMemoryRecord separately L · Sep 9, 2026

02Practical decisionRead the conditions before using an eligible feature

Anthropic’s eligibility documentation adds model-specific exceptions: Fable 5/5.1 and Mythos 5/5.1 require 30-day retention without express authorization. Search/fetch dynamic filtering is excluded from the eligible path. Flagged content may be retained up to two years, with legal exceptions. A feature-level yes cannot override those conditions.

OpenAI’s HIPAA guidance requires an executed BAA and Modified Retention for covered API use unless specified otherwise. Codex cloud is excluded. The API data-controls page separately conditions the cache-only web-search BAA path on supported non-preview tooling, disabled external web access and ZDR at organization and project level.

These details change how a procurement question should be phrased. Ask whether the exact model, endpoint, tools and settings are covered by the proposed agreement. A response about the general API may be accurate while leaving the intended hosted feature unanswered.

Our Astra–Fable comparison covers model selection. Use this feature census as a separate filter before running an evaluation with confidential material.

03Practical decisionWhat stateful agents cost the reviewer

Persistent state can be useful: it lets work resume, keeps files available and avoids asking the user to repeat context. The review cost is identifying which resources exist, who can access them, how long they remain and which operation removes them. That work is part of choosing the runtime.

Claude Managed Agents documentation says the stateful service is outside current ZDR and HIPAA BAA eligibility. Session deletion and uploaded-file deletion are separate. The question for a buyer is whether that persistence fits an acceptable arrangement, not whether persistence is automatically disqualifying.

The current OpenAI background-mode guide permits requests from ZDR projects with store=false while retaining temporary polling data for roughly ten minutes. That is a specific documented exception to a literal expectation of no storage. Quote the behavior when assessing it rather than relying on an older blanket description of background mode.

Google’s managed-agent preview guide restricts confidential input and commercial/production use. General cloud data-governance statements do not remove those preview restrictions. Our Google managed-agent analysis provides product context; the current feature terms decide the allowed use.

04Practical decisionFollow deletion through the derived data

Draw a simple resource list for a representative task: input request, session, uploaded file, tool result, memory, trace and export. Identify the owner and deletion operation for each. A request to delete the session should not be treated as proof that the other resources were removed.

AWS short-term event deletion documentation says deleting an event does not remove derived long-term memory. The latter has a separate DeleteMemoryRecord operation. Similarly, runtime lifecycle limits describe instance lifetime, not a universal data-retention promise. A stopped process and erased data are different outcomes.

Include destinations outside the runtime. A remote tool may receive information under its own policy, and an exported trace may remain in your observability system. The provider’s deletion operation cannot establish what your own retained export contains. Keep the data-flow map narrow enough that an engineer can verify it.

Our agent runtime and sandbox matrix helps identify execution boundaries. Add storage and deletion ownership to that runtime decision before calling the workflow ready for sensitive work.

05Practical decisionTurn unknown cells into precise provider questions

An unknown cell should produce a question with a subject and a requested answer. For example: does this feature retain session content after an explicit delete request, and what documented window applies to primary copies and backups? Avoid asking whether the whole platform is compliant; that invites an answer too broad to settle the deployment.

Attach the model ID, region, feature name and enabled tools to the question. Ask which contract covers the service and whether an eligibility exception requires approval. Request a source or written commitment that can be retained with the deployment record.

For implementation, test the operations available to you using non-sensitive sample data: create the resource, find it, delete it and confirm the visible result. Such a test can establish that the control works in your application. It cannot independently establish deletion of provider backups or other internal copies; those require the provider’s documented commitment.

Keep the census at the same URL and re-check it when the provider changes a feature or your workflow adds a new destination. A table read today is evidence for today’s decision, not a permanent certification. Our Claude Managed Agents update guide illustrates how runtime features can change the scope of an earlier review.

Methodology

This is a documentation comparison, not a hands-on performance test.

As-of date
September 9, 2026. Published September 8 as an editorial backfill; collection happened the following day.
Scope
Purposive census of 31 feature/surface rows across four providers, researched from 18 provider documentation pages. Each cell includes its source and read date. Conditional is not default eligibility; unknown is not a negative finding. Contract columns record documentation statements, not a signed agreement or legal assessment.
Refresh
Review after provider policy or model changes. Unknown marks information the cited documentation does not state.

06Next stepWhat to do next

Recommendation

Choose the complete data path, not the model label.

Filter the intended workflow by feature eligibility, retention behavior, contract and deletion path. Resolve consequential unknowns with the provider and preserve the answer with the deployment configuration. Stateful features can be a deliberate choice when their handling fits the requirement; a broad privacy label alone cannot establish that fit.

Our AI transformation services help teams define a useful pilot, evaluate its results and turn the findings into an implementation decision.

Make the decision measurable

Start with a workflow you can evaluate.

Digital Applied helps teams set practical acceptance criteria and measure the work that remains after automation.

Clear scopeUseful evidenceMeasured outcomes
Practical support

From evaluation to implementation

  • Define the required outcome
  • Check the operating constraints
  • Evaluate representative work
Questions and answers

Common questions

No. It means the inspected documentation did not establish the field. Request a feature-specific answer before relying on an assumption.
Related dispatches

Continue reading