Skip to main content

Free public instrument from GAGE

The AI Vendor Data Handling Ledger

As of September 2026 this ledger holds 31 records across 5 jurisdictions: 27 verified at a primary source, 0 reported by a secondary source, 0 announced with no document yet, 0 searched and absent, and 4 open questions. By kind: consumer tier 9, business tier 8, api and platform 10, open question 4.

31
Records

5 jurisdictions, 103 primary sources

27
Verified at the source

0 more reported, primary not reached

0
Announced or absent

0 announced with no document, 0 searched and absent

4
Open questions

Posed, sourced, not answered

As of 15 September 2026 the GAGE AI Vendor Data Ledger records 27 verified instruments, 0 reported at a secondary source, 0 announcements without a document, 0 absences and 4 open questions, across 5 jurisdictions. Counts are a floor, not a ceiling: an instrument the ledger has not found is not on it.

Why this ledger exists

Retention is a contract question, not a reputation question

The same vendor gives three different answers to what happens to your data, depending on which plan you are on and whether you reached it through an app or an API. A workplace policy that says which tools are allowed without saying which tier is allowed has not decided anything.

This ledger reads the vendor's own documents and records what each product tier says on ten dimensions, with the date the document was last changed. Where a document is silent, the record says silent, because a vendor that does not say is a fact a buyer needs as much as one that does.

Every row is fetched at its source where the source could be reached, and says so where it could not. The verdict language is the discipline: a reader learns five words once and never has to guess what a row claims.

  • Verified

    The document exists. The ledger fetched it at its publisher and quotes it.

  • Reported, primary not reached

    A reliable secondary source carries it, and the primary document could not be reached. Printed with this label, never as verified.

  • Announced, no document yet

    A body has said it will act. No document exists yet, so the row records the statement and nothing more.

  • Absent

    The ledger searched and found no instrument. The record says where it looked and when.

  • Open question

    No settled answer exists. The ledger poses the question, links the live debate, and does not answer it.

The grid

What the documents state, and where they are silent

For each of the ten dimensions, how many product tiers on the ledger state a rule and how many are silent. A silent cell means the ledger read the vendor's documents and found no statement.

  • Used for training by default

    26 stated, 1 silent.

  • Retention period

    25 stated, 2 silent.

  • Deletion on request

    23 stated, 4 silent.

  • Storage region and residency

    21 stated, 6 silent.

  • Subprocessor list published

    21 stated, 6 silent.

  • Human review of content

    20 stated, 7 silent.

  • Opt out available

    24 stated, 3 silent.

  • DPA available

    16 stated, 11 silent.

  • Persistent memory across sessions

    15 stated, 12 silent.

  • Last change to the terms

    25 stated, 2 silent.

Side by side

Every jurisdiction, counted by verdict and by kind

  • United States

    22 records

    Verified
    22
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    0

    7 consumer tier, 8 business tier, 7 api and platform.

  • European Union

    1 record

    Verified
    0
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    1

    1 open question.

  • France

    2 records

    Verified
    2
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    0

    1 consumer tier, 1 api and platform.

  • China

    2 records

    Verified
    2
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    0

    1 consumer tier, 1 api and platform.

  • Global

    4 records

    Verified
    1
    Reported
    0
    Announced
    0
    Absent
    0
    Open question
    3

    1 api and platform, 3 open question.

Figures of record

Every number on this ledger, with who measured it and when

45 figures, each one printed in the unit its publisher used, beside the publisher and the date it was true. Nothing here is summed across sources, converted between units, or forecast.

  1. 10 regions

    Data residency regions offered. The OpenAI API and platform

    OpenAI platform, data controls in the OpenAI platform, primary source, as of .

  2. 24 hours

    Prompt cache expiry. The OpenAI API and platform

    OpenAI platform, data controls in the OpenAI platform, primary source, as of .

  3. 30 days

    Abuse monitoring log retention. The OpenAI API and platform

    OpenAI platform, data controls in the OpenAI platform, primary source, as of .

  4. 30 days

    Code execution container data retention. The Anthropic API and Claude Developer Platform

    Anthropic platform docs, API and data retention, primary source, as of .

  5. 2 years

    Retention of flagged data even under zero data retention. The Anthropic API and Claude Developer Platform

    Anthropic platform docs, API and data retention, primary source, as of .

  6. 18 months

    Default storage of conversation activity. Microsoft Copilot on a personal account

    Microsoft, privacy FAQ for Microsoft Copilot, primary source, as of .

  7. 18 years

    Minimum age for public content used in European training. Meta AI on Facebook, Instagram and WhatsApp

    Meta newsroom, making AI work harder for Europeans, primary source, as of .

  8. 28 days

    Automatic deletion of unused Copilot memory entries. GitHub Copilot Business and Enterprise

    GitHub docs, Copilot memory, primary source, as of .

  9. 100 conversations

    Conversations kept in Copilot Chat history. GitHub Copilot Business and Enterprise

    GitHub docs, chat with Copilot on GitHub, primary source, as of .

  10. 28 days

    Retention of Copilot Chat messages on GitHub. GitHub Copilot Business and Enterprise

    GitHub docs, chat with Copilot on GitHub, primary source, as of .

  11. 30 days

    Abuse detection retention for flagged traffic. Amazon Bedrock

    AWS documentation, Amazon Bedrock abuse detection, primary source, as of .

  12. 30 days

    Retention cap for models that require review. Amazon Bedrock

    AWS documentation, Amazon Bedrock data retention, primary source, as of .

  13. 2 years

    Retention of flagged data under zero data retention at one vendor. Does zero data retention survive an abuse investigation?

    Anthropic platform docs, API and data retention, primary source, as of .

  14. 28 days

    Automatic deletion of unused memory entries at one vendor. Who owns the memory record an assistant builds about you?

    GitHub docs, Copilot memory, primary source, as of .

  15. 30 days

    Advanced model prompt and response logging. The paid Gemini API and Vertex AI

    Google Cloud, abuse monitoring, primary source, as of .

  16. 90 days

    Abuse monitoring prompt log retention. The paid Gemini API and Vertex AI

    Google Cloud, abuse monitoring, primary source, as of .

  17. 24 hours

    Default in memory cache lifetime. The paid Gemini API and Vertex AI

    Google Cloud, generative AI data governance, primary source, as of .

  18. 1 year

    Retention of account data after deletion. The Mistral consumer assistant

    Mistral AI privacy policy, primary source, as of .

  19. 5 years

    Retention of civil identity data after account termination. The Mistral consumer assistant

    Mistral AI privacy policy, primary source, as of .

  20. 30 days

    Rolling abuse monitoring retention for standard API calls. The Mistral developer platform

    Mistral AI privacy policy, primary source, as of .

  21. 30 days

    Deletion after a person deletes conversations or the account. Grok on the consumer app and website

    SpaceXAI privacy policy, published at x.ai, primary source, as of .

  22. 30 days

    Deletion of Private Chat conversations. Grok on the consumer app and website

    SpaceXAI privacy policy, published at x.ai, primary source, as of .

  23. 36 months

    Ceiling of admin controlled retention for the Gemini app under Workspace. Gemini for Google Workspace

    Google Workspace, generative AI privacy hub, primary source, as of .

  24. 90 days

    Floor of the admin controlled retention range for Gemini in Workspace. Gemini for Google Workspace

    Google Workspace, generative AI privacy hub, primary source, as of .

  25. 72 hours

    Retention when the keep activity setting is off. The Gemini app on a personal Google account

    Google, Gemini Apps privacy hub, primary source, as of .

  26. 3 years

    Retention of human reviewed chats. The Gemini app on a personal Google account

    Google, Gemini Apps privacy hub, primary source, as of .

  27. 18 months

    Default auto deletion of Gemini Apps Activity. The Gemini app on a personal Google account

    Google, Gemini Apps privacy hub, primary source, as of .

  28. 2,024 year

    Date Copilot became a covered workload in the Product Terms residency commitments. Microsoft 365 Copilot, now named Microsoft Copilot

    Microsoft Learn, data, privacy and security for Microsoft Copilot, primary source, as of .

  29. 7 years

    Retention of trust and safety classification scores. Claude Free, Pro and Max

    Anthropic privacy centre, how long do you store my data, primary source, as of .

  30. 2 years

    Retention of inputs and outputs when a chat is flagged. Claude Free, Pro and Max

    Anthropic privacy centre, how long do you store my data, primary source, as of .

  31. 30 days

    Back end deletion after a person deletes a chat. Claude Free, Pro and Max

    Anthropic privacy centre, how long do you store my data, primary source, as of .

  32. 5 years

    Retention in model training pipelines when training is allowed. Claude Free, Pro and Max

    Anthropic privacy centre, how long do you store my data, primary source, as of .

  33. 7 years

    Retention of trust and safety classification scores. Claude for Work, Team and Enterprise

    Anthropic privacy centre, how long do you store my organisation's data, primary source, as of .

  34. 2 years

    Retention of flagged inputs and outputs. Claude for Work, Team and Enterprise

    Anthropic privacy centre, how long do you store my organisation's data, primary source, as of .

  35. 30 days

    Back end deletion of commercial inputs and outputs. Claude for Work, Team and Enterprise

    Anthropic privacy centre, how long do you store my organisation's data, primary source, as of .

  36. 30 days

    Default retention of API inputs and outputs. The Anthropic API and Claude Developer Platform

    Anthropic privacy centre, how long do you store my organisation's data, primary source, as of .

  37. 30 days

    Storage of prompts and output under grounding with Google Search. The Gemini API on the unpaid tier

    Google, Gemini API additional terms of service, primary source, as of .

  38. 30 days

    Deletion of personal data from OpenAI systems. ChatGPT Free, Plus and Pro

    OpenAI privacy policy, primary source, as of .

  39. 30 days

    Removal of deleted or unsaved conversations. ChatGPT Business, the plan formerly called Team

    OpenAI enterprise privacy, primary source, as of .

  40. 30 days

    Removal of deleted conversations. ChatGPT Enterprise and ChatGPT Edu

    OpenAI enterprise privacy, primary source, as of .

  41. 30 days

    Window to object to a new subprocessor. ChatGPT Business, the plan formerly called Team

    OpenAI data processing addendum, primary source, as of .

  42. 30 days

    Objection window after notice of a new subprocessor in one vendor addendum. Is a subprocessor change notice period actually enforceable?

    OpenAI data processing addendum, primary source, as of .

  43. 30 days

    Automatic deletion of logged prompts and generations. The Cohere platform and API

    Cohere enterprise data commitments, primary source, as of .

  44. 30 days

    Post termination deletion window on request. The Cohere platform and API

    Cohere software as a service agreement, primary source, as of .

  45. 30 days

    Automatic deletion of business inputs and outputs. The Grok API and enterprise platform

    SpaceXAI enterprise FAQs, published at x.ai, primary source, as of .

The ledger

Every record, newest first

31 records. Each row opens a page carrying the answer, the verdict and what it means, the key facts, the figures with their sources, what it changes for a buyer or a workplace ai policy, and the sources it was verified against.

RecordVerdictWhereKindVerified
Who owns the memory record an assistant builds about you?AVD-2026-0031Open questionGlobalOpen question
Does zero data retention survive an abuse investigation?AVD-2026-0030Open questionGlobalOpen question
Is a subprocessor change notice period actually enforceable?AVD-2026-0029Open questionEuropean UnionOpen question
Does a promise not to train on your data cover the safety classifiers?AVD-2026-0028Open questionGlobalOpen question
The Cohere platform and APIAVD-2026-0027VerifiedGlobalAPI and platform
Amazon BedrockAVD-2026-0026VerifiedUnited StatesAPI and platform
GitHub Copilot Business and EnterpriseAVD-2026-0025VerifiedUnited StatesBusiness tier
Cursor and its privacy modeAVD-2026-0024VerifiedUnited StatesBusiness tier
Perplexity enterprise and the Sonar APIAVD-2026-0023VerifiedUnited StatesBusiness tier
Perplexity on the free and paid consumer plansAVD-2026-0022VerifiedUnited StatesConsumer tier
The DeepSeek open platform and APIAVD-2026-0021VerifiedChinaAPI and platform
The DeepSeek consumer appAVD-2026-0020VerifiedChinaConsumer tier
The Mistral developer platformAVD-2026-0019VerifiedFranceAPI and platform
The Mistral consumer assistantAVD-2026-0018VerifiedFranceConsumer tier
The Grok API and enterprise platformAVD-2026-0017VerifiedUnited StatesAPI and platform
Grok on the consumer app and websiteAVD-2026-0016VerifiedUnited StatesConsumer tier
Meta AI on Facebook, Instagram and WhatsAppAVD-2026-0015VerifiedUnited StatesConsumer tier
Azure OpenAI Service and models sold by Azure in Microsoft FoundryAVD-2026-0014VerifiedUnited StatesAPI and platform
Microsoft 365 Copilot, now named Microsoft CopilotAVD-2026-0013VerifiedUnited StatesBusiness tier
Microsoft Copilot on a personal accountAVD-2026-0012VerifiedUnited StatesConsumer tier
The paid Gemini API and Vertex AIAVD-2026-0011VerifiedUnited StatesAPI and platform
The Gemini API on the unpaid tierAVD-2026-0010VerifiedUnited StatesAPI and platform
Gemini for Google WorkspaceAVD-2026-0009VerifiedUnited StatesBusiness tier
The Gemini app on a personal Google accountAVD-2026-0008VerifiedUnited StatesConsumer tier
The Anthropic API and Claude Developer PlatformAVD-2026-0007VerifiedUnited StatesAPI and platform
Claude for Work, Team and EnterpriseAVD-2026-0006VerifiedUnited StatesBusiness tier
Claude Free, Pro and MaxAVD-2026-0005VerifiedUnited StatesConsumer tier
The OpenAI API and platformAVD-2026-0004VerifiedUnited StatesAPI and platform
ChatGPT Enterprise and ChatGPT EduAVD-2026-0003VerifiedUnited StatesBusiness tier
ChatGPT Business, the plan formerly called TeamAVD-2026-0002VerifiedUnited StatesBusiness tier
ChatGPT Free, Plus and ProAVD-2026-0001VerifiedUnited StatesConsumer tier

Answers

What people ask the AI Vendor Data Ledger

Which AI products train on what I type by default?

The training_use dimension on every record answers this for its tier as of September 2026. On the consumer tiers, 9 of 9 records carry a document that states training by default unless the person opts out; the record pages quote the sentence. Business and API tiers state the opposite default where the ledger could read it.

Which business tiers offer a data processing addendum?

8 of 8 business tier records state a DPA on the vendor's own page: GitHub Copilot Business and Enterprise; Cursor and its privacy mode; Perplexity enterprise and the Sonar API; Microsoft 365 Copilot, now named Microsoft Copilot; Gemini for Google Workspace; Claude for Work, Team and Enterprise; and more. A DPA is the document that makes retention and subprocessor promises enforceable rather than descriptive.

Where is my data stored?

The region dimension records what each document says about storage and residency. 6 records on the ledger are silent on it, which for a buyer in European Union is the question that decides whether the tier can be used at all.

How does the ledger handle a vendor changing its terms?

Every record carries the date the vendor's document was last changed as a dimension, and the record's own last verified date beside it. The ledger is re read every Monday and the same day a vendor announces a change; a change moves the record's date and appears on the changelog.

What happens to what a person types on a free or personal plan?

9 records of kind consumer tier are on the AI Vendor Data Ledger as of September 2026: Perplexity on the free and paid consumer plans; The DeepSeek consumer app; The Mistral consumer assistant; Grok on the consumer app and website; Meta AI on Facebook, Instagram and WhatsApp; Microsoft Copilot on a personal account; and 3 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What happens to what a team or an enterprise puts in?

8 records of kind business tier are on the AI Vendor Data Ledger as of September 2026: GitHub Copilot Business and Enterprise; Cursor and its privacy mode; Perplexity enterprise and the Sonar API; Microsoft 365 Copilot, now named Microsoft Copilot; Gemini for Google Workspace; Claude for Work, Team and Enterprise; and 2 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What happens to what a developer sends through the API?

10 records of kind api and platform are on the AI Vendor Data Ledger as of September 2026: The Cohere platform and API; Amazon Bedrock; The DeepSeek open platform and API; The Mistral developer platform; The Grok API and enterprise platform; Azure OpenAI Service and models sold by Azure in Microsoft Foundry; and 4 more. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What has nobody settled?

4 records of kind open question are on the AI Vendor Data Ledger as of September 2026: Who owns the memory record an assistant builds about you?; Does zero data retention survive an abuse investigation?; Is a subprocessor change notice period actually enforceable?; Does a promise not to train on your data cover the safety classifiers?. Each has its own page with the verdict, the facts, the sources it was checked against and the date.

What do the verdicts mean?

Verified: the document exists and the ledger fetched it at its publisher. Reported: a reliable secondary source carries it and the primary could not be reached. Announced: a body said it will act and no document exists. Absent: the ledger searched and found nothing, and the search is written into the record. Open: a question nobody has settled, posed and not answered.

How current is the AI Vendor Data Ledger?

Every record carries the date it was last verified; the ledger as a whole was last verified 15 September 2026 and holds 31 records with 103 primary sources. A change moves the record's own date and appears on the changelog, so a reader who cited a row can see whether it moved.

Every surface

Cut the ledger the way you need it

By jurisdiction

By kind

Every record page

Take the data

The whole dataset, free, in two formats

Licensed CC BY 4.0. Use it in an article, a paper, a slide or a product. The only condition is attribution, and the citation page gives you the line to paste.

How the ledger is built, what the verdicts mean, and what the gate refuses: the method page. Every change, dated: the changelog. The kinds on the shelf: consumer tier, business tier, api and platform, open question. Something missing or wrong is a bug, and we want to hear about it. Before you paste anything into any of them, the Paste Test decides whether you should. Which of these tiers your people are already using is the Shadow AI Self-Audit. The policy that names an allowed tier comes from the AI Acceptable Use Policy Builder.

Cite this page

Free to reuse under CC BY 4.0, with attribution.

In a sentence
According to the GAGE AI Vendor Data Ledger (as of 15 September 2026), ai vendor data ledger.
APA
GAGE (Global Academy of Generative-AI Education). (2026). AI Vendor Data Ledger. AI Vendor Data Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/ai-vendor-data-ledger
MLA
"AI Vendor Data Ledger." AI Vendor Data Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/ai-vendor-data-ledger.
Chicago
GAGE (Global Academy of Generative-AI Education). "AI Vendor Data Ledger." AI Vendor Data Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/ai-vendor-data-ledger.
Permalink
https://www.gage.academy/tools/ai-vendor-data-ledger

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any terms change a vendor announces.

10 regions

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.