The OpenAI API and platform
Since 1 March 2023 data sent to the OpenAI API is not used to train its models. Abuse monitoring logs are kept up to 30 days unless longer retention is required by law. Zero data retention and modified abuse monitoring exist but need prior approval. Ten data residency regions are offered, and non United States regions require approval.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AVD-2026-0004
- Kind
- API and platform
- Jurisdiction
- United States
- Last verified
- Added
- The platform guide states that as of 1 March 2023, data sent to the OpenAI API is not used to train or improve OpenAI models.
- Abuse monitoring logs are generated for all API feature usage and retained for up to 30 days unless longer retention is required by law.
- Objects that are not deleted through the API or the dashboard are retained indefinitely.
- Flagged image and file inputs are retained for manual review even where zero data retention, modified abuse monitoring or eyes off is enabled.
Dimension by dimension
10 dimensions, each one stated, silent or open
Used for training by default, Retention period, Deletion on request, Storage region and residency, Subprocessor list published, Human review of content, Opt out available, DPA available, Persistent memory across sessions, Last change to the terms. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- Used for training by defaultStated
- No, and dated. The platform guide states that as of 1 March 2023 data sent to the OpenAI API is not used to train or improve OpenAI models unless you opt in.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- Retention periodStated
- Not one number. Abuse logs up to 30 days, audio outputs one hour, prompt caches 24 hours, and stored conversations, files and vector stores until deleted.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- Deletion on requestStated
- Files can be deleted or set to expire and Assistants objects go 30 days after deletion, but objects never deleted through the API or dashboard are retained indefinitely.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- Storage region and residencyStated
- The only OpenAI tier with a residency control. Ten regions, per project or per request, and any region other than the United States requires approval for abuse monitoring controls.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- Subprocessor list publishedStated
- Yes, with the API named per entity and a marker on the entries that do not apply where zero data retention is used.OpenAI subprocessor list, primary source, 9 July 2026.
- Human review of contentStated
- Yes by default and never zero. Even under zero data retention or modified abuse monitoring, an image flagged as potential child sexual abuse material is retained for manual review.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- Opt out availableStated
- Already out of training. The further controls, zero data retention and modified abuse monitoring, are subject to prior approval by OpenAI and acceptance of additional requirements.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- DPA availableStated
- Yes, plus a business associate agreement for HIPAA work and enterprise key management for customer held encryption keys.OpenAI enterprise privacy, primary source, 8 January 2026.
- Persistent memory across sessionsStated
- No cross session memory feature. Persistence is a developer choice through the store parameter, the conversations endpoints or vector stores, and zero data retention forces store to false.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
- Last change to the termsSilent
- The guide that defines API retention, zero data retention and residency prints no date at all. The nearest dated instruments are the DPA effective 1 January 2026 and the enterprise privacy page of 8 January 2026.OpenAI platform, data controls in the OpenAI platform, primary source, 15 September 2026.
Figures
Every number, with who measured it and when
- 30 days
Abuse monitoring log retention
OpenAI platform, data controls in the OpenAI platform, primary source, as of .
- 24 hours
Prompt cache expiry
OpenAI platform, data controls in the OpenAI platform, primary source, as of .
- 10 regions
Data residency regions offered
OpenAI platform, data controls in the OpenAI platform, primary source, as of .
What it changes
For a buyer or a workplace AI policy
If you are choosing where to put regulated workloads, the API is the only OpenAI surface with a residency control, and it is also the surface whose governing document carries no date. Write the approval requirements into your plan: zero data retention and modified abuse monitoring are granted by OpenAI, not switched on by you, and a flagged image is reviewed by a person whatever you have been granted. Build the schedule around the approval, not the launch.
Sources
What this record was verified against
- OpenAI platform, data controls in the OpenAI platformPrimary · 15 September 2026
- OpenAI enterprise privacyPrimary · 8 January 2026
- OpenAI subprocessor listPrimary · 9 July 2026
Related
Records that sit beside this one
ChatGPT Enterprise and ChatGPT Edu
United States · verified 15 September 2026
The enterprise privacy page states plainly that OpenAI does not train its models on your data by default.
Amazon Bedrock
United States · verified 15 September 2026
Amazon Bedrock uses a zero data retention security model, so by default it does not store model inputs or outputs.
Does zero data retention survive an abuse investigation?
Global · verified 15 September 2026
OpenAI states a flagged image is retained for manual review even where zero data retention, modified abuse monitoring or eyes off is enabled.
GitHub Copilot Business and Enterprise
United States · verified 15 September 2026
GitHub states it does not use Copilot Business or Copilot Enterprise customer data to train AI models.
Cursor and its privacy mode
United States · verified 15 September 2026
The terms of service state that Cursor will not use content to train any AI models unless you have explicitly agreed.
Perplexity enterprise and the Sonar API
United States · verified 15 September 2026
The developer documentation states Perplexity does not use customer data to train its models or for any purpose beyond processing the immediate request.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AVD-2026-0004 is permanent and is never reused.
- In a sentence
- According to the GAGE AI Vendor Data Ledger (as of 15 September 2026), the openai api and platform.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). The OpenAI API and platform. AI Vendor Data Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0004-openai-api-platform
- MLA
- "The OpenAI API and platform." AI Vendor Data Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0004-openai-api-platform.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "The OpenAI API and platform." AI Vendor Data Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0004-openai-api-platform.
- Permalink
- https://www.gage.academy/tools/ai-vendor-data-ledger/records/AVD-2026-0004-openai-api-platform
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any terms change a vendor announces.
Back to the full ledger, or every record for United States and every api and platform record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.