An enterprise using an AI API may want assurance that the provider checks for misuse without keeping the prompts and responses those checks examine. OpenAI says its Zero Data Retention with Private Safety Processing option is designed to provide both.
OpenAI introduced the option in its DevDay 2026 recap as part of an initiative it calls Private Intelligence. The company says automated safety review can take place without its personnel accessing the underlying customer content. Its developer guide for Private Safety Processing says the review works without OpenAI retaining customer prompts or responses.
The promise is narrower than “OpenAI never processes your data.” It is also separate from Private Inference, a confidential-computing preview the company says it plans for fall. Customers evaluating the announcement need to know what the current retention commitment covers, who controls copies kept elsewhere, and what remains unproven about the future preview.
Safety Review Without Retained Prompts or Responses
The central change is to how safety oversight fits into a Zero Data Retention, or ZDR, arrangement. OpenAI describes Private Safety Processing as enabling offline automated safety review without retaining the customer prompts or responses being reviewed. The company also says its personnel do not get access to the underlying content through that process.
“Offline” should not be read as a detailed technical account of when every check runs or how it affects a particular request. The published description establishes that automated review remains possible under this ZDR option. It does not, by itself, specify every processing step, signal produced by a review, or operational exception a customer might need to assess.
An API provider still has to process a request to deliver a response, and safety systems can still evaluate its content. OpenAI’s stated commitment concerns retention of customer prompts and responses alongside an automated review process that does not give personnel access to the underlying content.
A provider may need safety controls even when a customer cannot accept storage of sensitive conversations for later inspection. Removing retained prompt and response text from the safety-review workflow could make ZDR more useful for those customers. Whether it satisfies a particular organization’s requirements depends on the applicable documentation, configuration, and agreement, not the feature name alone.
OpenAI’s Retention Commitment Is Not a Storage Plan
ZDR describes a boundary around OpenAI’s retention of customer content. It does not decide what happens to copies held by the customer using the API.

An organization may store inputs and outputs in its own application database so users can return to a conversation. It might also record them in logs, analytics systems, evaluation datasets, support tickets, or debugging tools. Those are design choices under the organization’s control. Private Safety Processing does not delete, secure, or govern those separate copies.
Consider an internal assistant that answers questions using company documents. Even if its API requests qualify for ZDR, the organization still has to decide whether chat history is saved, which employees can retrieve it, and how long any saved material remains available. If the assistant sends information to another service, the organization must assess that service’s handling of it too. OpenAI’s retention promise for its part of the workflow does not automatically extend across the larger system.
The Private Safety Processing guide also describes customer operating responsibilities. Teams still need to set policies for what users may submit, determine whether they require their own records for troubleshooting or compliance, and establish how they will investigate problems in their applications.
Keeping less content can reduce exposure if a system is compromised, but it can also leave an operator with less evidence when diagnosing a harmful output or investigating misuse. A customer may reasonably retain selected records in infrastructure it controls. That choice should be deliberate: ZDR does not mean no copy exists anywhere.
Questions Customers Should Settle Before Deployment
The announcement is a starting point for procurement and security review, not a complete statement of what every API deployment receives. OpenAI’s documentation and the customer’s agreement should establish eligibility, the covered services and configurations, and the terms that govern data handling. A team should not infer that enabling ZDR for one workflow automatically covers every model, endpoint, tool, or connected service it uses.
Customers with strict requirements should also ask what, if any, review results, security signals, or service metadata are handled separately from prompts and responses, and on what terms. OpenAI’s statement about not retaining prompts and responses is specific. These are boundaries to verify, not claims that OpenAI retains a particular category under this option.
Organizations should map the path of a request through their own systems. Where is the prompt assembled? Does an application log it before sending it? Is the response saved for the user, forwarded to a tool, or included in a monitoring trace? Answering those questions often matters more to a privacy assessment than repeating the provider’s ZDR label.
Teams must also decide how they will operate safety controls on their side of the API. OpenAI’s ability to run an automated review does not relieve an application owner of decisions about access, abuse handling, user notices, or incident response. The right arrangement depends on the use case and its risks; the announcement does not establish that Private Safety Processing satisfies any particular customer’s legal or regulatory obligations.
Private Inference Is a Separate, Future Preview
In the Private Intelligence announcement, OpenAI also discussed Private Inference, which it says it plans to preview in fall 2026. The company presents it as a confidential-computing approach. It is not a generally available capability or a component customers necessarily receive with ZDR and Private Safety Processing today.
The initiatives address different parts of the privacy question. ZDR with Private Safety Processing concerns whether OpenAI retains prompts and responses while performing automated safety review. Confidential computing, broadly, concerns protections around data while computation is taking place. A future Private Inference implementation would need to be evaluated on its own architecture and terms.
A preview announcement leaves substantial questions open for prospective customers. Which workloads will it support? What technical assurances will customers be able to inspect? How will safety review work within that environment, and what exceptions or operational limits will apply? OpenAI’s fall plan does not yet answer those questions for a production deployment.
Frequently Asked Questions
4 questions
1What Does OpenAI’s Private Safety Processing Do?
Private Safety Processing lets OpenAI conduct automated safety review for its Zero Data Retention option without retaining customer prompts or responses, according to its developer guide. OpenAI also says its personnel do not access the underlying content through that review process. The claim concerns OpenAI’s handling of content in this workflow, not copies a customer may keep in its own systems.
2
Sources
- DevDay 2026 recapopenai.com
- developer guide for Private Safety Processingdevelopers.openai.com
- Data controls in the OpenAI platformdevelopers.openai.com





