OpenAI previews Private Safety Processing with zero data retention
OpenAI on Aug 20 previewed Private Safety Processing, offering zero data retention for enterprise API frontier customers while keeping automated abuse monitoring by signaling only risk types, not content.
On August 20, 2026, OpenAI expanded its zero data retention commitment to eligible frontier model API customers and simultaneously previewed Private Safety Processing. The mechanism identifies abuse patterns across related interactions without exposing the underlying prompts or responses, sending OpenAI only narrowly defined risk signals rather than content.Per OpenAI, zero data retention means the company does not retain prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train models unless customers explicitly opt in. The policy targets eligible API customers, not consumer ChatGPT users.Private Safety Processing operates in two configurations: content stays on customer-controlled infrastructure, or content is stored on OpenAI infrastructure but encrypted with customer-controlled keys to which OpenAI personnel have no access. When the system detects risk, OpenAI receives only a narrowly defined risk signal indicating the type of activity, not the underlying content. The system is being tested with early customers, with full rollout and a technical white paper planned for September.OpenAI carved out an explicit exception for child sexual abuse material: flagged images will still be retained for manual review and legal reporting, even in zero data retention deployments. The announcement cited Glean, Databricks, Abridge and Microsoft as partners, with Glean CISO Sunil Agrawal publicly backing the approach.The policy positions OpenAI as a privacy-first alternative to Anthropic, which announced in June 2026 that it would require 30-day retention for all traffic on its Mythos-class frontier models. OpenAI is offering enterprise customers a way to access frontier capability without prompts and outputs being held by the model provider.