Skip to content

API and data retention changed Anthropic, Aug 5, 2026

Anthropic · Aug 5, 2026 · 67 added, 71 removed · found in an Internet Archive capture

  1. Added: This page covers the Claude API ( api.anthropic.com ), Claude Platform on AWS, and Claude in Microsoft Foundry , where Anthropic is the data processor. On Amazon Bedrock and Google Cloud's Agent Platform, the cloud provider is the data processor; refer to those platforms' data retention and compliance documentation for their equivalent controls.
  2. Added: Anthropic offers two data handling arrangements for the Claude API: zero data retention (ZDR) and HIPAA readiness . The feature eligibility table lists which API features each arrangement covers. For Anthropic's standard retention policies outside these arrangements, see the commercial data retention policy and the consumer data retention policy .
  3. Added: Different APIs and features have different storage needs. Where a feature does not require storage of customer prompts or responses, it may be eligible for ZDR. Where a feature necessarily requires storage, Anthropic designs for the smallest possible retention footprint under the following commitments:
  4. Removed: Information about Anthropic's standard retention policies is set out in Anthropic's commercial data retention policy and consumer data retention policy .
  5. Removed: Anthropic offers two data handling arrangements for the Claude API:
  6. Removed: Zero data retention (ZDR): Customer data is not stored at rest after the API response is returned, except where needed to comply with law or combat misuse.
  7. Removed: HIPAA readiness: For organizations handling protected health information (PHI), Anthropic offers HIPAA-ready API access with a signed Business Associate Agreement (BAA). See HIPAA readiness .
  8. Removed: Different APIs and features have different storage and retention needs. Where an API or feature doesn't require storage of customer prompts or responses, it may be eligible for ZDR. Where an API or feature necessarily requires storage of customer prompts or responses, Anthropic designs for the smallest possible retention footprint. For these features:
  9. Added: Only what is technically necessary for the feature to work is retained. Conversation content (your prompts and Claude's outputs) is not retained by default; the exception is Covered Models , which require 30-day retention.
  10. Added: Retained data is purged on the shortest practical time to live (TTL), and Anthropic aims to give customers control over how long data is retained. What is held, and the retention duration where a specific TTL applies, is documented on each feature's page.
  11. Added: Several retention models sit outside the ZDR and HIPAA arrangements described on this page. Data accessible through the Compliance API follows its own retention model: the Activity Feed and remote session transcripts retain data for 6 years, and chat, file, and project content from claude.ai follows your organization's retention policy set in claude.ai > Organization settings > Data and privacy .
  12. Added: Under a ZDR arrangement, Anthropic does not store customer prompts or responses at rest after the API response is returned. To request ZDR for your organization, contact the Anthropic sales team . ZDR is enabled per organization; each new organization requires ZDR to be enabled separately by your account team, and enablement does not automatically extend to other organizations under the same account.
  13. Added: Claude Messages and Token Counting APIs: ZDR applies to these endpoints for eligible features listed in the feature eligibility table . Features that ride on /v1/messages but are marked "No" in the table (such as code execution) are not covered.
  14. Added: Claude Code: ZDR applies when Claude Code is used with API keys from a Commercial organization (an organization under Anthropic's Commercial Terms of Service, as distinct from a consumer Claude account) or through Claude Enterprise with ZDR enabled. If metrics logging is enabled in Claude Code, productivity data such as usage statistics is exempted from ZDR and may be retained. See the Claude Code ZDR documentation for full details.
  15. Added: Claude Platform on AWS: Claude Platform on AWS follows the same data retention policy as the first-party Claude API. ZDR is available on request; contact your Anthropic account representative to enable it.
  16. Added: Console and Workbench: Any usage on Claude Console or the Workbench prompt-testing interface.
  17. Added: Claude Managed Agents: Claude Managed Agents is a stateful resource; session transcripts persist until you delete them.
  18. Added: Claude consumer products: Claude Free, Pro, and Max plans, including when customers on those plans use Claude's web, desktop, or mobile apps or Claude Code.
  19. Added: Claude Teams and Claude Enterprise product interfaces: These interfaces are not ZDR-eligible. The exception is Claude Code used through Claude Enterprise with ZDR enabled; see What ZDR covers .
  20. Added: Claude for Excel: Not currently ZDR-eligible.
  21. Added: Claude Fable 5 and Claude Mythos 5: These models require 30-day data retention and are not available under ZDR. See Model-specific data retention requirements .
  22. Added: Third-party integrations: Data processed by third-party websites, tools, or other integrations is not covered, though some may have similar offerings. Review each service's data handling practices.
  23. Added: Cross-Origin Resource Sharing (CORS): CORS is not supported for organizations with ZDR arrangements. To make API calls from browser-based applications, route requests through a backend proxy server. See the API security guidance for proxy patterns and API-key handling.
  24. Added: Flagged content and legal holds: See Retention regardless of arrangement .
  25. Added: For the most up-to-date information on which products and features are ZDR-eligible, refer to your contract terms or contact your Anthropic account representative.
  26. Added: The Claude API supports HIPAA-ready integrations for organizations that handle protected health information (PHI). With a signed BAA and a HIPAA-enabled organization, you can use supported API features to process PHI while supporting your organization's HIPAA compliance. Eligible organizations can review and execute the BAA and enable HIPAA readiness directly from the Claude Console. HIPAA readiness applies a broader set of privacy and security safeguards than ZDR (encryption, access controls, and audit logging that protect PHI throughout its lifecycle) rather than requiring immediate deletion. If your organization handles PHI, HIPAA readiness is the arrangement to use; you do not also need ZDR. See the feature eligibility table for which features each arrangement covers.
  27. Removed: Only what is technically necessary for the API and feature to work is retained. Conversation content (your prompts and Claude's outputs) is not retained by default. Certain models require 30-day data retention; see Model-specific data retention requirements .
  28. Removed: Data is purged on the shortest practical TTL, and Anthropic aims to give customers control over how long data is retained. What is held, and the retention duration where a specific TTL applies, is documented on each feature's page.
  29. Removed: Data accessible through the Compliance API follows its own retention model. The Activity Feed retains data for 6 years. Chat, file, and project content from claude.ai follows your organization's retention policy, set in claude.ai > Organization settings > Data and privacy .
  30. Removed: In the feature eligibility table , some features are marked "Yes (qualified)" in the ZDR eligible column. If your organization has a ZDR arrangement, you can use these features with confidence that what Anthropic retains is narrow and is required for optimal performance.
  31. Removed: Claude Fable 5 and Claude Mythos 5 are not available under ZDR; see Model-specific data retention requirements .
  32. Removed: Certain Claude APIs: ZDR applies to the Claude Messages and Token Counting APIs.
  33. Removed: Claude Code: ZDR applies when used with Commercial organization API keys or through Claude Enterprise (see Claude Code ZDR docs )
  34. Removed: Console and Workbench: Any usage on Console or Workbench
  35. Removed: Claude Managed Agents: Claude Managed Agents is a stateful resource. You can delete session transcripts, but there is no automatic deletion.
  36. Removed: Claude consumer products: Claude Free, Pro, or Max plans, including when customers on those plans use Claude's web, desktop, or mobile apps or Claude Code
  37. Removed: Claude Teams and Claude Enterprise: Claude Teams and Claude Enterprise product interfaces are not ZDR-eligible , except for Claude Code when used through Claude Enterprise with ZDR enabled for the organization. For other product interfaces, only Commercial organization API keys are eligible for ZDR.
  38. Removed: Third-party integrations: Data processed by third-party websites, tools, or other integrations is not ZDR-eligible , though some may have similar offerings. When using external services in conjunction with the Claude API, make sure to review those services' data handling practices.
  39. Removed: For the most up-to-date information on what products and features are ZDR-eligible, refer to your contract terms or contact your Anthropic account representative.
  40. Removed: Claude Fable 5 and Claude Mythos 5 are designated Covered Models and require 30-day data retention. Zero data retention is not available for Claude Fable 5 or Claude Mythos 5. On the Claude API, requests to either model from an organization whose data retention configuration does not meet this requirement return a 400 invalid_request_error .
  41. Removed: The 30-day data retention requirement applies wherever Covered Models are offered. On the Claude API (including Claude Platform on AWS), Anthropic handles retained data. On Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry, retained data stays within your cloud provider's environment; review each platform's documentation for enablement steps.
  42. Removed: Organizations with a ZDR arrangement can configure data retention at the workspace level in Claude Console > Settings > Workspaces : open a workspace's Privacy controls tab and turn on 30-day data retention for that workspace. This makes Claude Fable 5 and Claude Mythos 5 available in the designated workspace while the organization's other workspaces keep zero data retention. Workspaces without an override follow the organization default.
  43. Removed: The Claude API supports HIPAA-ready integrations for organizations that handle protected health information (PHI). With a signed BAA and a HIPAA-enabled organization, you can use supported API features to process PHI while supporting your organization's HIPAA compliance.
  44. Removed: Previously, organizations that required HIPAA readiness for the Claude API needed to enable ZDR. HIPAA-ready API access removes this requirement and provides a foundation for Anthropic to progressively enable additional features as they are audited for HIPAA readiness.
  45. Added: Claude API: HIPAA readiness applies to the Claude API ( api.anthropic.com ) for eligible features listed in the feature eligibility table .
  46. Added: Claude consumer products: Claude Free, Pro, and Max plans.
  47. Added: Console and Workbench: Usage through the Claude Console interface (enabling HIPAA readiness from Console settings is supported; processing PHI through the Console is not covered).
  48. Added: Partner-operated platforms: Amazon Bedrock and Google Cloud's Agent Platform. Refer to those platforms' compliance documentation.
  49. Added: Claude Platform on AWS and Microsoft Foundry: HIPAA readiness is not available on these platforms.
  50. Added: Third-party integrations: Data processed by external tools or services connected to your application.
  51. Added: Claude Code: Claude Code is not covered under HIPAA readiness.
  52. Added: Beta features: Features in beta are generally not covered under the BAA unless explicitly listed as eligible in the feature eligibility table .
  53. Added: Protected health information (PHI) includes any individually identifiable health information. In the context of the Claude API, PHI typically appears in message content (prompts and Claude's responses), attached files (images, PDFs), and file names or metadata associated with message content. The following fields are not expected to contain PHI under the BAA: workspace names, user information (name, email, phone number), billing data, and support tickets.
  54. Added: When using structured outputs or tools with strict: true , the API compiles JSON schemas into grammars that are cached separately from message content. These cached schemas do not receive the same PHI protections as prompts and responses. Do not include PHI in JSON schema definitions. This restriction applies to schema property names, enum values, const values, and pattern regular expressions. Patient-specific information should appear only in message content, where it is protected under HIPAA safeguards.
  55. Added: Your signed BAA is the official source of truth for which features are covered. The API also enforces these restrictions automatically. When a HIPAA-enabled organization sends a request that includes a non-eligible feature, the API returns a 400 error to prevent accidental use of features not covered by your BAA:
  56. Added: The error message lists the non-eligible features detected in the request; remove them and retry. The phrase "without Zero Data Retention" is the API's own wording and does not change the resolution.
  57. Added: There are two ways to set up HIPAA-ready API access. Most organizations can enable it directly in the Claude Console with Anthropic's standard BAA; organizations that require a negotiated BAA should work with their account team.
  58. Added: In Claude Console > Settings > Privacy , organization admins with the HIPAA management permission see a HIPAA compliance card. If your organization is eligible but you don't see the option to enable, ask an organization admin to complete these steps.
  59. Added: Download the Business Associate Agreement and the HIPAA Implementation Guide, then accept the agreement as an authorized legal representative of your organization. Each step becomes available after you download the prior document, and your enablement is bound to the exact BAA version you downloaded.
  60. Added: HIPAA readiness controls are applied to your organization as soon as you accept. Once HIPAA readiness is enabled for your organization, the configuration is permanent and cannot be disabled by an administrator. The API automatically enforces feature restrictions, returning an error for requests that use non-eligible features. See HIPAA error handling .

78 more changed paragraphs are on the page itself.

About this change
Page
platform.claude.com/docs/en/manage-claude/api-and-data-retention
Kind
Documentation
Text hash
9bb146baa759 to 622a25fe2788
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.