Skip to content

API and data retention changed Anthropic, Sep 1, 2026

Anthropic · Sep 1, 2026 · 8 added, 7 removed · found in an Internet Archive capture

  1. Added: Several retention models sit outside the ZDR and HIPAA arrangements described on this page. Data accessible through the Compliance API follows its own retention model. The Activity Feed retains data for 6 years. Chat, file, and project content from claude.ai follows your organization's retention policy set in claude.ai > Organization settings > Data and privacy . Local session transcripts (from sessions on users' machines, in apps such as Cowork and Claude Code) are stored for 6 years by default, or for your organization's custom conversation retention period when a finite one is set (the same claude.ai setting). Remote session transcripts (Cowork in the cloud) are retained for 6 years. The Compliance API does not capture local sessions for which ZDR is in effect, or any local sessions from organizations with HIPAA readiness enabled.
  2. Removed: Several retention models sit outside the ZDR and HIPAA arrangements described on this page. Data accessible through the Compliance API follows its own retention model: the Activity Feed and remote session transcripts retain data for 6 years, and chat, file, and project content from claude.ai follows your organization's retention policy set in claude.ai > Organization settings > Data and privacy .
  3. Added: Claude Console: Any usage in the Claude Console, including playground.
  4. Removed: Console and Workbench: Any usage on Claude Console or the Workbench prompt-testing interface.
  5. Added: Claude Console: Usage through the Claude Console interface (enabling HIPAA readiness from Console settings is supported; processing PHI through the Console is not covered).
  6. Removed: Console and Workbench: Usage through the Claude Console interface (enabling HIPAA readiness from Console settings is supported; processing PHI through the Console is not covered).
  7. Added: The error message lists the non-eligible features detected in the request; remove them and retry. The phrase "without Zero Data Retention" is the API's own wording and does not change the resolution. Client-side tools whose Details column in the feature eligibility table says they are not blocked are accepted but remain outside HIPAA readiness.
  8. Removed: The error message lists the non-eligible features detected in the request; remove them and retry. The phrase "without Zero Data Retention" is the API's own wording and does not change the resolution.
  9. Added: HIPAA readiness controls are applied to your organization as soon as you accept. Once HIPAA readiness is enabled for your organization, the configuration is permanent and cannot be disabled by an administrator. The API automatically enforces feature restrictions, returning an error for requests that use non-eligible features. See HIPAA error handling for the error and the client-side tool exception.
  10. Removed: HIPAA readiness controls are applied to your organization as soon as you accept. Once HIPAA readiness is enabled for your organization, the configuration is permanent and cannot be disabled by an administrator. The API automatically enforces feature restrictions, returning an error for requests that use non-eligible features. See HIPAA error handling .
  11. Added: No: The feature is not eligible. Under HIPAA readiness, the API blocks requests that include a "No" feature and returns a 400 error, unless the feature's Details column says otherwise. Under ZDR, the API does not block these features; using one is a choice to step outside your ZDR arrangement for that specific data, and the feature's own documented retention policy applies. Features marked "No" for ZDR are typically stateful (they store jobs, files, or container state), which is why they cannot be zero-retention.
  12. Removed: No: The feature is not eligible. Under HIPAA readiness, the API blocks requests that include a "No" feature and returns a 400 error. Under ZDR, the API does not block these features; using one is a choice to step outside your ZDR arrangement for that specific data, and the feature's own documented retention policy applies. Features marked "No" for ZDR are typically stateful (they store jobs, files, or container state), which is why they cannot be zero-retention.
  13. Added: Client-side tool. Anthropic does not run browser actions or retain page content beyond standard API handling. Not covered under HIPAA readiness; requests that include the browser use tool are not blocked. See Browser use .
  14. Added: Files retained until explicitly deleted or they reach their configured expiration. See Files API .
  15. Removed: Files retained until explicitly deleted. See Files API .
About this change
Page
platform.claude.com/docs/en/manage-claude/api-and-data-retention
Kind
Documentation
Text hash
622a25fe2788 to acf9db697b46
Dated by
the first Internet Archive capture sampled that shows the new text; the change happened on or before this date

Terms changes by email

Mondays, only in weeks when a watched page changed.

Double opt-in. Unsubscribe any time.