API and data retention changed Anthropic, Sep 24, 2026
Anthropic · Sep 24, 2026 · 24 added, 5 removed · seen by the daily check
- Added: Several retention models sit outside the ZDR and HIPAA arrangements described on this page. Data accessible through the Compliance API follows its own retention model. The Activity Feed retains data for 6 years. Chat, file, and project content from claude.ai follows your organization's retention policy set in claude.ai > Organization settings > Data and privacy , unless a user deletes it sooner. Local session transcripts (from sessions on users' machines, in apps such as Cowork and Claude Code) are stored for 6 years by default, or for your organization's custom conversation retention period when a finite one is set (the same claude.ai setting). Remote session transcripts (Cowork in the cloud) are retained for 6 years, unless a user deletes the session sooner. The Compliance API does not capture local sessions for which ZDR is in effect, or any local sessions from organizations with HIPAA readiness enabled.
- Removed: Several retention models sit outside the ZDR and HIPAA arrangements described on this page. Data accessible through the Compliance API follows its own retention model. The Activity Feed retains data for 6 years. Chat, file, and project content from claude.ai follows your organization's retention policy set in claude.ai > Organization settings > Data and privacy . Local session transcripts (from sessions on users' machines, in apps such as Cowork and Claude Code) are stored for 6 years by default, or for your organization's custom conversation retention period when a finite one is set (the same claude.ai setting). Remote session transcripts (Cowork in the cloud) are retained for 6 years. The Compliance API does not capture local sessions for which ZDR is in effect, or any local sessions from organizations with HIPAA readiness enabled.
- Added: Claude Fable 5.1, Claude Mythos 5.1, Claude Fable 5, and Claude Mythos 5: These models require 30-day data retention and are not available under ZDR unless expressly authorized by Anthropic. See Model-specific data retention requirements .
- Removed: Claude Fable 5 and Claude Mythos 5: These models require 30-day data retention and are not available under ZDR. See Model-specific data retention requirements .
- Added: Claude Fable 5.1, Claude Mythos 5.1, Claude Fable 5, and Claude Mythos 5 are designated Covered Models (see the Covered Models support article ) and require 30-day data retention; ZDR is therefore not available for any of them unless expressly authorized by Anthropic. On the Claude API, requests to Claude Fable 5 from an organization whose data retention configuration does not meet this requirement return a 400 invalid_request_error :
- Removed: Claude Fable 5 and Claude Mythos 5 are designated Covered Models (see the Covered Models support article ) and require 30-day data retention; ZDR is therefore not available for either model. On the Claude API, requests to Claude Fable 5 from an organization whose data retention configuration does not meet this requirement return a 400 invalid_request_error :
- Added: Organizations with a ZDR arrangement can make these models available in a specific workspace by enabling 30-day retention for that workspace only. Other workspaces in the organization keep zero data retention.
- Removed: Organizations with a ZDR arrangement can make Claude Fable 5 and Claude Mythos 5 available in a specific workspace by enabling 30-day retention for that workspace only. Other workspaces in the organization keep zero data retention.
- Added: Requests to Covered Models from this workspace now succeed. Workspaces without an override continue to follow the organization default.
- Removed: Requests to Claude Fable 5 and Claude Mythos 5 from this workspace now succeed. Workspaces without an override continue to follow the organization default.
- Added: Check your contract terms or contact your Anthropic account representative to confirm whether your organization has ZDR arrangements in place.
- Added: Yes. These features retain a minimal, documented set of technical data, not your prompts or Claude's outputs. See the feature eligibility table legend for what "Yes (qualified)" means and How Anthropic approaches data retention for the commitments that govern these features.
- Added: Nothing blocks the request. Features marked "No" for ZDR are fundamentally stateful: the Batch API stores your jobs, the Files API stores your files, and code execution runs in persistent containers. Data for these features is retained per the feature's documented policy. Using them is a choice to step outside your ZDR arrangement for that specific data.
- Added: Contact your Anthropic account representative to discuss deletion options for non-ZDR features.
- Added: ZDR prevents customer data from being stored at rest after the API response is returned. HIPAA readiness involves a broader set of privacy and security safeguards that protect PHI throughout its lifecycle, including encryption, access controls, and audit logging. Under HIPAA readiness, data can be retained with these safeguards in place rather than requiring immediate deletion. The two arrangements cover different feature sets; see the feature eligibility table .
- Added: No. HIPAA-ready API access is designed as an alternative to ZDR for organizations handling PHI. With HIPAA readiness enabled, you get access to supported API features while maintaining the privacy and security protections that HIPAA requires.
- Added: The API returns a 400 error with an invalid_request_error type, except for the client-side tools whose Details column in the feature eligibility table says they are not blocked (those are accepted but remain outside HIPAA readiness). The error message identifies which features are not available. Remove those features from your request and retry. See HIPAA error handling .
- Added: No. HIPAA readiness is enforced at the organization level and automatically blocks non-eligible features (client-side tools noted in the table's Details column are the exception: they are not blocked, but they are still outside HIPAA readiness). Use a separate organization for workloads that do not require HIPAA readiness.
- Added: Eligible organizations can enable HIPAA readiness directly in Claude Console > Settings > Privacy by reviewing and executing Anthropic's standard BAA; see Getting started with HIPAA readiness . If your organization requires a negotiated BAA, or self-serve enablement isn't available for your organization, contact the Anthropic sales team .
- Added: No. The ZDR and HIPAA arrangements described on this page apply to the Claude API, where Anthropic is the data processor. On Bedrock and Google Cloud, the cloud provider is the data processor; refer to those platforms' data retention and compliance policies for their equivalent controls.
- Added: Claude Platform on AWS follows the same data retention policy as the first-party Claude API. ZDR is available on request; contact your Anthropic account representative to enable it. HIPAA readiness is not available on Claude Platform on AWS. See Claude Platform on AWS for details.
- Added: Claude Code is eligible for ZDR through two paths:
- Added: API keys: Claude Code used with pay-as-you-go API keys from a Commercial organization
- Added: Claude Enterprise: Claude Code used through Claude Enterprise with ZDR enabled for the organization
- Added: ZDR is enabled on a per-organization basis. Each new organization requires ZDR to be enabled separately by your account team. ZDR does not automatically apply to new organizations created under the same account.
- Added: Additionally, if you have metrics logging enabled in Claude Code, productivity data (such as usage statistics) is exempted from ZDR and may be retained.
- Added: For full details on ZDR for Claude Code on Claude Enterprise, including disabled features and how to request enablement, see the Claude Code ZDR documentation .
- Added: No, Claude for Excel is not currently ZDR-eligible.
- Added: To request a ZDR arrangement, contact the Anthropic sales team .
About this change
- Page
- platform.claude.com/docs/en/manage-claude/api-and-data-retention
- Kind
- Documentation
- Text hash
- acf9db697b46 to ae0c7912a81e
- Dated by
- the daily check that first read the new text