Your AI prompts are not private by default
Every prompt you send to OpenAI, Anthropic, or Google passes through their infrastructure — and each provider handles your data differently. Understand what they log, what they train on, and how to lock it down before your data ever leaves your machine.
OpenAI, Anthropic, and Google all say they do not train on your API data — but each handles data retention, abuse monitoring, and ZDR differently. None of them default to zero data retention. Your prompts and responses are logged for abuse monitoring (30 days by default for OpenAI, not retained by default for Anthropic, limited time for Google's paid tier). The safest approach: protect your data before it leaves your machine — so it never reaches the provider in the first place.
Side-by-Side Comparison
| Dimension | OpenAI | Anthropic | |
|---|---|---|---|
| Training on API Data | No (since Mar 2023) | No (never) | Paid: No / Free: Yes |
| Default Retention | Up to 30 days | Not retained (standard) | Paid: limited / Free: may retain |
| Zero Data Retention | Available (sales) | Available (sales) | Not available |
| HIPAA / BAA | Available | Available | Vertex AI only |
| Audit Rights | Enterprise only | Enterprise only | Enterprise Cloud |
| Region Controls | US default / enterprise | US default / AWS regions | 40+ regions (Cloud) |
| CSAM Scanning | Yes (all images/files) | Not disclosed | Per safety policy |
| Consumer vs. API | Separate terms | Separate terms | Separate terms |
Where Your Data Goes
Every prompt flows from your machine to the provider's cloud. Without Shield, sensitive data reaches the provider before any redaction happens. With Shield, PII and secrets are stripped on your machine — the provider never sees them. ZDR helps, but it only affects what happens after the provider receives your data.
The critical insight: provider data policies only matter for data they receive. Shield prevents data from reaching them at all.
Common Questions
Related Articles
Don't bet on provider policies alone
Every provider says they protect your data — but they all log it, retain it, and scan it. Shield stops your passwords, customer data, and company secrets from ever leaving your computer in the first place. Provider policies become irrelevant when the data never reaches them.
Last updated: July 19, 2026