Privacy & Zero Data Retention (ZDR)
Zero Data Retention routes a request only to model providers contractually bound not to retain the payload or train on it; if a provider cannot meet that, the request is steered elsewhere rather than silently sent to one that logs. Toggle it per request, or set it as an account-wide default in Settings — and note it governs the upstream provider, not what VantagePrompt stores in your own history.
Zero Data Retention routes a prompt only to model providers that won't log or train on it. Here's what ZDR means, the per-request toggle, the account-wide default, and when to reach for it.
By Andrei Bădulescu, Founder at VantagePrompt·Updated
Some prompts carry things you don't want a third party to keep: an unreleased product spec, internal financials, a customer's PII pasted into a support draft. Zero Data Retention (ZDR) is how you tell VantagePrompt to route that request only to model providers that won't log it or train on it. This guide covers what ZDR actually means, the per-request toggle, the account-wide default, and when reaching for it is worth it.
What does Zero Data Retention actually mean?
By default, many model providers may temporarily log requests for abuse detection, debugging, or product improvement. ZDR is a stricter contract: the provider must not retain your request payload and must not use it to train models. When you enable ZDR on a request, VantagePrompt routes it only to providers that honor that guarantee. If a provider can't meet it, your request is steered elsewhere rather than silently sent to one that logs.
ZDR is about the upstream model provider's retention policy. It does not change what VantagePrompt itself stores in your history. To stop VantagePrompt from keeping your raw prompt text, use the separate 'log prompts' privacy flag in Settings.
How does the per-request ZDR toggle work?
Every optimization has a ZDR control. Flip it on for the runs that carry sensitive input, leave it off for throwaway prompts. Turning it on attaches a zero-retention flag to the request, and VantagePrompt only dispatches to providers that respect it. This is the right granularity for most people: you are not locked into one mode, you decide per prompt.
Concretely, picture two prompts from the same session:
Prompt A (ZDR off):
"Rewrite this tweet to sound more confident: ..."
-> public marketing copy, nothing sensitive. Route normally.
Prompt B (ZDR on):
"Draft an internal memo about the Q3 layoff plan, headcount
numbers attached below: ..."
-> confidential. Toggle ZDR so it only reaches a
no-retention provider.How do I make ZDR the default for my account?
If almost everything you run is sensitive, you don't want to remember the toggle every time. In Settings, under your profile privacy options, there is a ZDR default. When you turn it on, every optimization is forced to ZDR automatically, so the per-request toggle no longer has to be set by hand. It is a one-time switch that makes zero-retention the baseline for your whole account.
Set the ZDR default ON if you work with regulated, proprietary, or customer data as a rule. Leave it OFF and use the per-request toggle if only a minority of your prompts are sensitive. The account default always wins, so an enabled default keeps ZDR on even when the per-request switch looks off.
When should I use ZDR, and when can I skip it?
Turn ZDR on whenever it would matter that an outside company retained this exact text — confidential, personal, or contractually restricted input. Skip it for public-facing copy, where the wider provider pool is worth more than the guarantee.
| Input | ZDR | Why |
|---|---|---|
| Confidential or proprietary — internal docs, unreleased plans, source you cannot expose, financials. | On | A third party retaining this text is the risk you are managing. |
| Personal or regulated — anything resembling PII, health, or customer records. | On | Retention by an outside processor is a compliance problem, not just a preference. |
| Contractually restricted — a policy requires proof that no third party retained it. | On | ZDR is the routing guarantee you can point at. |
| Public-facing copy, generic brainstorming, sample prompts. | Off | Retention is harmless, and you keep the wider provider pool. |
One practical trade-off: ZDR narrows the pool of eligible providers to those that honor zero retention. That can mean fewer routing options for a given model. If a run needs to reach the widest set of providers, weigh that against the sensitivity of the input. For most sensitive work the privacy guarantee is worth the smaller pool. For routing strategy, fallbacks, and provider lists, see the model selection guide.
What is the quickest way to decide?
Ask one question before you hit optimize: would it be a problem if this exact text were logged by an outside company? If yes, ZDR on. If you'd answer yes most of the time, set the account default and stop thinking about it.
Frequently asked questions
- What does Zero Data Retention actually guarantee?
- That the upstream model provider must not retain your request payload and must not use it to train models. With ZDR enabled, VantagePrompt routes only to providers that honour that contract; a provider that cannot meet it is skipped rather than silently used.
- Does ZDR stop VantagePrompt from storing my prompt?
- No. ZDR is about the upstream provider's retention policy. To stop VantagePrompt itself from keeping your raw prompt text in history, use the separate 'log prompts' privacy flag in Settings.
- Should I use the per-request toggle or the account default?
- Set the account default ON if you work with regulated, proprietary, or customer data as a rule. Leave it OFF and use the per-request toggle if only a minority of your prompts are sensitive. The account default always wins, so an enabled default keeps ZDR on even when the per-request switch looks off.
- What is the downside of always leaving ZDR on?
- It narrows the pool of eligible providers to those honouring zero retention, which can mean fewer routing options for a given model. For most sensitive work the guarantee is worth the smaller pool.
- What is the quickest way to decide?
- Ask one question before you hit optimize: would it be a problem if this exact text were logged by an outside company? If yes, ZDR on. If the answer is usually yes, set the account default and stop thinking about it.
Sources
Put it into practice.
Run this technique in the optimizer.