> ## Documentation Index
> Fetch the complete documentation index at: https://zerodrift.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Retention

> How long ZeroDrift retains customer content, validation results, and Activity Center records.

# Data Retention

> How ZeroDrift retains and deletes customer data processed through the platform.

This page is the customer-facing data retention policy for the ZeroDrift platform. It supplements the [Privacy Statement](https://zerodrift.com/legal/privacy-statement) and [Data Processing Practices](https://zerodrift.com/legal/data-processing-practices). Contractual terms in your Customer Agreement or DPA control if they differ.

## Principles

* **Default to deletion.** Customer content is kept only as long as needed to deliver the service, then deleted.
* **Contracts can extend retention.** Enterprise agreements may require longer retention for exam-ready records.
* **No model training.** Customer data is not used to train, tune, or improve ZeroDrift or third-party AI models.
* **Deletion is automated.** Retention is enforced with scheduled deletion jobs and object-store lifecycle rules.

## What we store

| Category                  | Examples                                                                       |
| ------------------------- | ------------------------------------------------------------------------------ |
| Customer content          | Message bodies, documents, and files submitted for validation or policy import |
| Transient uploads         | Objects written to presigned S3 URLs before validation starts                  |
| Validation jobs & results | Job status, rule findings, and suggested fixes returned by the API             |
| Activity / audit records  | Compact Activity Center events (verdict, rules cited, timeline)                |
| Workspace configuration   | Users, API keys, rule packs, custom rules, and integration settings            |

ZeroDrift acts as a **processor** for customer-submitted communications content and processes it only on your documented instructions.

## Default retention schedule

Unless your Customer Agreement or DPA states otherwise:

| Data class                                      | Default retention                                                     |
| ----------------------------------------------- | --------------------------------------------------------------------- |
| Customer content submitted to the platform      | **7 days**, then deleted                                              |
| Transient presigned upload objects (S3 staging) | **24 hours**                                                          |
| Validation job records and results              | **7 days**, aligned with the underlying content                       |
| Activity Center records                         | Available in Command and via the Activities API for up to **30 days** |
| Workspace configuration                         | Life of the customer relationship **+ 90 days** after termination     |
| Product audit logs (admin/user actions)         | Life of the relationship **+ up to 24 months** after termination      |
| Aggregated / de-identified operational metrics  | Retained as needed for capacity and reliability (no message content)  |

### Contractual overrides

If your agreement requires ZeroDrift to retain regulated communications or audit artefacts longer than the defaults (for example, to support your SEC/FINRA recordkeeping obligations), ZeroDrift retains the covered data for the longer of the contractual minimum and the default above.

Shorter retention — including discard immediately after the response is returned — may be available under enterprise arrangements. Contact [support@zerodrift.ai](mailto:support@zerodrift.ai) or your ZeroDrift account team.

## Deletion and offboarding

* Send deletion or return requests through the channel in your Customer Agreement, or to [support@zerodrift.ai](mailto:support@zerodrift.ai).
* Verified requests are acknowledged within **5 business days** and approved deletions completed within **30 days** (backups cleared on the next backup cycle), except where a legal hold or contractual/regulatory minimum retention applies.
* On termination, the data-handling clause in your Customer Agreement governs return or deletion. Where the agreement is silent, remaining customer data is returned or deleted at your election, except where retention is required by law.

## Subprocessors and AI providers

Customer data may be processed by cloud infrastructure and AI model subprocessors solely to deliver the service. Current model providers include OpenAI and Anthropic. Those providers process data to deliver the inference and do not retain it for their own purposes or use it to train their models.

See the current subprocessor list in the [ZeroDrift Trust Center](https://app.vanta.com/zerodrift.ai/trust/8dwp517ay48r0q3abhwy09).

## Support

Questions about retention, deletion, or contractual overrides: [support@zerodrift.ai](mailto:support@zerodrift.ai)
