OpenAI previews Private Safety Processing to keep Zero Data Retention as Anthropic requires logs
OpenAI is previewing Private Safety Processing, a cross-session safety monitor that runs while prompts and responses stay under Zero Data Retention. The rollout and a technical white paper are planned for September. Anthropic still requires 30-day logs on its covered models.

OpenAI is previewing a system it calls Private Safety Processing (PSP) that runs safety monitoring across multiple conversations while keeping customer prompts and responses under Zero Data Retention (ZDR), according to its own post and reporting from TechCrunch and Axios. This is a controls change for eligible API customers, not a new toggle in consumer ChatGPT.
The instrument: what ZDR retains, and what it does not
Zero Data Retention means OpenAI does not keep prompts or model responses after a request is processed. Personnel cannot pull that content for review, and enterprise data is not used to train models unless the customer opts in. That is the baseline the preview builds on, not the new part.
Read the scope correctly. Axios is explicit that this does not touch consumer ChatGPT: the data settings on Free, Plus, Go and Pro stay as they are. If you are a paying individual user, nothing in this announcement changes what happens to your chats. The whole story lives inside the API and enterprise relationship, where a customer can already contract for ZDR today.
One footnote sits underneath the retention promise. Images flagged as potential CSAM are still retained for review even under ZDR. That carve-out is not new, but it is the one place where "we keep nothing" is not literally true.
Private Safety Processing looks across sessions, not just one
The genuinely new mechanism is cross-session. Existing ZDR-compatible safety systems judge each interaction on its own, which means an actor can spread a harmful task across many separate calls and stay under the per-request bar. PSP is built to assess the inputs and outputs of multiple related conversations rather than one, which TechCrunch describes as long-horizon monitoring designed to catch patterns deliberately split across sessions.
OpenAI describes two storage arrangements for the content PSP reasons over. In the first, content stays on customer-controlled infrastructure, the ZDR case. In the second, still in development, content sits on OpenAI infrastructure but is encrypted with keys the customer holds, and OpenAI says its own personnel do not have those keys.
When the automated review flags something, OpenAI says it receives only a "narrowly defined signal" naming the type of activity, not the underlying content. Staff still cannot open the conversation. If OpenAI decides enforcement may be warranted, it approaches the customer, and the customer may choose to share data at its own discretion to appeal or assist an investigation.
The date that matters is September, and the mechanism is not public yet
The number that is not already in a "OpenAI previews ZDR" headline is the timeline: the rollout and a technical white paper are planned for September. Until that paper lands, the exact way PSP inspects content across sessions without exposing it to staff is a claim, not a documented design. That gap is the whole ballgame for a security team deciding whether to trust it.
OpenAI's own post names Glean, Databricks, Abridge and Microsoft among the partners shaping the work, and quotes Glean's chief information security officer. Bloomberg, via The Next Web, separately names Microsoft and Databricks among the preview customers. Those are design partners, not proof the cryptography holds.
Anthropic still requires the logs
There is a live, on-the-record disagreement here, and it is the reason OpenAI shipped this now. Anthropic requires 30-day retention on its "covered models" (its Mythos-class systems and future models with similar capabilities), with human review running through a controlled access path and a small set of approved reviewers writing to a tamper-proof log. Anthropic has itself said the policy "will be unpopular with customers who have come to expect zero retention." OpenAI's pitch is the mirror image: keep the retention at zero and move the safety check to a signal that never carries the content.
Both cannot be the obvious right answer. One vendor says meaningful safety monitoring on frontier models needs retained logs; the other says it can do the monitoring across sessions while retaining nothing legible to its own staff. The cross-session mechanism that would let you referee that is exactly what is not published until September.
The takeaway
If you buy frontier API access, do not treat ZDR-plus-PSP as a drop-in replacement for Anthropic's 30-day log rule yet. You have two concrete moves before September. Wait for the white paper and read how content is inspected across sessions without staff access before you rely on the privacy claim. Or ask OpenAI now whether your account is in the preview and, specifically, where the content actually sits: on your own infrastructure, or on OpenAI's under keys you hold. The answer to that second question is the difference between a control you own and a promise you are trusting.
Subscribe to Techpresso
Free daily newsletter, read in 5 minutes.
Subscribe free