Resource · Security questionnaires
How long AI vendors keep your data
Every retention window we can quote from a page an AI vendor publishes, grouped by vendor, with the sentence it came from and the day we read it.
A vendor does not have a retention period
It has several, and they differ by what the data is. 5 of the 23 vendors below state more than one window on their own pages: Google Cloud (30 days, 180 days); Lovable (30 days, 90 days); Spellbook (30 days, 90 days).
Answer a questionnaire with the first number you find and you will be wrong about the second category, from pages the vendor published side by side. Read which data a window covers before quoting it.
And read what starts the clock
The windows below run from different events, and each sentence carries its own. Some start at termination, some when you delete something, some at collection, some when you ask. Two vendors quoting the same number can mean periods that end months apart, so the trigger deserves as much attention as the figure — it is in the quote either way.
What the record holds
28 stated windows across 23 vendors. 163 of the 186 vendors whose pages Xither reads state no window we could quote.
That last number is a finding rather than a hole. Where a vendor publishes no window, that is what its pages say, and the date we looked is on the record.
The shortest is 30 days (Anthropic); the longest is 7 years (Landing AI). Both are quoted below as written — comparing “13 months” against “365 days” needs a conversion, and no page states the converted figure.
Every window, and the sentence it came from
Ada · 90 days
Following termination, Ada retains data for up to 90 days, after which it is deleted or anonymized in accordance with Ada’s Data Processing Addendum.
90 days · https://ada.cx/privacy · read Aug 31, 2026
Anthropic · 30 days
You also are able to delete individual conversations, which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.
30 days · https://anthropic.com/privacy · read Sep 10, 2026
Demandbase · 13 months
Customer Data is retained during the relationship and with Demandbase and for up to 13 months following the expiration or termination of the relationship.
13 months · https://www.demandbase.com/security-policy/ · read Aug 31, 2026
Fireflies.ai · 30 days
If you close your account, we will delete personal information related to your account within 30 days.
30 days · https://fireflies.ai/privacy · read Sep 13, 2026
GitHub · 90 days
Upon Cancellation](#2-upon-cancellation) We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements, but barring legal requirements, we will delete your full profile and the Content of your repositories within 90 days of cancellation or termination (though some information may remain in encrypted backups).
90 days · https://github.com/terms · read Sep 13, 2026
Google Cloud · 30 days · 180 days
After a recovery period of up to 30 days from that date, Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days, unless European Law requires storage, where European Data Protection Law applies, or applicable law requires storage, where any other Applicable Privacy Law applies. 6.3. *Deferred Deletion Instruction*.
30 days · https://cloud.google.com/terms/data-processing-addendum · read Sep 10, 2026
Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days, unless European Law requires storage, where European Data Protection Law applies, or applicable law requires storage, where any other Applicable Privacy Law applies. 6.2 *Return or Deletion When Term Ends*.
180 days · https://cloud.google.com/terms/data-processing-addendum · read Sep 10, 2026
Intercom · 30 days
Intercom will permanently and securely delete all live (online or network accessible) instances of the Customer Data within 30 days upon Customer’s in-app deletion request.
30 days · https://intercom.com/data-processing-agreement · read Sep 13, 2026
Landing AI · 7 years
Your data will normally be stored for up to 7 years in order to meet our legal obligations and protect our interests.
7 years · https://landing.ai/privacy-policy · read Sep 11, 2026
LiveKit · 30 days
LiveKit may maintain encrypted backups of Customer Content for up to 30 days following deletion for disaster-recovery purposes, after which such backups are securely purged. 9.1 Retention Required by Law.
30 days · https://livekit.io/legal/data-processing-addendum · read Sep 13, 2026
Lovable · 30 days · 90 days
Upon account termination or expiration (including forfeiture of unused Credits as per the Terms), we will delete your Personal Data within 30 days, except for data required for fraud prevention, legal compliance, or legal defense purposes.
30 days · https://lovable.dev/privacy · read Sep 7, 2026
Backups may retain data for up to 90 days.
90 days · https://lovable.dev/privacy · read Sep 7, 2026
Make · 30 days
By default, log data is stored for 30 days.
30 days · https://make.com/security · read Sep 11, 2026
Nebius · 18 months
When we process partially obscured copies of your ID, we retain them for a maximum of 18 months in order to maintain the necessary records for our yearly audits.
18 months · https://nebius.com/privacy-policy · read Sep 13, 2026
New Relic · 90 days
Return or Deletion of Data ** Upon receipt of Customer’s written request, New Relic shall (at Customer's election) return Personal Data or close Customer’s account and delete all Personal Data within 90 days of the termination, save that this requirement shall not apply to the extent New Relic is required by applicable law to retain some or all of the Personal Data, which Personal Data New Relic …
90 days · https://newrelic.com/termsandconditions/dataprotection · read Sep 12, 2026
Notion · 60 days
AI embeddings are deleted within 60 days of page or workspace deletion.
60 days · https://trust.notion.com/subprocessors · read Sep 10, 2026
OpenAI · 30 days
Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to[ improve our models(opens in a new window)](https://help.openai.com/articles/5722486-how-your-data-is-used-to-improve-model-performanc…
30 days · https://openai.com/privacy · read Sep 12, 2026
Qdrant · 90 days
IP addresses are generally only stored for a maximum of 90 days and then deleted.
90 days · https://qdrant.tech/legal/privacy-policy · read Sep 13, 2026
Sourcegraph · 365 days
Logs are stored in GCP and the information is retained for up to 365 days.
365 days · https://sourcegraph.com/security · read Sep 7, 2026
Spellbook · 30 days · 90 days
(v) *Abuse Monitoring.* Solely with respect to Customers and Users accessing the Spellbook AI Platform through self-service onboarding options, Spellbook may collect, retain for up to 30 days (or longer if required for ongoing investigations or legal compliance), and use Customer Data (including Inputs) to detect and prevent malicious, abusive, or illegal activity.
30 days · https://spellbook.legal/terms-of-service · read Sep 13, 2026
QA Data will be: (A) retained for no longer than 90 days from the date of collection, then permanently deleted;
90 days · https://spellbook.legal/terms-of-service · read Sep 13, 2026
UiPath · 3 months
Recordings will be kept for up to 3 months.
3 months · https://uipath.com/privacy-policy · read Aug 31, 2026
Ultralytics · 12 months
For the Ultralytics Platform (SaaS), technical logs, access logs, and system backups are retained for up to 12 months and then deleted or anonymized.
12 months · https://ultralytics.com/privacy · read Sep 13, 2026
Weaviate · 5 years
We retain your personal data for a period of 5 years or as long as required to realize the objectives as described in this privacy policy.
5 years · https://weaviate.io/privacy · read Sep 13, 2026
Wiz · 63 days · 180 days
Notwithstanding Wiz's data retention policy, if upon termination, Customer requests expedited deletion of its Customer Data, Customer Data shall be deleted within 63 days. 3.5.
63 days · https://wiz.io/data-processing-agreement · read Sep 13, 2026
We retain most types of Service Data for a set period of up to 180 days (the exact number depends on the specific type of data).
180 days · https://wiz.io/legal/privacy · read Sep 13, 2026
xAI · 30 days
For example, when Private Chat is turned on, conversations will not appear in your conversation history and your conversations will be deleted from SpaceXAI systems within 30 days unless it is necessary that they be kept longer for legal, compliance, or safety purposes.
30 days · https://x.ai/privacy-policy · read Sep 11, 2026
Private Chat and User Content that you request to be deleted will be queued for deletion, which may take up to 30 days, except as required by law.
30 days · https://x.ai/terms-of-service · read Sep 11, 2026
What to ask for
Three questions turn a published number into something you can answer a customer with. Which categories the window covers, and which are excluded — backups, logs and telemetry are the ones usually carved out. What event starts it. And what happens to the copies: a deletion that leaves encrypted backups for another ninety days is a different promise from one that does not.
A window on a trust page can also change without anyone telling you. What your agreement obliges the vendor to send usually covers sub-processors and not retention, so a retention change often arrives as an edit and nothing else.
Take it with you
The same list as a Word document, with every quote, source and read date. It is generated when you download it, so it carries the record as it stands that day.
How these were read
Each window is quoted from a page the vendor publishes, with the URL and the date we read it. Nothing is converted between units, summarized or scored, and where a sentence hedges the hedge is left in. Where a vendor repeats a window in two places, both sentences are shown, because they are often about different data.
A number in a sentence is not automatically a retention window — an age limit, a regulatory lookback and a response deadline all put one next to the word “delete.” Only sentences where the number bounds how long data is held appear here. How the record is kept.
Common questions
- How long does an AI vendor keep my data?
- There is no single answer per vendor, and that is the useful finding. The same vendor commonly states one window for customer data on termination and a different one for backups or logs. Every window we can quote is on this page, grouped by the vendor that published it.
- What is a data retention window?
- The period a vendor states it will hold a category of data before deleting or anonymizing it. It is defined by three things: how long, which data, and what event starts the clock. A number quoted without the other two is not answerable to a customer.
- Is 30 days a standard retention period?
- It is the most common figure in the pages we hold, but it usually attaches to one category — deletion on request, or a backup cycle — rather than to everything a vendor holds. Read the sentence around it.
- Do backups count as deleted data?
- Several of the vendors below say explicitly that they do not, keeping encrypted backups for a further period after a deletion. Where a vendor is silent on backups, that silence is what its page says. Ask what happens to the copies.
- Where do these retention periods come from?
- Pages the vendors publish — privacy policies, data processing agreements, terms and trust pages. Each is quoted with its URL and the date we read it. Nothing here is summarized or converted between units.
Security questionnaires
Answer what a customer's security team asks about your AI stack.
- Answering “list every AI sub-processor”
What the question is asking for, where each vendor publishes the answer, and what to say about the gaps.
- Which certifications AI vendors say they hold
SOC 2, ISO 27001, ISO 42001 and more, counted off trust pages and kept apart by level — says, not holds.
- Which AI vendors say they will not train on your data
Commitments not to train, and opt-outs, quoted from vendor pages — with no list of vendors that do, because that list cannot be read honestly.
- Answering the AI questions in a security questionnaire
Eight questions, the answer that closes and the boundary on each — starting with the fact that “list every AI sub-processor” means about ninety companies.
- AI supply-chain question set
29 questions to put to an AI vendor — drafted by a language model, reviewed by a second, and published with all 15 edits shown.
- Where AI vendors say they keep your data
Residency commitments and transfer disclosures, quoted from vendor pages and kept apart — they look alike and mean opposite things.
This is not legal advice. The pages quoted are published documents read on the dates shown; your negotiated contract governs over anything here. The record behind this page is free to read, and corrections are free to request.