Resource · Security questionnaires

How long AI vendors keep your data

Every retention window we can quote from a page an AI vendor publishes, grouped by vendor, with the sentence it came from and the day we read it.

A vendor does not have a retention period

It has several, and they differ by what the data is. 5 of the 23 vendors below state more than one window on their own pages: Google Cloud (30 days, 180 days); Lovable (30 days, 90 days); Spellbook (30 days, 90 days).

Answer a questionnaire with the first number you find and you will be wrong about the second category, from pages the vendor published side by side. Read which data a window covers before quoting it.

And read what starts the clock

The windows below run from different events, and each sentence carries its own. Some start at termination, some when you delete something, some at collection, some when you ask. Two vendors quoting the same number can mean periods that end months apart, so the trigger deserves as much attention as the figure — it is in the quote either way.

What the record holds

28 stated windows across 23 vendors. 163 of the 186 vendors whose pages Xither reads state no window we could quote.

That last number is a finding rather than a hole. Where a vendor publishes no window, that is what its pages say, and the date we looked is on the record.

The shortest is 30 days (Anthropic); the longest is 7 years (Landing AI). Both are quoted below as written — comparing “13 months” against “365 days” needs a conversion, and no page states the converted figure.

Every window, and the sentence it came from

Ada · 90 days

Following termination, Ada retains data for up to 90 days, after which it is deleted or anonymized in accordance with Ada’s Data Processing Addendum.

90 days · https://ada.cx/privacy · read Aug 31, 2026

Anthropic · 30 days

You also are able to delete individual conversations, which will be removed immediately from your conversation history and automatically deleted from our back-end within 30 days.

30 days · https://anthropic.com/privacy · read Sep 10, 2026

Demandbase · 13 months

Customer Data is retained during the relationship and with Demandbase and for up to 13 months following the expiration or termination of the relationship.

13 months · https://www.demandbase.com/security-policy/ · read Aug 31, 2026

Fireflies.ai · 30 days

If you close your account, we will delete personal information related to your account within 30 days.

30 days · https://fireflies.ai/privacy · read Sep 13, 2026

GitHub · 90 days

Upon Cancellation](#2-upon-cancellation) We will retain and use your information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements, but barring legal requirements, we will delete your full profile and the Content of your repositories within 90 days of cancellation or termination (though some information may remain in encrypted backups).

90 days · https://github.com/terms · read Sep 13, 2026

Google Cloud · 30 days · 180 days

After a recovery period of up to 30 days from that date, Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days, unless European Law requires storage, where European Data Protection Law applies, or applicable law requires storage, where any other Applicable Privacy Law applies. 6.3. *Deferred Deletion Instruction*.

30 days · https://cloud.google.com/terms/data-processing-addendum · read Sep 10, 2026

Google will comply with this Instruction as soon as reasonably practicable and within a maximum period of 180 days, unless European Law requires storage, where European Data Protection Law applies, or applicable law requires storage, where any other Applicable Privacy Law applies. 6.2 *Return or Deletion When Term Ends*.

180 days · https://cloud.google.com/terms/data-processing-addendum · read Sep 10, 2026

Intercom · 30 days

Intercom will permanently and securely delete all live (online or network accessible) instances of the Customer Data within 30 days upon Customer’s in-app deletion request.

30 days · https://intercom.com/data-processing-agreement · read Sep 13, 2026

Landing AI · 7 years

Your data will normally be stored for up to 7 years in order to meet our legal obligations and protect our interests.

7 years · https://landing.ai/privacy-policy · read Sep 11, 2026

LiveKit · 30 days

LiveKit may maintain encrypted backups of Customer Content for up to 30 days following deletion for disaster-recovery purposes, after which such backups are securely purged. 9.1 Retention Required by Law.

30 days · https://livekit.io/legal/data-processing-addendum · read Sep 13, 2026

Lovable · 30 days · 90 days

Upon account termination or expiration (including forfeiture of unused Credits as per the Terms), we will delete your Personal Data within 30 days, except for data required for fraud prevention, legal compliance, or legal defense purposes.

30 days · https://lovable.dev/privacy · read Sep 7, 2026

Backups may retain data for up to 90 days.

90 days · https://lovable.dev/privacy · read Sep 7, 2026

Make · 30 days

By default, log data is stored for 30 days.

30 days · https://make.com/security · read Sep 11, 2026

Nebius · 18 months

When we process partially obscured copies of your ID, we retain them for a maximum of 18 months in order to maintain the necessary records for our yearly audits.

18 months · https://nebius.com/privacy-policy · read Sep 13, 2026

New Relic · 90 days

Return or Deletion of Data ** Upon receipt of Customer’s written request, New Relic shall (at Customer's election) return Personal Data or close Customer’s account and delete all Personal Data within 90 days of the termination, save that this requirement shall not apply to the extent New Relic is required by applicable law to retain some or all of the Personal Data, which Personal Data New Relic …

90 days · https://newrelic.com/termsandconditions/dataprotection · read Sep 12, 2026

Notion · 60 days

AI embeddings are deleted within 60 days of page or workspace deletion.

60 days · https://trust.notion.com/subprocessors · read Sep 10, 2026

OpenAI · 30 days

Once you choose to delete Personal Data, we will remove it from our systems within 30 days unless we need to retain it for longer as described below, or it has already been de-identified and disassociated from your account when you allow us to use your Content to[ improve our models⁠(opens in a new window)](https://help.openai.com/articles/5722486-how-your-data-is-used-to-improve-model-performanc…

30 days · https://openai.com/privacy · read Sep 12, 2026

Qdrant · 90 days

IP addresses are generally only stored for a maximum of 90 days and then deleted.

90 days · https://qdrant.tech/legal/privacy-policy · read Sep 13, 2026

Sourcegraph · 365 days

Logs are stored in GCP and the information is retained for up to 365 days.

365 days · https://sourcegraph.com/security · read Sep 7, 2026

Spellbook · 30 days · 90 days

(v) *Abuse Monitoring.* Solely with respect to Customers and Users accessing the Spellbook AI Platform through self-service onboarding options, Spellbook may collect, retain for up to 30 days (or longer if required for ongoing investigations or legal compliance), and use Customer Data (including Inputs) to detect and prevent malicious, abusive, or illegal activity.

30 days · https://spellbook.legal/terms-of-service · read Sep 13, 2026

QA Data will be: (A) retained for no longer than 90 days from the date of collection, then permanently deleted;

90 days · https://spellbook.legal/terms-of-service · read Sep 13, 2026

UiPath · 3 months

Recordings will be kept for up to 3 months.

3 months · https://uipath.com/privacy-policy · read Aug 31, 2026

Ultralytics · 12 months

For the Ultralytics Platform (SaaS), technical logs, access logs, and system backups are retained for up to 12 months and then deleted or anonymized.

12 months · https://ultralytics.com/privacy · read Sep 13, 2026

Weaviate · 5 years

We retain your personal data for a period of 5 years or as long as required to realize the objectives as described in this privacy policy.

5 years · https://weaviate.io/privacy · read Sep 13, 2026

Wiz · 63 days · 180 days

Notwithstanding Wiz's data retention policy, if upon termination, Customer requests expedited deletion of its Customer Data, Customer Data shall be deleted within 63 days. 3.5.

63 days · https://wiz.io/data-processing-agreement · read Sep 13, 2026

We retain most types of Service Data for a set period of up to 180 days (the exact number depends on the specific type of data).

180 days · https://wiz.io/legal/privacy · read Sep 13, 2026

xAI · 30 days

For example, when Private Chat is turned on, conversations will not appear in your conversation history and your conversations will be deleted from SpaceXAI systems within 30 days unless it is necessary that they be kept longer for legal, compliance, or safety purposes.

30 days · https://x.ai/privacy-policy · read Sep 11, 2026

Private Chat and User Content that you request to be deleted will be queued for deletion, which may take up to 30 days, except as required by law.

30 days · https://x.ai/terms-of-service · read Sep 11, 2026

What to ask for

Three questions turn a published number into something you can answer a customer with. Which categories the window covers, and which are excluded — backups, logs and telemetry are the ones usually carved out. What event starts it. And what happens to the copies: a deletion that leaves encrypted backups for another ninety days is a different promise from one that does not.

A window on a trust page can also change without anyone telling you. What your agreement obliges the vendor to send usually covers sub-processors and not retention, so a retention change often arrives as an edit and nothing else.

Take it with you

The same list as a Word document, with every quote, source and read date. It is generated when you download it, so it carries the record as it stands that day.

Get the checklist

A Word document, generated from the record when you download it. Every clause carries the page it came from and the date we read it.

How these were read

Each window is quoted from a page the vendor publishes, with the URL and the date we read it. Nothing is converted between units, summarized or scored, and where a sentence hedges the hedge is left in. Where a vendor repeats a window in two places, both sentences are shown, because they are often about different data.

A number in a sentence is not automatically a retention window — an age limit, a regulatory lookback and a response deadline all put one next to the word “delete.” Only sentences where the number bounds how long data is held appear here. How the record is kept.

Common questions

How long does an AI vendor keep my data?
There is no single answer per vendor, and that is the useful finding. The same vendor commonly states one window for customer data on termination and a different one for backups or logs. Every window we can quote is on this page, grouped by the vendor that published it.
What is a data retention window?
The period a vendor states it will hold a category of data before deleting or anonymizing it. It is defined by three things: how long, which data, and what event starts the clock. A number quoted without the other two is not answerable to a customer.
Is 30 days a standard retention period?
It is the most common figure in the pages we hold, but it usually attaches to one category — deletion on request, or a backup cycle — rather than to everything a vendor holds. Read the sentence around it.
Do backups count as deleted data?
Several of the vendors below say explicitly that they do not, keeping encrypted backups for a further period after a deletion. Where a vendor is silent on backups, that silence is what its page says. Ask what happens to the copies.
Where do these retention periods come from?
Pages the vendors publish — privacy policies, data processing agreements, terms and trust pages. Each is quoted with its URL and the date we read it. Nothing here is summarized or converted between units.

Security questionnaires

Answer what a customer's security team asks about your AI stack.

Everything in the resources section

This is not legal advice. The pages quoted are published documents read on the dates shown; your negotiated contract governs over anything here. The record behind this page is free to read, and corrections are free to request.