Product feature · security-privacy

Data retention controlsCommon product term

Configure or document retention and deletion for covered product data.

Terminology basis: Common product term. xAI — Grok Bot approvals, security, and privacy

Data retention controls: 3 supported, 3 partial, 0 unsupported, 25 unreviewed across 31 cataloged products.

Markdown · JSON

Explore this familyMore in Security and privacy7 capabilities

Current evidence by product

Can my agent use Data retention controls?

Read across for the answer. 6 of 31 current product columns have reviewed evidence; unreviewed does not mean unsupported.

  • Supported3
  • Partial3
  • Unsupported0
  • Unknown25
  • Not applicable0

Web

9 products

Desktop

13 products

CLI

9 products

Unknown means no public evidence has been reviewed for that product and capability. It does not mean unsupported.

How statuses are assigned

Definition and scope

What this capability means

This row asks what is retained, for how long, by whom, and how deletion works. The visible conversation is only one object; prompts, uploads, tool results, memory, generated files, feedback, telemetry, safety logs, caches, search indexes, and backups can have different lifetimes.

Evidence should record default and configurable periods, plan and workspace scope, deletion initiation and completion timelines, administrator versus user controls, legal or abuse-monitoring exceptions, backup expiry, account-deletion behavior, and APIs or exports that let an organization verify completion.

Traceable compatibility

Assertion ledger

Documentation evidence only. No runtime conformance test is implied.

Grok Botdesktop · current
Partial
Target
2026-08-28 Grok Bot desktop documentation observation · hosted-observation
Environment
hosted-default
Observed
2026-08-28
  • policyoperators can separately remove routines, connectors, shared files, browser sessions, Bots, and the account; deleting one Bot does not remove account-shared computer state
  • runtimeconfigurable retention periods, backup expiry, legal exceptions, and verified deletion-completion timelines are not established by the reviewed page
Evidence
Claudeweb · current
Supported
Target
2026-08-28 Claude Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Owner or Primary Owner can configure chat and project retention with a 30-day minimum; data is retained indefinitely by default when no custom period is set
  • runtimeactivity resets the applicable timer; expired chats, projects, and artifacts are permanently deleted at midnight UTC, and configuration changes are audited
Claudedesktop · current
Supported
Target
2026-08-28 Claude Enterprise documentation observation · hosted-observation
Environment
enterprise-managed
Observed
2026-08-28
  • planEnterprise Owner or Primary Owner can configure organization chat and project retention with a 30-day minimum; data is retained indefinitely by default when no custom period is set
  • runtimeactivity resets the applicable timer; expired chats, projects, and artifacts are permanently deleted at midnight UTC, and configuration changes are audited
Claude CLIcli · current
Partial
Target
2026-08-28 Claude Code documentation observation · hosted-observation
Environment
local-default
Observed
2026-08-28
  • planserver retention is 5 years for opted-in consumer improvement, 30 days for opted-out consumers and standard commercial use, and qualified Enterprise organizations may receive separately enabled ZDR
  • runtimelocal plaintext session transcripts are kept for 30 days by default and can be adjusted with cleanupPeriodDays
  • policyfeedback submissions, safety processing, remote sessions, cloud providers, and local artifacts have separate paths and retention rules
Evidence
Geminiweb · current
Supported
Target
2026-08-28 Gemini Apps privacy documentation observation · hosted-observation
Environment
hosted-default
Observed
2026-08-28
  • authapplies to signed-in personal accounts; work and school account retention is controlled by Google Workspace administrators
  • policyactivity auto-deletes after 18 months by default and can be changed to 3, 18, or 36 months or indefinite; manual item, range, or all-time deletion is supported
  • policyKeep Activity-off and temporary chats are retained 72 hours; human-reviewed data can remain up to three years and other Google services have separate retention
Evidence
Cursordesktop · current
Partial
Target
2026-08-28 Cursor privacy documentation observation · hosted-observation
Environment
local-default
Observed
2026-08-28
  • policyPrivacy Mode uses ZDR agreements with model providers; encrypted file-content caches are temporary and their server-side keys exist only for the request
  • runtimecodebase indexing may persist embeddings and metadata, and abuse-triggered data may follow provider investigation retention
  • policyuser-configurable retention periods, backup expiry, and verified deletion completion are not established by the reviewed page
Evidence
  1. 1. Evidence checked 2026-08-28: xAI documents steps to remove Grok Bot routines, connectors, shared files, and Bots, but deleting a Bot does not remove shared-computer files or browser sessions and backend retention follows applicable Cursor terms. No configurable retention period or verified completion timeline is documented on the reviewed page.
  2. 2. Evidence checked 2026-08-28: Claude Enterprise Owners can configure conversation and project retention with a 30-day minimum; retention is activity-based, defaults to indefinite when unset, deletes chats, projects, and artifacts at the boundary, and records changes in audit logs.
  3. 3. Evidence checked 2026-08-28: Claude Code documents different server retention by account and preference, optional qualified Enterprise zero-data-retention, a local plaintext transcript cache retained 30 days by default, and a configurable local `cleanupPeriodDays`.
  4. 4. Evidence checked 2026-08-28: Gemini Apps personal accounts default to 18-month activity deletion and allow 3, 18, 36 months, indefinite retention, or manual deletion. Keep Activity-off and temporary chats remain for 72 hours, while human-reviewed material can remain for up to three years.
  5. 5. Evidence checked 2026-08-28: Cursor Privacy Mode uses ZDR agreements for model providers and temporary encrypted file-content caches, but indexing may persist embeddings and metadata and safety investigations follow provider retention policies. No user-configurable retention period is documented on the reviewed page.