Zero Data Retention
Claude Code ZDR coverage, disabled capabilities, data boundaries, cache misconceptions and Passion8 considerations.
Zero Data Retention is an official mode for eligible Enterprise organizations that avoids normal retention of model-request contents. It does not mean every related record is absent.
ZDR belongs to Anthropic account/organization policy. Separately verify gateway, upstream, CI, MCP and local retention when using Passion8.
#Coverage
The primary scope is model-interaction content such as prompts, completions and tool context. It does not eliminate local transcripts or govern third parties.
| Object | ZDR interpretation |
|---|---|
| Model-request content | Core covered target |
| Analytics | No prompts/responses, but account/seat/usage metadata remains |
| Account/organization records | Standard administrative retention |
| Third-party tools/databases/CI | Outside Anthropic ZDR |
| Local transcripts | Require local cleanup policy |
| Passion8 logs | Separate gateway policy |
#Capabilities outside the scope
Official documentation distinguishes Code from other product surfaces. Do not assume these are covered:
| Scenario | Reason |
|---|---|
| claude.ai chat | Separate product surface |
| Cowork | Outside Code ZDR |
| Third-party integrations | Their own policies apply |
| Local logs/transcripts | Your filesystem responsibility |
| Administrative data | Seats, email and settings retained |
#Disabled capabilities
ZDR restricts features requiring server-side conversation storage.
| Capability | Reason |
|---|---|
| Code on the web | Server-side session history |
| Desktop cloud sessions | Persistent session data |
| Published Artifacts | Hosted page content |
| Feedback | Sends conversation data |
| Contributions | Usage metrics only in ZDR organizations |
Evaluate alternatives before enabling ZDR if you depend on cloud review, web or Artifacts. Sensitive repositories often stay in local CLI/IDE or self-hosted containers/runners.
#Policy violations and security records
Necessary safety events or metadata may still be retained to detect and handle violations. Therefore:
- ZDR does not justify bypassing permissions, audits or DLP.
- Sensitive repositories still need rules, hooks, MCP allowlists and network isolation.
- Resolve legal/security questions through the enterprise agreement and official support.
#Evaluate Passion8 paths
The actual path is:
Local Claude Code -> Passion8 gateway -> upstream providerCheck each layer:
| Layer | Questions |
|---|---|
| Local device | Transcript lifetime and access to ~/.claude/? |
| Passion8 | Request bodies, results, usage and error logging? |
| Upstream | Training, retention and ZDR/equivalent eligibility? |
| CI/CD | Do job logs expose prompts, diffs, secrets or output? |
| MCP | Are returned data stored, audited or forwarded elsewhere? |
Strict retention requires coordinated provider, gateway, MCP, CI and local policies, not merely an environment-variable change.
#Caching versus ZDR
Cache TTL measures inactivity before prefix expiry, not total request retention.
| Concept | Meaning |
|---|---|
| Prompt cache | Reuse prefixes for cost and latency |
| ZDR | Server-side content-retention policy |
| Local transcript | Plaintext conversation for resume |
| Gateway logs | Passion8/custom gateway records |
One-hour caching does not promise deletion after one hour; disabling caching does not enable ZDR. See caching and data flows.
#Action checklist
| Goal | Recommendation |
|---|---|
| Apply for official ZDR | Enterprise organization and Anthropic support |
| Sensitive repositories | Local CLI/IDE with sandbox and deny rules |
| Cloud capabilities | Identify disabled/degraded features |
| Local retention | Shorten cleanupPeriodDays and purge when needed |
| Gateway compliance | Define upstream/gateway retention and logging |
| Team auditing | Enforce read/export boundaries through managed rules/hooks |
#Official references
#Related pages
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

