Claude Code

Zero Data Retention

Claude Code ZDR coverage, disabled capabilities, data boundaries, cache misconceptions and Passion8 considerations.

Zero Data Retention is an official mode for eligible Enterprise organizations that avoids normal retention of model-request contents. It does not mean every related record is absent.

ZDR belongs to Anthropic account/organization policy. Separately verify gateway, upstream, CI, MCP and local retention when using Passion8.

#Coverage

The primary scope is model-interaction content such as prompts, completions and tool context. It does not eliminate local transcripts or govern third parties.

ObjectZDR interpretation
Model-request contentCore covered target
AnalyticsNo prompts/responses, but account/seat/usage metadata remains
Account/organization recordsStandard administrative retention
Third-party tools/databases/CIOutside Anthropic ZDR
Local transcriptsRequire local cleanup policy
Passion8 logsSeparate gateway policy

#Capabilities outside the scope

Official documentation distinguishes Code from other product surfaces. Do not assume these are covered:

ScenarioReason
claude.ai chatSeparate product surface
CoworkOutside Code ZDR
Third-party integrationsTheir own policies apply
Local logs/transcriptsYour filesystem responsibility
Administrative dataSeats, email and settings retained

#Disabled capabilities

ZDR restricts features requiring server-side conversation storage.

CapabilityReason
Code on the webServer-side session history
Desktop cloud sessionsPersistent session data
Published ArtifactsHosted page content
FeedbackSends conversation data
ContributionsUsage metrics only in ZDR organizations

Evaluate alternatives before enabling ZDR if you depend on cloud review, web or Artifacts. Sensitive repositories often stay in local CLI/IDE or self-hosted containers/runners.

#Policy violations and security records

Necessary safety events or metadata may still be retained to detect and handle violations. Therefore:

  1. ZDR does not justify bypassing permissions, audits or DLP.
  2. Sensitive repositories still need rules, hooks, MCP allowlists and network isolation.
  3. Resolve legal/security questions through the enterprise agreement and official support.

#Evaluate Passion8 paths

The actual path is:

Local Claude Code -> Passion8 gateway -> upstream provider

Check each layer:

LayerQuestions
Local deviceTranscript lifetime and access to ~/.claude/?
Passion8Request bodies, results, usage and error logging?
UpstreamTraining, retention and ZDR/equivalent eligibility?
CI/CDDo job logs expose prompts, diffs, secrets or output?
MCPAre returned data stored, audited or forwarded elsewhere?

Strict retention requires coordinated provider, gateway, MCP, CI and local policies, not merely an environment-variable change.

#Caching versus ZDR

Cache TTL measures inactivity before prefix expiry, not total request retention.

ConceptMeaning
Prompt cacheReuse prefixes for cost and latency
ZDRServer-side content-retention policy
Local transcriptPlaintext conversation for resume
Gateway logsPassion8/custom gateway records

One-hour caching does not promise deletion after one hour; disabling caching does not enable ZDR. See caching and data flows.

#Action checklist

GoalRecommendation
Apply for official ZDREnterprise organization and Anthropic support
Sensitive repositoriesLocal CLI/IDE with sandbox and deny rules
Cloud capabilitiesIdentify disabled/degraded features
Local retentionShorten cleanupPeriodDays and purge when needed
Gateway complianceDefine upstream/gateway retention and logging
Team auditingEnforce read/export boundaries through managed rules/hooks

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.