# Claude Code Zero Data Retention

> Claude Code ZDR coverage, disabled capabilities, data boundaries, cache misconceptions and Passion8 considerations.

URL: https://docs.passion8.cc/en/docs/claude-code/zero-data-retention
Language: en
Publisher: Passion8

Zero Data Retention is an official mode for eligible Enterprise organizations that avoids normal retention of model-request contents. It does not mean every related record is absent.




ZDR belongs to Anthropic account/organization policy. Separately verify gateway, upstream, CI, MCP and local retention when using Passion8.




## Coverage

The primary scope is model-interaction content such as prompts, completions and tool context. It does not eliminate local transcripts or govern third parties.

| Object | ZDR interpretation |
| --- | --- |
| Model-request content | Core covered target |
| Analytics | No prompts/responses, but account/seat/usage metadata remains |
| Account/organization records | Standard administrative retention |
| Third-party tools/databases/CI | Outside Anthropic ZDR |
| Local transcripts | Require local cleanup policy |
| Passion8 logs | Separate gateway policy |

## Capabilities outside the scope

Official documentation distinguishes Code from other product surfaces. Do not assume these are covered:

| Scenario | Reason |
| --- | --- |
| claude.ai chat | Separate product surface |
| Cowork | Outside Code ZDR |
| Third-party integrations | Their own policies apply |
| Local logs/transcripts | Your filesystem responsibility |
| Administrative data | Seats, email and settings retained |

## Disabled capabilities

ZDR restricts features requiring server-side conversation storage.

| Capability | Reason |
| --- | --- |
| Code on the web | Server-side session history |
| Desktop cloud sessions | Persistent session data |
| Published Artifacts | Hosted page content |
| Feedback | Sends conversation data |
| Contributions | Usage metrics only in ZDR organizations |

Evaluate alternatives before enabling ZDR if you depend on cloud review, web or Artifacts. Sensitive repositories often stay in local CLI/IDE or self-hosted containers/runners.

## Policy violations and security records

Necessary safety events or metadata may still be retained to detect and handle violations. Therefore:

1. ZDR does not justify bypassing permissions, audits or DLP.
2. Sensitive repositories still need rules, hooks, MCP allowlists and network isolation.
3. Resolve legal/security questions through the enterprise agreement and official support.

## Evaluate Passion8 paths

The actual path is:

```text
Local Claude Code -> Passion8 gateway -> upstream provider
```

Check each layer:

| Layer | Questions |
| --- | --- |
| Local device | Transcript lifetime and access to ~/.claude/? |
| Passion8 | Request bodies, results, usage and error logging? |
| Upstream | Training, retention and ZDR/equivalent eligibility? |
| CI/CD | Do job logs expose prompts, diffs, secrets or output? |
| MCP | Are returned data stored, audited or forwarded elsewhere? |

Strict retention requires coordinated provider, gateway, MCP, CI and local policies, not merely an environment-variable change.

## Caching versus ZDR

Cache TTL measures inactivity before prefix expiry, not total request retention.

| Concept | Meaning |
| --- | --- |
| Prompt cache | Reuse prefixes for cost and latency |
| ZDR | Server-side content-retention policy |
| Local transcript | Plaintext conversation for resume |
| Gateway logs | Passion8/custom gateway records |

One-hour caching does not promise deletion after one hour; disabling caching does not enable ZDR. See [caching](https://docs.passion8.cc/en/docs/claude-code/prompt-caching) and [data flows](https://docs.passion8.cc/en/docs/claude-code/data-usage).

## Action checklist

| Goal | Recommendation |
| --- | --- |
| Apply for official ZDR | Enterprise organization and Anthropic support |
| Sensitive repositories | Local CLI/IDE with sandbox and deny rules |
| Cloud capabilities | Identify disabled/degraded features |
| Local retention | Shorten cleanupPeriodDays and purge when needed |
| Gateway compliance | Define upstream/gateway retention and logging |
| Team auditing | Enforce read/export boundaries through managed rules/hooks |

## Official references

- [Zero data retention](https://code.claude.com/docs/en/zero-data-retention.md)
- [Data usage](https://code.claude.com/docs/en/data-usage.md)
- [Security](https://code.claude.com/docs/en/security.md)
- [Analytics](https://code.claude.com/docs/en/analytics.md)

## Related pages



- [Data usage and privacy](https://docs.passion8.cc/en/docs/claude-code/data-usage): Training, retention, local data, telemetry, WebFetch and gateway boundaries.
- [Security](https://docs.passion8.cc/en/docs/security): Keys, permissions, hooks, MCP, prompt injection and team settings.
- [Enterprise administration](https://docs.passion8.cc/en/docs/claude-code/enterprise-admin): Server/endpoint policy and managed MCP.

