Private does not have to mean invisible
OpenAI is trying to solve an awkward problem for companies using its API. Some customers need a strong promise that prompts and model replies will not be retained. At the same time, a serious safety pattern may only appear after several otherwise ordinary requests.
The company calls its proposed answer Private Safety Processing. It says the system can look for a pattern across related interactions while keeping the underlying content outside the reach of OpenAI personnel. If a risk is detected, OpenAI says it receives a narrowly defined signal about the category of activity, not the prompts or responses themselves.
That is a meaningful distinction, if the design works as described. It is not the same as saying there is no monitoring. It is a claim that monitoring can operate on sensitive content without staff being able to inspect that content.
What OpenAI is actually previewing
Zero Data Retention, or ZDR, already exists as an API control for eligible and approved customers. OpenAI's platform documentation says it excludes customer content from abuse-monitoring logs and changes some endpoint behaviour so stored responses are not created by default.
The new preview is about the gap left by single-request checks. OpenAI says current ZDR-compatible systems can assess each interaction separately, but may miss a pattern that appears only across a longer sequence, repeated probing or a task that keeps acting after it should stop.
The company describes two possible ways to run the new layer. In one, customer content remains on infrastructure controlled by the customer. In the other, content would sit on OpenAI infrastructure encrypted with keys the customer controls. OpenAI says its staff would not hold those keys. Those are design descriptions from OpenAI, not a public security audit or a released protocol.
ZDR still has edges
The name Zero Data Retention can sound broader than it is. OpenAI's API documentation lists endpoint and feature limits. Some capabilities can still need application state, and some are not ZDR eligible. The Responses API, for example, has different storage behaviour when a customer uses features such as background mode or extended prompt caching.
This matters because privacy choices are made in the details of a system, not its headline. A company may have an approved ZDR setting and still need to check which endpoints, tools and workflows it plans to use. The documentation also says that certain image or file inputs may be retained if automated systems flag possible child sexual abuse material for required review.
Private Safety Processing does not remove those boundaries. It is OpenAI's attempt to add a richer safety signal without turning a ZDR deployment into ordinary content retention.
The unanswered technical questions
OpenAI says the system is being tested with early customers and that it will publish a technical white paper in September. Until then, there is no public detail on how related interactions are grouped, what information a safety signal contains, how often ordinary activity is flagged or how a customer can challenge a mistaken enforcement decision.
Those questions are central. A privacy-preserving detector can still be too broad, too narrow or hard to appeal. The claim that staff cannot see content is important, but it is not the whole privacy story if automated classification and enforcement meaningfully affect a customer's work.
For now, the useful takeaway is narrower than the announcement. OpenAI is proposing a way to preserve a strict content-retention boundary while using more context for safety. It has not yet provided enough public technical evidence to show how well that balance holds in practice.
What is confirmed, what OpenAI says, and what is open
Confirmed: OpenAI published a preview of Private Safety Processing on 19 August, and its API documentation describes ZDR eligibility and feature-level retention limits. ZDR is available only to approved API customers under additional requirements.
OpenAI's claim: Private Safety Processing can identify patterns across related interactions without personnel accessing the underlying customer content. The company says it can work with customer-controlled infrastructure or with customer-controlled encryption keys, and that it will return limited safety signals.
Open questions: the architecture, independent security review, accuracy, false positives, grouping rules, appeal process, rollout scope and the meaning of a received safety signal. OpenAI says a technical white paper is planned for September.
Sources
- OpenAI — Offering Zero Data Retention for frontier modelsPrimary company announcement, published 19 August 2026. Source for the Private Safety Processing preview, OpenAI's stated design and planned white paper.
- OpenAI API documentation — Data controls in the OpenAI platformPrimary technical documentation. Source for ZDR approval, endpoint eligibility, application-state limits and noted exceptions.



