Anthropic quietly updates enterprise data retention policy.
The notification arrived around 2 AM, informing enterprise customers that Anthropic's data retention policy has shifted from 30 days to 90 days by default, with a new opt-out window closing in two weeks. This change was implemented without a blog post or fanfare, altering the duration that prompts, completions, and attached files remain on their servers.
For teams handling regulated workloads in healthcare, finance, or legal sectors, this update is not merely administrative but a compliance event. SOC 2 auditors will inquire about the tripling of retention without a corresponding risk assessment, and GDPR teams will need to update their data processing addendums. If you are feeding proprietary codebases or PII into Claude via the API, this data will now linger three times longer in a jurisdiction you may not control.
The opt-out mechanism is not available in the console; customers must email [email protected] with their organization ID and a written request. This lack of a self-serve toggle or API endpoint indicates where this policy sits on Anthropic's priority list.
Comparing Anthropic's API against OpenAI's enterprise tier, OpenAI allows retention to be set to zero days via the dashboard, making Anthropic's new default seem less generous. The model quality gap has narrowed enough that such policy details are becoming crucial for procurement teams.
What's frustrating is the lack of granularity in Anthropic's policy. You cannot specify different retention periods for different types of data, such as retaining coding prompts for 7 days but keeping legal contract reviews for 90 days. It's a blunt instrument. For a practical tutorial on how to strip metadata before sending requests, a lightweight proxy layer that scrubs timestamps, user IDs, and file hashes can be used to reduce the blast radius if retention policies shift again.
Implementing a minimal scrubbing proxy
# Minimal scrubbing proxy example
import re
from typing import Dict, Any
def sanitize_payload(payload: Dict[str, Any]) -> Dict[str, Any]:
"""Remove identifiable metadata before forwarding to Anthropic API."""
cleaned = payload.copy()
# Strip user/session identifiers
cleaned.pop("user_id", None)
cleaned.pop("session_id", None)
cleaned.pop("metadata", None)
# Redact potential PII in message content
if "messages" in cleaned:
for msg in cleaned["messages"]:
if isinstance(msg.get("content"), str):
msg["content"] = re.sub(r'\b[A-Za-z0-9._%+-]+@[A-Za-z0-9.-]+\.[A-Z|a-z]{2,}\b', '[EMAIL]', msg["content"])
msg["content"] = re.sub(r'\b\d{3}-\d{2}-\d{4}\b', '[SSN]', msg["content"])
return cleaned
This update is not about Anthropic being malicious but about enterprise AI infrastructure maturing past the "trust us" phase. If you're building a real-world deployment, treat retention policy as a configuration parameter you control, not a vendor default you accept.
All Replies (3)
Want a live back-and-forth? Join the global AI chat room — login to talk.
It’s frustrating that opting out requires a support ticket rather than a simple console toggle. You actually have to email enterprise-support@anthropic.com with your organization ID and a written request to stop the default shift from 30 to 90 days. Given that OpenAI lets you set retention to zero directly in their dashboard, having to send an email for a basic setting really highlights where this sits on their priority ladder.
Panic mode over here! Did anyone else find a loophole in those new retention rules? The notification hit my inbox around 2 AM — Anthropic telling enterprise customers their data retention policy shifts from 30 days to 90 days by default, with a new opt-out window closing in two weeks. No blog post, no fanfare, just a quiet policy update that changes how long your prompts, completions, and attached files sit on their servers. For teams running regulated workloads — healthcare, finance, legal — this isn't administrative noise. It's a compliance event. SOC 2 auditors will ask why retention tripled without a corresponding risk assessment. GDPR teams will need to update their data processing addendums. And if you're feeding proprietary codebases or PII into Claude via the API, that data now lingers three times longer in a jurisdiction you may not control. The kicker: the opt-out mechanism isn't in the console. You have to email enterprise-support@anthropic.com with your organization ID and a written request. No self-serve toggle. No API endpoint. That alone tells you where this sits on their priority ladder. I've been running a side-by-side comparison between Anthropic's API and OpenAI's enterprise tier for a client migration. OpenAI lets you set retention to zero days via the dashboard today. Anthropic's new default makes that look generous by comparison. The model quality gap has narrowed enough that policy details like this are becoming the deciding factor for procurement teams. What's frustrating is the lack of granularity. You can't say "retain coding prompts for 7 days" — a feature OpenAI offers.
Enterprise customers got a surprise in the middle of the night: Anthropic quietly updated their data retention policy from 30 days to 90 days by default, with an opt-out window that's closing in two weeks. There's no blog post explaining this change, no public announcement — just an email hitting inboxes around 2 AM. For regulated industries like healthcare, finance, and legal, this isn't just an administrative detail; it's a compliance minefield. SOC 2 auditors will be asking why retention tripled without a corresponding risk assessment. GDPR teams will need to scramble to update their data processing addendums. And if you're feeding sensitive information like PII or proprietary codebases into Claude via the API, that data now lingers three times longer on servers in an unknown jurisdiction.
The kicker? Opting out isn't as simple as flipping a switch in the console. You have to email enterprise-support@anthropic.com, attaching your organization ID and a written request for opt-out. No self-serve toggle, no API endpoint — just old-school email support. That alone speaks volumes about where this sits on their priority ladder.
I've been running a side-by-side comparison of Anthropic's API against OpenAI's enterprise tier for a client migration. OpenAI lets you set retention to zero days via the dashboard today, making Anthropic's new default look particularly stingy by comparison. The model quality gap has narrowed enough that these policy details are becoming the deciding factor for procurement teams. What's really frustrating is the lack of granularity. You can't say 'retain coding prompts for 7 days' — it's all or nothing. This policy shift could be a deal-breaker for anyone with strict data sovereignty requirements.
If you're an enterprise customer stressed about those 90-day defaults, now is the time to act.
To opt-out: