Gate.AIBlogHow Does Gate.AI Zero Data Retention (ZDR) Work?

    How Does Gate.AI Zero Data Retention (ZDR) Work?

    Learn

    Zero Data Retention (ZDR) on Gate.AI enforces privacy-centric data handling by restricting the retention period of API requests and responses at the routing layer, and by default, customer prompts are not used for product improvement initiatives.

    Teams running production-level LLM traffic through the gateway must distinguish between what is retained at the intermediary (routing) layer and what is retained by upstream model providers. Gate.AI sets ZDR as the default privacy posture at the control plane; as of June 2026, the pricing page indicates that enterprise customers can access contract-level Enterprise ZDR and DPA provisions.

    The following explains what ZDR means within the Gate.AI architecture, how data is handled during the routing process, the differences between default tiers and enterprise commitments, the relationship between console logs and retention policies, and key points teams must still verify with upstream vendors. This should be understood within the broader Gate.AI Enterprise AI Data Privacy framework, alongside RBAC and organizational controls.

    What is Zero Data Retention (ZDR) on Gate.AI, and Why Does It Matter?

    Zero Data Retention (ZDR) on Gate.AI is a data handling approach: the platform restricts the retention of customer API traffic within Gate.AI’s control systems and, by default, does not use related content to improve Gate.AI products.

    ZDR matters because LLM API calls often include prompts, generated results, and metadata that may contain personal data, trade secrets, or regulated information. Without clear routing-layer policies, teams struggle to answer audit questions: Are prompts stored? For how long? Are they sent to vendors’ training pipelines? Gate.AI addresses these concerns at the routing layer by officially stating default non-retention, non-use for product improvement, and offering enterprise ZDR and DPA options.

    Gate.AI’s ZDR applies to data processed through Gate.AI as a routing gateway. Gate.AI cannot override the retention policies of upstream model providers; once requests are forwarded, each vendor’s terms apply independently.

    What Conditions Must Be Met Before ZDR Takes Effect?

    For Gate.AI’s ZDR posture to apply to a given request, the caller must authenticate using a valid organization API Key and send traffic to endpoints such as https://api.gate.ai/openai/v1 or https://api.gate.ai/anthropic.

    The organization must be active on Gate.AI with valid credentials. Members generate keys via Console → Settings → API Keys. Integrations that bypass Gate.AI and connect directly to upstream vendors are not covered by Gate.AI ZDR.

    Routing and guardrail settings determine which models traffic reaches but do not replace the platform-level privacy baseline described on the pricing page. Enterprise customers requiring contract-level ZDR typically obtain it via enterprise agreements, not just self-serve tiers.

    How Does ZDR Take Effect as Data Passes Through Gate.AI?

    When an application sends prompts to Gate.AI, the routing layer receives the request, applies routing rules and organizational guardrails, and forwards compliant traffic to the selected upstream model.

    During this process, Gate.AI handles request and response content to fulfill the call, enforce quotas, and generate billing and operational records. Official documentation describes the default behavior as not using user data for product improvement, with ZDR as a privacy commitment. Under default policy, the routing layer acts as a transient control point, not a long-term content archive.

    After the upstream model returns results, Gate.AI relays the response to the client. Content may exist briefly in the processing chain as required to provide the service; ZDR covers retention for training and product improvement at the Gate.AI layer, not the elimination of all operational handling.

    Gate.AI ZDR flow: API client, transient routing layer without long-term storage, upstream model provider, response path
    Figure 1. Gate.AI ZDR restricts long-term retention at the routing layer and forwards to upstream providers; enterprise plans add ZDR and DPA contract terms (as of June 2026).

    How Does Default Tier Privacy Differ from Enterprise ZDR?

    As of June 2026, the pricing comparison table shows that Free and Pay-as-you-go tiers default to non-retention and non-use for product improvement, with some configurable options.

    The enterprise plan adds Enterprise ZDR and DPA, indicating that organizations requiring formal processor commitments can obtain written guarantees. The enterprise plan also includes organizational and access management, SSO, and dedicated support—features often required for regulated deployments, though these are separate from the ZDR policy itself.

    Privacy Dimension Free / Pay-as-you-go (per pricing page) Enterprise
    Stated Default Posture Default non-retention; not used for product improvement (configurable) Enterprise ZDR + DPA
    Agreement Channel Self-serve tiers Enterprise sales / contract
    Organization RBAC Organization features listed under enterprise Included
    Typical Procurement Questions Is this sufficient for development and general production? Does it meet legal and procurement review?

    Teams often upgrade from Pay-as-you-go to Enterprise for privacy reasons when legal requires DPA and explicit ZDR clauses, rather than because the routing mechanism is fundamentally different. DPA and Enterprise Data Compliance explains how enterprise contracts incorporate these commitments for regulated procurement.

    How Do Gate.AI Console Logs Relate to ZDR?

    Gate.AI provides operational visibility in Console → Logs, with three tabs: Generation Records (single API requests), Tasks (asynchronous jobs), and Sessions (multi-turn aggregation).

    Logs serve for troubleshooting, token and billing verification, and usage analysis; they are not the same as long-term datasets used for model training or product improvement. Privacy reviews should ask: What fields appear? Who can access them under RBAC? How long are operational records retained? These questions complement ZDR policy—they are not substitutes.

    According to the role matrix, super admins and primary admins have broader usage visibility than regular members. Log access therefore intersects with access control design, even when retention policy restricts training use.

    What Are Common Misconceptions About ZDR, and What Should Teams Verify?

    The most common misconception is assuming Gate.AI ZDR automatically covers all upstream vendors. Gate.AI forwards content to external providers, each with their own retention, logging, and training policies. A thorough enterprise review must map approved models to vendor terms and document subprocessors.

    Another misconception is equating ZDR with zero logging. Operational records required for billing and support may exist for a reasonable period as part of platform operations. Teams should document what Gate.AI commits to at the routing layer, and what remains the application’s responsibility—such as client-side caching, prompt logs in application libraries, or third-party observability tools.

    Misconfigured API Keys or shared credentials can cause traffic to leave the intended organizational boundary, which is unrelated to ZDR. ZDR addresses Gate.AI’s handling; credential hygiene remains critical.

    Summary

    Gate.AI Zero Data Retention (ZDR) restricts API traffic retention at the routing layer and, by default, does not use prompts for product improvement. This commitment applies to traffic authenticated and routed through Gate.AI endpoints. As of June 2026, Free and Pay-as-you-go tiers state a default non-retention posture, while the enterprise plan offers Enterprise ZDR and DPA. Console logs support troubleshooting and billing—they are distinct from retention policies for training purposes. Teams must independently review each upstream model provider’s data terms and incorporate approved models, subprocessors, and Gate.AI Enterprise AI Data Privacy access control design into compliance assessments.

    Frequently Asked Questions

    Q: What is Zero Data Retention on Gate.AI?
    A: According to official pricing and product documentation, Gate.AI ZDR restricts retention of API traffic at the routing layer and, by default, does not use customer prompts for product improvement.

    Q: Does Gate.AI ZDR apply to upstream OpenAI or Anthropic data policies?
    A: No. Gate.AI ZDR covers the routing layer within Gate.AI’s control. Each upstream vendor applies its own retention and training terms once requests are forwarded.

    Q: Which pricing tier includes Enterprise ZDR and DPA?
    A: The enterprise plan on gate.ai/pricing lists Enterprise ZDR + DPA. Free and Pay-as-you-go tiers describe default non-retention and non-use for product improvement, with configurable options.

    Q: If ZDR applies, can admins still view prompts in Gate.AI logs?
    A: Console logs provide operational records for API calls, tasks, and sessions. For compliance reviews, ZDR policy should be assessed alongside log content and RBAC visibility.

    The content herein does not constitute any offer, solicitation, or recommendation. You should always seek independent professional advice before making any investment decisions. Please note that Gate may restrict or prohibit the use of all or a portion of the Services from Restricted Locations. For more information, please read the User Agreement

    Related Articles