Data Retention and Deletion in AI Products
An AI product may retain customer information in uploaded files, saved conversations, generated responses, search indexes, vendor logs, and backups. A deletion request requires the business to identify the information covered by the request, determine where it is held, and apply the duties and exceptions that govern each location.
Many conventional applications also distribute information across several systems. AI features introduce additional questions about information sent to model providers, representations created from customer documents, and models trained with customer content. A business that promises deletion needs to understand which information it controls and what its vendors have agreed to do.
The Retention Duties That Apply
Retention obligations depend on the law, the business, and the information involved. Federal children’s privacy requirements and state privacy statutes impose different duties, and industry specific recordkeeping laws may require particular records to be preserved.
The Children’s Online Privacy Protection Rule applies to covered operators of websites and online services directed to children under 13 that collect personal information from them, and to other covered operators with actual knowledge that they collect such information online. Under 16 C.F.R. § 312.10, those operators must limit retention to the time reasonably necessary for the specific purpose of collection. Indefinite retention is prohibited.
Covered operators must establish, implement, and maintain a written retention policy identifying the collection purposes, the business need for retention, and a deletion timeframe. Under the same rule, they must include that policy in their online privacy notice.
California requires a business covered by the California Consumer Privacy Act to disclose, at or before collection, how long it intends to retain each category of personal information. If stating a period isn’t possible, it must disclose the criteria used to determine it. Under Civil Code § 1798.100, retention must also satisfy the statute’s necessity, proportionality, and purpose limitations.
The Texas Data Privacy and Security Act requires covered controllers, meaning the persons that determine why and how personal data is processed, to limit collection to information adequate, relevant, and reasonably necessary for the disclosed purposes. Its collection and privacy notice provisions don’t impose California’s specific requirement to disclose a retention period or criteria.
Texas separately requires businesses subject to Business and Commerce Code § 521.052(b) to securely destroy customer records containing sensitive personal information that the businesses no longer intend to retain. That disposal requirement addresses how covered records are destroyed. It doesn’t prescribe a general retention schedule.
Where Customer Information Is Stored
A product’s data inventory should account for information submitted by customers and information generated from it. For example, a product that summarizes uploaded documents may retain the documents, generated summaries, conversation history, and records of requests sent to a model provider.
Some products also create embeddings, numerical representations used to compare and retrieve information. A vector store is a database that holds those representations for search. If your product uses these features, you should identify what each system retains and whether the retained information identifies, relates to, or can reasonably be linked to a person under the applicable law.
Training a model with customer information creates a separate question about the resulting model and its outputs. The assessment should address whether personal information is retained or recoverable, what rights and restrictions apply to the training data, and whether a legal obligation extends to derived material.
The inventory should also include hosting logs, analytics records, older file versions, and backups. You should identify the purpose and responsible party for each category, including records held by vendors that have independent legal obligations.
Vendor Retention Depends on the Service and Configuration
A provider’s promise about model training addresses a different practice from storage. Information can be excluded from training and retained for service delivery, abuse monitoring, or legal compliance. You should review those practices separately before making a deletion promise to customers. A provider’s application programming interface, or API, is the connection through which your software requests its services.
OpenAI’s data controls documentation distinguishes abuse monitoring logs from information stored to support features such as saved conversations and files. Its default abuse monitoring period is up to 30 days, subject to stated exceptions. Approved retention controls and the particular feature used affect the result, and some features retain stored information until deletion.
Anthropic’s commercial retention documentation generally provides for deletion of API inputs and outputs within 30 days, with exceptions for features that retain information longer, contractual arrangements, policy enforcement, and legal requirements. Anthropic also publishes additional retention requirements for specified models. You should review the terms applicable to the model and service you select before describing their retention practices to customers.
Cloud services have separate arrangements. Microsoft’s documentation distinguishes automated abuse review from information stored for human review, while Amazon Bedrock’s documentation describes retention settings and model requirements. Google’s Gemini documentation separately addresses retention for abuse monitoring. You should confirm the applicable service, model, contract, and settings when selecting or changing a vendor.
Responding to a Deletion Request
Under California Civil Code § 1798.105, a covered business receiving a verifiable deletion request must address personal information it collected from the consumer, subject to the statutory exceptions. Its obligations include deleting covered information from its records and notifying service providers and contractors to delete their copies. Those providers and contractors also have obligations concerning downstream recipients.
The business must separately notify third parties to whom it sold or shared the information. Under § 7022, the impossibility or disproportionate effort qualification applies to that notification requirement. A business invoking it must explain the circumstances to the consumer.
The same regulation permits complete erasure from active systems or qualifying deidentification or aggregation. Removing identifying details or combining records satisfies these alternatives only when the result meets the applicable legal standards. For archived or backup information, deletion may be delayed until restoration to an active system or the next access or use for a sale, disclosure, or commercial purpose. You should have the technical team confirm how the product handles those events.
Texas permits consumers to request deletion of personal data provided by or obtained about them. Under §§ 541.051 and 541.052, a covered controller must respond without undue delay and within 45 days, subject to a permitted extension. Its processor contracts must also address assistance with consumer rights requests and deletion or return of data when services end, subject to legal retention requirements.
A vendor’s scheduled deletion date must be assessed against the applicable request and deadline. Merely recording that a vendor retains information for a particular period doesn’t establish that the business may wait for that period to expire. You should identify available deletion procedures, contractual assistance obligations, and any legal basis for continued retention.
Some information may lawfully be retained after a request. California’s statutory exceptions include specified needs relating to transactions, security, debugging, and legal compliance. The business should identify which records qualify and limit their continued use accordingly.
Withdrawal of consent requires a separate assessment. The business must stop processing for which the withdrawn consent is legally required. Whether an account or feature must be disabled depends on the processing involved and whether the service can continue lawfully without it. California’s consent requirements address consent to particular processing purposes.
When Enforcement Requires Destruction of Models
Privacy enforcement can affect products developed from unlawfully collected or used information. Several FTC settlements required destruction of defined models, algorithms, or other derived products as remedies for the conduct alleged.
In In re Everalbum, Inc., the FTC’s May 6, 2021 order required deletion or destruction, within 90 days, of models or algorithms developed in whole or in part using specified biometric information collected through the Ever app. It separately addressed photographs, videos, and facial representations, with exceptions for identified legal obligations.
In United States v. Kurbo, Inc., the 2022 settlement required WW International and Kurbo to destroy specified children’s information and models or algorithms developed using information collected in violation of COPPA. It also imposed a $1.5 million civil penalty and a restriction on retaining children’s information beyond one year after their last use of the service, subject to the order’s terms.
The July 2023 order in United States v. Amazon.com, Inc. imposed a $25 million civil penalty and requirements concerning Alexa voice information, geolocation information, and children’s data. It also prohibited specified uses of information subject to deletion requests to create or improve data products, including models and algorithms.
The FTC’s June 26, 2024 final order in In re Avast Limited required deletion of covered browsing information transferred to Jumpshot and products or algorithms derived from that information. That remedy followed allegations about collection, disclosure, and sale of browsing information after privacy assurances to consumers.
These remedies depended on the conduct and definitions in each order. Whether a particular model constitutes personal information or must be destroyed requires analysis of the applicable law and facts. You should maintain records connecting training datasets to model versions so that the business can identify material affected by a complaint, deletion obligation, or enforcement order.
Preserving Information for Litigation
A business with a duty to preserve evidence must retain information within the scope of that duty. The business should identify the relevant records, suspend their routine deletion, restrict their use, and determine when the preservation obligation ends.
In In re OpenAI, Inc., Copyright Infringement Litigation, the court ordered preservation of output logs that would otherwise have been deleted. The court subsequently recorded that an October 9, 2025 order terminated the broader ongoing preservation obligation following the parties’ stipulation.
The effect depended on the service and information involved. OpenAI’s explanation identified exclusions for ChatGPT Enterprise, ChatGPT Edu, and qualifying API use under zero data retention arrangements. It also explained that the broader ongoing obligation ended on September 26, 2025, while specified historical information continued to be preserved.
A provider’s preservation obligation requires a customer business to assess the effect on its particular service and customer commitments. The business must separately determine its obligations for records it holds. Its retention procedures should support preservation of identified records while ordinary deletion continues for information outside the hold, where appropriate.
Account Deletion Under App Store Rules
Apple’s App Review Guidelines, § 5.1.1(v), require apps that support account creation to offer account deletion within the app. Apple also requires the privacy policy to explain retention and deletion practices and how users can revoke consent or request deletion.
Google Play’s account deletion requirements generally require covered apps to provide both an option within the app and a web resource for requesting account deletion. Associated user data falls within the policy’s scope, and Google directs developers using service providers to request deletion by those providers. The policy permits specified legitimate retention, including security, fraud prevention, and regulatory compliance, with disclosure to users.
These platform obligations require review alongside the applicable privacy laws. For an AI product, you should determine which stored conversations, uploaded files, generated material, and vendor records are covered, and whether any continued retention is permitted. The treatment of trained models and other derived material requires its separate legal and factual assessment.
Putting the Retention Schedule Into Practice
A useful retention schedule identifies each category of information, its purpose, its storage locations, and the party responsible for it. You should record the applicable period or deletion criteria, the event that begins the period, available deletion procedures, and any preservation requirements or exceptions.
The schedule should correspond to the business’s privacy policy, customer agreements, app store disclosures, and notices to parents. You should assign implementation and testing to the technical team, including confirmation of vendor deletion procedures and what happens when backups are restored.
Legal review should address the applicable duties, permitted exceptions, contractual commitments, and accuracy of the business’s disclosures. You should revisit the schedule when a new feature, vendor, model, or use of customer information changes what the product retains or how deletion is performed.
Related practice area: Artificial Intelligence
This article is general information about the law, not legal advice, and reading it does not create an attorney-client relationship. Laws change and how they apply depends on your specific facts. For advice on your situation, consult a qualified attorney.
Need advice tied to your business issue?
Share the issue. Get direct attorney review. Receive a concrete recommendation.
Submit an Inquiry