Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The document states that fine-tuned models are exclusive to the customer and are not shared with other customers or used to train other models, and that fine-tuning data is retained indefinitely until the customer actively deletes the associated files.
This analysis describes what OpenAI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that fine-tuning data does not have an automatic deletion timeline, unlike the 30-day default retention for API inputs and outputs. Customers must actively delete fine-tuning files to trigger removal, creating an open-ended retention period that may require active management for data minimization compliance.
The updated terms state that workspace admins 'can control' data retention rather than directly controlling it. This conditional phrasing may suggest that retention control is optional or contingent rather than a guaranteed capability. Enterprise customers relying on admin-driven data retention policies should clarify with OpenAI whether this change affects their ability to set specific retention timelines for workspace data.
View change record →The updated terms shift governance of conversation access and retention from end users to workspace administrators. Under the revised policy, workspace admins can now view, access, export, and delete any end user conversations within their workspace and control how long workspace data is retained. Additionally, OpenAI now reserves the right to retain deleted or unsaved conversations beyond the standard 30-day deletion window if retention is reasonably necessary to protect its services or any third party from harm, beyond prior language that limited retention extensions to legal requirements. Within an enterprise account, end users no longer have unilateral control over conversation visibility or deletion of their own conversations.
View change record →This provision assures customers that fine-tuned models remain exclusive to them and their training data is retained at their discretion, protecting proprietary customizations and data.
View full change record →Under this provision, fine-tuning data submitted by customers is retained on OpenAI's systems without a fixed expiration date until the customer deletes the files. The agreement states that fine-tuned models are not shared with other customers or used to train other models.
Cross-platform context
See how other platforms handle Fine-Tuning Data Ownership and Retention and similar clauses.
Compare across platforms →Monitoring
OpenAI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.
"Yes, you can adapt certain models to specific tasks by fine-tuning them with your own prompt-completion pairs. Your fine-tuned models are for your use alone and never served to or shared with other customers or used to train other models. Data submitted to fine-tune a model is retained until the customer deletes the files.Excerpt from OpenAI's Enterprise Privacy
(1) REGULATORY LANDSCAPE: The indefinite retention of fine-tuning data until customer deletion engages GDPR's storage limitation principle, which requires that personal data not be retained longer than necessary. If fine-tuning data contains personal data, organizations must assess whether the open-ended retention period is consistent with their stated processing purposes and retention schedules. The FTC Act applies to the accuracy of exclusivity and non-sharing commitments. (2) GOVERNANCE EXPOSURE: Medium. The absence of an automatic deletion timeline for fine-tuning data distinguishes this from the 30-day API retention default and may require active data lifecycle management by customers. Organizations that submit fine-tuning data and do not actively manage file deletion may retain data on OpenAI systems beyond their internal retention policy periods. (3) JURISDICTION FLAGS: EU and UK organizations should assess whether open-ended fine-tuning data retention is consistent with GDPR storage limitation requirements and whether their DPA addresses fine-tuning data as a distinct processing category. Organizations in regulated sectors should assess whether fine-tuning data may contain regulated data types requiring specific retention controls. (4) CONTRACT AND VENDOR IMPLICATIONS: Procurement teams should confirm that fine-tuning data handling is addressed in executed DPAs or enterprise agreements. The customer's obligation to actively delete files should be incorporated into internal data lifecycle procedures and vendor management workflows. (5) COMPLIANCE CONSIDERATIONS: Compliance teams should establish procedures for periodic review and deletion of fine-tuning files that are no longer required. Data processing inventories should include fine-tuning data as a distinct category with a customer-managed retention lifecycle. Privacy impact assessments for fine-tuning deployments should address the open-ended retention period.
This provision establishes that fine-tuning data does not have an automatic deletion timeline, unlike the 30-day default retention for API inputs and outputs. Customers must actively delete fine-tuning files to trigger removal, creating an open-ended retention period that may require active management for data minimization compliance.
Under this provision, fine-tuning data submitted by customers is retained on OpenAI's systems without a fixed expiration date until the customer deletes the files. The agreement states that fine-tuned models are not shared with other customers or used to train other models.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by OpenAI.