Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The Zero Data Retention mode, enabled through Privacy and Security settings, prevents submitted content including texts, images, and prompts, as well as model outputs, from being stored or used for secondary purposes; however, once enabled, the company states it cannot subsequently access, retrieve, correct, export, or delete that data on the user's behalf.
This analysis describes what Together AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision creates a technical and contractual limitation on the company's ability to fulfill data subject rights requests for data processed under ZDR, which may require evaluation under GDPR Articles 15, 16, 17, and 20 to assess whether the architecture is consistent with data subject rights obligations or whether supplemental disclosures are required.
Interpretive note: Whether the ZDR technical limitation on data subject rights fulfillment is consistent with GDPR Articles 15 through 20 depends on regulatory interpretation and enforcement context in applicable jurisdictions.
Under ZDR, submitted content and model outputs are not retained beyond active processing, but the agreement states the company cannot fulfill access, correction, export, or deletion requests for data processed under this mode. This provision applies only prospectively from the moment of activation and does not affect previously processed data.
Cross-platform context
See how other platforms handle Zero Data Retention Mode and similar clauses.
Compare across platforms →Monitoring
Together AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Under ZDR, the content you submit, including texts, images, or prompts and any outputs provided to you by the Services are not stored, retained, or used for model training, product improvements, or any secondary purposes except as needed to provide the Services to you. ZDR applies only from the moment you enable it and does not affect any data processed prior. This means we cannot later access, retrieve, correct, export, or delete your Personal Data on your behalf as it is removed from our systems as soon as processing concludes.Excerpt from Together AI's Privacy Policy
(1) REGULATORY LANDSCAPE: This provision engages GDPR Articles 15 through 20 regarding data subject rights including access, rectification, erasure, and portability; the stated inability to fulfill these rights for ZDR-processed data warrants assessment against GDPR obligations. The provision also engages CCPA deletion and portability rights for California residents. (2) GOVERNANCE EXPOSURE: Medium. The ZDR limitation on data subject rights fulfillment is framed as a technical consequence of the user's own setting choice, but regulatory authorities may evaluate whether this framing adequately satisfies the company's independent obligations under GDPR, particularly where users may not fully understand the trade-off at the point of activation. (3) JURISDICTION FLAGS: EEA, Swiss, and UK users face heightened exposure given GDPR's explicit data subject rights framework; supervisory authorities in those jurisdictions may scrutinize whether user-controlled technical limitations on rights fulfillment are permissible under applicable law. California residents should note that ZDR-processed data may fall outside the scope of CCPA deletion and portability request fulfillment. (4) CONTRACT AND VENDOR IMPLICATIONS: B2B customers integrating Together AI APIs should evaluate whether their own data processing agreements with end users or applicable privacy notices accurately reflect the ZDR limitation on rights fulfillment, particularly where those customers are acting as data controllers under GDPR. (5) COMPLIANCE CONSIDERATIONS: Legal teams should assess whether the ZDR activation flow includes adequate informed disclosure of the rights fulfillment limitation before users enable the setting, and whether that disclosure meets GDPR Article 13 or 14 transparency requirements.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision creates a technical and contractual limitation on the company's ability to fulfill data subject rights requests for data processed under ZDR, which may require evaluation under GDPR Articles 15, 16, 17, and 20 to assess whether the architecture is consistent with data subject rights obligations or whether supplemental disclosures are required.
Under ZDR, submitted content and model outputs are not retained beyond active processing, but the agreement states the company cannot fulfill access, correction, export, or deletion requests for data processed under this mode. This provision applies only prospectively from the moment of activation and does not affect previously processed data.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Together AI.