Which AI Agent Features Fall Outside Zero Data Retention A procurement census of 31 AI agent feature and delivery-surface combinations across Anthropic, OpenAI, Google, and AWS, read on September 9, 2026, finds that zero-data-retention (ZDR) eligibility varies by feature, with Anthropic's Messages feature conditionally eligible for ZDR while Files and Batch are not, and many contract and deletion paths remain unknown. The analysis urges buyers to evaluate retention and eligibility at the feature level rather than relying on broad provider labels. A model can support a zero-data-retention arrangement while the agent feature around it stores sessions, files or memories. The purchase decision therefore belongs at the feature level. Start with the workflow you intend to run, identify every place it creates persistent state, and check each against the applicable provider arrangement. This census records 31 feature and delivery-surface combinations across Anthropic, OpenAI, Google and AWS. It separates what provider documentation states from what remains unknown. It is a procurement reference, not a legal opinion or a certification that any deployment meets its obligations. 1. 01A provider label is too broad.Messages, files, hosted sessions and tools can have different eligibility. 2. 02State and abuse monitoring differ.Disabling response storage does not establish that every copy or log disappears. 3. 03Deletion may require several operations.Session history, uploaded files and derived memories can have separate lifecycles. 4. 04Unknown is a useful result.Ask the provider for a feature-specific answer instead of inferring it from a nearby service. 01 — Practical decisionRetention and eligibility by feature ZDR means zero data retention under the provider’s defined arrangement. BAA means a HIPAA business associate agreement; DPA means a data processing agreement, with Google’s CDPA label retained where documented. Eligibility does not establish that your organization has executed the required agreement. Read the contract and deletion fields separately even where they share a column. “Conditional” requires the applicable account, model and feature settings. “Unknown” means the inspected source does not establish the field; it does not mean the provider has no agreement or deletion mechanism. Source letters resolve directly to provider pages. | Provider documentation linked in every cell, read September 9, 2026. This sample is not an exhaustive product inventory or a vendor ranking. | | | | |---|---|---|---| | Provider / feature | ZDR eligibility | Retention window | Contract and deletion path | |---|---|---|---| | Anthropic / Messages Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Conditional A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | No conversation-content storage by default; exceptions below A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Contract: HIPAA eligible; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | | Anthropic / Files Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | No A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Until deletion or configured expiry A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Contract: BAA no; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Separate file deletion M · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview | | Anthropic / Batch Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | No A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | 29 days A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Contract: BAA no; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Account representative A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | | Anthropic / Web search, no dynamic filtering Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Conditional A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Response handling A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Contract: HIPAA eligible; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | | Anthropic / Web fetch, no dynamic filtering Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Conditional A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Response handling; publisher policies separate A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Contract: BAA no; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | | Anthropic / MCP connector Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | No A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Standard policy A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Contract: BAA no; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Account representative A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | | Anthropic / MCP tunnels Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | No A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Unknown T · Sep 9, 2026 https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/security | Contract: BAA no; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Archive tunnel; remove local credentials; data erasure unknown T · Sep 9, 2026 https://platform.claude.com/docs/en/agents-and-tools/mcp-tunnels/security | | Anthropic / Managed Agents sessions Source · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview | No M · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview | Stored session history/state/output M · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview | Contract: BAA no; DPA unknown M · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview Delete: Delete session; uploaded files separately M · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview | | Anthropic / Scheduled deployments Source · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | No: Managed Agents sub-feature A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention | Session data persists; run-record TTL unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention S · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/scheduled-deployments | Contract: BAA no; DPA unknown A · Sep 9, 2026 https://platform.claude.com/docs/en/manage-claude/api-and-data-retention Delete: Archive stops schedule; delete sessions/files separately; record erasure unknown S · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/scheduled-deployments M · Sep 9, 2026 https://platform.claude.com/docs/en/managed-agents/overview | | OpenAI API / Chat Completions Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Conditional O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | No ordinary state; abuse logs up to 30 days by default; exceptions apply O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: BAA conditional; DPA unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: Unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Responses foreground Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Conditional; store=false under ZDR O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Default stored response ≥30 days O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: BAA conditional; DPA unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: Unknown in inspected page O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Responses background Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/background | Permitted from ZDR projects; temporary storage B · Sep 9, 2026 https://developers.openai.com/api/docs/guides/background | Roughly 10 minutes with store=false B · Sep 9, 2026 https://developers.openai.com/api/docs/guides/background | Contract: Responses BAA conditional; DPA unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: Automatic after temporary polling period B · Sep 9, 2026 https://developers.openai.com/api/docs/guides/background | | OpenAI API / Conversations Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | No O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Until deletion O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: Unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: Deletion required; exact operation not checked O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Files Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | No O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Until deletion/expiry O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: BAA conditional; DPA unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: API/dashboard; expires after O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Batch Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | No O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Until deletion O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: BAA conditional; DPA unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: Unknown in inspected page O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Live web search Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Tool-specific classification unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Tool-specific window unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: BAA no; DPA unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data Delete: Unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Cache-only web search Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | ZDR setup required for BAA path O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Tool-specific window unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: BAA conditional; DPA unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data Delete: Unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI API / Remote MCP Source · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Third-party boundary O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | MCP operator policy O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | Contract: Third-party agreement unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data Delete: MCP operator; exact path unknown O · Sep 9, 2026 https://developers.openai.com/api/docs/guides/your-data | | OpenAI / Codex cloud Source · Sep 9, 2026 https://learn.chatgpt.com/docs/enterprise/admin-setup | Unknown C · Sep 9, 2026 https://learn.chatgpt.com/docs/enterprise/admin-setup | Unknown numeric window C · Sep 9, 2026 https://learn.chatgpt.com/docs/enterprise/admin-setup | Contract: BAA no; DPA unknown H · Sep 9, 2026 https://help.openai.com/en/articles/20001069 Delete: Unknown C · Sep 9, 2026 https://learn.chatgpt.com/docs/enterprise/admin-setup | | Google Cloud / Plain model inference Source · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Conditional configuration and model G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Abuse/Advanced AI exceptions; inspect contract G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Contract: CDPA referenced; BAA unknown G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention Delete: Unknown G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | | Google Cloud / Search grounding Source · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | No for this feature G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Derived query/context logs ≤3 days G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Contract: CDPA referenced; BAA unknown G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention Delete: Logging cannot be disabled G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | | Google Cloud / Maps grounding Source · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | No for this feature G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Prompts/context/output 30 days G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Contract: CDPA referenced; BAA unknown G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention Delete: Logging cannot be disabled G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | | Google Cloud / Live session resumption Source · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Disable resumption for ZDR G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Cached inputs/outputs ≤24 hours G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | Contract: CDPA referenced; BAA unknown G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention Delete: Exact deletion operation unknown G · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/zero-data-retention | | Google Cloud / Managed Agents preview Source · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents | Unknown; confidential-data use prohibited V · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents | Unknown numeric window V · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents | Contract: Pre-GA restrictions; BAA/DPA unknown V · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents Delete: Project deletion documented; individual record erasure unknown V · Sep 9, 2026 https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents | | Gemini Developer API / Stored interactions paid Source · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Unknown program eligibility; stored state I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | 55 days; configurable 7/14/28/55 I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Contract: BAA/DPA unknown I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview Delete: interactions.delete or AI Studio; expiry I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | | Gemini Developer API / Stateless interactions Source · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Unknown program eligibility; store=false supported I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Interaction storage disabled; other retention unknown I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Contract: BAA/DPA unknown I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview Delete: No stored interaction; other deletion unknown I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | | Gemini Developer API / Background interactions Source · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | store=false incompatible I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Stored interactions follow tier policy I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | Contract: BAA/DPA unknown I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview Delete: interactions.delete or AI Studio; expiry I · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/interactions-overview | | Gemini Developer API / Files Source · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/files | Unknown program eligibility; file storage required F · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/files | 48 hours F · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/files | Contract: BAA/DPA unknown F · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/files Delete: files.delete or automatic expiry F · Sep 9, 2026 https://ai.google.dev/gemini-api/docs/files | | AWS AgentCore / Runtime sessions Source · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html | Unknown D · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html | Data window unknown; microVM lifetime is separate R · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-lifecycle-settings.html | Contract: Service HIPAA eligible; BAA/DPA terms unknown K · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/compliance-validation.html Delete: Timeout terminates instance; session can resume R · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-lifecycle-settings.html | | AWS AgentCore / Short-term memory Source · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-create-a-memory-store.html | Unknown program eligibility; persistent events W · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-create-a-memory-store.html | Configured event retention ≤365 days W · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-create-a-memory-store.html | Contract: Service HIPAA eligible; BAA/DPA terms unknown K · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/compliance-validation.html Delete: DeleteEvent; derived long-term memory survives E · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/short-term-delete-event.html | | AWS AgentCore / Long-term memory Source · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html | Unknown D · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html | Unknown numeric window W · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/memory-create-a-memory-store.html | Contract: Service HIPAA eligible; BAA/DPA terms unknown K · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/compliance-validation.html Delete: DeleteMemoryRecord separately L · Sep 9, 2026 https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API DeleteMemoryRecord.html | 02 — Practical decisionRead the conditions before using an eligible feature Anthropic’s eligibility documentation https://platform.claude.com/docs/en/manage-claude/api-and-data-retention adds model-specific exceptions: Fable 5/5.1 and Mythos 5/5.1 require 30-day retention without express authorization. Search/fetch dynamic filtering is excluded from the eligible path. Flagged content may be retained up to two years, with legal exceptions. A feature-level yes cannot override those conditions. OpenAI’s HIPAA guidance https://help.openai.com/en/articles/20001069 requires an executed BAA and Modified Retention for covered API use unless specified otherwise. Codex cloud is excluded. The API data-controls page https://developers.openai.com/api/docs/guides/your-data separately conditions the cache-only web-search BAA path on supported non-preview tooling, disabled external web access and ZDR at organization and project level. These details change how a procurement question should be phrased. Ask whether the exact model, endpoint, tools and settings are covered by the proposed agreement. A response about the general API may be accurate while leaving the intended hosted feature unanswered. Our Astra–Fable comparison /blog/gpt-6-astra-vs-claude-fable-5-1-comparison covers model selection. Use this feature census as a separate filter before running an evaluation with confidential material. 03 — Practical decisionWhat stateful agents cost the reviewer Persistent state can be useful: it lets work resume, keeps files available and avoids asking the user to repeat context. The review cost is identifying which resources exist, who can access them, how long they remain and which operation removes them. That work is part of choosing the runtime. Claude Managed Agents documentation https://platform.claude.com/docs/en/managed-agents/overview says the stateful service is outside current ZDR and HIPAA BAA eligibility. Session deletion and uploaded-file deletion are separate. The question for a buyer is whether that persistence fits an acceptable arrangement, not whether persistence is automatically disqualifying. The current OpenAI background-mode guide https://developers.openai.com/api/docs/guides/background permits requests from ZDR projects with store=false while retaining temporary polling data for roughly ten minutes. That is a specific documented exception to a literal expectation of no storage. Quote the behavior when assessing it rather than relying on an older blanket description of background mode. Google’s managed-agent preview guide https://docs.cloud.google.com/gemini-enterprise-agent-platform/build/managed-agents/interact-with-agents restricts confidential input and commercial/production use. General cloud data-governance statements do not remove those preview restrictions. Our Google managed-agent analysis /blog/google-managed-agents-api-single-call provides product context; the current feature terms decide the allowed use. 04 — Practical decisionFollow deletion through the derived data Draw a simple resource list for a representative task: input request, session, uploaded file, tool result, memory, trace and export. Identify the owner and deletion operation for each. A request to delete the session should not be treated as proof that the other resources were removed. AWS short-term event deletion documentation https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/short-term-delete-event.html says deleting an event does not remove derived long-term memory. The latter has a separate DeleteMemoryRecord operation https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API DeleteMemoryRecord.html . Similarly, runtime lifecycle limits https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/runtime-lifecycle-settings.html describe instance lifetime, not a universal data-retention promise. A stopped process and erased data are different outcomes. Include destinations outside the runtime. A remote tool may receive information under its own policy, and an exported trace may remain in your observability system. The provider’s deletion operation cannot establish what your own retained export contains. Keep the data-flow map narrow enough that an engineer can verify it. Our agent runtime and sandbox matrix /blog/agent-runtime-sandbox-matrix helps identify execution boundaries. Add storage and deletion ownership to that runtime decision before calling the workflow ready for sensitive work. 05 — Practical decisionTurn unknown cells into precise provider questions An unknown cell should produce a question with a subject and a requested answer. For example: does this feature retain session content after an explicit delete request, and what documented window applies to primary copies and backups? Avoid asking whether the whole platform is compliant; that invites an answer too broad to settle the deployment. Attach the model ID, region, feature name and enabled tools to the question. Ask which contract covers the service and whether an eligibility exception requires approval. Request a source or written commitment that can be retained with the deployment record. For implementation, test the operations available to you using non-sensitive sample data: create the resource, find it, delete it and confirm the visible result. Such a test can establish that the control works in your application. It cannot independently establish deletion of provider backups or other internal copies; those require the provider’s documented commitment. Keep the census at the same URL and re-check it when the provider changes a feature or your workflow adds a new destination. A table read today is evidence for today’s decision, not a permanent certification. Our Claude Managed Agents update guide /blog/claude-managed-agents-update-effort-webhooks-skills illustrates how runtime features can change the scope of an earlier review. This is a documentation comparison, not a hands-on performance test. - As-of date - September 9, 2026. Published September 8 as an editorial backfill; collection happened the following day. - Scope - Purposive census of 31 feature/surface rows across four providers, researched from 18 provider documentation pages. Each cell includes its source and read date. Conditional is not default eligibility; unknown is not a negative finding. Contract columns record documentation statements, not a signed agreement or legal assessment. - Refresh - Review after provider policy or model changes. Unknown marks information the cited documentation does not state. 06 — Next stepWhat to do next Choose the complete data path, not the model label. Filter the intended workflow by feature eligibility, retention behavior, contract and deletion path. Resolve consequential unknowns with the provider and preserve the answer with the deployment configuration. Stateful features can be a deliberate choice when their handling fits the requirement; a broad privacy label alone cannot establish that fit. Our AI transformation services /services/ai-transformation help teams define a useful pilot, evaluate its results and turn the findings into an implementation decision.