Data Retention and Conversation Storage
What Claude stores
When an employee uses Claude, the following data is stored in Anthropic's systems:
Conversation content — the full text of every message sent to Claude and every response generated. This includes anything the user types, pastes or uploads, and Claude's responses. This is stored to enable the conversation history feature (the ability to continue a previous conversation) and for service operation.
Metadata — timestamps, user identifiers, model used, token counts, and Project association. This is used for usage analytics, billing and service reliability.
Uploaded files — documents, images or other files attached to conversations. These are stored for the duration of the conversation session and subject to retention settings.
Account data — email address, display name, and organisational membership. This is standard SaaS identity data.
What Claude does not store:
- Voice data (Claude.ai does not record audio; only the transcribed text of voice inputs may be processed)
- Biometric data
- Payment information (handled by Stripe or similar payment processor, not by Anthropic directly)
Retention periods
In Claude Enterprise, conversation data is retained for a configurable period. The default and options depend on your specific contract terms, but the typical range is:
- 90 days — a common default that balances user experience (conversation history available for three months) with data minimisation principles
- 30 days — a shorter period for organisations with strict data minimisation requirements
- 1 year — for organisations that need longer audit trails or that want conversation history available for a full financial year
- Indefinite — not recommended for most organisations; conflicts with GDPR data minimisation unless there is a legitimate business purpose
Where to configure: Admin Console → Privacy & Data → Conversation Retention.
The retention period applies to all conversations in the organisation. You cannot currently set different retention periods for different users or Projects (as of 2025).
What happens when data is deleted
When a conversation reaches the end of its retention period, or when you submit a manual deletion request:
- The conversation content is removed from Anthropic's production systems.
- Backups containing that data are purged according to Anthropic's backup retention schedule (typically within 30–90 days after deletion from production).
- The user loses access to that conversation in their history.
Deletion is irreversible. There is no recovery mechanism once data is purged.
Requesting data deletion
There are two scenarios for manual deletion requests:
Individual deletion (GDPR right to erasure): when an employee leaves and invokes their right to erasure, navigate to Privacy & Data → Data Deletion Requests. You can submit a request tied to a specific user account. Anthropic will delete all conversation data associated with that user within the timeframe specified in your DPA (typically 30 days).
Bulk deletion: if a security incident occurs and you need to purge a set of conversations quickly, contact Anthropic support directly. Bulk deletion outside the standard retention mechanism is handled as a support case.
Best practice: add data deletion requests to your off-boarding checklist for any employee who requests erasure under GDPR or a similar regime, or for any employee whose role involved access to sensitive business data.
The difference between deletion and deactivation
Deactivating a user (removing their access) does not delete their data. The conversation history remains in Anthropic's systems until:
- The retention period expires, or
- You submit an explicit deletion request
This matters for GDPR compliance: if a former employee requests erasure of their personal data, you must submit a deletion request. Deactivation alone is insufficient.
Implications for data classification
Before configuring your retention period, consider what employees are likely to enter into Claude:
General business data (low sensitivity): email drafts, meeting summaries, publicly available information, code. A 90-day retention is typically appropriate.
Internal confidential data (medium sensitivity): financial projections, strategic plans, internal reports. Consider 30–60 days and include explicit instructions in your acceptable-use policy about what may and may not be entered.
Regulated personal data (high sensitivity): employee personal data, customer PII, patient health records. This data generally should not be entered into Claude at all. Your acceptable-use policy should prohibit it. Where it cannot be avoided (e.g., anonymised data for analysis), the shortest feasible retention period is appropriate.
Privileged information: legal advice, M&A details, litigation-related content. Consider whether Claude is the appropriate tool for these tasks at all, given that Anthropic's systems hold this data.
Scenario: a law firm's retention decision
A UK law firm deploys Claude Enterprise for their 80-person team. Their DPO reviews the data types that will enter Claude: research summaries (low sensitivity), draft counsel notes (medium sensitivity), and — the concern — client matter details that could appear if a solicitor pastes context into a prompt.
After review, the DPO recommends:
- Set retention to 30 days (data minimisation).
- Create a Project for legal research that instructs Claude not to store or repeat any client identifiers.
- Add a rule to the acceptable-use policy: "Do not include client names, matter numbers or identifying details in Claude prompts."
- Train all users on this rule as part of onboarding.
The firm also negotiates a DPA with Anthropic that specifies their 30-day retention requirement and confirms that conversation data is processed only within the EU. These terms are confirmed in writing before go-live.
Key takeaway
Retention configuration is one of the first governance decisions you make after signing your Enterprise contract. Match the retention period to your data classification policy, add data deletion to your off-boarding process, and document your decisions for the DPO and any future compliance audit.
📖 Official Documentation See this in practice in Anthropic’s live support docs: