I'm the security lead at a software company of about 22 people, and I'm also helping teams adopt AI. We're required to remove client data when a customer requests deletion or leaves, but I don't want to ban client information from AI tools if they provide real productivity benefits.
The concern is that data may persist in chat histories, projects, uploaded files, or memory features. Periodically deleting all chats and projects seems like the only comprehensive approach, but it would also destroy useful context and make long-running work difficult.
For teams using tools such as Claude, are periodic purges really the only practical option? Have you implemented better controls, such as zero-retention agreements, anonymization, restricted workspaces, or workflow-specific safeguards?
4 Answers
The safest baseline is not putting identifiable client data into a general-purpose AI tool. Have users remove names, addresses, account numbers, and other unnecessary identifiers before submitting material. For cases where that makes the workflow impractical, negotiate contractual protections such as zero retention and confirm the provider’s security, deletion, memory, and administrative controls before approving the use case.
Start by separating retention controls from deletion workflows. A zero-data-retention agreement can help prevent prompts and outputs from being retained for model training, but it doesn’t necessarily solve data that users deliberately keep in projects, files, conversation history, or memory. You still need to understand exactly what each feature stores and how it can be deleted.
Define what your deletion obligation actually covers. It usually means removing the customer’s data from systems that hold their account or service records, not deleting every email, audit record, billing entry, or internal discussion that happens to mention them. For AI, document the approved use cases, configure workspace permissions, disable persistent memory where possible, and create a process to locate and delete customer-specific chats, files, and projects when required.
I’d avoid a company-wide periodic purge unless the provider gives you no other practical choice. Use a separate workspace or tenant for sensitive work, keep client material out of personal histories, apply short retention periods to temporary conversations, and require an owner or ticket for any workflow that stores customer data. That preserves useful context while making deletion targeted and auditable.

That’s the part I’m unclear on too. Zero retention may stop long-term provider storage, but a project that runs for months still needs its context supplied somehow. Re-ingesting everything on every prompt could increase cost and complexity.