Home / AI Service Directory / OpenAI API

OpenAI API

OpenAI · Model API · US · platform.openai.com

Last verified 2026-09-16
Entry services/openai-api.yaml
Training on your data (default tier)
Organisation data not used to train models by default (API, Team, Enterprise); the organisation controls training use
Retention
Retention controls available to the organisation; API abuse-monitoring retention is set in the platform documentation
Data residency
Processing outside the EEA including the United States by default; data residency options offered to eligible API and enterprise customers

Vendor data-handling terms

Training on your data (default tier)
Organisation data not used to train models by default (API, Team, Enterprise); the organisation controls training use

This page blocks scripted access; the sentences were captured from the page text on the date shown and the weekly re-check will report it as needing a browser check.

We don’t train our models on your organization’s data by default. / You decide whether your data is used for training and model improvement.
checked 2026-09-16
OpenAI, Security and privacy page
Retention
Retention controls available to the organisation; API abuse-monitoring retention is set in the platform documentation

The platform documentation states the API retention window for abuse monitoring and the zero-data-retention option; that page is pending review.

Enhanced data retention controls help you stay compliant. / Your memories, conversations, and account data can be deleted when you choose.
checked 2026-09-16
OpenAI, Security and privacy page
Data residency
Processing outside the EEA including the United States by default; data residency options offered to eligible API and enterprise customers

OpenAI offers data residency in Europe for eligible API and enterprise customers; the terms for that are pending review.

OpenAI processes your Personal Data on servers located outside of the EEA, Switzerland and the UK for the purposes described in this policy.
checked 2026-09-16
OpenAI Privacy Policy (EEA, UK, Switzerland version), International transfers

Domains and endpoints

observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.

HostRoleSource
api.openai.comapiobserved
platform.openai.comappobserved

Assessment

API and platform, default settings: low

Reasoning: The programmatic surface: no training by default, retention controls, and a data residency option for eligible customers. The exposure moves from vendor terms to the caller: which application holds the key, what it sends, and whether the residency option and zero-retention setting are actually configured. That is a governance question on the customer's side.

Flags: GDPR Chapter V unless data residency is configured · Application credentials (who holds the key) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.

Changelog

  • 2026-09-16Documented. No-training default and controls verified against OpenAI's security and privacy page; transfers against the EEA privacy policy.
  • 2026-09-15Listed from the Unseen catalogue with observed domains.

Corrections

Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.

Edit on GitHub