OpenAI API
OpenAI · Model API · US · platform.openai.com
services/openai-api.yamlVendor data-handling terms
This page blocks scripted access; the sentences were captured from the page text on the date shown and the weekly re-check will report it as needing a browser check.
“We don’t train our models on your organization’s data by default. / You decide whether your data is used for training and model improvement.”
The platform documentation states the API retention window for abuse monitoring and the zero-data-retention option; that page is pending review.
“Enhanced data retention controls help you stay compliant. / Your memories, conversations, and account data can be deleted when you choose.”
OpenAI offers data residency in Europe for eligible API and enterprise customers; the terms for that are pending review.
“OpenAI processes your Personal Data on servers located outside of the EEA, Switzerland and the UK for the purposes described in this policy.”
Domains and endpoints
observed means seen in Unseen deployments; vendor-documented means listed by the vendor. Vendors do not publish complete lists.
| Host | Role | Source |
|---|---|---|
| api.openai.com | api | observed |
| platform.openai.com | app | observed |
Assessment
Reasoning: The programmatic surface: no training by default, retention controls, and a data residency option for eligible customers. The exposure moves from vendor terms to the caller: which application holds the key, what it sends, and whether the residency option and zero-retention setting are actually configured. That is a governance question on the customer's side.
Flags: GDPR Chapter V unless data residency is configured · Application credentials (who holds the key) · Assessed 2026-09-16. The assessment is Unseen's; the terms above are the vendor's.
Changelog
- 2026-09-16Documented. No-training default and controls verified against OpenAI's security and privacy page; transfers against the EEA privacy policy.
- 2026-09-15Listed from the Unseen catalogue with observed domains.
Corrections
Pull request on GitHub, or the form below. Changes are reviewed and recorded in the changelog.