Wysor privacy

What is zero data retention?

It means your text is never saved. The model reads your request, answers it, and writes no copy of it anywhere.

Not to a database, not to a log file, not to a queue waiting to be reviewed. Nothing is kept for thirty days and deleted later, because nothing is kept at all.

So there is no copy to delete afterwards, none to hand over, and none to lose. On Wysor this is the default, on every plan.

One real request, start to finish

Watch what is left of it at the end.

Your message

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.|

On the wire

8f2a c41d 90be 77a3 e5c0 1b46 aa39 d2f7 6e18 b3d5 0c92 4fa1 7d63 e80b 2519 cc74

In memory, being answered

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.

Referral drafted. Findings summarised, cardiology addressed, ready to review.

After the answer

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.

Nothing was written down.

Not deleted afterwards. Never saved in the first place, so there is no copy to delete.

Thirty days, or longer

Most providers keep your messages for 30 days. Some keep them far longer.

Thirty days is the common default, and it is a floor rather than a ceiling. While the copy sits there it is not simply parked: it is opened, read and analysed, next to everything else the request carries about you.

Retained copyAnalysing
Day 1Day 30

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.

patient namehealth datathird party
While it sits there
Opened, read and analysed
Classified against policy
Scored, and the score kept
Eligible for human review
Stored and analysed alongside it
IP addressapproximate locationdevice and browseraccount IDexact timestamp

Joined up, these stop describing a request and start describing a person: who asked, from where, on what, and when.

With zero retention there is nothing to join up
Any day

A court can reach it, including chats you deleted

In NYT v. OpenAI a federal judge ordered all output log data preserved, covering conversations users had already deleted. API and enterprise customers were excluded.

OpenAI
Not just the text

It is analysed next to everything that identifies you

A retained request is a record, not a sentence. The text is opened, read and scored, and it sits beside the IP address it arrived from, the location that resolves to, the device, the account and the exact time. Held together, those describe a person rather than a prompt.

When the company is not its own

A backed startup that fails does not get to simply delete it

A founder-owned company can decide its data is not for sale. A venture-backed one often cannot: winding it up means realising value for investors and creditors, and a database of real business conversations now has a price. Slack archives, email, documents and source code are going to AI companies at roughly $10,000 to $100,000 each, with one intermediary alone processing close to 100 deals in a year. Nobody who wrote those messages was asked. Wysor has no outside investors, so that decision is not on anyone else’s table.

Fast Company, Apr 2026
The one that ends it

Removing the copy is the only control that does not rest on trust

Settings change, policies get rewritten, deletion runs on a schedule, a court order overrides all of it, and an insolvency turns what is left into inventory. Every one of those needs a copy to exist. Zero retention is the only control that removes the copy instead of managing it.

Two different promises

Zero retention covers the model. Not the app you are typing into.

Zero data retention is something a provider has to go and arrange, and most tools never have. Where a tool does claim it, the claim describes the model: the model does not keep your text. The tool itself still keeps your messages so you can come back to them, and its own terms decide who at that company may open them.

What you send

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.|

Zero data retention, at the model

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.

Discarded the moment the answer is finished. Where a provider has arranged it, this is real and it is worth having. It is also where the promise stops.

And yet, still here

Summarise Frau Weber’s latest results and draft a referral letter to the cardiologist.

Zero retention covered the model, not the company you pay. Your messages sit in their database so you can come back to them, and their own terms decide who is allowed to open them.

The difference at Wysor, from our privacy policy
No human at Wysor reads your messages, emails, or AI conversations for product development, marketing, analytics, or model training.

Access is limited to a named security or misuse investigation, a support case you opened, or binding legal process. That list is the whole list.

For anyone who owes someone else confidentiality.

Doctors and practices
Lawyers and notaries
Tax advisors and auditors
HR and personnel records
Finance and insurance
Public sector and research

The parts people ask twice about

What does zero data retention actually mean?+

It means the AI provider processing your request keeps no copy of it. Your text is held in memory for as long as it takes to generate an answer, and then it is gone. There is no log file, no 30-day window, no queue waiting to be reviewed. Nothing is written to disk, so there is nothing to leak, subpoena, or forget to delete.

Does ISO 27001, SOC 2 or GDPR compliance mean my messages are safe?+

No, and this is the most common mix-up we hear. Those are real and they matter, but they answer a different question. ISO 27001 and SOC 2 certify that a company follows documented security and process controls, so access is governed, reviewed and audited. GDPR sets the lawful basis for processing and gives you rights over your data. Not one of them says that no copy is kept, and not one of them says that no person may open it. A provider can hold all three, store your messages for thirty days, and have staff read them, entirely within the rules. Retention and access are separate questions and you have to ask them separately.

Is zero data retention the same as GDPR compliance?+

No, and the difference matters. GDPR governs how a company is allowed to handle your data. Zero data retention removes the copy in the first place. A provider can be fully GDPR compliant and still store your prompts, analyse them, and let staff read them. Wysor does both: GDPR as the legal floor, zero retention as the technical default.

Could my data still be used to train a model?+

No. None of the AI providers Wysor works with train on your data, fine-tune on it, or use it for profiling, advertising, or marketing. That is not a setting we ticked, it is written into the data processing agreements we hold with each of them.

Does this mean Wysor keeps nothing either?+

Your chats, emails, and files stay in your Wysor workspace, encrypted at rest with AES-256, because that is the product you came for. That copy is yours: you can delete a single thread or your entire account. What zero data retention removes is the second copy, the one sitting on an AI provider infrastructure that you never asked for and cannot delete.

Do I have to turn it on or pay extra for it?+

Zero data retention is the default on Wysor, not an enterprise upgrade. There is no toggle to find and no tier to reach. The same protection applies whether you are on a free account or running a hundred seats.

Can I get this in writing for my compliance team?+

Yes. Our data processing agreement sets out the terms, and the subprocessor list names every provider that touches your data along with where it runs. Both are public, no sales call required. If your auditors need something more specific, contact us and we will work through it.