A retention promise can be true and still miss where the value went. Zero data retention says the provider does not keep the prompt and response after processing a covered request. By itself, that says nothing about what the provider is allowed to learn from them.
Picture the request as an envelope. Inside it, the provider's systems process the prompt, generate a response, and produce the model's internal activations. Suppose none of that survives the request. The response goes back, the temporary state is discarded, and an audit looking for stored customer content finds nothing. That answers the storage question. It leaves the use question open.
Something else could cross the boundary before the deletion: a score, a routing adjustment, a synthetic example. A model outside the envelope could then be trained or configured using that export. Deleting the source would not undo the change. The retained value would be downstream of the delete.
The surprising part is how little an export may resemble what it carries. In the subliminal learning experiments, researchers prompted a teacher model to favor owls, then asked it for number sequences. They filtered the outputs to keep only the required numeric format. A student trained on those sequences selected owls as its favorite animal more than 60 percent of the time, up from about 12 percent. Related experiments transmitted preferences through code and misalignment through numbers and math reasoning traces. The data passed the content filters. The behavior still transferred.
A later preprint followed three transmitting model lineages through ten generations. The owl tendency weakened but persisted. Removing the default system prompt at evaluation stopped the final students from mentioning owls, while an activation probe still detected a signal associated with the trait. That is a narrow result, but it makes a useful point: absence from the output is not proof of absence from the model.
Now put that mechanism inside the envelope. Suppose a provider uses customer content to condition a temporary teacher, has it generate filtered number sequences, and retains only those sequences. A student outside the envelope trains on them. If the relevant behavior transfers, the customer text can disappear while its influence survives in the student. This is a hypothetical pipeline; the experiments did not test it on ZDR traffic or establish that a provider operates it.
There are limits. The original number experiments relied heavily on teachers and students sharing a model initialization; mismatched models generally did not show reliable transfer. They demonstrated changes in behavior, not the recovery of a private document or a general way to improve a model's capabilities. The concern here is that influence can survive a filter designed to remove its visible subject matter.
That distinction matters because a no-training promise restricts use. OpenAI's services agreement, for example, says it will not use customer content to develop or improve its services without the customer's explicit agreement. Using that content to shape a teacher would already be a use, before any numbers left the envelope. Whether a particular implementation breaches a contract depends on its terms and permissions. An empty prompt log cannot settle that question.
There is a published example of a narrower export. OpenAI's Private Safety Processing documentation describes automated review of encrypted content held in customer-controlled storage. An attested runtime releases bounded safety signals and operational metadata, prevents human access to the protected content, and prohibits its use for model training. The distinction is the permitted purpose and the controls enforcing it. Removing text or adding noise does not, by itself, authorize another use.
The audit therefore has to follow what leaves the envelope and what happens to it. A provider can demonstrate that it deleted the source without demonstrating that it stopped using the result. The envelope holds the data. It does not hold the benefit.