Zero data retention for AI video APIs: what Sume keeps

Zero data retention means a provider stores nothing after it answers. Async AI video APIs can't: the video is a stored file. What Sume keeps, and why.

5 min readSume
All posts

Zero data retention (ZDR) means a provider keeps no copy of your data after it answers a request. An asynchronous AI video API can't work that way for its output: the video is a file the API stores so you can fetch it after the job finishes. Sume has no ZDR option, and its privacy policy says inputs and outputs may be retained as needed to run the service.

This post uses Sume's Video generation docs, which state that "Sume has no ZDR toggle", its Privacy Policy, its Terms and the Embed a Format cookbook, plus OpenRouter's ZDR page for the definition, all read on 2026-09-28. It is not legal or compliance advice.

What does zero data retention mean?

OpenRouter's ZDR page puts it plainly: ZDR "means that a provider will not store your data for any period of time." Its page separates two policies: a provider can retain data without training on it, for example to scan for abuse or for legal reasons, and a provider that retains nothing cannot train on it (OpenRouter).

On OpenRouter, ZDR is a routing rule for inference requests. You can enforce it globally, per model group, per guardrail, or per request with a zdr field in the provider preferences, and requests then route only to endpoints with a ZDR policy.

Can an AI video API offer zero data retention?

Not for the output, when generation runs as a job. On Sume, video generation is asynchronous: you submit a job, poll it, and download the file once the status is completed. GET /v1/videos/{id}/content redirects to the generated video for a completed job, so the file has to exist somewhere after the model is done.

On Sume the file is also meant to last. Format and job artifacts are durable media.sume.com URLs that do not expire, and the cookbook warns that a durable URL is a public URL: anyone who has it can fetch it. Do AI-generated video URLs expire? covers which URLs last and which are signed.

What does Sume keep?

Sume's own pages describe what is kept. They set no fixed retention periods:

From Sume's Privacy Policy and the Embed a Format cookbook, read 2026-09-28.
DataWhat the page saysPage
Prompts, scripts, images, reference media, voice inputProcessed by Sume or its providers; may be retained as needed to provide the service, keep your asset library and threads available, and reproduce or debug issuesPrivacy Policy
Generated videos and other outputsKept so you can fetch them; Format and job artifacts are durable media.sume.com URLs that do not expireEmbed a Format
Operational logsRequest and job identifiers, account or organization identifiers, IP address, and error contextPrivacy Policy
Billing and usage recordsKept to maintain billing and usage historyPrivacy Policy
How longAs long as needed for those purposes; periods vary by the type of dataPrivacy Policy
WhereThe United States and other countries where Sume or its service providers operatePrivacy Policy

Who else sees my prompts and images?

The privacy policy lists AI model providers for image, video, avatar, speech and language generation among Sume's service providers, and says they may process information only as needed to provide services to Sume, comply with legal obligations, or as otherwise permitted by law.

Under the Terms you keep ownership of what you submit, and you grant Sume the rights needed "to host, process, transmit, display, store, reproduce, and create outputs from your content to provide, secure, support, and improve the Services" (Terms).

How do I limit what is kept?

Without a ZDR switch, the controls are on your side of the request:

  • Send less. The privacy policy asks you not to submit sensitive personal information unless it is necessary for your use.
  • Keep outputs private yourself. Proxy the bytes through your own authenticated route, or copy them into your own storage when the job completes, as the cookbook suggests; Download a generated video shows the download.
  • Ask for deletion. You can contact Sume to request access, correction, deletion or export of personal information, subject to applicable law, and revoke API keys and authorized MCP clients yourself.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume