Backfrom Google Vertex AI’s own policies · verified 2026-09-02
Google Vertex AI: data residency & retention
Headquarters
🇺🇸 United States (US)
Where inference runs
US, EU, Other
Vertex AI publishes regional and jurisdictional endpoints (US, EU, and other listed regions): data at rest stays in the customer-selected region, and ML processing occurs in the region/multi-region of the request for listed regional endpoints. The global endpoint carries no residency or ML-processing-location guarantee.
Region pinning
Yes, self-serve
Customers pin residency themselves by calling a regional/jurisdictional endpoint (e.g. US or EU); Google documents at-rest and ML-processing commitments for listed regions. Avoid the global endpoint when residency matters.
Prompt retention
Retained · up to 24h (cache); up to 30 days (flagged abuse logs)
Default: prompts/responses may be cached up to 24 hours to speed repeat requests; if automated safety classifiers flag suspicious activity, prompts may be logged for abuse review for up to 30 days, stored in the customer-selected region/multi-region. Both are avoidable (disable caching; abuse-logging opt-out form).
Trains on API data
No
Vertex AI data-governance docs: customer prompts/data are not used to train or fine-tune models without permission; abuse-monitoring logs explicitly 'won't be used to train or fine-tune any AI/ML models'.
Zero data retention
Available
Effective zero data retention for Gemini on Vertex is achievable self-serve/by request: disable prompt caching and opt out of abuse logging via Google's exception form.
Compiled from Google Vertex AI’s published privacy policy, terms, and documentation on 2026-09-02. “Not disclosed” means Google Vertex AI publishes nothing on the point. Policies change without notice, so verify against the sources above before relying on this for compliance decisions.