Backfrom xAI’s own policies · verified 2026-09-02 · some facts not published
xAI: data residency & retention
Headquarters
🇺🇸 United States (US)
Where inference runs
Not disclosed
xAI's API security FAQ and enterprise docs do not disclose the datacenter regions where Grok API inference runs.
Region pinning
Not disclosed
No data-residency or region-pinning controls are published for the Grok API; compliance questions are routed to xAI's NDA-gated Trust Center.
Prompt retention
Retained · 30 days
By default API requests and responses are stored encrypted at rest for 30 days for abuse auditing, then automatically deleted.
Trains on API data
No
xAI states it never trains on API inputs or outputs without explicit permission.
Zero data retention
Available
ZDR can be enabled at team level via the xAI Console so prompts are never persisted to disk, but it disables stateful features (Stateful Responses, Files, Collections, Batch APIs).
Compiled from xAI’s published privacy policy, terms, and documentation on 2026-09-02. “Not disclosed” means xAI publishes nothing on the point. Policies change without notice, so verify against the sources above before relying on this for compliance decisions.