HomeArticle

From Apology to "Burn After Use": Zhipu Launches the "No Data Retention" Policy, Can the Trust Gap of ZCode Be Filled?

AI唱反调2026-09-21 16:07
After data is no longer retained and managed, where did the previously transmitted data go?

48 hours after the apology, Zhipu upgraded its crisis public relations response.

On the evening of September 20, Zhipu's MaaS platform officially announced that the "no data retention" feature will be launched soon: the platform will not perform static storage of user inputs and outputs, and data will only be used for the current model call and be deleted immediately after use. All users can apply to enable this feature in the console.

The timing is highly thought-provoking. Two days ago, ZCode just issued an apology for "silently uploading the entire code repository"; one day ago, enterprise customer Chengming Technology released an open letter, raising 12 points of doubt and stating that independent forensics found "the repair effect is questionable".

Before the ZCode package upload controversy settled, Zhipu MaaS announced the launch of "no data retention": inputs and outputs will not be stored persistently and will be erased immediately after use, except for Batch API and compliance review. From apology to architecture adjustment, this trust reconstruction has entered the institutional level — but the phrase "to be launched soon" leaves too much leeway.

What Loopholes Are Left In The "No Data Retention" Rule

First look at the full content of the official statement, the expression this time is quite restrained.

The core commitment is summed up in one sentence: after activation, Zhipu MaaS platform will not statically store user inputs and outputs, data will only be temporarily processed within the lifecycle of a single request, and will be released immediately after the call ends, with no copies retained.

However, the exception clauses are also clearly stated: interfaces such as Batch API and File API that require persistent storage of tasks or files on the platform side are not covered; for data that laws and regulations require to be retained, or for the investigation of suspected violations or abuse, the platform may retain the data for 30 days or more in accordance with regulations.

There are three other noteworthy details: this feature is "available for any user to apply for activation", not enabled by default — which means that for users who do not apply, data will still be retained as before; the effective time is "subject to the platform's confirmation result", so the initiative is in the hands of the platform; the official wording is "to be launched soon", and as of press time, the feature has not been actually implemented.

When the commitment and exceptions are combined, the actual profile of this mechanism is: real-time call services can be used in a "flash" manner, batch processing and file services will still store data persistently, and the compliance backdoor is open. The framework is a progress, but there is still a gap from "zero retention".

Why Now: The Crisis Timeline Speaks For Itself

Sort out the events of the past 72 hours, and the logic is clear at a glance.

On the daytime of September 18, the reverse engineering report from developer ferstar detonated the community: ZCode silently packaged and uploaded the entire code repository, Git history accounts for the majority, the two interface switches were all invalid, and the encrypted private key was only stored in the cloud. In the evening, Zhipu apologized in the official Feishu group, launching a combination of measures including repair, open source, third-party review and quota reset.

On September 19, the controversy did not subside, but escalated: some users posted a Huorong monitoring screenshot in the official communication group, showing that a single process was frantically uploading 43GB of data, and the screenshot was withdrawn by the administrator two or three minutes after being sent, this action itself became a new point of controversy; that night, enterprise customer Chengming Technology released an open letter, putting forward 12 response requirements, and clearly stated that independent forensics found "the repair effect is questionable".

On the evening of September 20, the "no data retention" mechanism was officially announced.

From the apology in the Feishu group to the official announcement of the platform-level rule, Zhipu's response is upgrading: the bug fix of a single product has become an architecture commitment of the entire MaaS platform. A reasonable deduction is that the public pressure from enterprise customers has played a decisive role: once a paying B-end customer like Chengming Technology publicly challenges, the damage is no longer limited to the developer reputation, but will affect the procurement decisions of the MaaS platform. For customers in industries such as finance, government affairs and healthcare, "data sovereignty" is originally an access threshold, and the ZCode incident has left a scar on Zhipu's enterprise-level business.

The Evidence The Community Demands Has Not Yet Been Delivered

While the official has taken frequent actions, the list of demands from the community has barely changed. The feedback from the Feishu group sorted out by Bianews is very representative: about 70% of users expressed strong dissatisfaction, and the core demands are five points — publish the repaired version and code diff, provide verifiable data destruction evidence, offer user-self-checkable upload records, confirm in writing and delete all uploaded data, and make the third-party audit report public.

Check the progress one by one: no code diff; destruction evidence is technically impossible to self-certify (the private key is stored in the cloud, which is the core of the last controversy); no upload record query; no written confirmation of deletion of uploaded data; the third-party audit report is still in the promised state.

The "no data retention" mechanism itself cannot fill these gaps — it only governs "no retention in the future", while what users ask is "where did the previously uploaded data go". The comment from ChinaVenture hits the nail on the head: no matter it is "destroy immediately" or "will not save", this kind of commitment cannot be verified or falsified from the outside, the only thing users can confirm is that the data has left their own computers, and what happens next depends entirely on the manufacturer's self-discipline.

In addition, it should be reminded that some "insider details" circulating on the Internet, such as "Zhipu rewrote 70% of the observability components for this" and "more than 120 financial institutions have entered the gray test", have no reliable sources, and are most likely interpretations from self-media, do not take them seriously.

Industry Level: This Move Does Have Demonstration Significance

Putting aside the motivation of crisis public relations, the direction of the mechanism itself is correct.

The focus of competition in China's domestic MaaS market this year is quietly shifting: after the model capabilities are gradually leveled, "how data is processed" has become the core clause for enterprises to select service providers. OpenAI and Anthropic have long had commitments that API data will not be used for training. Domestic manufacturers previously relied mainly on the statements in privacy policies. Zhipu's move to make "no static storage" a switchable platform-level mechanism is indeed the first of its kind in China.

If Zhipu can later connect this mechanism with open source code libraries and third-party audits to form a verifiable chain — the code is accessible to you, the behavior is checked by a third party, and the commitment has credible basis — then this crisis may instead become a model for rebuilding trust assets. On the contrary, if "to be launched soon" is delayed indefinitely and the audit report is never released, this mechanism will only be remembered as a PPT for crisis public relations.

Conclusion

Three actions in three days: apology, repair, and official announcement of the new mechanism. Zhipu's crisis response speed is impeccable, but the rules of the trust test are very cruel — the wrong question you answered before will not automatically get points just because you write faster later.

The 12 questions from Chengming Technology are still there, the doubt about the 43GB screenshot is still hanging, and the list of third-party auditors has not been announced. "No data retention" is a good start, but it only proves that Zhipu "does not want to retain data in the future", and has not yet proved that "it did not misappropriate data before".

There is no shortcut to trust repair, only the fulfillment of the commitment list. For the next news, we are waiting to see the audit report, not a new feature.

This article is from the WeChat official account "AI Contrarian", and is authorized for release by 36Kr.