Grok's standard API is now off limits for personal data

Stani Mihov

Founder & CEO

·

TL;DR

What changed:

  • Personal data may now be sent to SpaceXAI only through its zero data retention (ZDR) API.

  • Sending personal data to any non-ZDR service is a material breach of the agreement.

  • SpaceXAI says it is not responsible for personal data processed outside ZDR.

  • Because ZDR keeps nothing, SpaceXAI cannot help with data requests, audits, or incident details for that data.

What to do: If your product sends customer or user data to Grok through the API, make sure that traffic goes through the ZDR-Enabled API, or remove personal data before it is sent.

The change

SpaceXAI, the company behind Grok, updated its Data Processing Addendum with a new version effective September 22, 2026. The DPA is part of SpaceXAI's Enterprise Terms and covers personal data that customers send through the API and other business services. SpaceXAI links the previous version from the top of the page.

Most of the update is cleanup. One new paragraph changes how any company building on Grok has to handle personal data. Venpo flagged the new version on September 23, and the redline is on the public change page.

What changed

The new paragraph reads: "Customer agrees that it will process Personal Data through the Services only using SpaceXAI's ZDR-Enabled API." ZDR stands for zero data retention: the service processes a request and keeps nothing afterward. Around that sentence, the DPA now says:

  • One route for personal data. "SpaceXAI requires that Customer does not submit Personal Data to SpaceXAI's non-ZDR Services."

  • Breaking it is serious. "Customer's failure to use the ZDR-Enabled API to process Personal Data as required will constitute a material breach of the Agreement."

  • No responsibility outside ZDR. SpaceXAI "will not be responsible for any processing of such Personal Data outside of the ZDR Service."

  • Nothing is kept. With ZDR, SpaceXAI "will immediately delete User Content after processing."

What a material breach means here

A material breach is the kind of contract violation that usually gives the other side the right to end the agreement. In practice, that means the everyday path many developers take, calling the standard API with real customer names, emails, or support messages in the prompt, now puts the whole contract at risk.

It also shifts the consequences. If personal data goes through a non-ZDR service, the DPA says SpaceXAI is not responsible for that processing. The protections a DPA normally provides for that data would not apply.

Zero retention also means less help

Zero data retention is a real privacy improvement: nothing stays on SpaceXAI's side after a request is processed. The DPA spells out the trade-off. It says SpaceXAI "will not have the information necessary to fulfill many of the obligations typically required" under a DPA.

The new text repeats this section by section. Because nothing is retained, SpaceXAI will have no data to secure, audit, or report on after a security incident, nothing to answer a person's data access or deletion request, and nothing to disclose to a government authority. That work, and the records it depends on, sits with the customer.

What did not change

Several protections remain. SpaceXAI still commits to notify customers of a security incident without undue delay and, where feasible, within 48 hours. It still gives 15 days' notice of new subprocessors, with a right to object. The confidentiality duty for its staff now expressly survives the end of their employment. And the DPA still says SpaceXAI will not sell or share personal data covered by U.S. privacy laws.

Why this matters

Many SaaS companies now call several AI models from the same product, and switching between providers can take a single line of code. A team might add Grok for one feature and send it the same support tickets, CRM notes, or user messages it sends to other providers. Under the new DPA, that only works if the traffic goes through the ZDR-Enabled API.

Each AI vendor is drawing these lines differently, as we saw when OpenAI widened how it uses data from advertisers and Lovable started training on prompts by default. Keeping track of those rules for every model you call is part of monitoring AI subprocessors.

Potential impact

For a SaaS company that uses Grok through the API, the update raises four practical questions:

  • Does any feature send customer or user data to Grok, and is that traffic going through the ZDR-Enabled API?

  • Can you strip personal data from prompts before they reach a non-ZDR endpoint?

  • If a person asks you to delete or export their data, do you keep the records you need, since SpaceXAI will not have them?

  • Does your own privacy notice and DPA with customers still describe how you use Grok accurately?

Changes like this land in a legal document, not an API changelog, which is the hidden risk of vendor legal changes.

How Venpo detected it

Venpo monitors SpaceXAI's legal pages as part of continuous vendor risk monitoring. On September 23, it flagged the new DPA and separated the ZDR requirement from a long list of wording and formatting edits. The redline is on the SpaceXAI change page, and every monitored SpaceXAI document is listed on the SpaceXAI vendor profile.

Business outcome

Teams that track SpaceXAI got a plain-English note the day after the new DPA took effect, with the material breach sentence quoted exactly. That leaves time to check which features call Grok, confirm the ZDR setting, and update internal records before a customer or regulator asks. The alternative is learning about the rule from a termination notice.

Key takeaway

SpaceXAI now allows personal data only through its zero data retention API, treats anything else as a material breach, and says it cannot help with most DPA obligations for data it no longer holds. Rules like this change in the contract, not the code, which is why automated monitoring should cover every AI provider you call.

The change

SpaceXAI, the company behind Grok, updated its Data Processing Addendum with a new version effective September 22, 2026. The DPA is part of SpaceXAI's Enterprise Terms and covers personal data that customers send through the API and other business services. SpaceXAI links the previous version from the top of the page.

Most of the update is cleanup. One new paragraph changes how any company building on Grok has to handle personal data. Venpo flagged the new version on September 23, and the redline is on the public change page.

What changed

The new paragraph reads: "Customer agrees that it will process Personal Data through the Services only using SpaceXAI's ZDR-Enabled API." ZDR stands for zero data retention: the service processes a request and keeps nothing afterward. Around that sentence, the DPA now says:

  • One route for personal data. "SpaceXAI requires that Customer does not submit Personal Data to SpaceXAI's non-ZDR Services."

  • Breaking it is serious. "Customer's failure to use the ZDR-Enabled API to process Personal Data as required will constitute a material breach of the Agreement."

  • No responsibility outside ZDR. SpaceXAI "will not be responsible for any processing of such Personal Data outside of the ZDR Service."

  • Nothing is kept. With ZDR, SpaceXAI "will immediately delete User Content after processing."

What a material breach means here

A material breach is the kind of contract violation that usually gives the other side the right to end the agreement. In practice, that means the everyday path many developers take, calling the standard API with real customer names, emails, or support messages in the prompt, now puts the whole contract at risk.

It also shifts the consequences. If personal data goes through a non-ZDR service, the DPA says SpaceXAI is not responsible for that processing. The protections a DPA normally provides for that data would not apply.

Zero retention also means less help

Zero data retention is a real privacy improvement: nothing stays on SpaceXAI's side after a request is processed. The DPA spells out the trade-off. It says SpaceXAI "will not have the information necessary to fulfill many of the obligations typically required" under a DPA.

The new text repeats this section by section. Because nothing is retained, SpaceXAI will have no data to secure, audit, or report on after a security incident, nothing to answer a person's data access or deletion request, and nothing to disclose to a government authority. That work, and the records it depends on, sits with the customer.

What did not change

Several protections remain. SpaceXAI still commits to notify customers of a security incident without undue delay and, where feasible, within 48 hours. It still gives 15 days' notice of new subprocessors, with a right to object. The confidentiality duty for its staff now expressly survives the end of their employment. And the DPA still says SpaceXAI will not sell or share personal data covered by U.S. privacy laws.

Why this matters

Many SaaS companies now call several AI models from the same product, and switching between providers can take a single line of code. A team might add Grok for one feature and send it the same support tickets, CRM notes, or user messages it sends to other providers. Under the new DPA, that only works if the traffic goes through the ZDR-Enabled API.

Each AI vendor is drawing these lines differently, as we saw when OpenAI widened how it uses data from advertisers and Lovable started training on prompts by default. Keeping track of those rules for every model you call is part of monitoring AI subprocessors.

Potential impact

For a SaaS company that uses Grok through the API, the update raises four practical questions:

  • Does any feature send customer or user data to Grok, and is that traffic going through the ZDR-Enabled API?

  • Can you strip personal data from prompts before they reach a non-ZDR endpoint?

  • If a person asks you to delete or export their data, do you keep the records you need, since SpaceXAI will not have them?

  • Does your own privacy notice and DPA with customers still describe how you use Grok accurately?

Changes like this land in a legal document, not an API changelog, which is the hidden risk of vendor legal changes.

How Venpo detected it

Venpo monitors SpaceXAI's legal pages as part of continuous vendor risk monitoring. On September 23, it flagged the new DPA and separated the ZDR requirement from a long list of wording and formatting edits. The redline is on the SpaceXAI change page, and every monitored SpaceXAI document is listed on the SpaceXAI vendor profile.

Business outcome

Teams that track SpaceXAI got a plain-English note the day after the new DPA took effect, with the material breach sentence quoted exactly. That leaves time to check which features call Grok, confirm the ZDR setting, and update internal records before a customer or regulator asks. The alternative is learning about the rule from a termination notice.

Key takeaway

SpaceXAI now allows personal data only through its zero data retention API, treats anything else as a material breach, and says it cannot help with most DPA obligations for data it no longer holds. Rules like this change in the contract, not the code, which is why automated monitoring should cover every AI provider you call.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago