There's no fixed Canadian-law number for this — the obligation on your business is a duration test, not a countdown clock the vendor sets for you.
Short answer
No Canadian statute sets a specific retention period for AI prompts. What PIPEDA sets is a principle: personal information can only be retained as long as necessary for the purpose it was used for, and it has to be disposed of once that purpose is fulfilled. The vendor's own technical retention window — 30 days, 90 days, indefinite — is a separate, contractual fact your business has to check and match against that principle, not a legal answer on its own.
PIPEDA Schedule 1, clause 4.5 states it directly: “Personal information shall not be used or disclosed for purposes other than those for which it was collected, except with the consent of the individual or as required by law. Personal information shall be retained only as long as necessary for the fulfilment of those purposes.” Clause 4.5.3 carries it to the end: “Personal information that is no longer required to fulfil the identified purposes should be destroyed, erased, or made anonymous.” Neither clause names a number of days, because the right length depends entirely on what the information was for.
This is a different question from whether the vendor can see the prompt at all — that's about access; this is about duration. A vendor's stated retention window is a fact about its own product, set by its own terms of service, and it is not itself a Canadian legal requirement. Your business's own retention obligation under clause 4.5 doesn't disappear just because the information now sits on a third party's server — the same accountability that follows a transfer for processing under clause 4.1.3 means matching the vendor's actual, contractual retention terms against your own purpose is the real compliance step, not simply trusting a marketing line that says data is deleted quickly.
Ask the vendor for its retention and deletion terms in the actual data-processing agreement or enterprise contract — not the consumer-facing FAQ, which often describes the free tier's defaults rather than what a business account actually gets. Then set your own internal trigger for when a given piece of client or company information stops being necessary, so your business isn't relying on the vendor's default as its only retention control. Treadstone Law’s guide to PIPEDA customer-data rules covers the broader retention and disposal obligations that apply regardless of which tool is involved.
See how a live AI system gets kept accountable once it's running.