# xAI API – Grok

## Kurzbeschreibung
**xAI** offers Grok models via its API for text generation, reasoning, coding, tool use, document-centric workflows, and agentic research. The current docs focus primarily on Grok 4.20 as the new flagship, as well as on server-side tools such as Web Search, X Search, Code Execution, and Collections Search. 




Additionally, xAI documents classic model-listing endpoints such as /v1/models and /v1/language-models.

## Claim
LLM “Build with Grok, the AI model designed to deliver truthful, insightful answers.”

## Geeignet für
- API Integration
- Automation / Workflows
- Data Analysis
- Data Extraction / Document Analysis
- Customer Service & Chatbots
- Programming / Software Development
- Research
- Knowledge Management / Internal Search

## Kernfunktionen
- Image Generation
- Function Calling
- AI Agents
- LLM API
- Multimodal AI
- Programming
- Reasoning Model
- Language Model

## Preismodell
- **other:** **Token-based API usage** Billing based on input, reasoning, completion, image, and cached prompt tokens per model.


**Server-side Tools** Additional billing for tool invocations; costs may increase with the complexity of agentic requests.


**Credits / API Key** API usage takes place via an xAI account, API key, and purchased credits.


**Enterprise / ZDR** Enterprise customers can use Zero Data Retention so that API requests and responses are not stored.


**Voice / Imagine / Batch / Tools** Additional product areas for real-time conversations, TTS/STT, image/video generation, batch processing, web search, and structured outputs.

## DSGVO und Datenschutz
**Gesamteinschätzung:** Conditional

**On-Prem / local hosting: indirect / not available**

No true on-premise or local model deployment on the customer's own infrastructure was found on the website. What is documented is primarily the use of xAI inference services; with Grok Build, tool execution and parts of the data processing take place locally, but inference still runs via the provider.

**Private Cloud / data center: partial**

The website mentions for Enterprise 'EU data residency options', 'Regional processing for compliance requirements', 'Multi-region infrastructure with custom SLAs' as well as dedicated Enterprise features such as ZDR. However, an explicitly dedicated private cloud or isolated EU data center deployment is not specifically described on the website.

**EU SaaS / managed: partial**

There are references on the website to 'EU data residency options' and 'Regional processing for compliance requirements'. However, specific EU/EEA data centers, countries, or EU data residency available by default for all API customers are not mentioned.

**Hybrid: partial**

For Grok Build, the website describes a mixed approach: user inputs and file contents are assembled locally, tool execution takes place locally in a sandbox, but inference is sent to the xAI service. This is a hybrid pattern, but it is not described as a formal hybrid hosting offering for the entire platform.

**DPA / DPA: partial**

The website refers to 'Legal Resources' with 'Data Processing Addendum' and mentions 'Data processing agreements' for the Voice APIs. However, a specifically accessible DPA text or detailed terms were not found on the reviewed domain itself.

**No training: covered**

The website explicitly states that xAI does not use API inputs and outputs for training without explicit permission. In addition, for Collections it is explained that user data stored there is not used for model training. For Voice APIs, it also states that audio data is processed in real time and is neither stored nor used for training.

**Open source / transparency path: partial**

There is some transparency path on the website: protobuf definitions can be downloaded and a repository called 'xai-proto' is mentioned; in addition, local policies, sandboxing, and client-side control for Grok Build can be configured. However, no clear open-source or self-hostable model path for the core models was found.

**Data processing**

According to the Security FAQ, the standard API temporarily stores requests and responses for 30 days for abuse review and deletes them afterward. For Enterprise, there is Zero Data Retention, in which prompts, responses, and metadata are processed in real time but not persisted. For Grok Build, the website describes a process in which inputs and file contents are assembled locally, inference runs via the provider, and tool execution takes place locally in a sandbox. For Voice APIs, the website additionally mentions EU data residency options and regional processing without naming specific EU/EEA locations.

**Conclusion**

For an EU/EEA tool directory, from the website perspective xAI API – Grok is **not clearly fully GDPR-ready in the standard configuration**, but can potentially be used in a more privacy-friendly way *under certain conditions*: in particular with an Enterprise agreement, DPA, enabled Zero Data Retention, and explicitly agreed EU data residency. Without these additional prerequisites, too many points remain open or are only stated in general terms from a European perspective, especially regarding specific server locations, subprocessors, and standard data processing.

**Sources**

- [https://docs.x.ai/developers/faq/security](https://docs.x.ai/developers/faq/security)
- [https://docs.x.ai/developers/faq/general](https://docs.x.ai/developers/faq/general)
- [https://docs.x.ai/developers/model-capabilities/audio/voice](https://docs.x.ai/developers/model-capabilities/audio/voice)
- [https://docs.x.ai/docs/guides/using-collections](https://docs.x.ai/docs/guides/using-collections)
- [https://docs.x.ai/build/enterprise](https://docs.x.ai/build/enterprise)

The website documents several privacy-relevant components for use in the EU/EEA region, but no consistently clear, demonstrable full GDPR compliance for standard use of the xAI API. Positive aspects include statements such as "no training without explicit permission," an Enterprise option for Zero Data Retention, references to a "Data Processing Addendum," as well as to "EU data residency options." At the same time, essential points remain unclear on the provider's website or are only indirectly evidenced: a specific server location or specific EU/EEA data centers are not named, subprocessors are not listed on the website, and a DPA/AVV is mentioned but could not be found in detail on the domain reviewed here. For GDPR-compliant use in the European region, the tool therefore appears realistic only under certain conditions, in particular with an Enterprise setup, DPA/AVV, and ideally Zero Data Retention or explicitly agreed EU data residency.

**Positive**

Several positive privacy signals can be found on the website: xAI states that API inputs and outputs are not used for training without explicit permission. For Enterprise accounts, there is "Zero Data Retention," meaning API requests and responses are not stored. For the Voice APIs, the website also mentions "GDPR Compliant," "Data processing agreements and EU data residency options," as well as "Regional processing for compliance requirements." SOC 2 Type 2 is also mentioned.

**Negative**

From an EU/EEA perspective, crucial details are missing from the website or remain vague: specific EU/EEA server locations or named data centers are not provided; subprocessors are not listed on the website; a DPA/AVV is mentioned, but its contents could not be found on the reviewed domain; according to the Security FAQ, the standard API generally stores requests and responses for 30 days unless Zero Data Retention is activated as an Enterprise feature. As a result, a simple blanket GDPR approval for all types of use is not substantiated.

**Server location**

Not specified on the website. There are references to "EU data residency options" and "Regional processing for compliance requirements," but no specifically named server locations or data centers in the EU/EEA.

## Hosting und Daten
- **On-Prem / lokales Hosting:** unknown
- **Private Cloud / Rechenzentrum:** teilweise / indirekt
- **EU SaaS / Managed:** teilweise / indirekt
- **Hybrid:** teilweise / indirekt
- **AVV / DPA:** teilweise / indirekt
- **Kein Training auf Kundendaten:** abgedeckt
- **Open-Source / Transparenz-Pfad:** teilweise / indirekt

## Standort
**Land:** USA

**Taxonomie:** USA

X.AI LLC, 1450 Page Mill Road, Palo Alto, CA 94304, USA

## Vorteile
- Very strong in real-time research because Grok integrates web search and X search as official tools.
- Well positioned for coding, agentic tool workflows, and document-based analysis.
- xAI explicitly positions Grok 4.20 as a fast, precise model with strict prompt adherence.
- For enterprise/API data, there is a DPA, a subprocessor list, and according to the Enterprise Terms, a 30-day deletion of User Content unless an exception applies.

## Nachteile
- The documentation is currently inconsistent between new model names like grok-4.20-reasoning and older/dated IDs like grok-4-0709; as a result, the model landscape is less clear than with some competitors.
- Exact token prices for some new models are referenced on the official pricing page, but in the officially parseable sources here they are not cleanly extractable for every model.
- xAI itself points out that outputs may hallucinate or be inaccurate and must be reviewed by the customer.
- For enterprise customers, operating competing services with the xAI API is prohibited according to the Terms.

## Quellen
- Offizielle Website: https://docs.x.ai/developers/models

## Letzter Datenstand
2026-04-17

## Originalseite
https://kifox.ai/en/ki-tools/xai-api-grok-en/
