How to Create a Coaching Client Record Retention and Deletion Policy for Session Notes, Messages, Recordings and AI Outputs

The ICF puts it plainly: "Maintain, store, and dispose of any records, including electronic files and communications, in a manner that promotes confidentiality, security, and privacy, and complies with applicable laws and agreements." Most coaches read that and nod. Very few actually build the policy it describes. The result is a practice sitting on years of session notes, chat threads, call recordings, and AI-generated summaries with no plan for when any of it should be deleted.
This is not about paranoia. It is about professionalism. A retention policy protects your clients' privacy, limits your liability if something goes wrong, satisfies the ICF Code of Ethics, and keeps your practice aligned with data protection laws like the GDPR. And it takes about an afternoon to set up.
This guide covers every record type a modern coaching practice creates, how long to keep each one, how to delete securely, and the specific challenge that AI outputs introduce. Coachful details were checked on 30 September 2026.

What counts as a coaching record
The ICF's Ethics Ethical Insights and Considerations document defines records broadly: "emails, text messages, written notes, recording files, audio or video notes, and entries in databases or tools." For a coaching practice running on modern software, that list is longer than most coaches realize.
The full inventory
Before you can write a retention policy, you need to know what you are retaining. Walk through each category and note where each type lives in your current setup.
- Session notes. Your written observations, reflections, and action items from each coaching session. These might live in a coaching platform, a notes app, a Google Doc, or a paper notebook.
- Client intake forms and questionnaires. The information clients provided when they signed up: goals, background, health disclosures, consent forms. Often stored across your booking tool, coaching platform, and email.
- Messages and chat. Direct messages, Slack or WhatsApp threads, in-app chat, SMS, and email exchanges between you and the client. This category surprises coaches because the volume accumulates quietly.
- Session recordings. Audio or video recordings of coaching calls, whether full sessions or clips. These are the highest-sensitivity records in your practice because they capture the client's voice, face, and unfiltered words.
- AI-generated outputs. Session summaries, pre-session briefings, suggested action items, and any other content your AI tools produce from client data. These are new, and most coaches do not have a policy for them yet.
- Progress tracking data. Goals, habits, check-in responses, completion rates, and any quantified client data your platform collects over the engagement.
- Financial records. Invoices, payment history, refund records, and subscription details. These have separate legal retention requirements in most jurisdictions.
- Agreements and contracts. Signed coaching agreements, terms of service acceptances, and consent forms. These are your legal protection and typically outlast all other record types.

Coachful centralizes most of these record types in one client view: session history, progress data, goals, habits, check-in responses, intake form answers, and notes all live on the client record. That consolidation matters for retention policy because you only need to manage deletion in one place rather than hunting across five separate tools. Coachful is GDPR-ready with full data export (client roster, notes, check-ins, goals, habits, sessions, form responses) and data stays until you request deletion.
How long to keep coaching records
There is no single universal answer. The retention period depends on three overlapping requirements: your jurisdiction's laws, your professional body's guidance, and your coaching agreement with the client.
Baseline retention periods by record type
These are practical defaults based on common legal requirements and professional standards. Adjust them based on your jurisdiction and the advice of a local attorney or data protection officer.
- Session notes and progress data: 3 to 7 years after the engagement ends. Most professional liability insurance policies define a claims window of 3 to 7 years. Keeping notes within that window protects you if a former client raises a complaint. Beyond it, the records become a liability rather than a protection.
- Messages and chat: 1 to 3 years after the engagement ends. Chat messages are rarely needed after the relationship concludes, and they contain a high volume of personal information. A shorter window reduces your data footprint without losing anything operationally important.
- Session recordings: delete within 90 days of the session, or immediately after the purpose is served. Recordings are the most sensitive record type. If you record sessions for your own review or to produce AI summaries, delete the raw recording once the summary is finalized. Keeping years of recordings without a specific purpose is a risk with no upside.
- AI-generated outputs: same retention as the source data, or shorter. An AI session summary should follow the same retention schedule as session notes. An AI briefing generated for a single session should be deleted within 30 days, because it was ephemeral by design and contains concentrated personal data.
- Intake forms and questionnaires: same retention as session notes (3 to 7 years). These contain baseline information that may be relevant to understanding the arc of the engagement.
- Financial records: 7 to 10 years. Tax authorities in most jurisdictions require you to keep financial records for at least 7 years. These are typically lower-sensitivity than coaching content, but check your local requirements.
- Agreements and contracts: 7 to 10 years, or longer if required by your jurisdiction. These are your legal evidence of consent, terms, and scope. They should be the last records you delete.

The GDPR rule that changes the calculation
If you coach clients in the EU or EEA, or if you are based there, the GDPR applies. The core principle is data minimization: you should not keep personal data longer than necessary for the purpose it was collected. "We might need it someday" is not a valid purpose.
Under the GDPR, you need:
- A lawful basis for processing. For coaching, this is typically "legitimate interest" (you need the notes to deliver the service) or explicit consent (the client agreed to recording). Once the engagement ends, the lawful basis shifts to "legitimate interest for professional defence" during the retention window.
- A documented retention schedule. You must be able to explain how long you keep each data type and why. "I never thought about it" is not compliance.
- A deletion process you actually follow. Stating a policy and never acting on it is worse than having no policy, because it proves you knew the obligation existed and ignored it.
- A response plan for data subject requests. A client can ask you to export or delete their data. You have 30 days to respond. If your data is scattered across seven tools, that clock will feel very short.
Coachful's full data export (ZIP containing roster, notes, check-ins, goals, habits, sessions, and form responses) was built specifically for this scenario. A data subject access request can be fulfilled from one export rather than piecing together records from a spreadsheet, a chat app, a calendar, and a cloud drive.
The AI output problem most coaches have not thought about
AI tools in coaching create a new category of record that does not fit neatly into traditional retention frameworks. When your AI assistant generates a session summary, a pre-session briefing, or a suggested action plan, that output contains distilled personal data, often more concentrated than the source material.
Three questions your policy needs to answer about AI
- Where does the AI process the data? Is client information sent to a third-party API? Stored on external servers? Processed locally? Your clients have a right to know, and the GDPR requires you to disclose third-party processors in your privacy notice.
- Does the AI provider retain the data for training? Some AI services use customer inputs to improve their models. If your session notes or recordings are being fed into a training dataset, your clients' words are now part of a system they never consented to. Check the data processing agreement of every AI tool you use.
- How do you delete AI outputs when the retention window closes? Deleting the source notes but leaving the AI summary defeats the purpose. Your deletion process needs to cover every derivative of the original data, including cached summaries, briefing documents, and any AI-generated insights stored separately from the client record.
Coachful's AI assistant (Michelle) works from live practice context, including clients, programs, sessions, calendar, and payments. Session summaries and pre-session briefings are tied to the client record, so they follow the same data lifecycle and export path as the notes they were derived from, rather than sitting in a separate system with its own retention rules.
How to build the policy: a step-by-step framework
A retention and deletion policy does not need to be a legal document. It needs to be a clear internal document that tells you (and anyone on your team) what to keep, how long, where it lives, and what triggers deletion. Save the legal language for the client-facing privacy notice.
Step 1: Audit your current records
List every type of client data you currently hold. For each type, note:
- What tool or location stores it
- Whether it is encrypted at rest and in transit
- Who has access (you, an associate, a virtual assistant, a third-party service)
- Whether the client consented to its collection and the specific consent language used
- How old the oldest record is
Most coaches discover records they forgot about during this step. Old WhatsApp conversations with clients from three years ago. A Google Drive folder of discovery call recordings from 2023. Intake form responses in a Typeform account they no longer use. These orphaned records are the highest risk because nobody is managing them.
Step 2: Define your retention schedule
Using the baseline periods above and any jurisdiction-specific requirements, create a simple table:
| Record type | Location | Retention period | Deletion trigger |
|---|---|---|---|
| Session notes | Coaching platform | 5 years after last session | Annual review |
| Client messages | Coaching platform chat | 2 years after last session | Annual review |
| Session recordings | Cloud storage | 90 days after session | Quarterly sweep |
| AI summaries | Coaching platform | Same as session notes | Annual review |
| Intake forms | Coaching platform | 5 years after last session | Annual review |
| Financial records | Coaching platform / accounting | 7 years | Annual review |
| Agreements | Coaching platform | 10 years | Annual review |
Adjust the periods to match your liability insurance claims window and local tax requirements. The point is to have a written schedule, not to guess at the "perfect" number.
Step 3: Consolidate where records live
The fewer tools that hold client data, the simpler your retention policy is to execute. Every additional system means another deletion checklist, another access audit, and another potential gap.

Coachful consolidates session history, client records, messages, progress data, intake forms, agreements, invoices, and AI outputs into a single platform. That means one place to audit, one place to export, and one place to delete. If you are currently running client data across a calendar app, a chat tool, a payment processor, a notes app, and an AI service, the consolidation alone simplifies your compliance work significantly. For the broader operational case for consolidation, see our guide on automation for coaches.
Step 4: Set up your deletion process
A policy without an execution process is a promise you will break. Schedule a recurring calendar event (quarterly or biannually) to run through your retention table and delete anything past its window.
For each deletion:
- Verify the retention period has elapsed. Count from the last session date, not the engagement start date.
- Check for active legal holds. If a client has filed a complaint or you are involved in any legal proceeding involving that client, do not delete anything until the matter resolves, regardless of your retention schedule.
- Delete from all locations. The coaching platform, cloud storage backups, local copies, email threads, and any AI service that retained input data. A record that exists in one forgotten backup is not deleted.
- Log the deletion. Keep a brief log (date, client identifier, record types deleted, who performed it). This log does not contain the deleted data. It proves you followed your policy.
- Confirm with the client if they requested deletion. If the deletion was triggered by a data subject request, send a brief confirmation: "Your records have been deleted as requested on [date]."
Step 5: Tell your clients
Your retention policy should be disclosed to clients before they share anything with you. The right place is your coaching agreement and your privacy notice.
In the coaching agreement, add a clause covering:
- What records you create and maintain
- How long you keep them after the engagement ends
- The client's right to request export or deletion
- How you handle session recordings and AI processing (if applicable)
This does not need to be dense legal language. Clear, plain sentences work better and are more likely to be read. For the full structure, see our coaching agreement template.
Session recordings: the record type that needs the most care
Recordings are uniquely sensitive because they capture everything: tone, emotion, hesitation, vulnerability. A leaked set of session notes is bad. A leaked recording is catastrophic. The ICF source document specifically names "recording files" and "audio or video notes" as records requiring careful handling.
Recording consent
Get explicit written consent before recording any session. "Is it okay if I record this?" at the start of a call is not sufficient documentation. Your coaching agreement should include a specific recording clause that covers:
- What is being recorded (audio, video, or both)
- The purpose of the recording (your review, AI processing, quality assurance)
- Who will have access to the recording
- How long it will be stored
- Whether the client can revoke consent and what happens to existing recordings if they do
Recording storage
- Store recordings in an encrypted cloud service, not on your laptop's desktop or in a shared Google Drive
- Use a separate, access-controlled folder or storage location, not mixed in with general business files
- Do not share recordings with anyone without the client's explicit consent, including team members, supervisors, or AI services that might use them for training
- If you use recordings to generate AI summaries, delete the raw recording as soon as the summary is finalized and reviewed
Recording deletion
Recordings should have the shortest retention window of any record type. Ninety days is generous. If you only record to review your own coaching or to generate a summary, 30 days is more appropriate. The longer a recording exists, the greater the risk and the lower the operational value.
What to do with records from former clients you have lost track of
Every coach has old records from clients who finished years ago: the Google Doc from 2021, the Dropbox folder of recordings from a client who ghosted, the notebook from when you started coaching. These are the records most likely to cause problems, because they sit outside any system and nobody is managing them.
The practical approach:
- Inventory everything. Spend an hour finding every location where former client data lives. Check email, cloud storage, chat apps, old coaching platforms, paper files, and your phone.
- Apply your retention schedule retroactively. If a record is past its retention window, delete it now. Most of those 2021 records are well past any reasonable retention period.
- Consolidate anything you are keeping. Move records within the retention window into your current system. Delete the scattered copies.
- Destroy paper records properly. Shredding, not recycling. A stack of session notes in a recycling bin is not a deleted record.
Frequently asked questions
How long should coaches keep session notes?
Three to seven years after the last session is the common range. The specific number depends on your professional liability insurance claims window and your jurisdiction's statute of limitations for professional negligence claims. If your insurer covers claims made within six years, six years is a reasonable retention period. Beyond that, the notes become a liability rather than a protection.
Does the ICF require coaches to keep records for a specific period?
The ICF does not mandate a specific retention period. The ICF Code of Ethics (Standard 10) requires coaches to maintain records "in a manner that promotes confidentiality, security, and privacy" and to "create a regular and careful handling plan" for destroying records. The ICF expects you to have a policy and follow it, but leaves the specific periods to your judgment and local law.
What should a coaching privacy notice include about AI tools?
Disclose which AI tools process client data, what data is sent to them, whether the AI provider retains or uses that data for training, where the processing happens geographically, and how AI-generated outputs (summaries, briefings) are stored and deleted. Under the GDPR, you must also name AI processors in your Record of Processing Activities. Clients cannot make informed consent decisions about information they do not have.
Can a coaching client request deletion of all their records?
Under the GDPR, yes, with exceptions. Clients have the right to erasure ("right to be forgotten"), but you can retain records necessary for legal compliance (financial records for tax purposes) or for establishing, exercising, or defending legal claims (notes within your liability insurance window). Communicate clearly which records you can delete immediately and which you must retain, with the specific legal basis for each.
Do coaches need to encrypt client records?
The GDPR requires "appropriate technical measures" to protect personal data, and encryption is the most commonly cited measure. At minimum, ensure your coaching platform uses encryption in transit (HTTPS) and at rest. For recordings and highly sensitive documents, client-side encryption or an encrypted cloud service adds a meaningful layer. An unencrypted spreadsheet of client notes on a shared laptop does not meet any reasonable standard.
How should coaches handle client data when switching platforms?
Export all client data from the old platform before closing your account. Verify the export is complete (spot-check several clients). Import into your new platform. Then delete your account and data from the old platform, and get written confirmation of deletion. Coachful offers full data export as a ZIP file containing client roster, notes, check-ins, goals, habits, sessions, and form responses. Do not leave orphaned data on a platform you no longer use.
What happens to coaching records if a coach dies or becomes incapacitated?
This is the question nobody wants to think about. Designate a "professional executor" in your business continuity plan: a trusted colleague who knows where your records are, has emergency access credentials, and will notify clients and execute your deletion policy. Without this, your clients' most sensitive records sit indefinitely on platforms and devices that nobody is managing.
Is Coachful HIPAA compliant for health coaching records?
Coachful is GDPR-ready with full data export but is not HIPAA-certified. If you are a health coach working with protected health information (PHI) in the United States and are required to comply with HIPAA, verify that every tool in your stack, not just your coaching platform, meets HIPAA requirements and will sign a Business Associate Agreement.







