Client Confidentiality and AI for Coaches: What Stays Out of the Prompt

The Coach Factory Team
Client Confidentiality and AI for Coaches: What Stays Out of the Prompt

The usual advice for coaches using AI is to take the client’s name out before you paste anything in. It sounds responsible. It isn’t enough. A name is the smallest part of what identifies a person, and a client’s story with the name removed is often still their story.

That’s why the working rule on client confidentiality and AI for coaches should start stricter than most guidance does. By default, no client, sponsor, or third-party material goes into a general-purpose AI tool like ChatGPT, Claude, Gemini, or Copilot. There’s a narrow, deliberate path for the exceptions, and a wide, useful lane for everything else.

Why taking the name out doesn’t make it anonymous

Privacy researchers have been showing this for more than 25 years. In a study of US census data, Latanya Sweeney found that 87% of the US population likely had a unique combination of just three details: five-digit ZIP code, gender, and date of birth. The data is old, but the point hasn’t aged. Ordinary facts, combined, point to one person.

A 2019 study by researchers at Imperial College London went further. Its authors estimated that 99.98% of Americans could be correctly re-identified in an “anonymised” dataset using 15 characteristics such as age, gender, and marital status. Both studies are about demographic datasets, not coaching notes. Still, think about what a typical coaching story contains. A role, an industry, a city, a recent reorganization, a difficult boss, a family detail. That’s often more than 15 characteristics.

The UK Information Commissioner’s Office defines personal data as information about a person who can be identified “directly or indirectly,” including by combining it with other information. Indirectly is the word that matters for coaches. Your client’s manager, colleague, or spouse could recognize a story you thought you’d anonymized.

What your ethics code already asks of you

You don’t need a new rule to get here. The ICF Code of Ethics, in the version that took effect April 1, 2025, asks coaches to “maintain the strictest level of confidentiality with all parties involved, regardless of the role I am fulfilling” (Standard 2.1). Standard 2.5 extends your obligations to anything you do “through any technology systems I may utilize,” and it names artificial intelligence specifically.

The Code’s definition of confidentiality is broader than many coaches assume. It covers “any information obtained in or around the coaching relationship,” unless there’s a legal requirement, a threat of harm, or the client’s written consent. In or around. That includes what a sponsor tells you about a restructure and what a client tells you about a colleague.

The ICF has also published an AI Coaching Framework and Standards. It’s written for companies that build AI coaching systems, not for coaches using a chatbot, so it isn’t your rulebook. But one line in it is worth borrowing. Its data transparency standard notes that everyone involved is “concerned about where and how their data is stored, as well as who will have access to it.” Those are the same two questions you should be able to answer before anything about a client leaves your hands.

Why we go further than “de-identify at a minimum”

Some respected guidance sets a lower bar. Writing for the Institute of Coaching, Dr. Jonathan Marion says client-related content in a consumer AI tool should “at a minimum, be de-identified before use.” The same article makes the point that pasted session notes sit on third-party servers “regardless of your privacy settings.”

We agree with the direction and take a firmer line on the method. The re-identification research above shows how hard real de-identification is, especially for the rich, specific stories coaching produces. So the default here isn’t “de-identify first.” It’s “keep it out,” with a written-consent path for the cases where using client material is truly worth it.

What counts as client material

If it’s on this list, it stays out of a general-purpose AI tool by default.

  • Direct identifiers. Names, email addresses, phone numbers, employers, and social media handles.
  • Sponsor and employer information. Company details, budgets, restructures, and what the sponsor wants from the engagement.
  • Other people in the story. The boss, the co-founder, the partner. They never agreed to anything.
  • Session content. What your client said, your notes, transcripts, and your own read on their patterns.
  • Anything that could be combined. Role plus industry plus city plus a recent event is enough to point to one person.

One category is a hard stop, even with consent. The ICO’s guidance on special category data covers information that’s “likely to be more sensitive,” including health, religious beliefs, sexual orientation, and political opinions. If a client has shared anything like that, it doesn’t go into these tools. Privacy law differs by country and state, so check what applies where you and your client live. This isn’t legal advice.

What privacy settings change, and what they don’t

Every major tool has settings that affect how your chats are used, and they differ more than most coaches realize. A few examples from the vendors’ own pages, checked in late September 2026:

  • Google Gemini. Google’s Gemini privacy help page says a subset of chats is reviewed by human reviewers, and reviewed chats can be kept for up to three years.
  • Claude. Anthropic lets consumer users choose whether their chats help improve Claude. With that choice on, data is kept for five years. With it off, the standard 30-day period applies.
  • Microsoft Copilot. The work version under enterprise data protection states that prompts and responses aren’t used to train the underlying models. The consumer version works differently, so know which one you’re signed into.
  • ChatGPT. OpenAI has its own data controls. Read them in your account settings on the day you decide, rather than relying on anyone’s summary (including this one).

Settings like these change what a vendor does with your data after it arrives. They don’t change the fact that you sent it. A vendor’s privacy policy doesn’t move the responsibility off you, and the ICF Code is clear about whose responsibility it is. These pages also change often, which is why any exception needs a fresh check.

When client material can go in

Using AI for prep and reflection can be genuinely useful. Pulling themes from months of your own notes, for example, or getting ready for a session with a long-term client. If you want to do that with real client material, run it through two gates.

  1. Written agreement from the client. Not a general privacy clause. A specific agreement that names the kind of tool and the kind of material. If you already cover session recording and notetakers, our guide to AI notetaker consent for coaches shows how to build that into your process.
  2. A same-day check of the vendor’s pages. Where is the data stored, who can access it, is it used for training, and how long is it kept? If you can’t answer all four, stop.

Even with both gates passed, keep the special categories out, and keep the material to what the task actually needs. What you choose to write down in the first place matters too. Our post on coaching session notes covers what belongs in the record at all.

The checklist below turns all of this into a test you can run at the moment you’re about to paste something in. It walks through what counts as client material, how to check when you’re unsure, the consent path, and the stop conditions.

Client-Safe AI Boundary Checklist

Client-Safe AI Boundary Checklist

The safe lane is wider than you think

None of this means keeping AI out of your practice. It means keeping clients out of the prompt. Plenty of real work needs zero client data. Drafting a blog post, outlining a workshop, tightening your sales page, writing a welcome email template, planning your content calendar. If you use AI for that kind of writing, it’s worth learning how to keep your own writing voice in the output.

There’s one kind of question that stays out of bounds even when it feels harmless. “Here’s what my client said. What did they really mean?” The tool wasn’t in the room. It can’t hear tone or know the history you’ve built together. That question belongs to you and your notes, or to your supervisor or peer group if you need a second view.

Clients trust you with things they may not have said out loud to anyone else. Holding that line with a new kind of tool is the same promise you’ve always made, kept in a new place. Keep the client’s story with you and use AI for the work around it. Your clients should never have to wonder where their words went.

Join Coach Factory for free and build a practice that’s impossible to overlook.

Join Coach Factory and get instant access to every worksheet, template, checklist, and tool you can put to work this week in your coaching business.