Coaching runs on a promise: what is said in the session stays in the session. That holds whether the client is an executive talking through a succession plan or a health coaching client sharing medical history. AI tools are now sitting in on those sessions, taking notes and finding patterns. Whether that breaks the promise or keeps it depends entirely on how the AI is set up.
We built Vibly for coaching organizations, and this question comes up in almost every conversation we have with them. Heads of coaching services want the admin relief that AI brings. They also know their sessions carry sensitive client data, often paid for by an employer or sponsor, and that nothing kills a coaching program faster than a client wondering where the session data went.
This page sets out the standard we believe any coaching organization should hold an AI vendor to, including us. It ends with a checklist you can send to your own clients, and a one-page version you can download and share.
What clients and sponsors actually worry about
When coaching organizations raise AI with their clients, three fears come up again and again.
The notes will leak. Session notes are the most sensitive document in coaching. Many executive coaching firms never share session notes with anyone, including their own leadership. Clients fear that an AI tool quietly changes that: notes flowing to a vendor’s servers, visible to people who were never in the room.
The data will train someone’s model. Leaders being coached talk about succession plans, conflicts with named colleagues, and their own doubts. The idea that any of it could become training data for a general purpose AI model is disqualifying, and rightly so.
The recording happens silently. Consent is the foundation of a coaching relationship. If a client discovers after the fact that sessions were transcribed by software they never agreed to, the trust damage extends past the tool to the coach and the firm.
These fears are reasonable, and they are solvable with the right structure. The rest of this page describes it.
The consent chain: who agrees, and when
Confidentiality in organizational coaching involves three parties: the coach, the client being coached, and the sponsor organization paying for the engagement. A serious AI setup gets consent at each link.
The client consents in the session. Before any transcription or AI note taking starts, the person being coached should see an explicit prompt and accept it. If they decline, the AI does not run. Not “runs but discards”, does not run. This should happen per session, in the meeting interface itself, where the client can see it.
The coach and organization control the defaults. Consent prompts are the floor. Above them, the organization should be able to switch AI features off entirely, for everyone, for specific programs, or for specific clients. A firm serving one privacy sensitive sponsor should be able to disable AI for that sponsor’s engagements while leaving it on elsewhere.
The sponsor gets transparency, in writing. Sponsors do not need session content. They do need to know, before the program starts, what technology touches their leaders’ sessions and under what terms. The practical answer is a one page summary they can read in two minutes. That is what the download at the bottom of this page is for.
The contractual layer: no-training guarantees, DPAs, and the right certifications
Consent settings are software. Contracts and audits are what make the promises enforceable. Which documents matter depends on the kind of coaching you deliver.
A no-training clause, always. The single most important sentence in the stack, for every kind of coaching: your data is never used to train AI models. Ask for it in writing. On Vibly, no client data trains any model, ours or our providers’.
A Data Processing Agreement (DPA) with the platform, always. The DPA defines what the platform may do with your data, where it lives, how long it is retained, and what happens when you leave. If a vendor cannot produce one, stop the conversation.
For health related coaching: a Business Associate Agreement (BAA) with every AI provider in the chain. HIPAA and BAAs apply when coaching touches health information, which covers health coaching, wellness programs, and behavioral health work. A BAA binds the vendor, and the vendor’s own AI suppliers, to handle protected health information under healthcare rules (the HHS guidance on business associate contracts sets out what these cover). Vibly signs BAAs with the AI providers behind our features, including OpenAI and Anthropic, so for health adjacent work the no-training and confidentiality terms are contractual, not aspirational.
For executive and leadership coaching: security certifications. HIPAA is not the relevant regime when no health data is involved. What matters there is independent evidence that the vendor’s security controls actually hold: a SOC 2 report or ISO 27001 certification. Ask which one the vendor has, ask for the report under NDA, and be wary of vendors who can produce neither and offer adjectives instead. Vibly is SOC 2 Type II compliant, and the report is available to customers under NDA.
What “tenant isolation” means in plain English
Vendors say “tenant isolated” and move on. Here is the plain version.
Your organization’s data is logically isolated: every record is bound to your organization and access controlled so that AI features run on your data only. The mechanism is called logical multi-tenancy isolation, and the practical meaning is this: insights generated for your organization come from your sessions, your notes, and your programs. Nothing from another customer’s data informs what you see, and nothing of yours informs theirs.
The test question for any vendor: “If a competitor of ours uses your platform, can anything we put in ever influence anything they see?” The only acceptable answer is no, followed by an explanation of how.
Where the line sits: what AI should and should not do in coaching
Structure and contracts decide whether AI is safe. Product philosophy decides whether it belongs. Our view, shaped by the coaches who use Vibly, is that AI supports the coach and never replaces the relationship.
In practice that means AI is welcome in the admin layer: drafting session notes for the coach to review, summarizing a recording the client consented to, packaging program level themes for a sponsor report once the data is aggregated and anonymized above a critical mass. Where AI plays a more direct role in a client’s experience, one principle governs it: it must be an explicit, opt-in choice made by the coaching organization and clearly labeled for the client, never a silent substitute for the human coach. The relationship stays at the center, and the organization decides what supports it.
One detail that matters at the sponsor reporting level: aggregation thresholds. Organization wide insights, common themes, competency gaps, engagement patterns, should only be generated when enough engagements exist that no individual can be identified. Below that threshold, the report refuses to run. This is how it works on Vibly: organization level insights are generated only above a minimum number of engagements, so no report can ever describe an individual by implication.
The 8 questions to ask any AI-enabled coaching platform
Send these to any vendor, including us. A serious vendor answers all eight in writing.
- Does the client see an explicit consent prompt before any recording or transcription starts, and what happens if they decline?
- Can we disable AI features per client, per program, and organization wide?
- If our coaching touches health data: do you have signed BAAs with every AI provider your features rely on? If not: which SOC 2 report or ISO 27001 certification can you show us?
- Is our data ever used to train AI models, yours or anyone’s? Show us the clause.
- Will you sign a DPA, and where is our data stored and for how long?
- Is our organization’s data isolated from other customers, and how?
- Who inside your company can access our session content, and under what controls?
- Can we get a one page summary of all of the above that we can share with our clients?
How Vibly answers
For completeness, our own answers: consent prompts before any transcription, with decline meaning no AI runs; AI switchable off globally, per program, and per client; BAAs signed with our AI providers including OpenAI and Anthropic for health adjacent work; a contractual no-training commitment; a standard DPA; SOC 2 Type II compliance, with the report available under NDA; HIPAA compliant infrastructure with role based access and audit trails; logical multi-tenant isolation as described above; organization level AI insights gated behind the aggregation threshold described above. AI on Vibly is an optional add-on at a flat 20 dollars per month, not metered, so the cost of doing this properly never becomes a reason to cut corners.
If you run a coaching organization and want the details in a form your clients can read, the one pager is yours to use, with or without a Vibly conversation attached.
Download the one-pager: How AI and Client Data Are Handled on Vibly (PDF)
See how Vibly works for coaching organizations
Frequently asked questions
Is AI note-taking confidential enough for executive coaching?
It can be, if four conditions hold: the client explicitly consents before each session is transcribed, the vendor has signed BAAs with its AI providers where health data is involved, the contract states that no data trains AI models, and the organization can switch the feature off per client. Without any one of these, decline the feature.
Do coaching clients have to agree before AI joins a session?
Yes. The accepted standard is an explicit consent prompt shown to the client before recording or transcription begins, with a real decline option. Consent buried in onboarding paperwork does not meet the bar for executive coaching.
Can AI tools use coaching session data to train their models?
Only if the contracts allow it. Reputable platforms sign agreements with their AI providers that prohibit training on customer data, and put the same commitment in their own customer contracts. Ask to see the clause; a vendor that has it will show it.
What is a BAA and when does it apply to coaching?
A Business Associate Agreement is a HIPAA contract that binds a vendor to healthcare grade data handling. It applies when coaching touches health information, such as health, wellness, or behavioral coaching. For executive and leadership coaching with no health data, the relevant assurances are security audits instead: ask the vendor for a SOC 2 report or ISO 27001 certification.
Should sponsors see AI-generated reports about their leaders?
Sponsors should see program level reporting, never session content. AI generated organizational insights are appropriate only above an aggregation threshold where no individual can be identified, and the sponsor should know in advance that AI is involved and under what terms.
