Answer capsule
Valence says it tailors data-retention policies to each client's security preference while coaching conversations remain confidential and organizations receive aggregated, anonymized reporting. Configurability is not itself a retention control. A system buyer needs an artifact-by-artifact schedule and test proving that expiration and deletion reach conversations, attributes, summaries, reports, logs, exports, backups, and subprocessors without breaking an authorized hold.
What the source establishes
- Valence says individual coaching interactions remain confidential, managers cannot see individual conversations, and aggregated, anonymized reporting is provided.
- The company says it does not use user data to train underlying AI models and has zero-data-retention policies with subprocessors.
- Valence says it tailors retention policies to client security preferences and offers US or EU data storage depending on client requirements.
- The page also describes SSO, SCIM, role-based access control, encryption, third-party assessments, annual audits, and security certifications. It is an undated current page, not verified post-cutoff news.
Inventory every retained coaching artifact
Map the system from enrollment through offboarding and list participant identity, eligibility and role data, goals, preferences, assessments, conversation text or audio, prompts, responses, safety events, inferred attributes, summaries, nudges, action plans, progress measures, sponsor reports, aggregated datasets, support cases, audit logs, exports, integration payloads, caches, backups, and subprocessor copies. For each artifact, name controller and processor roles, purpose, system of record, region, access groups, creation event, default and configured retention, deletion method, legal or contractual basis, hold behavior, and evidence available to the customer and participant. A statement about confidential conversations does not answer how derived or operational records are retained.
Translate configurable preference into a binding schedule
Put the chosen retention periods and triggers in the order form, data-processing terms, configuration record, and runbook rather than relying on a sales description. Distinguish deletion after a session, inactivity, program end, employment change, license removal, account closure, participant request, contract termination, and backup rotation. State which customer administrator may configure each value, how changes affect existing data, what minimums or exceptions apply, and whether aggregated or anonymized outputs can remain. Require the provider to identify subprocessors and any zero-retention setting, scope, region, and exception. If a retention choice cannot be configured or verified for one artifact, preserve that gap and decide whether reduced data collection or a different deployment is required.
Run deletion and hold tests before scaling
Create a synthetic participant with distinctive test values across a conversation, goal, inferred attribute, safety event, sponsor aggregate, support ticket, export, and integration. Trigger normal expiration and an individual deletion request, then search participant views, administrator tools, APIs, reports, logs, exports, downstream HR systems, caches, backups, and subprocessor evidence according to the agreed timetable. Repeat with an authorized legal or investigation hold and confirm that held data is isolated, access-limited, released by a named owner, and deleted afterward. Record request, scope, identity verification, approvals, start and completion times, exceptions, evidence, and retest. A success message or removal from the user interface is not proof that all retained copies were handled.
Approve the platform on demonstrated lifecycle control
The buyer should require coaching-program, HR, privacy, security, legal, records, employee-relations, accessibility, procurement, and technical owners to review the schedule and tests. Participant notices should explain actual configured retention, reporting boundary, requests, and exceptions in plain language. Monitor configuration drift, new artifact types, changed subprocessors, region moves, reporting changes, incidents, and deletion failures; each should reopen the decision. Valence's trust page is useful provider evidence about its stated safeguards, certifications, confidentiality, training, retention flexibility, residency, and access controls. It does not establish the scope or operation of those controls in a buyer's contract, tenant, integrations, report, backup, subprocessor chain, or participant experience.
Turn this source into a reviewable decision
For AI Coaching Platforms for Leadership Development, use this briefing as a dated decision record rather than a substitute for the source. Preserve Trust and Security, the exact URL, the September 10, 2026 review date, the supported facts above, the editorial interpretation, the limitations, and any buyer-specific evidence. Link that record to the decisions most directly affected: Data flow and confidentiality; Workflow and identity integration; Safety, boundaries, and escalation; Accessibility, language, culture, and user control. State whether the source changes the scope, evidence requirement, control, sequence, or only the language used to describe the decision.
Before action, name the accountable owner, affected population and workflow, exact offering or configuration, source data and rights, human decision point, exception and appeal path, complete cost, expected benefit, failure and stop conditions, retained evidence, and next review date. Keep official facts, provider statements, buyer observations, representative tests, measured outcomes, editorial inferences, and unknowns visibly separate. Reopen the record when the source, offer, model, integration, data, policy, population, responsible person, or measured result changes.
Limitations and unknowns
The primary source is Valence's current undated trust-and-security page and contains provider claims. It is not treated as a verified post-cutoff development. Certification names, stated practices, flexible retention, confidentiality, no-training, zero-retention, residency, encryption, and access features do not establish contract scope, configured operation, deletion completion, anonymization quality, report privacy, subprocessor behavior, backup treatment, legal compliance, coaching quality, safety, or outcomes for a buyer. Current contracts and data-processing terms, trust-center and audit materials, subprocessor list, data-flow and artifact inventory, tenant configuration, notices, access records, synthetic lifecycle tests, and qualified coaching, HR, privacy, security, records, legal, employee-relations, accessibility, procurement, and technical review control.
Decision test
Ask whether the source changes the decision itself, the evidence required, the implementation sequence, or only the language used to describe an existing capability. Record which claims are directly supported, which are provider statements, which require an independent test, and which remain unknown. A source-linked review should make uncertainty easier to see, not bury it inside a blended score.
Questions to take into review
- What does the system ingest, infer, retain, share, and expose to coaches or administrators?
- Where does coaching appear and what data or actions flow through HRIS, collaboration, calendar, email, and identity systems?
- How does the system respond when coaching is unsuitable or a person discloses harm, crisis, discrimination, legal, medical, or employment issues?
- Can the intended population understand, use, contest, pause, correct, export, and leave the experience?
The publication supports research and executive decision preparation. It does not provide legal, financial, accounting, employment, clinical, cybersecurity, investment, procurement, or implementation advice.