What Do AI Therapy Apps Actually Retain?

AI therapy data retention policies determine how long a company keeps your conversations, questionnaire answers, voice recordings, account details, and generated psychological profiles. The honest answer is that there is no single universal policy: retention depends on the provider, the product tier, whether you use a consumer chatbot or a clinician-supervised system, and the country where the service is based. A conversation may be stored to provide the service, prevent abuse, improve models, comply with a business record, or support clinical documentation. Some of those purposes conflict, particularly when a user requests deletion but the company claims a legal or safety-related reason to retain the information.

Also worth reading: What are AI data retention policies and how do they impact psychological profiles in 2026? · What are the current AI therapy data privacy regulations and how do they affect mental health chatbot users in 2026? · How Can AI Therapy Bias Be Mitigated Without Ignoring Clinical Risk?

As of September 25, 2026, the most reliable way to evaluate a product is to read its current privacy policy, terms of service, data deletion page, and any separate notice for health or training data. Marketing language such as “private,” “secure,” or “anonymous” does not by itself answer the retention question. Ask for four concrete facts: what categories of data are collected, whether human review is possible, how long retention lasts, and whether deletion removes backups and derived data. If the vendor will not provide those answers, treat the uncertainty as a material privacy risk rather than assuming that the default is short-term storage.

A useful mental model is that retention has several layers. The live account is one layer; operational logs and support records may be another; backups, fraud-prevention records, and legally required records can persist longer. Deleting your account may remove the obvious profile while leaving limited records in systems that cannot immediately be erased. A profile generated from your responses can also be treated as derived information rather than as a raw chat, so users should ask whether that output is deleted too.

Why Therapy Conversations May Be Kept Longer Than Expected

Providers often defend retention as necessary for continuity. If an AI assistant forgets your history between sessions, repeated disclosures become necessary and the experience may be less useful. Keeping records can help a service maintain preferences, track changes in symptoms, identify patterns over time, and support a clinician if the tool is used as part of care. That reasoning may justify retaining a limited, structured history while providing controls over how it is used, but it does not automatically justify indefinite storage or unrestricted model training.

A second reason is safety and abuse prevention. Mental health platforms may retain records to investigate threats, harassment, self-harm alerts, or attempts to circumvent age and safety rules. A company may need to preserve information after an account is closed when it has a credible legal obligation or an active safety investigation. The key question is whether retention is proportionate and disclosed. A blanket policy that stores everything “for safety” without time limits or access controls is difficult to evaluate and can expose highly sensitive information to people who have no clinical role.

The third reason is product improvement. Some services de-identify conversations, aggregate them, or use them to tune ranking and response systems. Other providers reserve the right to review conversations for quality assurance or may use data for future model development. De-identification is useful but not equivalent to erasure, and removing names does not always prevent a person or an organization from reconnecting records through timestamps, device identifiers, or distinctive narratives. Users who would not want their therapy language republished should decline training-related uses where that choice is available.

Retention may also be connected to billing, tax, fraud prevention, or legal claims. These are business-record purposes, not necessarily clinical purposes. A user cannot reasonably expect every invoice or transaction record to disappear on the same day as an account closure, but the company should separate required records from the much more sensitive content of a therapy conversation. The more health-related the data, the stronger the expectation that access is restricted and deletion is prompt.

How AI Therapy Retention Differs From HIPAA Retention

HIPAA is a U.S. health-care privacy framework, not a general federal privacy law for every consumer wellness app. Its application depends on whether a provider is a covered entity or business associate performing covered functions, not simply on whether the service calls itself therapy. Many direct-to-consumer AI companions, journaling apps, and general chatbots fall outside HIPAA in ordinary circumstances, while products used by hospitals, clinicians, or insurers may be covered or contractually required to follow HIPAA protections. A user should therefore ask whether the product is covered by HIPAA rather than assuming the answer from the product category.

When HIPAA does apply, a provider must follow its legal obligations, including appropriate safeguards, access and amendment processes, breach-response duties, and record-retention requirements. The HIPAA Security Rule does not create one universal deletion period for every piece of clinical data. State medical-record laws, professional requirements, litigation holds, and the organization’s own policies can affect how long records remain available. In other words, “HIPAA-compliant” is not a promise that a user can erase all records immediately.

HIPAA also has a general standard that an accounting of disclosures be retained for six years, but that is not a six-year retention rule for all therapy conversations. Do not confuse a documentation requirement with a general instruction to keep every chat forever. A provider should be able to explain which specific rule supports continued retention. For non-U.S. users, the GDPR in the European Economic Area and comparable national rules may be more directly relevant, including rights to access, correction, deletion, restriction, and objection to certain processing.

QuestionConsumer wellness or general AI appClinician-supervised health system appWhat a user should verify
HIPAA coverageOften absent, depending on the service and relationshipOften present when the system supports covered health-care operationsWhether the provider is a covered entity or business associate
Main purposeConversation, coaching, entertainment, or self-reflectionSupport for assessment, care, documentation, or treatment workflowsThe actual functions performed with the data
Deletion requestMay be voluntary but governed by the vendor’s policyMay require amendment, restriction, or records-retention proceduresWhether deletion affects the legal health record
Human accessMay include support, safety, or quality reviewUsually limited to authorized workforce members under safeguardsRoles, permissions, and access logging
Model trainingMay be allowed, opt-in, or prohibited depending on settingsOften governed by institutional policy and contractWhether inputs can be used to improve models
Typical costFree to roughly $20–$30 per month for many consumer tiersInstitutional pricing, with the patient’s cost varying by coverage and clinicTotal price, insurance coverage, and add-on fees
## What to Look for in a Data Retention Policy

Start with definitions. A credible policy should distinguish account information, conversation content, health information, technical logs, billing data, and “content” generated by the AI. It should also identify third parties, such as cloud hosts, analytics providers, payment processors, safety contractors, or model vendors. A list of “service providers” is not enough if it does not clarify which parties receive identifiable health data or whether those parties may retain copies for their own purposes.

Next, find the time periods. Policies sometimes state that information is kept while an account is active, then deleted within 30 or 90 days, while backups roll off over a longer cycle. Those numbers are not universal, so they should not be presented as industry standards. A policy that says “we may retain information as long as necessary” without examples of the relevant purposes leaves a user unable to estimate exposure. Better policies distinguish ordinary deletion from exceptions involving security, fraud, legal disputes, or an account request.

The policy should also state whether user data is used for model training. An opt-out is not equivalent to “never used,” and an opt-in may be revoked only for future use rather than deleting data already incorporated into a trained model. Users should ask whether human reviewers can see conversations, whether reviews are used for safety or quality, and whether identifying details are removed before analysis. A service that offers no training controls may still be reasonable for casual experimentation, but it is a different risk choice from a person discussing abuse, medication, or a diagnosed condition.

Practical Steps Before You Begin Therapy-Like Use

The safest practice is to minimize data before uploading or typing anything. Do not include a full name, address, date of birth, medical-record number, insurance details, or identifying information about other people. A fictional nickname and approximate life context can preserve conversational usefulness without turning a private journal into a searchable identity profile. Avoid uploading clinical documents unless the service has a clear authorization process and a stated deletion policy for the uploaded files.

Before paying, search the provider’s site for “privacy,” “retention,” “delete account,” “training,” and “business associate agreement” if the service is used through a health provider. Screenshot or save the version of the policy you relied on, because policies can change. If you are using a clinician-supervised tool, ask the organization which data becomes part of the medical record and which remains only with the vendor. Also ask how an AI-generated psychological profile is treated: as part of the record, a temporary communication, or a derivative artifact that can be removed.

Use a separate email address and a dedicated payment method when the stakes are high. Strong, unique account credentials and multifactor authentication reduce the risk that another person can access the history. Review connected apps, browser extensions, export tools, and shared devices, and revoke access you no longer need. If the service offers conversation export, use it only when you can store the export securely; exporting a transcript creates another copy outside the provider’s deletion system.

Common Mistakes in Assessing These Policies

One common mistake is treating deletion as a binary switch. It is usually a process involving primary databases, caches, backups, vendor systems, and records that must be retained. Ask whether deletion is complete, limited, or completed on a backup cycle, and obtain written confirmation when the distinction matters. Another mistake is relying on an old review or a single article from 2024 or 2025. Policies and product architecture change, and a service may have changed its training practice, corporate owner, or storage provider since the review was published.

Users also make the mistake of assuming a short subscription equals short data retention. Paying for one month does not, by itself, guarantee that the company deletes everything after 30 days. Conversely, a service may keep a small transaction record for years without keeping the full therapy history. The important issue is the category of data and the purpose of retention, not just the number printed in the price page.

A final mistake is asking whether a service is “safe” in the abstract. AI therapy involves privacy, model accuracy, crisis response, dependency, and unequal access to human care. A provider may have a reasonable retention policy while still producing poor clinical advice or failing to respond appropriately to a crisis. Retention is one part of safety; it should not be used as a proxy for clinical quality.

When to Act and What It May Cost

Act before entering highly sensitive information if the policy is unclear. Immediate warning signs include missing deletion instructions, no description of model training, unrestricted human access, no breach-notification process, or a provider that discourages users from asking questions. You can also act by deleting an old account, exporting a record, revoking connected applications, and requesting written confirmation of the deletion date. If you believe the service mishandled health information, document the dates, account, communications, and impact before closing the account, and consider reporting the issue to the provider or relevant privacy authority.

Consumer subscriptions often range from free to approximately $20–$30 per month, with some higher tiers adding voice, long-term memory, or advanced features. Institutional tools may be priced through employers, hospitals, or insurers, so the user’s direct cost can be $0, a copay, or a substantial annual arrangement. The fee is not the only cost: time spent reviewing settings, maintaining separate accounts, and managing exports also matters, while emergency or clinical care should never be delayed because an AI service is cheaper.

For psychprofile.io readers, the practical conclusion is to evaluate the vendor rather than the label “AI therapy.” Prefer a product that explains retention, deletion, training, human access, and crisis limitations in language a non-lawyer can understand. Those features are more informative than a claim that a service is “anonymous” or uses “military-grade security.” As of September 25, 2026, no product should be treated as risk-free simply because it offers a polished psychological profile or a reassuring conversational experience.