Your law firm does not need to keep every intake recording forever.
Recording and transcribing an intake call can improve review, training, and accountability. It can also create a permanent collection of names, medical details, family disputes, alleged crimes, financial information, and conversations with people the firm never represented. Storage is cheap. Exposure is not. A serious intake program decides what to keep, why to keep it, where it lives, and when it should disappear.
Storage is not governance
Most intake technology makes preservation effortless. The recording remains in the voice platform. The transcript moves into an intake system. A summary enters the CRM. An email copy lands in an inbox. Staff may download the file for review. Within minutes, one conversation can exist in five places without anyone making an affirmative retention decision.
That convenience encourages a weak rule: keep everything because it may be useful someday. The rule sounds cautious. It is often the opposite. Indefinite retention increases the volume of sensitive information the firm must secure, locate, govern, and eventually produce or explain. It can also make a vendor's storage default more consequential than the firm's actual judgment.
The Federal Trade Commission's business guidance recommends keeping sensitive information only while there is a business reason to have it and using a written retention policy when information must be preserved. That guidance is not a law-firm retention schedule. Its operating principle is sound: possession should have a purpose.
One call creates several different records
Firms often discuss ‘the call’ as though it were one object. It is not. The raw audio captures tone, hesitation, background voices, and every unnecessary fact the caller volunteered. The transcript converts speech into searchable text but may contain transcription errors. The structured summary extracts selected facts. The CRM record adds status, ownership, and follow-up. A client-file note may preserve only what counsel needs after engagement.
Those records do not have equal value or equal risk. A summary may support conflicts review after the audio has served its quality-control purpose. A recording may help investigate a complaint that the transcript cannot resolve. A downloaded training copy may have no legitimate use once review is complete.
Treating all artifacts alike produces either excessive deletion or excessive storage. A defensible policy names each record type and assigns a purpose, location, owner, access rule, and disposition method to it.
- Call audio
- Machine or human transcript
- Structured intake summary
- CRM or practice-management entry
- Email, text, and calendar confirmations
- Quality-review annotations and exported copies
Start with purpose, not a number of days
A universal retention period is attractive because it avoids judgment. It is also difficult to defend across different practices, jurisdictions, caller outcomes, contractual obligations, litigation holds, and professional rules. A criminal defense firm, a trusts practice, and a mass-tort operation may have materially different needs.
Begin with the reason the record exists. Audio may be needed briefly to confirm intake quality, investigate exceptions, or correct summaries. A transcript may support attorney review. Conflict information may need to remain searchable after the firm declines a matter. An accepted matter may require relevant information to move into the client file under a different records policy.
Then ask the harder question: when does that purpose end? If nobody reviews recordings after a defined quality window, indefinite audio storage is not an audit program. It is accumulation. If the firm needs only parties, matter type, decision, and notice history for a declined inquiry, retaining the caller's complete narrative may be unnecessary.
Do not ask how long the platform can store a call. Ask how long the firm can explain why it still has the call.
Accepted and declined matters should diverge
Once the firm accepts an engagement, selected intake information may become part of the client file. That does not mean every pre-engagement artifact belongs there. The responsible lawyer should decide what is relevant, correct material errors, and avoid treating an automated transcript as an authoritative statement of fact.
Declined matters require a different analysis. The firm may need enough information to document the inquiry, check conflicts, show who reviewed the matter, preserve the non-engagement communication, or satisfy applicable obligations. The complete recording may not be necessary for each of those purposes.
The correct result depends on governing law, ethics rules, insurer requirements, contracts, actual or reasonably anticipated disputes, and the firm's approved policy. Automated deletion must pause when a legal hold or another preservation duty applies. This article is general operational guidance, not a jurisdiction-specific retention opinion.
Permission to record and permission to retain are different questions
Call-recording laws and disclosure requirements vary by jurisdiction and circumstance. Firms must determine which rules apply to the caller, the participants, and the technology being used. A script that works in one state may be inadequate in another.
Even a lawfully recorded call does not answer every downstream question. The firm still must decide who may access the recording, whether it may be used for training, whether a vendor may use it to improve models, whether it can be exported, how long each copy remains, and how deletion requests or legal holds are handled.
ABA Formal Opinion 512 addresses lawyers' duties when using generative AI, including competence, confidentiality, communication, and supervision. It does not establish a specific retention period for intake recordings. The narrower lesson is that a lawyer must understand how a system handles information rather than assuming that vendor possession resolves professional responsibility.
Vendor deletion is part of the architecture
A policy that says ‘delete after review’ is meaningless if the firm cannot identify every copy. Ask the voice provider whether deletion removes audio, transcripts, summaries, logs, exports, and backups, or merely hides an item from the dashboard. Ask whether subprocessors receive the data, whether customer content is used for training, and how long backups persist before aging out.
The same questions apply to integrations. Deleting a recording from the intake platform may not remove the transcript copied into a CRM, the email sent to a lawyer, or the file downloaded by a manager. Retention is a system map, not a setting on one screen.
Contract language matters, but it must match technical behavior. The firm should know who can initiate deletion, whether deletion is logged, what exceptions exist, and what happens when the relationship with the vendor ends. If the answer is ‘we keep it indefinitely unless you ask,’ the firm has been assigned a governance job whether it recognizes it or not.
A workable retention matrix
The policy can be concise. For each artifact and intake outcome, record the approved purpose, system of record, access group, retention trigger, deletion event, exception owner, and evidence of deletion. Avoid placing an arbitrary duration into the matrix until counsel has evaluated the firm's jurisdiction, practice, contracts, insurer guidance, and preservation obligations.
NIST's voluntary Privacy Framework treats data lifecycle management, deletion, destruction according to policy, access control, and data minimization as connected practices. It does not prescribe a law-firm timetable. It does provide a useful management model: the organization should be able to identify data, control it with sufficient granularity, explain how it is processed, and protect it throughout disposition.
- What record is this?
- Why does the firm need it?
- Which system is authoritative?
- Who can access, export, or alter it?
- What event starts the retention clock?
- What suspends routine deletion?
- How is deletion executed and verified?
Test deletion before trusting the policy
A written schedule does not prove that information disappears. Select a test call, trace every artifact it created, apply the ordinary deletion workflow, and verify the result across the voice platform, intake system, CRM, email, exported files, and available audit records. Confirm what remains in backups and for how long.
Repeat the test after material platform or integration changes. Review access logs and export permissions. Sample old records to see whether the system contains data beyond the approved period. Treat unexpected copies as a process defect, not harmless clutter.
The objective is not maximum deletion. It is deliberate retention. Keep what the firm can justify, protect it according to its sensitivity, preserve it when required, and dispose of it when its approved purpose ends.
The default should belong to the firm
AI intake produces useful evidence and unusually sensitive data at the same time. That tension cannot be resolved by choosing ‘save forever’ or ‘delete everything.’ It requires a record-by-record policy connected to real operating needs and professional obligations.
The firm should decide the default before the vendor does. Inventory the artifacts. Separate accepted from declined matters. Define the purpose of each copy. Map every system. Build holds and exceptions. Verify deletion. Cheap storage is not a reason to inherit permanent responsibility for information the firm no longer needs.
Sources and further reading
Primary and industry sources used to support this page. External guidance should be reviewed in context and for your jurisdiction.
- Federal Trade Commission, Protecting Personal InformationFTC business guidance on minimizing sensitive information, written retention policies, secure storage, and disposal when the business need ends.
- NIST Privacy Framework 1.0A voluntary framework addressing data lifecycle management, minimization, deletion, destruction according to policy, access, and data security.
- ABA Formal Opinion 512ABA guidance on competence, confidentiality, communication, and supervision when lawyers use generative AI tools.