← Back to blog

What Actually Happens to Your Data With Cloud AI Notetakers

privacy meeting notes compliance

“Enterprise-grade security” is on the homepage of every AI notetaker. It’s not a lie, exactly — most of these companies really do encrypt data in transit and at rest, and many hold a SOC 2 report. But it answers a question nobody asked. Encryption protects your meeting from strangers. It says nothing about what the vendor itself does with the recording, which subprocessors it hands the audio to, how long the transcript lives, or who can subpoena it later.

Those are the questions worth asking, and the answers are almost always in the privacy policy rather than the marketing page. Here’s what’s actually on the other end of that “Notetaker has joined the meeting” message.

The audio makes more stops than you’d guess

The mental model most people have is a straight line: your call goes to the notetaker’s servers, comes back as a transcript. The real path usually has more hops, because almost none of these companies build their own speech recognition or their own language model.

Granola is a useful example precisely because it’s one of the more privacy-conscious products in the category, and it’s explicit about the architecture. It doesn’t join your call as a bot; it captures audio locally on your Mac. But that audio is then streamed to third-party transcription providers — Deepgram and AssemblyAI — and summaries are generated by OpenAI or Anthropic, with transcripts stored in an AWS environment in the US. Granola’s own privacy policy states plainly that recordings aren’t retained once transcription is done, and that third parties aren’t allowed to train on your data. Both of those are meaningfully better than the norm.

But note what “bot-free” turned out to mean: not on-device. The audio still left the machine, passed through several companies you never chose, and the text of everything said in the meeting is sitting in a cloud account. If your objection to a notetaker bot was the awkwardness in the participant list, that’s solved. If your objection was that a recording of your client conversation shouldn’t travel, it isn’t.

The rest of the category follows the same pattern with less transparency. Bot-based tools like Otter and Fireflies transmit the meeting audio to their own servers for transcription and storage, then fan pieces of it out to model providers. When you’re evaluating one of these, the subprocessor list is the document that actually tells you where your meetings go — not the security page.

”We don’t train on your data” has a lot of asterisks

This is where the language gets slipperiest, because there are at least three separate claims that all get compressed into one sentence.

Third-party training — whether OpenAI, Anthropic, or another model provider can train on your transcripts. This is the easiest to promise, because the enterprise API tiers of those providers contractually don’t train on submitted data anyway. When a vendor says “your data is never used to train AI models,” this is often the only thing they mean.

First-party training — whether the vendor trains its own models on your meetings. This is where the real exposure is, and it’s frequently opt-out rather than opt-in. Otter’s privacy documentation describes training on de-identified user data automatically, with a setting buried in account data controls that you have to find and flip yourself. Most users never do, because most users never read that far.

De-identification — the mechanism that’s supposed to make first-party training safe. This is the claim that has drawn the sharpest scrutiny, because de-identifying voice is a genuinely unsolved problem. A voice is biometric. Stripping the account name off an audio file doesn’t stop the speaker from being identifiable, and it certainly doesn’t remove the customer names, deal numbers, salary figures, and patient details spoken inside the recording. The pending litigation against Otter argues exactly this: that the company doesn’t publicly explain how its de-identification works, and that the process neither removes confidential content nor guarantees speaker anonymity. Whether that argument prevails in court is unresolved — but “de-identified” doing this much work in a privacy policy should not be reassuring.

The retention answer is usually “until you delete it”

Ask how long a transcript is kept and you’ll rarely get a number. The de facto answer across most consumer-tier notetakers is: indefinitely, unless you go delete it by hand. Fireflies, for instance, retains recordings and transcripts until manually removed, even while advertising a zero-day retention option that governs training rather than storage. Granola offers scheduled org-wide auto-deletion, but as an Enterprise admin control — not a default.

The default matters more than the option. Two years of accumulated transcripts is a searchable archive of every candid thing said in your meetings, held by a third party, governed by a policy that can be revised with an email notification. Zoom discovered in 2023 how quickly a terms-of-service revision about AI training becomes a public incident; the underlying dynamic — that the terms are theirs to change — hasn’t gone anywhere.

For the last two years the pushback on AI notetakers looked like individual squeamishness. In 2026 it’s institutional, and for three concrete reasons.

Wiretap exposure. Around a dozen US states — California, Florida, Pennsylvania, Washington and others — require consent from every party to record a conversation. A consolidated federal class action against Otter.ai, filed in the Northern District of California in December 2025 after four suits were combined, alleges that the service recorded private conversations without all-party consent and trained its models on them, under the federal Electronic Communications Privacy Act, the CFAA, and California’s all-party consent statute. The core allegation is structural: that the bot obtains permission from the meeting host and nobody else, and other participants can’t turn it off. Otter has denied that any interception occurred; its motion to dismiss was argued in May 2026 and, as of this writing in July 2026, no ruling has issued. It’s the first federal test of whether wiretap statutes written for phone lines reach an AI bot in a video call, and law firm after law firm has published client guidance about it.

Discoverability. A transcript is a permanent, searchable, timestamped business record. That means it’s discoverable in litigation — strategy discussions, offhand remarks, the sentence someone said before they thought better of it. Material prepared for a legal matter can be protected work product; routine call transcripts generally are not. Once transcripts exist and litigation becomes foreseeable, they’re also subject to litigation hold, and destroying them at that point creates its own problem.

Privilege. For anyone whose meetings are privileged, this is the sharpest edge. Privilege depends on confidentiality being maintained. Letting a vendor access, store, and process a privileged conversation — under terms that don’t recognize attorney-client or work-product protection — is at minimum an argument the other side gets to make about waiver. It’s why bar associations have begun publishing ethics guidance on notetakers specifically.

None of this makes cloud notetakers illegitimate. It does explain why “our IT department blocked it” has become such a common answer, and why the professionals with the most meetings — consultants, lawyers, clinicians, financial advisors — are frequently the ones who can’t use the tools built for meeting-heavy work.

The clauses to actually read

If you’re evaluating a notetaker, five specific questions get you past the marketing:

  1. Does the audio leave my machine, and to whom? Find the subprocessor list, not the security page. “Bot-free” and “local capture” do not mean on-device.
  2. Is training opt-in or opt-out, and does that cover the vendor’s own models? Check the account settings, not just the policy language.
  3. What’s the default retention? Not the retention option — the default that applies if you never configure anything.
  4. Who owns the transcript, and what happens to it when I cancel? Export path, deletion path, timeline.
  5. What changes if I stop paying? A tool that holds your notes hostage behind a lapsed subscription has a different risk profile than a file on your disk.

Any vendor worth using can answer all five in writing.

The architectural alternative

There’s a category of tool where these questions mostly stop applying, because the audio never goes anywhere. Speech recognition good enough for meeting transcription now runs perfectly well on a modern Mac — Whisper on Apple Silicon handles it locally, no server involved.

That’s how Life Manager Pro is built. It captures your Zoom, Teams, Webex, or Slack calls without a bot, and transcription runs on your Mac with local Whisper. The audio never leaves the machine, there’s no account holding your recordings, and no subprocessor list to audit, because there are no subprocessors in that path. It also works with no network connection at all.

Where we’ll be precise, because this is a post about vendors being imprecise: the optional AI analysis step — the one that produces a summary, decisions, and action items — can call Anthropic’s or OpenAI’s API, using your own API key, and it sends the transcript text only, never the audio. That’s a direct relationship between you and a provider you chose, under your own account terms, not data pooled into ours. You can also leave it switched off entirely and keep a purely local recording and transcript, which is what people in regulated fields generally do.

And to be equally clear about what we don’t claim: Life Manager Pro is not a HIPAA-certified product, and no software can be. Local-only processing removes the third-party disclosure problem that makes cloud notetakers hard to clear — it doesn’t substitute for your own compliance review, and your recording-consent obligations are the same regardless of which tool you use.

Meeting notes that don't require a data-processing agreement

Life Manager Pro records your meetings without a bot and transcribes them on-device with local Whisper — then turns the action items into real tasks alongside your projects, CRM, and goals. Native Mac app, $49 once, no subscription. 14-day free trial, no credit card.

Try Life Manager Pro free

The trade you’re actually making

Cloud notetakers buy you real things: work on any device, transcription that keeps up in real time, shared team workspaces, and integrations with everything. If your meetings are internal and low-sensitivity and you want a searchable team archive, that’s a reasonable trade and you should take it.

The trade stops being reasonable when the content of your meetings is the thing you were trying to protect. At that point the question isn’t which vendor has the best privacy policy — it’s whether a policy is what you want standing between your client conversations and the internet, given that policies are revised, companies are acquired, and breaches are a category of event rather than a hypothetical. Architecture doesn’t get revised by email notification.

Sources: Otter.ai privacy & security · Granola privacy policy · Fireflies security · Fisher Phillips on the Otter class action · Mayer Brown on notetaker legal risk · White & Case on governance risk · Kilpatrick on training-data risk

Try it for 14 days. Then decide.

Full features, no credit card, no nag screens. If it fits the way you live and work, $49 keeps it forever — through January 31, 2027.