A colleague has set up an AI notetaker for your team’s weekly call. The bot joins the meeting, announces itself, and starts transcribing. By the end of the call, you have a summary with action items in your inbox.
You also have no clear idea which third-party company just received a verbatim transcript of your meeting — including the candid comment you made about a project decision, the personal context a colleague shared to explain their availability next week, and the client information discussed under the assumption it was staying in the room.
AI meeting notetakers have become a standard tool in many workplaces. Bloomberg reported in June of this year that they’ve grown prevalent enough to create significant friction around workplace etiquette and privacy norms. The privacy questions they raise are specific and deserve direct answers.
What AI Meeting Notetakers Actually Do
An AI meeting notetaker is a third-party service that joins a video conference — Zoom, Google Meet, Microsoft Teams, Webex — and records, transcribes, and summarises the call. Well-known services include Otter.ai, Fireflies.ai, Grain, tl;dv, and Fathom. Platform-native versions also exist: Zoom’s AI Companion, Microsoft Teams Copilot, and Google Meet’s AI Notes.
The typical process: the user authorises the notetaker to access their calendar, the service’s bot joins at the scheduled time, audio is processed in real time to generate a transcript, and a summary is available to the user — and often all participants — after the call.
The convenience is real. The privacy implications depend on which service you’re using and whether you’ve read the terms.
Where Your Call Data Goes
Third-Party Notetakers
Third-party AI notetakers — tools separate from your video conferencing platform — have widely varying data practices.
Otter.ai retains user content indefinitely and explicitly reserves the right to use de-identified transcripts to “improve and develop our products and services.” This is AI training language. When you use Otter.ai, the transcripts generated from your calls are retained and can become training data under those terms.
Fireflies.ai stores call transcripts and audio. The service offers a searchable archive of past meetings — which requires indefinite retention by design. Their privacy policy reserves the right to use data to improve the service.
Grain and tl;dv operate similarly: recordings and transcripts are stored on the platform’s servers, accessible to the account holder and anyone they share the notes with, under terms that reserve rights to data use for product improvement.
The question worth asking about any free-tier notetaker is what the business model is. Call transcripts are genuinely valuable data. They contain detailed records of how organisations operate, what decisions are being made, and who said what about what. When a service is free, the data it generates is typically part of how the business sustains itself.
Google Meet AI Notes
In February of this year, a data handling controversy emerged around Google Meet’s AI Notes feature. Reports surfaced that meeting transcripts were being used to train Google’s AI systems — including conversations from calls users understood to be private business meetings.
Google subsequently updated its documentation to clarify data use terms, but the incident reflects a recurring pattern: AI features are added to productivity platforms without clear upfront disclosure of how the data those features generate will be used.
The meeting is no longer just a meeting. It’s a potential training example.
Platform-Native Tools: Zoom and Teams
Zoom has stated explicitly that it does not use customer audio, video, chat, screen sharing, or attachments to train Zoom’s AI models or third-party AI models. This is a meaningful commitment and distinguishes Zoom’s approach from many third-party notetakers.
Microsoft Teams Copilot operates under Microsoft’s AI terms, which for enterprise customers include data handling commitments that are generally cleaner than free-tier third-party tools.
The distinction matters practically: the same call, transcribed by a platform-native tool under enterprise terms versus by a free third-party notetaker, produces transcripts governed by very different privacy commitments.
The Consent Problem
AI meeting notetakers create a consent problem that workplace norms haven’t fully addressed.
When a notetaker bot joins a meeting without explicit notice to all attendees, participants may not know their words are being transcribed by a third-party service — or which service, or what its data practices are.
This is particularly significant for external participants: clients, candidates, contractors, partners. They join a meeting without having agreed to the notetaker service’s terms. Their words are captured and stored by a company they’ve never heard of and never consented to interact with.
Some services announce themselves at the start of a call. Others don’t. Even when announced, participants are rarely told which service is being used, what it does with the data, or that they have any option to opt out before the recording starts.
What Ends Up in the Transcript
This matters because meeting transcripts contain information that wasn’t meant for permanent record.
Business meetings regularly include:
- Candid assessments of colleagues, clients, or strategic decisions that would never be put in a written email
- Personal context shared to explain availability or performance (“I’ve been dealing with a health issue”)
- Early-stage strategy discussions before ideas are ready for formal documentation
- Client information shared in confidence
- Financial details, personnel matters, or legal discussions
When these end up in a third-party notetaker’s archive, they’re subject to that service’s security practices, data handling terms, retention policies, and potential future uses — including AI training.
They’re also a security target. A database of business meeting transcripts is an extraordinarily detailed intelligence file about how an organisation operates. A breach of that database would be more damaging than most other types of business data loss.
Indefinite Retention and Its Consequences
Most AI notetaker services retain transcripts for as long as the account exists. This is a product feature — the value proposition includes searching past meetings. But it also means sensitive data is accumulating indefinitely in a third party’s system.
What happens when the company is acquired? When its terms change? When it faces financial difficulty and the data becomes a valuable asset? When it receives a legal demand or government request?
These are not hypothetical risks. Any company that holds years of business meeting transcripts holds an extraordinary amount of sensitive information about the organisations and individuals in those calls. The handling of that data across the company’s lifecycle is outside the control of the individuals whose words are in the archive.
Practical Guidance
Know What Notetaker Is In Your Meeting
If you’re hosting a meeting, check your connected integrations and calendar apps to see whether a notetaker bot will be joining. If you’re attending a meeting hosted by someone else, it’s reasonable to ask whether an AI notetaker is being used.
Read the Privacy Policy Before Using a Third-Party Notetaker
The key questions: Does the service use transcripts to train AI? How long is data retained? What happens on account deletion — is data actually deleted or just removed from your view? What are the data sharing practices with third parties?
Prefer Platform-Native Tools Under Enterprise Terms
If your organisation has enterprise agreements with Zoom, Microsoft, or Google, the platform-native AI tools are generally governed by stronger data commitments than free-tier third-party tools. The number of parties handling your call data is smaller.
Be Explicit With External Participants
If you’re recording or using a notetaker in a meeting with external participants — clients, candidates, contractors — tell them at the start of the meeting which service you’re using. Give them the option to opt out before recording begins.
Think About What Gets Said in Recorded Meetings
Sensitive personal context, early-stage strategy, confidential client information — these may be better suited to conversations that don’t produce a permanent third-party transcript. The meeting where an AI notetaker is running is a different environment from one where it isn’t, even if the social dynamics feel the same.
The Bigger Picture
AI notetakers are a genuine productivity tool. The problem isn’t the concept — it’s the inconsistent implementation and inadequate disclosure around what happens to the data they generate.
The same principle that applies to personal photos and documents applies to meeting transcripts: information that matters to you deserves storage arrangements you’ve consciously chosen, under terms you’ve read, with providers whose business model aligns with keeping your information private rather than monetising it.
Your most candid professional conversations — the ones that happen in meetings rather than in emails — are no exception. The fact that they feel ephemeral doesn’t mean they are, once a notetaker is in the room.