Your team started using an AI notetaker six months ago. Meetings are more organized. No one has to argue about who said what. The tool transcribes everything automatically and emails a summary before you’ve even made it back to your desk.
Here’s the question nobody asked when you signed up: where do those recordings actually live, and who has access to them?
What AI Notetaker Apps Actually Do
AI meeting recorders work by joining your video calls as a bot participant — or, in some implementations, by requesting microphone access directly on your device. They capture audio, generate a transcript in real time, and then store both the audio and the text on their own servers.
The output you see — the clean summary with action items — represents a fraction of what gets collected. Behind that summary sits:
- The full audio recording of your meeting
- A complete word-for-word transcript
- Speaker identification data (who said what)
- Meeting metadata: participants, timestamps, duration, calendar event details
- Email addresses of everyone who attended
- In some cases, video recordings
Every word spoken in every meeting you’ve run through one of these tools is sitting in a cloud database you don’t control.
The Litigation Wave Nobody Told You About
Otter.ai is currently facing multiple consolidated federal lawsuits over its data collection practices. The central allegations involve the app joining meetings without adequately disclosing its presence to all participants — meaning people on the other end of your call may not have known they were being recorded and transcribed.
Fireflies.ai faces similar claims, including complaints under the Illinois Biometric Information Privacy Act. BIPA treats voiceprints — the biometric signature captured when an AI system learns to distinguish your voice from others — as sensitive biometric data requiring explicit consent before collection.
The legal argument in these cases is straightforward: AI notetakers routinely record people who never agreed to be recorded, using interfaces that make it easy for the meeting host to forget the bot is present.
Whether or not these suits succeed, they’ve surfaced a real structural issue. Consent in AI notetaker deployments is typically one-sided: the person who set up the subscription agreed. Everyone else in the meeting is a bystander.
What Happens to Your Transcripts
The data retention policies for AI notetakers vary considerably and are worth reading carefully before trusting any of these tools with sensitive meetings.
Most services retain recordings and transcripts for as long as your account is active. Some offer manual deletion. Some delete automatically after a configurable period — but that default period is often measured in months or years, not days.
“Free” tiers frequently come with the loosest retention policies, because the transcript data has commercial value. Services can use aggregated meeting data to train their own AI models, sell analytics to enterprise customers, or improve transcription accuracy.
The question to ask about any AI notetaker: if I cancel my account tomorrow, what happens to the audio and the transcript? The answer should be in their privacy policy, but it often isn’t as clear as it should be.
Who Can Subpoena Your Meeting Recordings
This is where AI notetakers create a risk that most users haven’t considered.
A transcript of a meeting stored on Otter.ai’s servers is subject to US law. If a party in a lawsuit serves Otter.ai with a valid legal demand for records, Otter.ai must comply. The same applies to Fireflies, tl;dv, or any other US-based service.
The practical scenarios where this matters:
Employment disputes. If a former employee sues your company for wrongful termination, AI-transcribed meetings where that employee was discussed could become discoverable evidence.
Investor or partnership disputes. Strategy discussions, valuation conversations, due-diligence meetings — anything recorded by an AI notetaker becomes third-party data that can be subpoenaed without your involvement.
Personal legal matters. If you used an AI notetaker on a personal device to transcribe calls about a divorce, medical situation, or legal matter, those transcripts exist in a third party’s database.
In each case, the subpoena goes to the platform, not to you. You may not even be notified until after the data has been disclosed.
Conversations That Should Never Be Transcribed
AI notetakers are marketed primarily for professional efficiency, but people use them in all kinds of contexts. Some of those contexts create specific risks:
Therapy and mental health sessions. Transcribing a therapy session through an AI notetaker means your private mental health disclosure now lives on a third-party server. Most AI notetaker services are not HIPAA-compliant, which means they don’t offer the same legal protections as your therapist’s own records.
Legal consultations. Attorney-client privilege covers communications between you and your lawyer, but that privilege can be complicated by the presence of a third-party recording service. Check with your attorney before using any AI notetaker on legal calls.
Job interviews. Candidates who secretly transcribe job interviews through AI notetakers are creating a record on a third-party server that includes the interviewer’s statements — often without any consent from the interviewer’s organization.
Family conversations. People use video calling AI notetakers for family meetings, care planning calls for elderly relatives, and estate discussions. These are among the most sensitive conversations imaginable, and most families don’t think about where the transcript goes after the call ends.
The Speaker ID Problem
Modern AI notetakers don’t just transcribe speech — they assign speech to specific people. The output reads “Sarah: We need to close that deal by Thursday” rather than “[Speaker 2]: We need to close that deal by Thursday.”
Building that attribution requires the system to process your voice as a biometric data point. Your voiceprint — the acoustic signature that makes your voice recognizable as yours — is extracted and stored alongside your transcript.
This is the core of the BIPA litigation against these platforms. Voiceprints are biometric identifiers. Under Illinois law, and emerging laws in other jurisdictions, biometric identifiers require explicit opt-in consent and strict retention limits.
Whether your state or country has specific voiceprint protections today, the data collection is real. Every AI notetaker that attributes speech to named speakers is building and storing a biometric identifier for everyone who appears in your meetings.
Practical Steps: What to Do Right Now
If you’re using AI meeting notetakers — or your colleagues are — these steps reduce the risk:
Audit your existing recordings. Log into your AI notetaker account and review what’s stored. Most services give you a library view. Delete recordings that contain sensitive information, especially anything involving personal matters, medical information, legal advice, or financial discussions.
Set retention limits. Most platforms let you configure automatic deletion after a period of time. Set the shortest retention window that still serves your practical needs. Ninety days is almost always enough for a meeting summary to be useful; six months is excessive for most purposes.
Configure consent notifications. Many AI notetakers can be set to announce their presence at the start of a meeting. Enable this. “This meeting is being recorded and transcribed” gives participants an opportunity to object or to move sensitive topics off the record.
Never record certain meetings. Some conversations simply shouldn’t be transcribed through a third-party cloud service. Establish a clear policy: legal calls, HR matters involving specific individuals, health discussions, and any meeting where attendees haven’t explicitly consented to recording should happen without AI notetakers.
Read the privacy policy before the free trial. Specifically look for: what data is retained after account deletion, whether data is used for model training, and what legal processes trigger data disclosure.
The Enterprise Trap
Many companies adopt AI notetakers at the team or department level without IT or legal involvement. An individual contributor signs up with a work email, the tool starts attending every meeting, and within six months, years of business conversations are sitting in a vendor’s database.
This creates a problem that’s harder to solve retroactively than proactively. When that employee leaves, the data doesn’t necessarily leave with them. The vendor’s terms determine what happens to recordings made under a subscription tied to a company email address.
Organizations that care about the confidentiality of internal discussions — which should be most organizations — need a clear policy on which tools are approved for meeting transcription, what data those tools retain, and how to offboard properly when an employee leaves or a subscription ends.
What to Look for in a Private Alternative
If you need to store meeting notes and personal memos privately, the key questions to ask any storage service:
Does the service use your data to train AI models? If yes, your transcripts become training material.
Is the service subject to US discovery rules, and if so, does it resist legal process or simply comply? Compliance is the default.
What happens to your data if you delete your account? The answer should be complete deletion within a defined, short timeframe — not “may take up to 180 days.”
daftei stores files with AES-256 encryption at rest and TLS 1.3 in transit. It never uses your content to train AI models, never sells your data, and never shows ads. When you delete your account, a 30-day grace period applies before all data is permanently and irreversibly erased.
That last detail matters more than people realize. An AI notetaker that retains your recordings for months after account deletion isn’t really giving you control — it’s giving you the appearance of it.
The Principle Behind the Problem
AI notetakers emerged from a genuinely useful insight: meetings generate decisions, and decisions need context. Transcription solves a real problem.
But the privacy architecture of most notetaker products was designed for enterprise sales, not for individual privacy. The model is: capture everything, store it centrally, make it searchable, sell the enterprise version. Individual privacy controls are an afterthought at best and a marketing claim at worst.
Before your next meeting with a bot in the room, it’s worth knowing exactly what that bot is doing with what it hears. Because it is doing something with it — and that something isn’t nothing.