Recording a video call used to require dedicated software and a deliberate setup. Now it’s a button press, often available to anyone in the meeting, generating a file that’s uploaded automatically to the cloud before the call is even finished.
The recording sits somewhere. It contains voices, faces, screen content, sensitive conversations — everything said during the meeting. Most people have no idea where it goes, who can access it, or how long it stays there.
The answer varies significantly depending on the platform, and the differences carry real privacy implications.
The Three Platforms, Three Different Storage Models
Zoom: Recordings in Zoom’s Own Cloud
When you use Zoom’s cloud recording feature, the recording file is stored on Zoom’s servers — not on your own cloud storage. Zoom hosts this as a service on infrastructure managed by Zoom (backed by AWS). The host receives a link to the recording and can share it, but the file itself lives in Zoom’s system.
The default access controls make any anyone with the link able to view the recording unless the host applies additional restrictions. Zoom administrators in an organization can access all recordings made within the account, regardless of whether they were in the meeting. The recording stays in Zoom cloud storage until it expires (Zoom applies a retention limit that depends on account settings and plan) or the host manually deletes it.
Zoom’s privacy policy permits them to access recordings to operate, maintain, and improve the service. Local recordings — saved to your own computer rather than Zoom’s cloud — are not subject to this, but most users default to cloud recording.
AI Companion, Zoom’s built-in transcription and summary feature, creates a separate text record of the meeting alongside the recording. This transcript is stored in Zoom’s cloud and may be processed to generate summaries. If AI Companion is enabled at the account level, it may run automatically without meeting participants being individually notified.
Microsoft Teams: Recordings in OneDrive or SharePoint
Teams recordings go into Microsoft 365 storage — either OneDrive (for meetings not tied to a Teams channel) or SharePoint (for channel meetings). This means the recording lives alongside your other organizational files, governed by the same access controls, retention policies, and Microsoft 365 compliance settings.
The practical implication is that recordings are subject to the same e-discovery, legal hold, and administrator access as any other file in your organization’s Microsoft 365 tenant. A compliance administrator or IT administrator can access recordings they weren’t part of, can apply retention policies that prevent deletion, and can pull recordings as part of litigation discovery.
Copilot in Teams — Microsoft’s AI assistant — can generate transcripts and summaries of recorded meetings. These are stored as separate files in the same OneDrive or SharePoint location. Microsoft’s data processing agreements specify that they don’t use customer content to train their foundational AI models, but they do process content to deliver AI-powered features within the service.
Unlike Zoom, Teams allows any participant (not just the host) to start recording, depending on the organization’s policy settings. The person who starts the recording doesn’t control where it goes — storage is determined by organizational settings.
Google Meet: Recordings in Google Drive
Google Meet recordings go to the meeting organizer’s Google Drive. The recording file is a Google Drive file, subject to all the privacy implications that come with Google Drive — including Gemini’s ability to access and summarize Drive files if the feature is enabled.
The organizer’s Drive storage quota counts against the recording. Anyone the organizer shares the file with can access it, and Google Drive’s link-sharing defaults can make files more broadly accessible than intended if the organizer doesn’t apply explicit restrictions.
Google Workspace users have organization-level controls similar to Microsoft Teams. Consumer Google accounts have less administrative infrastructure around recordings.
AI Transcription: A Second Record of Your Conversations
Recording video creates a video file. AI transcription creates something different: a searchable, indexable, text representation of everything said during the meeting.
This distinction matters because of how these records are used and who can search them. A video recording requires someone to watch it to extract information. A transcript can be searched, analyzed, summarized, and fed into other systems automatically. Sensitive information mentioned in a meeting — financial figures, medical discussions, personnel matters, personal details — can be extracted from a transcript by keyword search in seconds.
All three major platforms now offer AI transcription as a default or near-default feature:
Zoom AI Companion generates transcripts and meeting summaries. These are stored in the host’s Zoom account. The summary may be emailed to participants automatically depending on settings.
Teams Intelligent Recap (via Microsoft Copilot) creates transcripts, chapter markers, and summaries. These live in Microsoft 365 storage with the same access permissions as the recording itself.
Google Meet transcripts are generated through Google Workspace and appear as Google Docs in the meeting organizer’s Drive — alongside the video recording.
The privacy concern is not just that these transcripts exist, but that their existence often isn’t communicated to all participants, and the scope of who can access them is broader than most participants assume.
Who Has Access (Besides You)
Thinking of a cloud recording as “my recording” is imprecise. The access picture is more complicated.
Meeting hosts and organizers have primary access and control over recordings on all three platforms, within the constraints of organizational policies.
IT and compliance administrators can access all recordings within an organization’s account on Teams and within a business Zoom account. This is by design — organizational compliance requires audit capability. It means your manager, your IT department, or your employer’s legal team may be able to access a recording of a call you hosted, without your notification.
Anyone with the link can often view Zoom recordings if the host shares the link without applying access restrictions. Default link sharing settings are frequently more permissive than users realize.
Platform employees, in limited circumstances specified in each platform’s terms, can access recordings for support, compliance, and legal purposes. This is standard across enterprise cloud services.
Legal and government access: a subpoena or court order served on Zoom, Microsoft, or Google requires these companies to produce recordings stored in their cloud. They cannot refuse on the grounds that the recordings are private. This applies to both organizational and personal accounts.
Retention: How Long Does It Stay?
Retention policies vary by platform and account type.
Zoom applies a default expiration to cloud recordings — typically 180 days for paid accounts, though administrators can modify this. After expiration, files are moved to trash and permanently deleted after a grace period. There’s no automatic audit notification when this happens.
Teams recordings are subject to Microsoft 365 retention policies set by the organization. By default, Teams recordings remain in OneDrive or SharePoint indefinitely unless a retention label or policy is applied. Organizations under regulatory compliance requirements (legal, financial, healthcare) often apply mandatory retention periods that prevent deletion — which means a Teams recording of a sensitive meeting may be irrevocably retained for years.
Google Meet recordings in Drive persist until the organizer or someone with editor access deletes them, or until a Google Workspace retention policy applies deletion. Consumer Drive recordings have no automatic expiration.
The practical takeaway: recordings don’t disappear after the meeting. They stay in cloud storage, accessible to the people described above, until actively deleted or expired by policy.
The Consent Problem
Video call recordings raise a specific consent issue: not everyone who participates in a recorded meeting agreed to be recorded in any meaningful way. Notification banners appear and disappear. People join late and miss them. In multi-party calls with dozens of participants, the consent flow is minimal.
The legal landscape adds complexity. In the US, some states require all-party consent to record a conversation — meaning every participant must actively consent, not just be notified. California is all-party consent. In the EU, GDPR requires a legitimate legal basis for recording — typically consent or legitimate interest — and audio-video recordings of individuals qualify as personal data processing, requiring clear disclosure of purpose, retention period, and who has access.
Most organizations that record meetings regularly do not meet GDPR’s requirements for those recordings in any rigorous sense. The recording starts, the banner appears for 15 seconds, and the meeting continues. That banner is not meaningful consent.
Reducing Your Exposure
You may not control whether calls you participate in are recorded — that’s often up to the host or organizational policy. But you can reduce your exposure where you do have control.
Use local recording instead of cloud recording where possible. Local recordings on Zoom stay on your device. They’re not stored in Zoom’s cloud, not subject to Zoom’s access, not served through Zoom’s infrastructure. The tradeoff is that you manage storage and backup yourself.
Review and tighten link-sharing defaults. If you host recordings on Zoom, check that recordings require authentication rather than working for anyone with the link. The default is often more open than you’d choose deliberately.
Set explicit retention policies. If your organization uses Teams, work with IT to apply retention labels that automatically expire meeting recordings at a defined interval rather than retaining them indefinitely.
Disable AI transcription for sensitive meetings. On each platform, transcription can be disabled at the meeting level, the user level, or the organizational level. If you’re discussing sensitive topics — health matters, personnel issues, legal strategy — disabling automatic transcription eliminates the searchable text record.
Understand who you’re actually recording. The participants in a recorded call are people whose voice, face, and words are being stored in a third-party cloud service. It’s reasonable to tell people explicitly when a call will be recorded and why, and how long it will be retained — not because a banner requires it, but because it’s what you’d want if the roles were reversed.
A Different Category of Personal Memory
Meeting recordings occupy an unusual position in the landscape of personal data. They feel transient — a conversation captured for reference — but they’re actually persistent, multi-person, audiovisual records stored on commercial cloud infrastructure with broad organizational and legal access.
For one-on-one calls or small personal conversations, recordings may feel more like private notes than organizational records. They’re not treated that way by the platforms that host them.
The files you genuinely want to keep private — personal conversations, documents, family memories — are in a different category from business meeting recordings. A cloud storage service you choose specifically for privacy, that doesn’t share your data with third-party AI or run advertising against your content, is built for the former. The video conferencing platforms above are built for the latter. The difference matters when you’re deciding what to trust with what.