privacy

Zoom Cloud Recordings: Where They Go and Who Can See Them

Zoom cloud recordings sit on third-party servers, can be used for AI training, and your account admin can access them. Here's what you need to know.

You Pressed Record. Now What?

Millions of people click “Record to Cloud” in Zoom every day without giving it much thought. The recording will be there when the meeting ends — convenient, automatic, and seemingly private.

It is none of those things in the way most people assume.

Cloud recording in Zoom means your meeting is transmitted to third-party infrastructure, processed, stored in a location you didn’t choose, accessible to people beyond just you, and potentially used in ways you’d object to if you knew about them. The privacy assumptions most people carry into a recorded call are wrong in almost every detail.

This post maps out exactly what happens when you record to cloud on Zoom: where the data goes, who can access it, how long it stays, and what you can actually do about it.

Where Zoom Cloud Recordings Actually Live

Zoom’s cloud recordings are stored on infrastructure operated by Amazon Web Services and Oracle Cloud — third-party data centers distributed across multiple global regions. When you record to cloud, Zoom routes your file to one of these facilities. Unless you’re on a Business, Education, or Enterprise plan with a specific data residency setting configured by your admin, you have no control over which region that is.

If you’re on a free or Pro Zoom plan, your recordings may be stored in any country in Zoom’s network. That includes jurisdictions with very different data protection standards than the country you’re calling from.

For most consumer and small-business users, this is entirely opaque. You get a recording link in your Zoom portal. Where the file physically sits is not shown anywhere in the interface.

Who Can Actually See Your Recordings?

The most common assumption is that cloud recordings belong to the person who hit Record. That’s not how Zoom works.

Zoom recordings are governed at the account level. Any administrator of a Zoom workspace — your company’s IT department, your school’s technology team, a platform running a shared workspace — has access to every cloud recording made under that account.

If you’re using a business Zoom account, your employer can see your recordings. If you’re using a university-issued Zoom license, the institution can access them. If you’re a freelancer using a workspace someone else set up, the account owner may have admin visibility.

Beyond internal admins, Zoom itself holds the encryption keys to cloud recordings. This means Zoom employees with the appropriate internal access level, lawful legal processes like subpoenas, or government requests can compel access to recordings. This is fundamentally different from a file saved locally on a device only you physically control. When the file lives in Zoom’s cloud, Zoom holds the keys.

The AI Training Problem

In 2023, Zoom updated its terms of service in a way that sparked public concern: the language appeared to allow meeting audio, video, and chat content to be used for training AI models. Zoom responded quickly to the backlash, clarifying it would not use customer content for AI training without consent.

But here’s the practical catch: for many accounts, the default state still requires an administrator to actively opt out, not an individual participant. A participant on someone else’s Zoom call has no direct control over whether their words are used to train AI.

For meetings where you’re the host and account administrator, you can find the relevant toggle under Account Settings → AI Companion → “Allow Zoom to use meeting data to improve AI models.” Disabling it removes your account’s content from this use.

But if you’re joining a call someone else hosts, on someone else’s account, you cannot verify from inside the meeting what that account’s settings are. You are relying on the host’s admin to have configured it correctly.

This matters most for sensitive discussions. Medical consultations run on telehealth platforms built on Zoom. Legal strategy calls. Financial planning sessions. HR discussions. If the account admin hasn’t opted out, meeting content from these calls may be contributing to AI model training.

What Happens When You Delete a Recording?

You decide a recording is no longer needed and delete it from your Zoom recordings panel. Is it gone?

Not immediately.

Deleted cloud recordings in Zoom move to a “Trash” folder where they’re retained for 30 days. During that window, account administrators can still access them. After 30 days, Zoom removes the file from your accessible storage.

What Zoom’s privacy policy doesn’t commit to is a precise timeline for clearing derived data — AI-generated transcripts, meeting summaries, or any other processed outputs Zoom may have created from that meeting content. The original recording follows one deletion timeline; processed derivatives from it are a separate matter.

For anyone who has used Zoom’s AI summary or automatic transcript features, the summary may outlast the recording. This is worth keeping in mind for any call you’d prefer to have genuinely gone.

Retention: The Files That Accumulate

Cloud recordings on paid Zoom plans don’t expire by default. They accumulate indefinitely until someone manually deletes them or an administrator configures a retention policy.

Over a year of regular use, this can mean hundreds of recorded meetings sitting on Zoom’s servers — business calls, interviews, medical appointments, personal conversations — all retained indefinitely, accessible to admins, subject to discovery in legal proceedings, and governed by whatever Zoom’s privacy terms say at the time.

Privacy policies change. Zoom’s terms have changed multiple times in recent years, sometimes quietly. What Zoom commits to today about how recordings are handled may not reflect what the company decides later.

The most protective stance is to delete recordings you no longer actively need, as soon as you no longer need them. Most people never do this. Their Zoom recording history becomes a growing archive they’ve forgotten exists.

Cloud recordings carry a legal exposure risk that most people don’t think about until it’s too late.

In civil litigation, divorce proceedings, employment disputes, and criminal investigations, recordings stored in a third-party cloud service are discoverable with appropriate legal process. Zoom must comply with valid legal requests and may be required to produce recordings you considered private or long deleted.

This extends to recordings within the 30-day trash retention window — the file may still be accessible even after you thought you deleted it. Depending on the jurisdiction and the nature of the legal request, records outside the standard retention window may still be producible if backup infrastructure retained them.

If you use video calls to discuss anything legally sensitive — contract negotiations, custody arrangements, financial disputes — treat cloud recordings as potential legal evidence from the moment they’re created.

Local Recording Is Meaningfully More Private

If you have the option to record locally rather than to cloud, local recording is significantly more private for sensitive content:

  • The file goes directly to your device, not Zoom’s servers
  • Account administrators cannot browse local recordings through Zoom’s admin panel
  • Local recordings are not processed by Zoom for AI training by default
  • Deletion is entirely within your control
  • The file isn’t subject to Zoom’s retention policies or key management

The practical downside is that local recordings take up storage on your device and aren’t automatically available from other devices. But for any meeting where the content is sensitive, this tradeoff is almost always worth accepting.

What If You’re a Participant, Not the Host?

Participants who are recorded on someone else’s Zoom call have very limited formal protections under Zoom’s own terms in most jurisdictions. The host controls the recording. The host’s admin settings govern AI training. Participants get a visual notification when recording starts, but notification is not consent over how the recording is later used, retained, or processed.

The most practical protection is to treat every video call as a potential recording that may exist indefinitely on a third-party server you don’t control. Adjust what you say and share accordingly.

For sensitive personal calls — therapy sessions on telehealth platforms running Zoom infrastructure, medical consultations, anything genuinely private — ask the provider directly: are recordings stored locally or in cloud? What are your account’s AI data settings? Has your organization opted out of AI training? A legitimate provider should have a clear answer ready.

Where to Store Meeting Recordings If You Must Keep Them

If you legitimately need to keep a recording — a deposition, an important consultation, a personal archive — local recording plus intentional storage is the more private path.

Record locally to your device, then transfer the file to storage you actually control. Services that store files with strong encryption and don’t process your content for AI training put you in a meaningfully different position than leaving recordings parked in Zoom’s cloud indefinitely.

The key distinction is control: who holds the encryption keys, who can browse the file, and what happens to your data if the provider’s policies change or the provider is acquired. Those questions have very different answers depending on where your recordings live.

A Ten-Minute Audit for Zoom Account Owners

If you’re an administrator on a paid Zoom plan, these steps take about ten minutes:

Disable AI training data use: Account Settings → AI Companion → Turn off “Allow Zoom to use meeting data to improve AI models”

Set an automatic recording retention policy: Account Settings → Recording → Enable automatic deletion after a defined number of days for cloud recordings

Review and delete existing cloud recordings: Recordings → Cloud Recordings → Work through what’s there and delete anything sensitive you’ve already reviewed

Switch sensitive meetings to local recording: In your default recording settings, switch from Cloud to Local storage for meeting types where content is particularly sensitive

Audit admin access: Admin panel → User Management → Confirm who in your organization holds admin-level permissions and can browse recordings you thought were private

None of these are buried in an inaccessible settings menu. They’re steps most users never take because the interface doesn’t guide you toward them — and the defaults favor Zoom’s feature development goals, not your privacy.

The Defaults Are Not Working in Your Favor

The consistent pattern across Zoom’s cloud recording practices is that defaults favor convenience and capability, not user privacy. Cloud storage is the default over local. AI training requires an admin to opt out, not a participant to opt in. Recordings don’t auto-delete. Admin visibility is broad.

None of this makes Zoom a harmful product. But it does mean that privacy in Zoom isn’t something you get automatically — it’s something you have to actively configure.

The gap between what most users assume and what’s actually happening to their recordings is substantial. Most people assume cloud recordings are private to them. Most people assume deleting a recording makes it disappear. Most people don’t know their words may be training an AI model.

Closing that gap starts with understanding what the default settings actually do.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts