In this article
- What this article covers
- What the sources say: does the vendor train models on your meetings?
- What the sources say: retention, deletion and storage
- What the sources say: security reports and certifications
- What we could not verify
- What to consider (our assessment)
- Questions to ask a vendor
- Limits of this article
- When this article is not the right choice
- Related pages

Key takeaways
Documented- Answer: What AI note taker vendors state about storage, retention, model training and security reports, with dates, plus questions to ask before you record.
- Evidence: Based on 13 dated primary or official sources, most recently checked .
- Scope: This article does not claim hands-on testing. Performance or safety verdicts require a linked test record.
No page can tell you whether an AI note taker is safe for your meetings. What you can check is what each vendor states about storage, retention, model training and security reports, and whether those statements cover your plan. This article lists dated vendor statements and a checklist of questions to ask before you record.
What this article covers
An AI note taker is software that records or captures a meeting, produces a transcript and writes a summary. This article looks at four things vendors publish about that data: where it is stored, how long it is kept, whether it is used to train AI models, and which security reports the vendor cites.
Nothing here was tested. Every statement below comes from a vendor page that we fetched and read on 2026-10-03. Vendor pages change, so treat each statement as a snapshot and re-read the page before you decide. This is not legal advice, and it gives no verdict on any product. For the rules about telling participants that you record, see recording consent for AI note takers.
What the sources say: does the vendor train models on your meetings?
Vendors use different words for this, and the differences matter. "Never used", "opt-in", "opt-out" and "de-identified" describe different arrangements. Each line below is the vendor's own wording, with the page and the date we read it.
- Otter. Vendor states: "Otter uses a proprietary method to de-identify user data before training our models so that an individual user cannot be identified" (Privacy & Security page, 2026-10-03). The privacy policy, with an effective date of June 16, 2026, lists "training our proprietary AI technology on de-identified audio recordings and on transcriptions" among its purposes (Privacy Policy, 2026-10-03). The Privacy & Security page also states that no customer data will be used to train or improve its AI service providers' models.
- Fireflies. Vendor states: "Your meeting content — including audio, video, transcripts, and summaries — is never used to train any AI models" (How Fireflies.ai keeps your information safe, 2026-10-03). The Fireflies security page states that "your meeting data is never used for AI model training" (Security page, 2026-10-03).
- Fathom. Vendor states: "None of our AI sub-processors (Anthropic, OpenAI, or Google) are contractually permitted to use our users' data to train their AI models." The same help article states: "Fathom uses de-identified customer data to improve the accuracy of our proprietary AI models," and that users can opt out in My Settings (Is Fathom secure?, 2026-10-03).
- Granola. Vendor states: "Granola trains on your anonymized data so we can keep making Granola better. You can opt out of this in your Settings" (Security page, 2026-10-03). The help-center FAQ states that on Free and Business plans anonymised data may be used for its own model improvements by default, and that on Enterprise admins can set an org-wide opt-out (Security, Privacy & Data FAQs, 2026-10-03).
- Read AI. Vendor states: "AI training is opt-in. Contributing to model improvement is off by default" (Privacy page, 2026-10-03).
- tl;dv. Vendor states that its operating company "does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models" (Privacy Policy, "Current version published: September 9th, 2026" per the page, read 2026-10-03).
- Jamie. Vendor states: "Your data is never used for training of models, not by us or any of the model providers" (Security page, 2026-10-03).
- Krisp. Vendor states: "We always make sure to opt out of any data sharing or training permissions when working with third-party service providers" (Security for AI Meeting Assistant page, 2026-10-03). The next sentence of the page reads: "This ensures that neither Krisp's data nor that of our customers is ever used for model training purposes."
What the sources say: retention, deletion and storage
Retention statements describe what the vendor keeps, not what you must keep. They can also differ by plan.
- Otter states that deleted conversations move to Trash and are removed after 30 days. The privacy policy says it stores personal information "for as long as necessary to fulfill the purposes set out in this Policy, or for as long as we are required to do so by law or in order to comply with a regulatory obligation" (Privacy & Security page and Privacy Policy, 2026-10-03).
- Fathom states that when an account is deleted, recording data and metadata are removed, and after an additional 7 days the data is also removed from backups. It states that all Fathom data is stored in the United States (Is Fathom secure?, 2026-10-03).
- Granola states that notes and transcripts are retained indefinitely unless the user or an admin configures a retention policy. It states that audio is temporarily cached and deleted after transcription, and that data is stored on AWS servers in the United States (Security, Privacy & Data FAQs, 2026-10-03).
- tl;dv's privacy policy lists a retention period for video and audio recordings and written transcriptions of "Free user: 3 months" and "Paying user: until account deletion". It states that it primarily stores data in the European Economic Area, with AI features processing transcripts in the EU or the United States depending on the user's hosting preference (Privacy Policy, 2026-10-03).
- Jamie states that meeting audio is deleted after transcription and that data storage and processing stays within the EEA, Switzerland and the UK (Security page, 2026-10-03).
- Krisp states that transcripts are generated on the user's machine and that deleted transcripts and summaries are wiped from its infrastructure (Security for AI Meeting Assistant page, 2026-10-03).
- Fireflies states a "0-day data retention policy with all vendors and partners" and says users can delete their data anytime (Security page, 2026-10-03). It describes Private Storage for data location as Enterprise-only. We did not find default storage regions on the pages we read.
What the sources say: security reports and certifications
The AICPA's SOC 2 publication page describes a SOC 2 examination as "an examination of controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy." Vendors cite SOC 2 in different ways.
- Otter states it "has achieved SOC 2 Type 2 report" (Privacy & Security page, 2026-10-03).
- Fathom states it is "HIPAA, SOC2 Type II, and GDPR-compliant" and also that it does not have ISO 27001 (Is Fathom secure?, 2026-10-03).
- Granola states it has shown independent auditors that its practices meet SOC 2 Type 2 standards (Security page, 2026-10-03).
- Read AI states: "We're SOC 2 Type II, HIPAA, and GDPR compliant" (blog article "Read AI: The Privacy-First Meeting Notetaker and AI Assistant", undated, 2026-10-03).
- Krisp's security page states that its SOC 2 Type II report demonstrates its commitment to security and privacy (2026-10-03).
- Jamie states ISO 27001 is "Independently audited and certified to the international standard for information security management." It lists "SOC 2 Type II (pending)" with "Audit in progress," and states "Fully compliant with the EU General Data Protection Regulation" (Security page, 2026-10-03).
- Fireflies uses more than one wording. Its guide page says the company is "built on a foundation of SOC 2-compliant practices" and lists "SOC 2 Type II: Independently audited annually." Its Security page says "SOC 2 Type II" and "Fireflies follows industry standards for data security, privacy, and confidentiality," and separately "Certified for GDPR, SOC 2 Type II, and HIPAA compliance" (Fireflies guide and Security page, 2026-10-03). Ask which report exists and ask for it.
A vendor sentence does not tell you the audit period, the systems in scope or any exceptions the auditor noted. Those details sit in the report itself. We did not verify any report. This article also does not cover HIPAA or BAA claims.
For GDPR, vendors say things such as "we offer a Data Processing Addendum" (Granola, Security, Privacy & Data FAQs) or "happy to sign a DPA" for EU and UK users (Fathom, Is Fathom secure?). Whether such a document meets your obligations is a question for your counsel.
What we could not verify
Some vendor trust-center and help-center pages did not return readable text when we fetched them. Statements that live only on those pages are not included. Fellow is listed in our directory, but we did not verify any Fellow data-handling statement for this article.
What to consider (our assessment)
This section is our reading of the statements above. It is not a test result.
- Check each claim's scope. "Never used to train" on a security page and "de-identified data is used to improve our models" in a privacy policy can both be true of one product. Read the policy, not only the marketing page, and note the date.
- Check the plan. Granola's pages describe different defaults for Free and Business versus Enterprise. Do not assume that a paid or free tier behaves like the one a vendor describes.
- Separate the vendor from its sub-processors. Fathom's statement about Anthropic, OpenAI and Google is about sub-processors. It sits next to a separate statement about Fathom's own models.
- Where the output goes matters. Summaries and transcripts often move to other tools through exports or integrations. Those tools have their own data handling.
- Words like "anonymized" and "de-identified" are the vendor's own definitions. Ask what they mean in practice.
Questions to ask a vendor
Use this checklist in a security review or a vendor email. Ask for answers in writing and note the date.
- What exactly is stored: audio, video, transcript, summary, speaker names, calendar data?
- How long is each item kept by default, and who can change that period?
- What happens when a user or an admin deletes a recording? Are backups covered, and for how long?
- In which region is data stored and processed? Does that change for AI features?
- Is customer content used to train or improve any model, yours or a provider's? Is that on or off by default, and does it differ by plan?
- If data is de-identified or anonymized before use, how do you define that?
- Which sub-processors handle customer content, and how are customers told when the list changes?
- Which SOC 2 report do you hold (Type 1 or Type 2), for what period, and can we see it under NDA?
- Do you offer a data processing agreement, and on which plans?
- Which admin controls exist: who can record, default sharing settings, retention settings, audit logs?
- Can your staff or providers read recordings, and under what conditions?
- How do you tell meeting participants that recording is on, and can a participant opt out?
Limits of this article
This article reports statements, not behavior. We did not use any tool, review any report, or test any deletion or opt-out. We read marketing, help and policy pages, which can disagree with each other and change without notice. We cover eight vendors only. Fellow is not covered for the reason above.
When this article is not the right choice
If your meetings involve regulated data, legal privilege, health information, or a contract that restricts third-party processing, a directory article is not enough. Use your security and privacy team and your counsel, and ask the vendor for its current documents. If you only need to know how recording notice works, read the explainer on recording consent rules instead.
Related pages
Browse AI meeting tools, or read the profiles for Otter.ai, Fathom and Granola. Litigation and news about named vendors are outside this evergreen page.
Tools mentioned
Otter.ai
AI Productivity & Meetings
Meeting transcription and notes with a joining agent, a bot-free desktop app and mobile
Fireflies.ai
AI Productivity & Meetings
Meeting recorder and note taker with a joining bot, a desktop app and a Chrome extension
Fathom
AI Productivity & Meetings
AI note taker that records, transcribes and summarizes meetings
Granola
AI Productivity & Meetings
Meeting notes app that captures device audio locally, with no bot joining the call
Read AI
AI Productivity & Meetings
Meeting notes and search across meetings, email and chat, with bot and bot-free capture
tl;dv
AI Productivity & Meetings
Meeting recorder for Zoom, Google Meet and Teams with bot and bot-free recording
Krisp
AI Productivity & Meetings
Noise cancellation and AI note taker that works at the audio level, with no bot required
Jamie
AI Productivity & Meetings
Bot-free meeting notes app with EU hosting and audio deleted after transcription
Fellow
AI Productivity & Meetings
AI meeting assistant for notes, recaps and action items
Sources
- Otter.ai: Privacy & Securityaccessed
- Otter.ai: Privacy Policy (effective June 16, 2026)accessed
- Fireflies.ai: How Fireflies.ai keeps your information safeaccessed
- Fireflies.ai: Securityaccessed
- Fathom: Is Fathom secure?accessed
- Granola: Security, Privacy & Data FAQsaccessed
- Granola: Security at Granolaaccessed
- Read AI: Privacyaccessed
- Read AI: The Privacy-First Meeting Notetaker and AI Assistantaccessed
- tl;dv: Privacy Policyaccessed
- Krisp: Security for AI Meeting Assistantaccessed
- Jamie: Securityaccessed
- AICPA: SOC 2 reporting publicationaccessed
Related guides and updates
- ExplainerAI Note Taker Recording Consent: What to CheckOct 3, 2026 · 9 min read
- ExplainerBot vs Bot-Free AI Meeting AssistantsOct 4, 2026 · 9 min read
- ExplainerBest MCP Servers for Search, Memory and FilesOct 4, 2026 · 9 min read
- ExplainerClaude Skills vs MCP: Instructions or External Tools?Oct 4, 2026 · 9 min read
- ExplainerAre Claude Skills Safe? What a Skill Can Contain and RunOct 3, 2026 · 8 min read