How-To

AI Meeting Notes Privacy: What to Check Before Recording Calls

Review recording, consent, retention, AI training, subprocessors, access, and deletion before adopting an AI meeting notetaker.

  • #AI meeting notes
  • #privacy
  • #meeting transcription
  • #security

Before using an AI meeting notetaker, identify exactly what it captures, tell participants what will happen, set a defensible retention period, restrict access, and test deletion. A “bot-free” interface does not remove the need for notice, and a promise not to train a model does not answer where transcripts go or who can read them.

This is an operational privacy checklist, not legal advice. Recording and data-protection rules vary by location, relationship, industry, and meeting content. Have qualified counsel or your privacy team determine the lawful basis and notice or consent requirements that apply to your organization.

Product and regulatory facts in this article were checked against official sources on July 23, 2026. Policies and features change, so repeat the checks before procurement and periodically after deployment.

Recording mode matters

Start by mapping the data flow, not by comparing summary quality. “AI notes” can describe several materially different systems:

  • A visible bot joins the call as a participant and receives meeting audio or video.
  • A desktop application captures microphone and system audio without adding a participant.
  • A conferencing platform creates its own recording or transcript, which is then summarized.
  • A user uploads an existing audio or video file after the meeting.
  • A mobile device records an in-person conversation.

These modes change what participants can see, which platforms receive data, and whether a replayable recording exists. They do not, by themselves, determine whether the processing is appropriate.

For example, Granola’s official documentation says its desktop app captures microphone and system audio locally without adding a bot. It says meeting audio is temporarily cached for transcription and deleted after transcription, while transcripts and notes are stored. Granola also says its mobile workflow may use temporarily cached audio. See Granola’s security and privacy FAQ and security overview.

Fathom’s product is in transition: its official help center describes both a previous bot-based experience and a newer bot-free experience. Its privacy policy defines meeting content to include recordings, transcripts, attendee names and emails, and calendar information. See Fathom’s recording-mode guidance and privacy policy.

That comparison is an example, not a universal verdict. Our separate Granola vs Fathom comparison examines their broader workflows. For privacy review, ask each vendor for a current diagram covering capture, transport, transcription, summarization, storage, sharing, export, and deletion.

Map each artifact to a control

Do not use one retention or access answer for every output. This table turns the data-flow diagram into a compact review record:

ArtifactMain privacy questionEvidence to collect before approval
Raw audio or videoIs a replayable copy created, and when is it deleted?Capture method, storage location, deletion period, backup treatment
TranscriptDoes it include speaker labels or sensitive statements?Default access, correction process, export controls, retention rule
Summary and action itemsCan an inaccurate or decontextualized statement affect a person?Named reviewer, correction path, sharing default
Calendar and attendee metadataWhat is collected before the meeting starts?Permission scopes, synchronization behavior, deletion behavior
Integration copiesWhich system becomes the new source of truth?Destination owner, access policy, retention and deletion test
Audit and service logsCan logs reconstruct meeting content or participant activity?Logged fields, administrator access, log retention, incident use

For every row, assign an internal owner and mark unanswered vendor claims [VERIFY]. A product can delete raw audio quickly while retaining transcripts, summaries, metadata, or integration copies under different rules.

Do not treat a bot in the participant list, a recording icon, or a line in your terms as a complete notice process. Participants should understand, before substantive discussion begins:

  1. That audio, video, or both will be captured or transcribed.
  2. Which organization and tool will process the meeting.
  3. Why the notes are being created.
  4. Who will receive the recording, transcript, summary, and action items.
  5. How long each artifact will be kept.
  6. How to object, ask questions, or join through a non-recorded alternative.

The UK Information Commissioner’s Office says an organization recording an online meeting should consider whether its purpose could be achieved through a less intrusive method, such as taking minutes. It also says attendees should be told why the session is recorded, what the recording will be used for, and how long it will be retained. This guidance was checked on July 23, 2026: ICO data-sharing advice.

Consent is not the only possible legal basis in every jurisdiction, and it may be inappropriate where people lack a genuine choice. The ICO specifically warns that workplace power imbalances can make employee consent unsuitable. Do not copy a generic “by staying, you consent” script without legal review.

If your organization does rely on consent, record what participants were told, when and how they agreed, and whether consent was later withdrawn. The ICO’s consent record guidance describes those audit-trail elements.

Make notice a human workflow even when the product provides automation. Fathom’s official help states that its bot-free experience uses an in-chat recording notice or in-app prompts, while its prior experience visibly adds a bot and recording notifications. Granola provides an optional customizable consent message but says the user remains responsible for obtaining consent. Verify that the mechanism works on every supported conferencing platform, external call, dial-in route, and in-person setting.

Retention and deletion

Retention is not answered by “customers can delete their data.” Define separate periods for:

  • Raw audio and video
  • Speaker-labelled transcripts
  • AI summaries and action items
  • User-authored notes
  • Calendar and attendee metadata
  • Copies sent to CRM, chat, storage, or email systems
  • Backups, logs, and legal holds

The EU General Data Protection Regulation states principles of data minimization and storage limitation: personal data should be limited to what is necessary and kept in identifiable form no longer than needed for its purpose. Those are principles, not a universal number of days. See the official GDPR text, Article 5.

Turn “we retain notes only as long as needed” into an enforceable rule. Give each meeting class an owner, period, deletion trigger, and exception process. A recruiting interview may need different treatment from a public webinar or a routine project sync. For highly sensitive meetings, the right period may be zero because the notetaker should never start.

Test deletion with a pilot record. Delete it through the user interface, request account or workspace deletion if relevant, and ask the vendor what remains in backups and for how long. Then check connected systems. Deleting the vendor’s transcript will not necessarily remove a summary copied into a CRM or a recording already downloaded by a participant.

Record the result as evidence: deletion request date, visible deletion date, systems checked, vendor response, and unresolved copies. Mark any unverified backup or subprocessor deletion period as [VERIFY] in your procurement record rather than assuming that “deleted” means immediate removal from every layer.

Training and subprocessors

Ask two different questions:

  1. Does the notetaker vendor use customer content to train or improve its own models or product?
  2. May any transcription, hosting, analytics, or model provider use that content for its purposes?

A “no training” answer can still involve processing by several companies. Granola’s security page, checked July 23, 2026, says third-party AI providers are not allowed to train on customer data. It separately says Granola may train on anonymized data, with an opt-out in settings, while Enterprise model training is off by default. That distinction is why the exact policy language and plan-specific controls matter.

Request the current subprocessor list and compare it with the actual data-flow diagram. For each party, record its role, data categories, hosting region, transfer mechanism, retention, incident-notification obligation, and deletion behavior. Review the data processing agreement rather than relying only on a marketing page.

If the GDPR applies, document which party determines the purposes and means of processing and which parties process data on its behalf. The European Data Protection Board’s final guidance explains the controller and processor concepts and treats accountability as a core part of that analysis. Source checked July 24, 2026: EDPB Guidelines 07/2020 on controller and processor concepts.

Also examine optional integrations. Calendar access can expose titles, attendees, and join URLs before recording begins. CRM and chat integrations can create new durable copies after the meeting. Apply the same care you would use when deciding where other AI-generated artifacts may flow; our guide to reviewing AI-generated code offers a parallel lesson: convenient output still needs a named human owner and an explicit review boundary.

An integration should receive only the permissions and data it needs. The same boundary-setting approach appears in our MCP security checklist, which covers least privilege, secrets, logging, and approval controls for AI-connected tools.

Admin and access controls

Privacy failures often happen after a successful transcription. Test access as a normal user, an administrator, an external participant, and a person who should have no access.

Check for:

  • Private-by-default notes and recordings
  • Role-based access and separate administrator privileges
  • Single sign-on and account deprovisioning
  • Domain restrictions and external-sharing controls
  • Controls over download, export, and public links
  • Audit logs for views, shares, exports, and deletion
  • Organization-wide retention and recording policies
  • Separate defaults for internal and external meetings

Sharing defaults deserve hands-on verification. Fathom’s current official help says auto-sharing can send a summary and recording, a summary only, or nothing. It also says calendar invitees can receive an auto-share even if they did not attend. Its sharing guide offers “anyone with the link,” same-domain, and named-person access modes. Sources checked July 23, 2026: Fathom auto-sharing guidance and recording access guidance.

Create a test meeting with internal and external accounts. Confirm who receives notifications, who can open the artifact, whether links survive forwarding, and whether revoked users immediately lose access. Repeat after changing an organization-level policy; a setting that affects only new meetings may leave older recordings exposed.

If meeting video could later be turned into training, marketing, or synthetic-media material, obtain a separate approval for that new purpose. A recording notice for internal notes is not automatically permission for every later use. The reuse questions in our HeyGen vs Synthesia comparison are downstream decisions, not part of the original notetaking approval.

Vendor checklist

Use this list during procurement and preserve the vendor’s dated answers:

  • We know whether capture uses a bot, local application, platform recording, upload, or mobile recorder.
  • We know whether raw audio or video is stored, where, and for how long.
  • We have listed every stored artifact, including transcript, summary, metadata, and logs.
  • We have a reviewed notice process and a meeting path for people who object.
  • Counsel or the privacy owner has documented the applicable legal basis; the product’s notice feature is not being treated as legal approval.
  • We have checked vendor and third-party model-training terms by plan.
  • We have reviewed the current subprocessor list and data processing agreement.
  • Hosting and international-transfer arrangements meet our requirements.
  • Retention can be enforced by meeting class or workspace, not only by manual deletion.
  • Backup and subprocessor deletion periods are documented or marked [VERIFY].
  • Notes are private by default, and public-link sharing is disabled or tightly governed.
  • Administrators can remove access promptly when a user leaves.
  • Integrations do not copy meeting content into unapproved destinations.
  • Audit logs cover the actions our incident process needs to investigate.
  • The contract defines incident notice, data return, deletion, and termination assistance.
  • We have identified meeting categories where the notetaker must remain off.

Reject answers that collapse several controls into one certification badge. A security certification can support due diligence, but it does not choose your lawful purpose, retention period, access list, or recording notice.

Run a safer pilot

Pilot with low-sensitivity, synthetic, or deliberately scripted meetings. Do not begin with legal strategy, medical information, employee relations, credentials, unreleased financial results, customer secrets, or discussions involving children.

Before the first pilot, write a one-page operating rule: approved users, allowed meeting types, prohibited topics, required notice, sharing default, retention period, integrations, and incident contact. Turn off auto-recording and auto-sharing until the team proves the manual workflow.

Treat the pilot as a documented risk-management cycle, not a one-time feature demo. NIST’s voluntary Privacy Framework recommends identifying processing activities, privacy risks, values, and legal requirements; setting target outcomes; addressing gaps; and reassessing during operation. Source checked July 24, 2026: NIST, Using Privacy Framework 1.1.

Run three tests:

  1. Participant test: Does every attendee receive clear notice before capture, including dial-in and external participants?
  2. Access test: Can an unintended employee, former user, forwarded-link recipient, or uninvited external account open the result?
  3. Lifecycle test: Can the owner export, correct, restrict, and delete the record, and can an administrator verify those events?

Document gaps and require fixes before expanding scope. Recheck official policies, subprocessors, and product defaults at contract renewal and after major feature changes. A safe adoption decision is not “the vendor is private.” It is a narrower conclusion: the verified data flow, controls, contract, and operating process are acceptable for specified meeting categories, with named owners and tested deletion.

Frequently asked questions

There is no universal answer. The applicable rule depends on location, meeting participants, employment relationships, sector, content, and the organization’s legal basis. Have qualified counsel or the privacy owner approve the notice or consent process before deployment.

Visibility is not necessarily sufficient notice or valid consent. Participants should understand what is captured, why, who receives it, how long it is kept, and what alternative is available. Whether consent is required or appropriate must be assessed for the specific context.

Does “no AI training” mean the meeting data is private?

No. It answers only one question. The service may still transmit content to subprocessors, retain transcripts or metadata, create integration copies, or allow broad sharing. Verify the full data flow, contract, access controls, retention, and deletion behavior.

How long should AI meeting notes be retained?

There is no single safe number of days for every meeting. Choose a period tied to a documented purpose and meeting class, keep raw media separate from notes and metadata, define exceptions such as legal holds, and test that deletion works across the vendor and connected systems.