The standing file
AI note-taker privacy: where your meetings really go
An AI note-taker turns your most candid professional conversations into files — audio, transcripts, summaries — that live on somebody's infrastructure under somebody's policy. Before you compare summary templates, compare answers to the questions on this page. We wrote it because vendor trust pages are where enthusiasm goes to hide.
The five questions that sort the market
- 1Processingon your device, or on theirs?
- 2Retentionhow long is everything kept?
- 3Trainingdoes your audio teach their models?
- 4Accesswho inside your org can see what?
- 5Certificationswhat backs the claims?
1. Where does processing happen?
Most note-takers are cloud services: audio leaves your machine, gets transcribed and summarized on vendor servers, and comes back as notes. The documented exception on our board is Krisp, which runs English transcription on-device — raw audio can become text without leaving your computer — with additional languages processed server-side, and on-device options expanded at Enterprise tier. If "audio never leaves the building" is a hard requirement, that architectural difference is your starting point, and you should verify the current details against Krisp's own documentation for your exact plan and languages.
2. How long is everything kept?
Recordings and transcripts persist until something deletes them. The operative questions: what's the default retention, can admins set shorter policies, and does deleting in the app actually purge backend copies within a stated window? Fireflies documents custom data retention at Enterprise; other vendors put retention controls at various tiers. If a vendor's answer to "how do I delete a meeting everywhere?" takes more than a paragraph, notice that.
3. Is your audio training their models?
The question everyone asks after signing up. Vendors in this category generally state that customer meeting content isn't used to train shared models, or offer an opt-out — but the wording moves, differs by tier, and occasionally differs between the marketing page and the privacy policy. Read the privacy policy's actual sentence, check for an admin toggle, and if the answer matters to you, get it in writing from sales. We deliberately don't reproduce each vendor's current sentence here, because these clauses are edited too often for our word to be worth anything — always confirm at the source, today.
4. Who inside your org can see what?
The under-asked one. A searchable archive of every meeting is an insider-risk surface: the intern can now query what the executive team said, unless workspace permissions say otherwise. Look for workspace roles, private-by-default meeting settings, channel or folder scoping (Fireflies documents private channels at Business tier), and audit logs at team tiers. Then decide your policy — who can search old transcripts is a governance question no vendor answers for you; our consent guide covers the human half.
5. What certifications and controls back the claims?
Look for the standard artifacts — SOC 2 reports, GDPR/DPA terms, SSO/SCIM at enterprise tiers, encryption statements, and for health-adjacent work, whether the vendor will actually sign a BAA (Krisp advertises HIPAA compliance options at Enterprise; verify scope with them directly). A trust page listing badges is a start; the report behind the badge is the substance, and vendors provide it under NDA to serious buyers.
Practical hygiene, whatever you pick
- Default to less capture. Record the meetings whose minutes matter, not everything with a calendar entry. The cheapest data breach is the recording that never existed.
- Keep sensitive meetings out of scope. HR conversations, legal strategy, anything with health details — off the note-taker by policy, per the consent guide's off-the-record protocol.
- Set retention short and forget-friendly. Ninety days of transcripts answers "what did we decide"; seven years of them answers a subpoena.
- Route summaries, not raw transcripts. Summaries travel to channels and CRMs; transcripts carry every aside and misfire. Share the digest, restrict the verbatim.
- Use the workspace controls you paid for. SSO, roles, private meetings — team tiers include them because rollouts without them go feral.
- Re-check clauses on renewal. Training and retention language changes. Put "re-read the privacy policy" in the renewal checklist next to the price.
How this shapes our scores
Privacy controls carry 10% weight in our rubric — enough to reward documented architecture, not enough to pretend we've audited anyone. Krisp's 8 reflects the on-device English transcription path; the cloud-only tools sit at 5–6 with differences for documented controls. If your weighting would be higher, our script is public — tools/score.py — re-run it with your numbers.
The least data that can leave, leaves
Krisp transcribes English on your device — notes without shipping raw audio to anyone. Free plan: unlimited transcripts, two AI notes a day.
Noted for the record: this is an affiliate link. A subscription started from it pays MinuteHand a referral fee; your price stays the list price. Verify plan-specific privacy details against Krisp's current docs.Fair questions
Is a bot recording more or less private than device-level capture?
Different, not strictly better. The bot announces itself but routes everything through vendor cloud; device capture can keep more local (per vendor architecture) but shifts disclosure onto you. Privacy and consent are separate axes — score them separately.
Can I just ask the vendor to delete everything?
Vendors document deletion and export mechanisms with varying completeness, and privacy laws in several jurisdictions back your request with teeth. The practical test before you commit: export your data and delete an account during the trial, and watch what actually happens.
Why don't you print each vendor's training-data policy verbatim?
Because those paragraphs are living documents and a stale quote is worse than a pointer. Our rule (see method): we characterize what we verified on the stamp date and send you to the primary source for the sentence that binds.