Most of the newer notetakers now say "no bot". Granola, Notion, Jamie and Cluely all record from a desktop app on your own machine, tl;dv offers the same as an option, and nothing shows up in the participant list. People read that as "local". It is not. Granola passes the audio to the transcription providers its security page names, "Deepgram and Assembly" (AssemblyAI).1 Notion sends the audio file "directly to our sub-processors for real-time transcription".2 Jamie uploads the recording to a server in Frankfurt.3 tl;dv saves bot-free recordings to your tl;dv library, "where they are automatically transcribed".4 Cluely's privacy policy lists "Audio transcription providers and processors" among the third parties it shares with.5 The microphone is on your desk. The transcription is not.
I build a recorder that transcribes on the machine, so I have a stake in this. I read a lot of privacy pages while building it. What I learned is that "where does my audio go" is three questions, and vendors answer them on three different pages, if at all.
Three questions, not one
The first question is where the audio becomes text. That needs a speech model, which runs either on your CPU or GPU or on a server. The second is which AI model reads the text to write the summary, and where it runs. The third is what is kept when the job is done, and whether any of it trains a model. A vendor can answer "local", "Anthropic" and "yes, by default", and all three can be true at once.
Where the audio becomes text
01On the device
A few tools run the speech model on your computer. MacWhisper transcribes with local models and tells you to "process sensitive content locally without data ever leaving your Mac".6 Its privacy policy, dated 14 February 2024, is blunter: "No data (audio, text or other) leaves your device."7 That covers the default. MacWhisper also has optional cloud transcription with your own key,8 and an Assistant subscription that sends files to its own servers.9 Anarlog, an open-source desktop app,10 says you can use it "entirely offline with local transcription and a local language model".11 Meetily, also open source,12 says "audio capture and transcription always run on your device".13 Krisp transcribes English on the device and the 15 other languages it supports on its servers.14 That is the pattern to watch: "on-device" with an asterisk for the language you speak.
02In the cloud
Everyone else uploads, and the notetaker is often not the one doing the transcription. Granola names Deepgram and AssemblyAI.1 Notion names OpenAI, Anthropic, Fireworks, Baseten, X.AI and AssemblyAI; if real-time processing fails, the cached audio is uploaded to Notion and kept for up to 3 days.2 Jamie uploads the audio to a server in Frankfurt, transcribes it on serverless GPUs from Modal, and deletes the audio once the transcript exists.3 Otter's subprocessor list, effective 31 March 2026, names no transcription vendor. Its infrastructure entry is Amazon Web Services, "cloud service provider and customer data storage platform", so the speech model reads as Otter's own.15 Fireflies does not name its transcription vendor in its privacy policy. It does say it imposes "a Zero Data Retention policy for meeting content" on its vendors, which tells you the vendors see the content.16 Zoom transcribes in its own cloud and deletes the audio once the transcript exists; the transcript is kept unless an admin disables and locks the meeting transcript setting.1718 In that case summaries run on "temporary speech-to-text data" that is discarded once the summary exists.18
"Granola doesn't store the audio from meetings", the security page says. It "transcribes in real time on macOS/Windows, or after your meeting using temporarily cached audio on Mobile."
granola.ai/security, checked 6 September 2026
It is true, and it is why people think Granola is local. Not storing the audio is a retention answer. It says nothing about where the audio became text; the same page says Deepgram or AssemblyAI.1 A vendor that never keeps your audio can still stream every second of it off your machine.
Which model reads the text
Once there is a transcript, a language model writes the notes. Most vendors now say which one. Fathom names OpenAI, Anthropic and Google.19 Otter names Anthropic for "backend support of AI-enabled functionality" and OpenAI for checking whether output "may contain harmful information".15 Granola names OpenAI and Anthropic.1 Jamie sends the transcript to "an Anthropic or OpenAI API".3 Anarlog's cloud option routes requests through OpenRouter to providers "such as Anthropic, Google, and Mistral", or you can run a local language model and nothing leaves the computer.11 Zoom lists its own models plus Anthropic (Claude 4.1 or later) and OpenAI (GPT-5.1 or later).18
Where that model runs is a separate line on the page, and two vendors' pages carrying that line are dated July 2026. tl;dv's privacy policy, updated 1 July 2026, says summaries may come from Anthropic models "via Google Cloud Vertex AI".20 They run in the EU or the United States, "depending on the AI hosting location that you select in your account's preferences".20 Microsoft's Copilot privacy page, dated 9 July 2026, says it now offers "third-party AI models in Microsoft Copilot, such as Anthropic and OpenAI models".21 Admins decide whether to use them, and the Anthropic models "are currently excluded from the EU Data Boundary".21 Krisp's privacy policy says meeting content may be shared with "third party service providers" to generate summaries, and the list of who they are lives on a trust centre, not in the policy.22
What is kept, and whether it trains a model
The answers split into five groups.
Yes, by default. Otter's privacy policy, effective 16 June 2026, lists among its purposes:
"Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)"
otter.ai/privacy-policy, effective 16 June 2026, checked 6 September 2026
I did not find a self-serve opt-out described for that in the policy.23 Granola is also yes by default: "Granola trains on your anonymized data so we can keep making Granola better".1 There is an opt-out in Settings, and a promise that OpenAI and Anthropic are not allowed to train on it.1 Otter turns training off by default on Enterprise workspaces,24 and so does Granola on Enterprise plans.1 Fathom's policy, updated 16 August 2026, says it may use de-identified meeting content to train its in-house models, with an opt-out in account settings.19 It adds that OpenAI, Anthropic and Google are not authorised to train on it.19
Yes, in the Terms. Cluely's privacy policy, last updated 10 June 2025, says "Cluely does not sell your data or train on your data".5 Its Terms of Service, dated 10 June 2025, say that for Free and Pro tiers the customer "expressly grants Cluely and its authorized sub-processors permission to use Customer Data to train".25 Only Enterprise data is excluded.25 The privacy policy and the Terms are dated the same day and say the opposite. I would not sign either until they agree.
Listed as a purpose. Krisp's privacy policy names "Improving our proprietary AI models and providing more accurate services" as a purpose for using personal information, on a consent basis.22 I could not find the switch that withdraws that consent. The same policy also says stored recordings and meeting notes are used only to provide the service and for no other purpose.22 So the training purpose reads as applying to personal information generally rather than to meeting content, and Krisp does not say which it means. The policy does say audio recorded for server-side transcription is deleted once the transcript is generated.22
No. Fireflies: "We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training."16 tl;dv says it does not use customer content "to train, fine-tune, or improve foundation models, large language models, or other generative AI models" for itself or any third party.20 Notion: "By default, Notion and its AI Subprocessors do not use Customer Data to train any models", with LLM providers keeping data 30 days or fewer on non-Enterprise plans and zero on Enterprise.26 Jamie: "Your data is never used to train Jamie's models, or any third-party models."3 Anarlog: "We never use your notes, transcripts, audio, or connected calendar data to train AI models."11 Zoom says it does not use customer audio, chat or other content to train its own or third-party models.18 Microsoft says prompts, responses and Graph data "aren't used to train foundation LLMs".21
Not stated. Meetily's privacy page says audio never leaves your machine and that it does not retain summaries, but it says nothing about training either way.13 When nothing reaches the vendor that is defensible, but I would still like to see the sentence.
Why the third question carried the Otter ruling
On 13 August 2026, Judge Eumi K. Lee of the Northern District of California ruled on Otter's motion to dismiss in In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL. The court had to decide whether Otter was a third-party eavesdropper under California's wiretap statute, and the deciding fact was what Otter does with the recording afterwards:
"Because Plaintiffs plausibly allege that Otter independently collects, retains, and uses communications for its own commercial purposes, they have sufficiently alleged that Otter is a third-party eavesdropper under section 631."
Order on motion to dismiss, N.D. Cal., 13 August 2026, checked 6 September 2026
The order also declined to infer that a participant had consented just because the Otter Notetaker was visible in the meeting.27 On the eavesdropper question, what carried the ruling was a third party keeping and using the recording for itself, not whether a bot was visible. That is question three, and it applies just as well to a desktop app that captures on your machine and uploads. The separate duty to tell people they are being recorded does not depend on the answer.
Where the audio becomes text, who reads it, and whether it trains a model. From each vendor's own pages, checked 6 September 2026.
| Vendor | Audio becomes text | AI providers it names | Trains on your meetings? |
|---|---|---|---|
| Otter.ai | Otter's cloud, stored on AWS15 | Anthropic, OpenAI15 | Yes, de-identified23 |
| Fireflies.ai | Cloud vendors, zero retention16 | Not named in the policy16 | No16 |
| Fathom | Fathom's cloud and third parties19 | OpenAI, Anthropic, Google19 | Yes, opt-out in settings19 |
| tl;dv | tl;dv's cloud4 | Anthropic via Google Vertex AI20 | No20 |
| Granola | Deepgram, AssemblyAI1 | OpenAI, Anthropic1 | Yes, opt-out in settings1 |
| Notion AI Meeting Notes | Sub-processors, real time2 | OpenAI, Anthropic, Fireworks, Baseten, X.AI, AssemblyAI2 | No26 |
| Jamie | Frankfurt upload, Modal GPUs3 | Anthropic, OpenAI3 | No3 |
| Cluely | Transcription providers, cloud5 | Not named in the policy5 | Policy no, Terms yes25 |
| Krisp | On device for English, Krisp's servers for 15 languages14 | Not named in the policy22 | Listed as a purpose22 |
| Zoom AI | Zoom's cloud, audio deleted, transcript kept unless admins disable and lock it1718 | Zoom-hosted, Anthropic, OpenAI18 | No18 |
| Microsoft Copilot in Teams | Microsoft's cloud, from the Teams transcript28 | Microsoft-hosted, Anthropic, OpenAI21 | No21 |
| MacWhisper | On the Mac, local models by default; optional cloud transcription with your own key, or on the vendor's servers with the Assistant plan689 | None needed; optional BYOK to OpenAI, Anthropic and others6 | Nothing leaves the device in local mode7 |
| Anarlog | On device, or its cloud providers11 | Anthropic, Google, Mistral and others via OpenRouter, or a local model11 | No11 |
| Meetily | On device, Whisper.cpp12 | Local model, or your own key13 | Not stated13 |
| MidMeetingthis site | On your computer, whisper | Only the one you connect, with your own key, or a local model | No server to train with |
Three questions to put to any vendor
Be sceptical of any vendor whose answer to all three is one word.
01Which company turns my audio into text, and where?
"We do not store audio" is not an answer. Ask for the provider's name and the server's country.
02Which model writes the notes, and whose servers does it run on?
Anthropic on Google's Vertex AI in the EU, OpenAI on Azure, a model on my own machine: these are different answers with different retention terms.
03What do you keep, for how long, and does any of it train a model?
Audio, transcript, notes, and the backups of each. The Otter order turned on retention, so ask for the days. If the training answer lives in the Terms of Service rather than the privacy policy, read the Terms.
Then ask what happens when you cancel. Fireflies says it deletes the personal information tied to a closed account within 30 days.16 Cluely's Terms say deleted data "may remain in immutable electronic backups".25 A local folder you can delete is a third answer. Fine, as long as you know which one you have.
The trade-offs
Keeping everything on the machine is a trade.
- The provider you connect has its own retention terms, and I cannot change them. When you turn the copilot on, transcript text goes to Anthropic, OpenAI, Google, xAI or OpenRouter under that company's API terms, not mine. If those terms matter to you, run a local model and nothing leaves.
- A speech model on a laptop can be less accurate than a cloud one, especially on rare languages, heavy accents and bad audio. I will not quote an accuracy number, because it depends on your machine, the model you picked and the room you are in.
- Local means you are the backup. There is no server holding a copy, so if the disk dies and you never copied the folder, the meeting is gone.
- Local capture does not settle consent. Nothing joins the call, so nobody is notified by a bot tile, which means telling the other people is on you. The recording laws that apply to a tape recorder apply to MidMeeting.
- It is not a team product. Nothing syncs and there is no shared workspace. If your team needs one searchable archive, a cloud vendor with a good no-training clause is the better fit.
I would rather you pick a cloud notetaker knowing exactly which servers your audio visits than pick mine because "local" sounded safer than it was. The answers are usually on the page, and when they are not, that is an answer too.
Sources
- Security at Granola, granola.aichecked 6 September 2026
- AI Meeting Notes, Notion help centrechecked 6 September 2026
- Data handling, Jamie docschecked 6 September 2026
- Bot-free recording, tl;dv help centrechecked 6 September 2026
- Privacy Policy, cluely.comchecked 6 September 2026
- MacWhisper, macwhisper.comchecked 6 September 2026
- Privacy policy, macwhisper.comchecked 6 September 2026
- Cloud transcription, MacWhisper docschecked 6 September 2026
- Assistant, MacWhisper docschecked 6 September 2026
- Anarlog, anarlog.sochecked 6 September 2026
- Privacy Policy, anarlog.sochecked 6 September 2026
- Meetily, meetily.aichecked 6 September 2026
- Privacy Policy, meetily.aichecked 6 September 2026
- AI Meeting Assistant, krisp.aichecked 6 September 2026
- Subprocessors, otter.aichecked 6 September 2026
- Privacy Policy, fireflies.aichecked 6 September 2026
- My Notes, Zoom AI whitepaperchecked 6 September 2026
- Models, processing, storage and usage, Zoom AI whitepaperchecked 6 September 2026
- Privacy Policy, fathom.aichecked 6 September 2026
- Privacy Policy, tldv.iochecked 6 September 2026
- Data, Privacy, and Security for Microsoft Copilot, Microsoft Learnchecked 6 September 2026
- Privacy Policy, krisp.aichecked 6 September 2026
- Privacy Policy, otter.aichecked 6 September 2026
- Enterprise Admin Controls Overview, Otter help centrechecked 6 September 2026
- Terms of Service, cluely.comchecked 6 September 2026
- Notion AI security and privacy practices, Notion help centrechecked 6 September 2026
- Order on motion to dismiss, In re Otter.AI Privacy Litigation, N.D. Cal., via Courthouse Newschecked 6 September 2026
- Copilot in Teams meetings and transcription, Microsoft Learnchecked 6 September 2026