AI Meeting Assistant Privacy: What Happens to Your Audio
AI note-takers upload your meeting audio and join the call — but only one person agreed. What happens to the recording, the consent rules, and what to ask.
You click the button that adds the AI note-taker. A few seconds later a new participant appears in the list. It has a name, sometimes an avatar, and everybody in the call can see it.
You agreed to that. Nobody else in the room did.
That sentence is the whole of this article, and it has almost nothing to do with whether the summary is any good — they are mostly fine now. It is a question about whose voices are being sent where, who was asked, and what you can reasonably promise the other people in the meeting.
What follows is the honest version: what actually happens to the audio, why every major tool is built the same way, what the law generally expects, the questions worth putting to any vendor, and where the alternative architecture helps — plus, just as importantly, where it doesn't.
1. The consent problem nobody names
Most privacy discussions about AI note-takers are framed as your privacy. That framing is comfortable and slightly wrong.
When you add a note-taker to a call, you are making a data-processing decision on behalf of every other person in it:
- The client who assumed the conversation was between the two of you.
- The candidate in an interview, who is not in a strong position to object.
- The patient, student, or advice-seeker in a regulated conversation.
- The colleague who mentioned something personal in the first two minutes, before the agenda started.
None of them read the vendor's terms. Most of them will not know what the bot in the participant list actually does, and a fair number will not notice it at all.
That asymmetry — one person consenting, several people affected — is the real issue, and it exists no matter which tool you pick. We wrote about how that plays out in the room itself in a meeting bot is a privacy decision you make for everyone else.
Why "it's disclosed" isn't a complete answer
Vendors do disclose this. Terms of service explain that audio is uploaded, that recordings are retained, that sub-processors are involved. None of it is hidden and most of it is lawful.
But disclosure to the account holder is not consent from the room. The person who clicked has read (or at least accepted) the terms. The other four have not, and were not offered the chance.
2. What actually happens to your audio
The mechanics are worth understanding because they explain everything else.
Most AI meeting assistants work like this:
- A bot joins your call as a participant. It has to, because that is how the audio gets out of the meeting.
- The audio stream is captured and uploaded to the vendor's servers.
- Speech recognition runs there, on their infrastructure, not yours.
- The transcript comes back. The recording, or a derived copy of it, stays.
Once audio has left the meeting, a series of questions apply that most users never ask:
- How long is it retained, and does deleting the transcript delete the audio?
- Who can access it — support staff, engineers, automated systems?
- Which sub-processors does it pass through? Cloud storage, ASR vendors, large-language-model providers for the summary?
- Is it used for model training, by default or on an opt-out basis?
- What happens on acquisition or insolvency, when the data becomes an asset?
- Where is it stored, and does that cross a border that matters to your contracts?
None of these are gotchas. They are ordinary questions with real answers. The point is that the person best placed to ask them — the client, the candidate, the patient — is never the person who clicked the button.
3. Why every major tool is built this way
It would be easy, and unfair, to read the above as carelessness. It isn't. It's cost.
Server-side speech recognition costs the vendor money for every minute it processes. That single economic fact shapes the entire category:
- Free tiers have to be capped. At the time of writing, Fireflies stores 400 minutes per team on its free plan. That is not stinginess — every minute you send them is a minute they pay for.
- A paid tier is inevitable. If the marginal cost per customer is above zero, the business has to charge, and the pricing page follows.
- The audio has to be uploaded, because that is where the model lives.
- A bot has to join, because that is how the audio gets out of the call.
Even the platform vendors charge for it. Google Meet's own transcription requires a paid Workspace edition — Business Standard or Plus, Enterprise, or an Education tier. On an ordinary Gmail account the feature simply is not there.
So the bot sitting in your participant list is not an arbitrary design choice. It is the visible end of a cost structure. Understanding that is what lets you evaluate the alternatives honestly rather than tribally.
4. The legal layer, in general terms
This is not legal advice, and rules change. We cover the ground in more detail in is it legal to record meetings. What follows is the shape of the landscape so you know which questions to take to someone qualified.
One-party versus all-party consent
In many jurisdictions, recording a conversation is lawful if one participant consents — which can be you. In others, every participant must consent.
In the United States this varies by state. A number of states — California and Illinois among the well-known examples — require all parties to consent to the recording of a private conversation. The commonly cited count is around a dozen, though the exact list depends on how each statute is interpreted and whether it addresses wiretapping, recording, or both.
The practical consequence for meetings is straightforward: a call with participants in several states or countries can be governed by more than one rule at once, and the stricter one tends to be the safe assumption.
GDPR and the UK
Under GDPR-style regimes, a meeting recording containing identifiable voices is personal data. That brings obligations around having a lawful basis for processing, being transparent about it, honouring access and deletion requests, and being able to say who your processors are.
If your note-taker uploads audio to a vendor, that vendor is a processor in your chain, and their sub-processors are in it too.
Voice as biometric data
This one is under-discussed. Some regimes treat voiceprints — not the words, the voice characteristics used to identify a speaker — as biometric data with a higher bar for consent. Illinois' Biometric Information Privacy Act is the most-litigated example in the United States.
Speaker identification is a standard feature of meeting assistants. It is worth knowing whether a given product creates and stores a voiceprint, and whether it does so for everyone in the call or only the account holder.
Regulated conversations
Legal, medical, financial and HR conversations often carry duties of confidentiality that sit above general privacy law. In those settings, "the tool was fine under GDPR" is not the standard you are being held to.
5. The questions worth asking any vendor
If you take one practical thing from this article, take this list. It works for any meeting assistant, including ours.
- Does audio leave the device? If yes, to where, and in which country?
- Does anything join the call and appear in the participant list?
- How long is audio retained, and is that different from transcript retention?
- Does deleting a meeting delete the audio, or only the transcript?
- Who can access recordings internally, and under what controls?
- Which sub-processors are involved, and is there a public list?
- Is my data used for model training by default?
- Are voiceprints created, and for whom?
- What happens to the data if the company is acquired or shuts down?
- Can I get a written answer to all of the above? A vendor who will not put it in writing has told you something.
A good vendor will answer these quickly and specifically. The speed of the answer is itself informative.
6. The other architecture: running the model locally
Speech recognition models have become small enough, and browsers fast enough, that recognition can run on the participant's own machine instead of a server.
That is how Meetings Brief works. The speech model downloads into your browser and runs on your computer. You share your meeting tab with tab audio, and the transcript builds as the conversation happens — every 30 seconds, capturing everyone in the call, not only you — and saves on your device as it goes. When you stop, you get the summary, the topics, the action items with owners, the open questions, and the transcript attached, by email.
Four things follow from that single architectural decision:
Nothing joins the call. There is no bot in the participant list, because there is no bot. Nobody else has to notice, object to, or be surprised by anything.
The audio never leaves your device. Not stored, not retained, not handed to a sub-processor — it is never sent anywhere in the first place. There is no retention policy to read because there is nothing being retained.
There is no cap. Transcription costs us nothing per meeting, so there is no minute counter to enforce. This is the honest reason Meetings Brief is free with no paid tier and no card: not generosity, just a cost structure that does not require metering.
You are not deciding for anyone else. Because nothing is uploaded and nothing joins, most of the consent question in section 1 simply stops arising.
The trade-offs, stated plainly
Local processing is not magic, and it costs something:
- It needs a capable device. The model runs on your hardware, so your hardware has to run it. That is the trade for not uploading anything.
- It runs in a browser tab, on Chrome or Edge on a desktop. You share the meeting tab with tab audio; there is a setup step, and it is not a native app.
- The transcript lives with you. Which is the point — but it also means the responsibility for storing it sensibly is yours.
7. What on-device does not fix
An honest article has to include this section, so here it is.
You still need to tell people you are recording. Running the transcription locally changes where the audio goes. It does not change the ethics, or the law, of making a record of a conversation. Assume you need to ask, because usually you do.
A transcript is still a record. It sits on your machine and in the brief you email yourself. It can be forwarded, disclosed, subpoenaed, or read by whoever can open your laptop. On-device is not the same as ephemeral.
Being invisible is not a licence to be secretive. "No bot appears in the participant list" is a privacy property, not a way to record people quietly. If you would not have told the room, do not do it.
That last point matters more than the rest of this article. The architecture removes a disclosure you were making unintentionally. It does not remove the disclosure you owe people deliberately.
8. How to actually handle this in a meeting
Practical, and it takes ten seconds.
Say it at the top. "I'm taking AI notes on this — the transcription runs on my laptop and the audio isn't uploaded anywhere. Shout if you'd rather I didn't."
Put it in the invite for recurring meetings, so nobody is surprised on the day.
Offer the off-switch and mean it. If someone says no, stop. A note-taker that costs you a candidate's honesty is a bad trade.
Say what you'll do with it. "This goes into our project notes" is a different promise from "this is just for me."
For regulated or sensitive conversations, ask first, not after. And write the answer down.
Frequently asked questions
Is Otter.ai safe to use? Otter, Fireflies, Read.ai and similar tools are legitimate products that disclose what they do. The question is not whether they are safe but whether uploading a given conversation to a third party is appropriate, and whether the other participants would agree if asked. That answer changes with the meeting.
Can I transcribe a meeting without a bot joining? Yes. If speech recognition runs on your own machine rather than on a server, nothing needs to join the call to capture the audio. That is how Meetings Brief works.
Does Google Meet have free transcription? Google Meet's built-in transcription requires a paid Workspace edition — Business Standard or Plus, Enterprise, or an Education tier. On a standard Gmail account the feature is not available.
Do I need everyone's permission to record a meeting? It depends on jurisdiction, and a single call can span several. Some places require only one participant to consent; others require all of them. Treat all-party consent as the safe default and take specific situations to a qualified adviser.
Is a meeting transcript personal data? Under GDPR-style regimes, a recording or transcript containing identifiable voices or names is generally personal data, which brings obligations around lawful basis, transparency, access and deletion.
What is the difference between on-device and cloud transcription? Cloud transcription uploads your audio to a vendor's servers, where the model runs. On-device transcription downloads the model to your machine and runs it there, so the audio does not leave your computer. The trade-off is that on-device needs a capable device; cloud needs trust and a retention policy.
Does on-device transcription mean I don't need consent? No. It changes where the audio goes, not whether you should tell people you are making a record of the conversation.
The question worth asking before you add a note-taker
Not "is the summary accurate" — they mostly are now. Ask instead:
Whose voice am I sending to a company they have never heard of, and did I ask them?
If that question makes you slightly uncomfortable, the discomfort is useful information. There is an architecture where it does not arise, and it is available free, in a browser tab, with no account.
Try Meetings Brief — live transcription for Google Meet, Zoom and Microsoft Teams. No bot joins, the audio stays on your machine, and there is no signup.
Competitor plan details and platform requirements described here are as at August 2026 and change frequently — check current terms before relying on them. Nothing in this article is legal advice; recording and privacy rules vary by jurisdiction and by the nature of the conversation. Meetings Brief is made by KCF LLC and built by MyMind Studio.