From Shubhi K | Product & Market Analysis

AI Note-Takers Compared: What Each One Does With Your Meetings

On this page

On 13 August 2026 a federal judge decided that an AI note-taker which trains on your meetings is not a participant in them. It is a third party. That single line reorganises how you should compare AI meeting notes tools, because the feature list and the data policy stopped being separate columns. California alone sets damages at 5,000 dollars per violation.

Key takeaways

  • Training rights now decide your legal status, not just your privacy posture. The court found Otter was not a tool handed back to participants but an independent party using recordings to train its own models. That reasoning travels to any vendor with the same clause.
  • The vendors being sued are the ones that trained. Otter, Fireflies and Granola all face 2026 privacy actions. Zoom, Microsoft and Google publish a no-training commitment for meeting content and face no equivalent case over these features.
  • The controls you need sit above the tier most teams buy. Otter puts custom data retention on Business and single sign-on on Enterprise at 100 users. Fireflies puts custom retention, private storage and audit logs on Enterprise only.
  • Consent is running at roughly one call in three. In a July 2026 survey of 500 employed US adults, 33.4% said an AI note-taker had been present and only 34.7% said they were always asked first.
$5,000Damages per violation under California Penal Code section 637.2. Applied to note-takers in In re Otter.AI Privacy Litigation, 13 August 2026.
33.4%US workers who say an AI note-taker has joined a work meeting. Only 34.7% were always asked first. Directional. Source: Pollfish survey of 500 adults, July 2026.
1 billionMeetings Otter says it has processed, across 35 million users. Company-reported. Source: UC Today, April 2026.

What the 13 August 2026 ruling changed

Here is the direct answer. A recorder that only transcribes and hands the file back to the people on the call can be treated as an extension of whoever invited it. A recorder that keeps the audio and trains on it is arguing something different, and one court has now said so.

The case is In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL in the Northern District of California, before Judge Eumi K. Lee. Four suits filed between August and September 2025 were consolidated in October 2025, argued in May 2026, and decided in part on 13 August 2026.

Judge Lee dismissed several counts and let the important ones stand. The federal Wiretap Act claim survived, along with California Invasion of Privacy Act section 631, both Illinois biometric privacy voiceprint claims and the unfair competition claim. The Computer Fraud and Abuse Act, CDAFA and Washington Privacy Act counts were dismissed with leave to amend.

The invited-participant defence, and why it failed

Otter argued it was an invited participant, relying on the cases holding that software acting purely as a client's own tool is not a third-party interceptor. That defence has worked for plenty of analytics vendors. It did not work here, and the reason was the training clause.

The court put it plainly. Otter is not just a tool that transcribes the conversation and hands it back to the participants, but an independent party who uses the recordings to train its models for its own benefit.

Read that as a test rather than a verdict. The question a buyer now has to put to a vendor is narrow and answerable: do you retain and reuse conversation content for model training? That single fact moved Otter from one legal category into another, and you can check it before you sign.

The three things a note-taker does with your meeting

Comparisons of AI meeting notes tools sort on summary quality, integrations and price. Those matter operationally. They are not the variables that carry risk.

Retention

How long the audio, the transcript and the summary survive, and whether you can shorten that. Otter commits to storing personal information for as long as necessary to fulfil the purposes it sets out, with no published maximum. Fireflies says it holds account data while the account is active and deletes within 30 days of closure.

Those are different promises. One is bounded by an event you control. The other is bounded by the vendor's own reading of its purposes.

Training rights

Whether the vendor may use what was said to improve its models. Otter's privacy policy of 16 June 2026 lists, among its purposes, training its proprietary AI technology on de-identified audio recordings and on transcriptions, and notes those transcriptions may contain personal information.

De-identification is doing heavy work in that sentence. A transcript of a pricing negotiation stays commercially sensitive after the names come off. The same ambiguity runs through the model providers' own enterprise terms, where the training carve-out and the retention window are usually written by different teams.

Speaker identification and voiceprints

The quietest of the three, and the one carrying per-person damages. Otter generates speaker identification information so users can tell voices apart, and its policy files that under biometric information.

Illinois treats a voiceprint as a biometric identifier, requires written consent before collection, and sets damages at 1,000 dollars for a negligent violation and 5,000 for an intentional one. Both of those counts against Otter survived.

AI note-taker comparison: what each vendor's own policy says

Every row below is a vendor describing itself. That is the right source for a contractual commitment and the wrong source for a verified fact, a distinction worth holding for the rest of this section.

What each vendor publishes about training on meeting content
ToolTrains on your meeting content?Source
Otter.aiYes, on de-identified audio and on transcriptions, as a stated purposePrivacy policy, 16 Jun 2026
Fireflies.aiNo. Does not use personal information for model training, and prohibits its vendors from doing soPrivacy policy, 6 Mar 2026
GranolaContested. A July 2026 complaint alleges training on by default; the policy concedes data absorbed into model weights cannot be extractedComplaint, 30 Jul 2026; policy, 24 Jul 2026
Zoom AI CompanionNo. Customer content is not used to train Zoom or third-party modelsAI Companion privacy pages, 2026
Microsoft 365 CopilotNo. Prompts, responses and Graph data are not used to train foundation modelsMicrosoft Learn, 2026
Gemini in Google MeetNo. Workspace data is not used to train models outside Workspace without permissionWorkspace privacy hub, 2026

Read the Granola row twice. The allegation is untested and the company has not conceded it. The model weights language is its own, and it is the part a buyer should care about however the case ends.

The tools facing privacy suits are the tools that trained Training position is each vendor's published policy. Litigation covers cases filed in 2025 and 2026. TOOL TRAINS ON CONTENT HOW IT IS SOLD NAMED IN A SUIT Otter.ai YES Standalone Yes, N.D. Cal. Fireflies.ai NO Standalone Yes, Illinois Granola CONTESTED Standalone Yes, N.D. Cal. Zoom AI Companion NO Bundled None on this Microsoft 365 Copilot NO Bundled None on this Gemini in Google Meet NO Bundled None on this Fireflies breaks the pattern. It publishes a no-training policy and still defends biometric claims.
The correlation runs down the first and last columns, with one exception. A no-training policy weakens the strongest claim. It does not clear the voiceprint claim.

The bundled assistants converge on one answer

Zoom, Microsoft and Google all say the same thing about training on meeting content, and they say it because enterprise buyers demanded it years ago. Google went further in May 2026, shipping an admin control that requires participants on supported devices to actively agree before recording, transcription or Gemini note-taking starts.

It is off by default with no end-user setting, which is the correct design. Consent policy is an administrative decision, not a personal preference. The awkward finding for the standalone category is that the tool your team likes usually has the weaker consent architecture, and the tool already inside your licence usually has the stronger one. Whether that reorders your shortlist is the kind of call covered in the comparison of enterprise AI governance controls.

Otter vs Fireflies on the terms that actually differ

These two get compared endlessly on summary quality and integrations. On price they are close enough that price should not decide it.

Otter.ai and Fireflies.ai, list price and where the data controls sit
ItemOtter.aiFireflies.ai
Pro, annual billing$8.33 per user per month$10 per user per month
Business, annual billing$19.99 per user, 5 seats minimum$19 per user
Custom data retentionBusiness and aboveEnterprise only
Single sign-on and SCIMEnterprise, 100 users and aboveEnterprise only
Audit logsActivity logs from BusinessAudit log API on Enterprise
Training on meeting contentPermitted by the policyProhibited by the policy

List prices from each vendor's public pricing page, August 2026. Annual figures are the discounted per-month equivalents the vendors advertise. Tiers change without notice.

The control you need sits above the tier you buy

Read the middle three rows again. The features that reduce legal exposure are retention control, single sign-on and audit logging. On both products, all three are gated above the entry tiers.

Here is where I part company with how this category gets reviewed. Comparison posts score these tools on transcription accuracy, which is now broadly solved, and treat the security section as a footnote. The security section is the product. A tool with a 4% better word error rate and no retention control is the worse purchase for any team that talks to clients.

The second-order effect is predictable. Because the controls are gated, teams buy Pro on a card and spread it person by person, and the company ends up with meeting archives it cannot see or delete. That is the shape of unmanaged AI tools and what a breach costs, arriving through a different door.

Eleven to twelve US states require consent from every party to a confidential conversation, depending on how you count the states with unsettled case law. California, Illinois, Washington, Pennsylvania, Maryland, Massachusetts, Florida, Delaware, Montana, Nevada and New Hampshire appear on every list.

The mechanism matters more than the count. On a video call, one participant in California pulls the whole call under California Penal Code section 632. You do not apply the rule of the state you are sitting in. You apply the strictest rule of anyone on the invite, which you often will not know until they join. So the policy has to be uniform rather than conditional.

Twelve months from first complaint to a usable legal test Filings in the Northern District of California, plus the one product change shipped in response. 15 Aug 2025 Brewer v. Otter filed 22 Oct 2025 Four suits consolidated 5 Dec 2025 Consolidated complaint 5 May 2026 Google ships consent gate 20 May 2026 Dismissal motion argued 30 Jul 2026 Granola class action filed 13 Aug 2026 Core claims proceed The green marker is the only entry that changed a product rather than a legal filing. Sources: N.D. Cal. dockets; Google Workspace release notes, May 2026.
Notice the ordering. The platform shipped a consent control three months before the ruling that made consent design a liability question.

What the exposure is actually worth

Statutory damages are why this category attracts class actions. The plaintiff need not prove a dollar of harm, and the per-violation figures multiply across participants and calls.

Statutory damages per violation, as pleaded Ceilings available under each statute. None has been awarded in the note-taker cases. Federal Wiretap Act $10,000 or $100 per day, whichever is greater California, Penal Code 637.2 $5,000 or three times actual damages Illinois biometrics, intentional $5,000 per person whose voiceprint was collected Illinois biometrics, negligent $1,000
The Illinois bars are the ones that scale badly. They attach per person, and a recurring internal meeting collects the same voiceprints every week.

Now do arithmetic you can hold in your head. A weekly client call with six external participants, running for a year, is 312 participant-instances. At the California figure alone that is a number no mid-market company wants to read in a demand letter.

The counterweight is that statutory ceilings are pleaded far more often than they are awarded, and courts can cut aggregate damages that would be ruinous. Treat these as the shape of the risk. The same discipline applies to liability caps and remedies in AI vendor contracts, where the ceiling and the realistic outcome sit far apart.

Where this argument is weakest

Three places, and the first one matters most.

A pleading-stage ruling is not a verdict

The 13 August 2026 order decided only that the claims are plausible enough to proceed. It accepts the complaint's allegations as true for that purpose and makes no finding that Otter violated any law. Otter may win at summary judgment or at trial.

A pleading-stage decision still changes vendor behaviour, because it sets the cost of defending the clause. Anyone telling you the law is settled has read a headline rather than the order. A ZwillGen analysis published on 30 July 2026 made the narrower point that privacy policies are not cure-alls, and that a vendor should not delegate informed consent obligations to its customers.

The consent survey is small and commissioned

The 33.4% and 34.7% figures come from one online survey of 500 employed US adults, fielded on Pollfish on 8 July 2026 and commissioned by a law firm that works on privacy claims. One field date, a modest sample, an interested sponsor.

That is not a reason to discard it. It is a reason to quote it with the sample attached and not build a business case on the decimal. I use it because no better public measurement of consent practice exists, which is itself a finding about the category.

The third weakness is simpler. Every no-training claim in the table above is self-reported, and nobody outside these companies has audited their training pipelines. A SOC 2 report tells you controls were tested against stated criteria, not that no transcript ever reached a training set.

The seven questions to put to a note-taker vendor

Send these before the demo, not after. A vendor who will not answer in writing has told you something.

Diligence questions for AI meeting recorders, and what a weak answer looks like
Ask thisWhy it mattersA weak answer
Do you train any model on our meeting content, including de-identified?The fact that decided the Otter rulingAnything turning on the word de-identified
What is the maximum retention period, and can we set it?Retention control is usually a paid tierAs long as necessary for our purposes
Do you create speaker voiceprints, and where are they stored?Voiceprints carry per-person damagesWe do speaker labelling, not biometrics
Can an admin force a consent prompt for all participants?Consent has to be enforceableHosts can announce it at the start
Who is contractually responsible for obtaining consent?Most policies push this onto the customerSilence, or a clause naming you
On deletion, what is removed and what survives in a model?Weights cannot be unwound after trainingWe delete your data within 30 days
Which sub-processors receive audio, and on what terms?The transcription vendor has its own rightsA link to a page with no dates on it

Question six separates a real answer from a rehearsed one. Granola's own policy concedes that once data is incorporated into model weights, it is not technically possible to isolate or extract it. That is an honest statement of how training works, and it means a deletion right written without a training carve-out is worth less than it reads. Pre-negotiate it alongside the rest of the AI contract terms a finance team should be asking for.

Frequently asked questions

Is it legal to use an AI note-taker without telling everyone?

It depends on where the participants sit. Eleven to twelve US states require consent from every party to a confidential conversation, and one participant dialling in from California or Illinois pulls the whole call under that rule. A federal court allowed wiretap and California Invasion of Privacy Act claims against Otter.ai to proceed on 13 August 2026. Silent capture with no notice is the highest risk pattern.

Does Otter.ai train its AI on my meetings?

Yes, by its own account. Otter's privacy policy, last updated 16 June 2026, lists training its proprietary AI technology on de-identified audio recordings and on transcriptions among its stated purposes, and notes those transcriptions may contain personal information. That single clause is what the court pointed to when it decided Otter looked less like a tool held by a participant and more like an independent party.

Which AI note-takers do not train on your data?

Fireflies.ai states in its privacy policy that it does not use personal information for AI model training and contractually prohibits its vendors from doing so. Zoom, Microsoft and Google all publish the same commitment for AI Companion, Microsoft 365 Copilot and Gemini in Workspace. Every one of those is the vendor describing itself, so treat it as a contractual promise you can enforce rather than a fact you have verified.

Otter vs Fireflies: which is safer for client calls?

On the training question Fireflies is the safer default, because Otter's policy permits model training on de-identified recordings and the Fireflies policy forbids it. On the controls question the two are close and both disappoint. Otter puts custom data retention on its Business tier and single sign-on on Enterprise at 100 users. Fireflies puts custom retention, private storage, single sign-on and audit logs on Enterprise only.

How long do AI meeting tools keep my recordings?

Longer than most buyers assume, and often for as long as the account exists. Otter's policy commits to storing personal information for as long as necessary to fulfil its stated purposes, with no fixed period published. Fireflies stores account data while the account is active and deletes it within 30 days of closure. Granola's policy concedes that data already absorbed into model weights cannot be extracted afterwards.

What happens if someone on the call is in California?

California Penal Code section 632 requires consent from all parties to a confidential communication, and section 637.2 sets damages at 5,000 dollars per violation or three times actual damages. One California participant is enough to put the whole call under that rule. The practical answer is to run the same consent step on every call rather than trying to work out jurisdiction at the top of each meeting.

Where to start this week

Start with an inventory, because most companies do not have one. Pull the list of meeting bots that joined calls on your Zoom, Teams or Meet tenant in the last 90 days. Expect to find tools nobody procured, arriving on individual subscriptions bought with personal cards, which is the perimeter gap described in the piece on personal AI accounts inside a company.

Then change one default. If your platform can force a consent prompt, turn it on at the domain level today. If it cannot, write one sentence into the calendar template for every external meeting and make it the host's job to read it aloud. Neither needs legal sign-off and both are reversible.

The transferable idea

The training clause now decides your legal status, not just your data posture. That test reaches well beyond meeting recorders, which is why it reads well next to the EU AI Act transparency obligations, arriving at the same disclosure question from the other direction.

References

  1. National Law Review, Invited participant or third-party eavesdropper, August 2026, on In re Otter.AI Priv. Litig., No. 25-CV-06911-EKL (N.D. Cal. 13 Aug 2026). The quoted holding.
  2. Recording Law, Judge lets core privacy claims proceed, 2026. Which claims survived and which were dismissed.
  3. Otter.ai, privacy policy, 16 June 2026. Training purpose, retention language, speaker identification.
  4. Fireflies.ai, privacy policy, 6 March 2026. No-training commitment, 30-day deletion window.
  5. Barnes & Thornburg, What the Granola class action means, 12 August 2026. Chamberlain v. Granola, No. 3:26-cv-07926 (N.D. Cal., filed 30 July 2026), and the model weights language.
  6. Google Workspace Updates, Require explicit consent in Google Meet, 5 May 2026. The consent control and its default state.
  7. UC Today, Otter.ai on trial, April 2026. User and meeting counts, statutory damages, the Fireflies biometric actions.
  8. Stacker, AI notetakers in 1 in 3 US workers' meetings, 16 July 2026. Pollfish survey of 500 adults for Kolmogorov Law, fielded 8 July 2026. Labelled directional.

Weakest thing about this source base: every no-training claim is the vendor describing itself, and the only consent measurement available is one commissioned survey of 500 people. Prices were read from public pages in August 2026 and change without notice.

AV
Aryan Vatsa
Founding Member, Zan Digital. Writes about AI product economics, B2B software markets and what the numbers behind vendor claims actually say.

Related reading