AI note takers: the bot is not the privacy question
By Andrey ChmerevI build Kekoso, which records meetings locally, so I have an interest in you caring about this. That is exactly why every claim below is a quote from the vendor's own privacy policy or pricing page with a link, read on 4 September 2026 — including the parts that are inconvenient for my argument.

Every comparison of AI note takers ranks them on summary quality, integrations and price. Search for an AI notetaker and you get the same ten products in a different order every time. This is not another ranking of the best AI note takers, because the thing that should decide your choice is not on those lists. Almost none separate the three questions people are actually asking when they say they want a private one:
- Does something join my call?
- Is my meeting used to train someone’s model?
- Where does the audio physically end up?
These get treated as one question, and they are three. Worse, among the services people actually choose between, the first two point in opposite directions.
What five vendors say, in their own words
Read from each company’s own pages on 4 September 2026 and linked below.
| Bot in the call | Trains on your content | Opt-out of training | Audio | |
|---|---|---|---|---|
| Otter | Yes | Yes, de-identified | Not offered | Cloud |
| Fathom | Optional (bot-free in beta) | Yes, de-identified | Yes, in settings | Cloud |
| Granola | No | Yes, de-identified | Yes, in settings | Cloud |
| Fireflies | Yes | No | — | Cloud |
| Zoom AI Companion (the Zoom AI notetaker) | Built in | No | — | Cloud |
| A local app | No | No | — | Your machine |
Look at the first two columns together. The two services that spare you the bot are the two that train on your meetings. The two that put a bot in the room are the two that do not train on anything.
That is not a coincidence to explain away — it is what happens when a market competes on one visible feature. The bot is visible to everyone in the call. The training clause is on page four of a policy nobody opens.
The quotes
Otter, whose free-tier limits and alternatives are their own article, lists among its processing purposes: “Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)”. The policy uses the phrase “opt out” eight times, and every one of them is about advertising or Google Analytics. There is no opt-out for the training.
Fathom: “Based on how you configure your account settings, we may use and create de-identified data generated from Meeting Content Information to improve our Service by training, improving, and customizing our in-house artificial intelligence models. You can opt out from this use of your data in your account settings. We do not authorize third parties (e.g., OpenAI, Anthropic, Google, etc) to use your personal information or Meeting Content Information to train their artificial intelligence models.”
Granola: “We do not allow third parties such as OpenAI or Anthropic to use your Personal Data to train AI models. We only use de-identified data to train AI models, which you can opt-out of within your Granola account settings.” It also says where the data lives: “We store your Personal Data in Amazon Web Services (‘AWS’) servers located in the U.S.”
Fireflies: “We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training.”
Zoom: “Zoom does not use any customer audio, video, chat, screen sharing, attachments, or other communications-like customer content (such as poll results, whiteboard, and reactions) to train Zoom’s or its third-party artificial intelligence models.”
What “de-identified” is doing in those sentences
Three of the five train on de-identified data, and that one word carries the whole weight of the claim.
De-identification removes the labels that tie a recording to a person: names on the account, identifiers, metadata. It does not remove what was said. If your meeting contained a client named aloud, an unannounced product, a salary figure or a patient’s symptoms, that content is in the audio and in the transcript, and stripping your account ID off the file does not take it out.
For a weekly standup this is theoretical, and paying for convenience is a rational choice. For an HR investigation, a therapy session, a call under an NDA or a conversation with a source, the calculation is different — and it is usually made by someone in legal rather than by you.
The honest version: de-identified training is a real reduction in risk and not the same thing as no training.
Why the bot became the whole conversation
A notetaker that dials in as a participant is visible, has to be admitted, and turns “can I record this?” into a negotiation at the start of every meeting. People find that either honest or a small daily tax, and vendors discovered that removing it sells.
So “no bot” became the privacy headline, and it answers exactly one of the three questions. Granola puts it plainly: “Uses your computer audio, so doesn’t invite a bot.” True, and useful. The audio still goes to AWS in the US, and it is still used for training unless you go into settings and say no.
If you left Otter over the training clause and landed on Granola because it has no bot, you moved along the wrong axis.
The third question, which nobody markets
All five options above are cloud services. Whatever their policies say today, the audio leaves your machine, sits on someone’s servers, and is governed by a document they can revise.
Recording on your own machine removes all three questions structurally rather than contractually: nothing joins the call because nothing is in the call, nothing is uploaded because there is no upload, and there is no policy to read because there is no second party. The test takes ten seconds — turn off the network and record a meeting. If it works, nothing was sent.
That is how call recording works in Kekoso, which I build: your microphone and the system audio are captured as two separate tracks through a Core Audio process tap, so the two sides of the conversation arrive already labelled, without any speaker diarization guessing at it. That is not decoration: on a mixed recording, an overlapping reply can vanish from the transcript entirely. And because the transcript is a local file, an MCP server lets your own AI agent read it — the summary comes from a model you picked rather than the one your notetaker bundled.
QuickTime plus a virtual audio driver does a cruder version of the same thing for free.
Where the free tiers actually stop
Since “free AI note taker” is what a lot of people search for, the caps are worth naming, because they are rarely about minutes alone.
Otter’s free plan: 300 transcription minutes a month, 30 minutes per meeting, and 3 lifetime audio or video file imports — lifetime, not monthly. Only your 25 most recent conversations are kept.
Fireflies’ free plan advertises “Unlimited transcription” with an asterisk, then gives you 400 minutes of storage per team and 20 AI credits. Downloading transcripts, summaries and recordings starts on Pro, at $18 a month or $10 billed annually. Unlimited transcription you cannot store or export is a demo, not a plan.
Fathom is the outlier: “Unlimited recordings + transcriptions” at $0, with a choice of bot-free or bot capture. Its trade is the training clause above, which you can switch off.
A local app has no free tier at all, which is its own kind of honesty about the trade.
When a cloud service is the right answer anyway
A comparison that never reaches this section is selling something.
You work in a team. A shared, searchable archive with per-meeting permissions is the entire product for most customers of these services, and no local app does any of it.
You live in the calendar. A service that joins scheduled meetings without you remembering to press anything is a real reduction in effort. A local recorder needs you to start it.
You need notes from meetings you did not attend. Only a bot can do that, and there the bot is the feature rather than the bug — it is the one job an AI meeting note taker does that nothing on your own laptop can.
Your meetings are unremarkable. Internal standups and routine customer calls would bore an attacker. Optimising them for privacy is a hobby, not a requirement.
The short version
Ask the three questions separately. If the problem is the bot, Granola or Fathom’s bot-free mode solves it, and both train on your content unless you opt out. If the problem is training, Fireflies and Zoom both say they do not, and both put a bot in the room. If the problem is that the audio leaves your machine at all, no cloud service solves it, however good its policy reads this quarter.
And whichever you pick: removing the bot removes the announcement, not the obligation. In several US states every participant has to consent, and the law does not care what recorded the call — the statutes, quoted, are shorter than most summaries of them.
Every quote here comes from the vendor’s own pages, read on 4 September 2026 and linked where it appears. Policies change; the links are there so you can check whether they have.
Questions people ask
Does an AI note taker without a bot keep my recording private?
Not necessarily, and this is the most common mistake in choosing one. Not sending a bot into the call and not training on your content are separate promises. Granola does not join the meeting, and its privacy policy also states it uses de-identified data to train AI models with an opt-out in settings. Fireflies does send a bot, and states it does not use personal information for AI model training at all. The two axes are independent.
Which AI note takers train on my meetings?
Of the five checked on 4 September 2026: Otter states it trains its proprietary AI technology on de-identified audio recordings and transcriptions. Fathom and Granola both state they train on de-identified data and both offer an opt-out in account settings. Fireflies states it does not use personal information for AI model training and prohibits its vendors from doing so. Zoom states it does not use customer audio, video or chat to train its own or third-party models.
Can I opt out of AI training in Otter?
Otter's privacy policy lists training on de-identified recordings among its processing purposes and does not offer an opt-out for it. The policy mentions opting out eight times, all of them about advertising and Google Analytics. Fathom and Granola both say plainly that you can opt out of model training in account settings, which is a real difference between them and Otter.
What is the most private way to take meeting notes?
Recording and transcribing on your own machine, because it removes all three questions at once: nothing joins the call, nothing is uploaded, and there is no vendor policy to read. The cost is everything a cloud service gives a team — a shared searchable archive, calendar automation, permissions, and notes for meetings you did not attend.
Is a free AI note taker worse for privacy?
Not by itself, but free tiers are where the limits bite in ways people do not expect. Otter's free plan caps at 300 monthly minutes and 3 lifetime file imports. Fireflies advertises unlimited transcription on its free plan but gives 400 minutes of storage per team, and downloading transcripts starts on Pro. A transcript you cannot export is a transcript you do not really have.
Do I still have to tell people I am recording?
Yes. Removing the bot removes the visible notice, not the obligation. In several US states every participant must consent to being recorded, and the law does not care whether the recording is made by a bot, by a cloud service or by an app on your laptop. Bot-free means no uninvited guest in the meeting, not permission to record silently.