In short
Only the vendor's own documents can say. Read its privacy policy, data processing terms and sub-processor list for a plain statement on whether recordings, transcripts or notes train models, by the vendor or its AI provider, whether that is on by default, and how to opt out.
Whether an AI notetaker trains on your meetings is something only its own documents can tell you, and the answer often has more than one layer. The notetaker's maker may or may not use your recordings, transcripts or notes to train models; the AI provider it sends text to has its own terms; and the answer can change with your plan and a setting you may never have seen. Look for a plain statement on each layer, on the default, and on how to opt out.
This guide lists the questions that settle it and where vendors answer them. It is narrower than where does your meeting audio go?, which is the full checklist for any notetaker; this one is about training alone.
Why it matters
A meeting transcript is unusually dense personal data. It holds names, voices turned into words, opinions, client details, prices, health mentions and things people said because they thought only the room would hear them. If it is used to train a model:
- it is copied into a training process that may be hard to reverse;
- people who never agreed to the notetaker are included, because they were in the call;
- depending on the model, fragments could in principle influence what the model produces for others.
Under data-protection law, using meeting data for training is also a purpose of its own, which needs its own basis. That is a question for your organisation's data-protection lead, not this guide.
Three layers to ask about
| Layer | Who | The question |
|---|---|---|
| The notetaker | The company whose app you use | Does it use your recordings, transcripts or notes to train or tune its own models? |
| The AI provider | The company whose language model writes the notes | Does it receive your text as a processor, and do its terms exclude training? |
| The transcription provider | Whoever turns audio into text, if not your own computer | Does it keep the audio, and does it train on it? |
A vendor can truthfully say "we do not train on your data" while its transcription or AI provider operates under different terms. A complete answer covers all three.
The questions
1. Is my data used to train or improve models? Look for the words "train", "training" or "machine learning". "To improve our services" can include training, or it can mean fixing bugs. If the text is vague, ask.
2. Which data? Audio, transcripts, notes, your edits to notes, and usage data are different things. Some vendors train on how you edit summaries, not on the meeting itself.
3. Is it on by default? The practical difference between opt-in and opt-out is large. Most people never change a default.
4. Who can opt out, and where? An individual user, only a workspace admin, or only on some plans? Is the setting in the app, or do you have to email someone?
5. Does it differ by plan? Terms for free, individual and business plans are sometimes different. Check the terms for the plan you are actually on.
6. What about "de-identified" data? Meeting transcripts are hard to de-identify: people say names, companies and details that point to them. Ask what the vendor removes and how.
7. Do people read it? Human review, for quality or safety, is a separate question from training and deserves its own answer.
8. How long is it kept? Data kept for a long time can be used for more purposes later. Retention periods for audio, transcripts and notes should be stated.
9. Which sub-processors receive it? A sub-processor list names the other companies involved. The model and transcription providers should be on it.
10. Does opting out reach back? Opting out usually covers future use. Ask about data already collected.
Where vendors answer
| Document | What to look for |
|---|---|
| Privacy policy | Purposes of processing; the word "train"; retention |
| Data processing agreement (DPA) | Whether the vendor acts only on your instructions; sub-processors; deletion |
| Sub-processor list | Which AI and transcription providers receive data |
| Trust or security page | Summaries; useful, but the policy and DPA are what bind |
| In-app settings | The actual default, and whether you can change it |
If the documents disagree, the binding ones (the terms, the privacy policy and the DPA) are what count. If a question is not answered anywhere, email the vendor and keep the reply.
Reading the answers
Some phrases to read carefully:
- "We don't sell your data." A different question from training.
- "Aggregated" or "anonymised". Ask what that means for a transcript.
- "Our AI providers are contractually prohibited from…" Good. Check the provider is named and on the sub-processor list.
- "You can request deletion." Useful, but ask whether it covers backups and data already used.
A clear answer looks like a sentence you could quote to a client: what is sent, to whom, for what, for how long, and whether it trains anything.
Beyond training
Training is one question in a larger one: where does the meeting go at all? A tool that never trains on your data but uploads every recording to be transcribed still holds your audio. How AI meeting notes are made explains which steps send what, and labelling what the AI wrote is a separate good habit, covered in the guide on the EU AI Act's transparency rules.
Notey's answer
Stated in the same terms as the questions above, from Notey's privacy policy:
- Audio: never sent anywhere. It is written to your Mac's disk and transcribed there, by Apple's on-device speech recognition. There is no transcription provider.
- Transcript text: sent only when you ask for a note or a question about a meeting, or when a meeting ends if you have chosen to have meetings written up automatically. What is sent is the transcript text and the names you gave people.
- Who receives it: Notey's service, which passes it to OpenAI as a data processor. It is not used to train models, and Notey does not retain the transcript after the response is returned.
- Notes you get back: stored on your Mac, labelled as AI-generated, with your edits marked.
- Usage records: count minutes summarised per day for billing, with no title, participant or text.
- Without an account: nothing is sent at all. Recording, transcription, search and reading back work with no account and no network.
Frequently asked questions
Do AI notetakers use meeting recordings to train their models?
Some say they do not, some use data unless you opt out, and some use de-identified data. It varies by vendor, plan and setting, so read the vendor's privacy policy and data processing terms rather than assuming.
Is "used to improve our services" the same as training?
Not necessarily, but it can include it. Look for the words "train" or "machine learning" and a plain statement. If the policy only says "improve our services", ask the vendor directly whether that includes training models.
If the notetaker does not train on my data, does its AI provider?
That is a separate question. The notetaker usually sends transcript text to a model provider. Check what the vendor says about that provider, and whether it is engaged as a processor under terms that exclude training.
Is anonymised meeting data safe to use for training?
Meeting transcripts are hard to anonymise, because people say names, clients, numbers and details that identify them. Treat "anonymised" or "de-identified" as a claim to ask about, not an answer.
Does opting out delete data already used?
Usually opting out covers future use. Ask the vendor whether it also applies to data already collected, and how deletion works.