In short
Every AI notetaker sends your meeting somewhere, even if "somewhere" is only your own disk.
The useful questions are the same for every tool: where the audio is transcribed, what is kept and for how long, who can read it, whether anyone trains on it, which other companies receive it, and how to delete it. This guide turns those into a checklist you can put to any vendor, explains why each question matters, and answers it for Notey in the last section.
The answers should come from the vendor's own documents — its privacy policy, data processing agreement, subprocessor list and security page — not from its marketing. If a document does not answer a question, ask in writing.
Why the path matters
A meeting produces three kinds of data, and a tool can treat each differently:
- the audio, which carries everyone's voice;
- the transcript, which is the same conversation as searchable text;
- the notes, such as a summary, action items and anything an AI wrote.
All three are personal data about everyone in the meeting, not only about you. Under data protection law, each company that receives them on your behalf is a processor you have to account for, and each copy is one more place a breach, a subpoena or a mistake can reach. Recording meetings under GDPR explains the obligations; this guide is about finding the facts.
The checklist
1. How does the tool hear the meeting?
- Does a bot join the call as a participant, or does an app on your computer record it?
- If a bot joins, who operates it, and does it receive video and screen shares as well as audio?
- Do the other participants see anything, and can they refuse?
A bot run by the vendor receives the whole meeting stream on the vendor's servers from the first second. A recorder on your computer starts with the data on your machine, and the rest of the checklist decides whether it stays there. Bot-free meeting notes explains the two approaches.
2. Where is the audio transcribed?
- On your device, or on a server?
- If on a server, whose — the vendor's own, or a speech-to-text provider's?
- In which country or region?
This is the single biggest difference between tools. If transcription happens in the cloud, the audio has to leave your computer, and the speech provider becomes a processor, possibly in another jurisdiction.
3. What is stored, where, and for how long?
- Is the audio stored after transcription? For how long?
- Where are transcripts and notes stored?
- Can you set a retention period, or is it fixed?
- Are the retention periods different for audio, transcript and notes?
A vendor that deletes audio once it is transcribed but keeps transcripts forever has only half answered the question.
4. Who can read it?
- Can the vendor's staff access recordings or transcripts? Under what conditions, and is access logged?
- Is the data encrypted at rest, and who holds the keys?
- If you share a meeting with colleagues, what can they see, and can they re-share it?
"Encrypted" alone says little. Data encrypted with keys the vendor holds can be read by the vendor. Data encrypted with a key only you hold cannot.
5. Is it used for training?
- Does the vendor use your audio, transcripts or notes to train or improve its models?
- Is that on by default, and can you opt out?
- Does the AI provider the vendor uses have its own terms on training and retention?
Look for this in the terms, not the FAQ. The vendor's promise does not bind the AI provider; the contract between them does.
6. Which other companies receive it?
- Is there a published subprocessor list?
- Which subprocessors receive audio, and which receive only text?
- How will you be told if the list changes?
- For data leaving the EU or UK, what transfer mechanism is used?
7. How does deletion work?
- When you delete a meeting, is every copy deleted — audio, transcript, notes, search index, backups?
- How long do backups keep deleted data?
- When you close your account, what happens to everything?
- Can you delete one person's data on request, to answer an access or erasure request?
8. What happens without a network or an account?
- Can you record and read your meetings with no account?
- Does the tool work offline, or does it fail without a connection?
- What does the tool send in the background — analytics, crash reports, diagnostics — and can those include meeting content?
The last question catches more tools than any other. A crash report that attaches a recent audio buffer, or analytics that include meeting titles, can send data you believed stayed local.
9. Voices and other biometric data
- Does the tool recognise voices across meetings?
- Is that on by default? Where are voiceprints stored, and can they be deleted per person?
A voiceprint used to identify people is biometric data under GDPR and some US state laws, including the Illinois Biometric Information Privacy Act.
10. What is labelled and what is checked?
- Is AI-written content labelled as such?
- Can you see what was edited by a person?
This is not a privacy question, but it belongs in the same review: people will act on the notes.
Using the answers
Once you have the answers, write down, for each kind of meeting you record, the list of places the audio, transcript and notes go. If that list is longer than your policy allows, or includes a processor your clients' contracts forbid, the tool does not fit that kind of meeting — whatever else it does well.
For health data, the same list tells you which vendors need a business associate agreement; see AI notetakers and HIPAA. For how two bot-free tools answer some of these questions differently, see Notey vs Granola. For the legal side of recording in the first place, start with is it legal to record a meeting?
The checklist answered for Notey
These answers come from Notey's privacy policy and landing page. Notey is made by AInject, LLC.
| Question | Notey's answer |
|---|---|
| How does it hear the meeting? | An app on your Mac records the microphone and what the Mac plays, as two separate tracks. Nothing joins the call. |
| Where is audio transcribed? | On your Mac, by Apple's on-device speech recognition. After an English meeting, a second on-device recogniser can re-transcribe it; that also runs on the Mac. |
| Is audio stored, and where? | On your Mac's disk, in Notey's application support folder, until you delete the meeting. |
| Does audio ever leave the Mac? | No. Not for transcription, not for sync, and not encrypted either. There is no fallback, debug mode or crash report that sends it. |
| What is sent for AI notes? | The transcript text and the names you gave speakers, when you ask for a note or ask a question, or when a meeting ends if automatic write-ups are on. Never the audio. |
| Who receives it? | Notey's service, which passes it to OpenAI to produce the result. |
| Is it used for training? | OpenAI processes it as a data processor and does not use it to train models. Notey does not retain the transcript after the response is returned. |
| What does Notey store about you? | If you make an account: your email address, your subscription status, and a usage record of how many minutes were summarised on which day, with no title, participant or text. |
| Who can read synced copies? | Sync is optional. Each meeting is encrypted on your Mac with a key derived from a recovery key that exists only on your Macs. Notey holds ciphertext it cannot read. Lose the key and the synced copy cannot be recovered. |
| Voice recognition? | Off by default. When on, a voiceprint is made only when you name someone; it is stored on the Mac, listed, and can be deleted with "Forget this voice". |
| How does deletion work? | Deleting a meeting removes its recording, transcript and notes, and with sync on, from every one of your Macs. Account deletion is by email to the address in the privacy policy. |
| Without an account or network? | Recording, transcription, speaker separation, search and reading meetings back all work with no account and no network. Nothing leaves the Mac. |
| Is AI output labelled? | Yes, wherever it appears, and your edits are marked. |
| Calendar data? | Only if you connect Google Calendar: read-only, used to notice meetings, and not sent to the AI. |
Two honest limits. Keeping audio on the Mac makes that Mac's security part of the answer: disk encryption, a login password and who else uses it matter. And if you turn AI notes on, transcript text does go to two companies, which is the point to raise with your data protection officer if your meetings contain data that should not leave your organisation.
Frequently asked questions
Do AI notetakers store my meeting audio?
Many do, at least for a while, and some keep it until you delete it. The only way to know is the vendor's privacy policy and data processing terms. Look for how long audio is kept, separately from transcripts and notes.
Do notetaker vendors train AI on my meetings?
Some reserve the right to, some offer an opt-out, and some rule it out. Check the vendor's terms and the terms of any AI provider it passes your data to, because the two can differ.
What is a subprocessor?
A company your notetaker vendor uses to process your data, such as a cloud host, a speech-to-text service or an AI model provider. Under GDPR a vendor acting as a processor has to tell you who they are, and most publish a list.
Is on-device transcription more private?
It means the audio does not have to be sent anywhere to become text, which removes the transcription service from the list of places your meetings go. It does not say anything about what the tool does with the transcript afterwards, so the rest of the checklist still applies.