Privacy
Where Your Meeting Recordings Actually Go
A plain walkthrough of the data path behind AI notetakers: who holds the audio, who can retrieve it, and which questions to ask before you switch one on.
When a notetaker joins your call, the audio does not stay on your laptop. It takes a fairly long journey, and most people adopt these tools without ever seeing the map.
This is not an argument that the tools are dangerous. It is an argument that you should be able to describe the path before you agree to it, particularly when the voice being carried along it belongs to someone else who did not choose the vendor.
The usual path
For a typical cloud notetaker, roughly this happens:
- Capture. Either a bot joins as a participant, or a desktop app records the audio your machine can hear. Bot-free means the bot is not visible. It does not mean nothing is captured.
- Upload. Audio leaves your device for the vendor’s infrastructure, normally a major cloud provider in a region you did not pick.
- Transcription. The audio is converted to text, sometimes by the vendor, often by a third-party speech model. That is a second company touching the recording.
- Summarization. The transcript goes to a large language model, frequently a third provider again, to produce the summary and action items.
- Storage. The audio, the transcript, and the summary are retained so you can search them later. Retention is usually indefinite by default.
- Distribution. The result may sync to a CRM, a shared workspace, or a team library, where the audience is much wider than the people who were on the call.
So a single thirty-minute conversation can end up in the hands of the vendor, a speech provider, a model provider, and a CRM, and be visible to colleagues who were never in the room.
The questions worth asking
Before switching a notetaker on, especially for conversations involving clients, candidates, or friends, these are the ones that actually matter:
- Retention. How long is the audio kept by default, and can you delete it in a way that reaches the sub-processors too?
- Sub-processors. Who else touches the recording? Most vendors publish a list. It is usually longer than people expect.
- Training. Is your content used to improve models, and is the opt-out on by default or something you have to find?
- Access. Inside your own organization, who can retrieve a recording of a conversation you had? Admin access is often broader than participants assume.
- Region. Which jurisdiction does the data sit in, and does that match the obligations you have to the other person?
- Deletion on exit. When you cancel, what happens to the archive?
If your answer to most of these is “I assume it is fine,” that is the actual finding. It probably is fine. But you are making a promise on someone else’s behalf without knowing what you promised.
Why this is not fearmongering
Cloud notetakers are legitimate software and most vendors handle this responsibly. SOC 2 reports, encryption in transit and at rest, and regional hosting are real and worth something.
The point is narrower: the more parties hold a copy of a conversation, the more places it can be retrieved from, subpoenaed from, misconfigured, or breached. That is arithmetic, not suspicion. And the risk is not evenly shared, because the person whose voice is in the file is often not the person who agreed to the terms.
For a sales call about pricing, this is a reasonable trade and the recording earns its keep. For a candidate explaining why they are leaving, or a client discussing a family situation that explains a decision, the same trade looks different.
The short path
There is a version of this with almost no path at all.
You have the conversation. Nothing is recorded. Afterwards you write two or three lines about what you now know, and those stay on your device, encrypted, visible to you alone. There is no upload of anyone’s voice, no speech vendor, no model provider holding a transcript, no team library, and nothing to delete from four systems if you change your mind.
The trade is real: you give up the verbatim record, permanently. For anything where the exact words matter later, that is the wrong trade and you should use a proper recorder with proper consent.
For remembering people, it is usually the right one, and it is what Intriq is built to do. The data path is short because there is no audio in it.
That is worth knowing before you decide, in either direction.