
Are AI note takers safe? They can be, but encryption is the smallest part of the answer. The larger risks are recording people without valid consent, keeping transcripts you later have to produce in a legal dispute, and sending audio through vendors you never vetted.
This guide covers the legal exposure, the model-training and subprocessor questions, ten questions to put to any vendor, and the internal settings that matter most.
Why "encrypted" does not mean safe
Encryption protects stored and moving data from outsiders. It says nothing about who is allowed to record, who can read the transcript, how long it exists, or whether the vendor's own pipeline uses it.
Most vendor security pages stop at TLS, AES and SOC 2. Those are worth having. But a meeting can be perfectly encrypted and still be a problem:
- A bot joined an external call without the other side knowing it was recording.
- A transcript sat in a shared workspace and was visible to people who were never in the meeting.
- A sensitive legal discussion was captured verbatim and kept for years.
- Audio passed through a speech engine and a language model hosted by companies you have never heard of.
None of these are failures of encryption. They are failures of defaults, policy and contracts. That is where most of your vetting effort should go.
Are AI note takers safe legally? Consent, wiretapping and discovery
The legal risk comes from recording without consent and from keeping what you recorded. Both are policy decisions you control.
Consent and wiretapping
Rules differ by place. In the US, California Penal Code Section 632 prohibits recording confidential communications without all-party consent, with statutory penalties of up to $2,500 per violation for a first offense. California is not alone: over a dozen US states enforce all-party consent laws for call and meeting recording, including Florida, Maryland, Illinois and Pennsylvania.
The practical problem is that a meeting often includes people in several jurisdictions. The safest rule is also the simplest: announce recording at the start, get a clear yes, and treat the strictest location among your attendees as the standard. If you work across borders, ask counsel about each country involved. For Myanmar specifically, our guide to Myanmar meeting minutes covers the record-keeping rules we have documented.
Discovery and privilege
Consent is only half of it. Retaining indefinite verbatim transcripts creates major electronic discovery (ESI) liabilities during litigation and risks destroying attorney-client privilege during sensitive discussions, according to Jackson Lewis, a US employment law firm.
In plain terms: if a transcript exists, someone can ask for it in a dispute, and an offhand remark in a meeting becomes a searchable document. A summary with decisions and action items is usually enough. A word-for-word record of a conversation with your lawyer is the one you least want lying around.
Two habits reduce this risk:
- Do not run automated recording on meetings with legal counsel or on HR investigations.
- Set a retention period and delete on schedule, ideally under a written policy that your lawyer has seen.
This is general information, not legal advice. Have counsel review your policy.
Model training and subprocessors: where your audio actually goes
Two questions decide where your audio ends up: does the vendor train models on it, and who else handles it along the way.
Model training
Training use is the question people ask most, and the answer varies by product. Some tools ship with model-training opt-outs off by default, and that same check found default settings that can cause unexpected sharing across a whole internal workspace or through public links.
So do not stop at "it's in the settings." Ask for a contractual commitment that your data is not used for training, and ask whether it applies to every plan you might buy, not only the enterprise tier.
Subprocessors
Every AI notetaker relies on third-party subprocessors, such as cloud providers, speech-to-text engines, LLM hosts and analytics, and using the vendor means accepting the data handling practices of everyone in that pipeline.
That matters for two reasons. First, your audio may be processed by a secondary AI service you did not choose. Second, those services may sit in different countries, which complicates data residency promises. A vendor that says "we store data in region X" may still send audio elsewhere for transcription or summarization.
Ask for the full subprocessor list, what each one receives (audio, text, or metadata only), and where it runs. A vendor that publishes this has already thought about it.
10 questions to ask an AI note taker vendor before signing
A good vendor answers these directly and in writing. Fireflies' own guide lists the baseline as SOC 2 Type II certification, a contractual prohibition on AI model training with customer data, and verified data residency. The table adds the questions that guide leaves out.
| # | Question | What a good answer looks like |
|---|---|---|
| 1 | Do you hold SOC 2 Type II, and can we see the report? | Yes, shared under NDA. A Type I or "in progress" is a weaker answer. |
| 2 | Is training on our audio and transcripts prohibited in the contract? | Written into the terms or DPA, not only a marketing page. |
| 3 | Where is data stored and processed? | Named regions for storage and for AI processing. |
| 4 | Who are your subprocessors? | A published list with what each one handles. |
| 5 | Does a bot join calls, and how does it announce itself? | A visible participant, or a clear notice if recording is local. |
| 6 | Is auto-join on or off by default? | Off, or controllable by an admin. |
| 7 | Who can see a transcript by default? | Only the owner until they share it. |
| 8 | What is the retention period, and can we change it? | A defined period, deletable by users, configurable by admins. |
| 9 | What happens to data when we delete a meeting or close the account? | Real deletion, including derived data such as summaries and search indexes. |
| 10 | Will you sign a DPA and notify us of breaches? | Yes, with defined timelines. |
Question 9 is often skipped. Summaries, embeddings and caches are derived copies of your meeting. If deletion only removes the audio, the content still exists.
Internal best practices: auto-join, access and retention
Most real incidents come from defaults nobody changed. A short internal policy fixes more than a long vendor questionnaire.
Stop bots joining by themselves
Some tools join any meeting on a connected calendar. Auto-join settings differ by product, so use this order:
- List every note-taking tool connected to company calendars, including ones individuals added themselves.
- Turn off auto-join, or limit it to meetings the user explicitly selects.
- Check what external guests see when recording starts. If they see nothing, require a spoken announcement.
- Send a test invite from an outside address and confirm nothing joins uninvited.
- Revisit the setting after every major product update, since defaults can change.
Limit who sees what
Set sharing to private by default. Disable public links unless there is a specific need. Use role-based access so that a finance meeting is not readable by the whole company just because everyone is in the same workspace.
Set retention you can defend
Pick a retention period tied to a purpose: long enough to act on the notes, short enough that you are not holding years of verbatim speech. Write it down and enforce it. Exclude legal, HR and board discussions from automatic recording.
Tell people
Add a line to calendar invites for recorded meetings and say it aloud at the start. Participants who know are less likely to object later, and you have evidence of consent if anyone asks.
Choosing less data over more
The safest transcript is the one you never keep, so the practical choice is a tool that collects and stores as little as your workflow allows.
Three design choices cut exposure:
- No bot in the call. Recording in the browser or uploading a file means nothing joins invisibly. It does not remove the consent duty, since you still need to tell people. See our explainer on meeting transcription without a bot for how this works and what to check.
- Short, deletable retention. Fewer months of stored audio means less to produce, leak or lose.
- A short subprocessor list. Fewer parties in the chain means fewer places to audit.
If you are comparing the larger names, our Otter vs Fireflies comparison covers privacy alongside pricing and languages.
No tool is risk-free. A tool that stores nothing is safest for privacy but gives you no searchable history. Decide which trade-off your team can live with, then check each vendor against it.
Where Loka Note fits
Loka Note records meetings in the browser or takes uploaded audio and video, so no bot joins your call. It produces a transcript, summary, decisions and action items, and it is built Burmese-first, including mixed Burmese-English meetings.
On the questions above, this is what we can state. The full details are on our security page.
- Encryption. TLS 1.2+ in transit. At rest, transcripts, summaries, action items, notes and search embeddings are encrypted with AES-256-GCM under a unique per-user key held in Google Cloud KMS. This is defense-in-depth for stored data, not end-to-end encryption.
- Training. Customer audio and transcripts are processed for transcription and summarization only and are never used to train AI models.
- Retention and deletion. Recordings are kept for 6 months and can be deleted at any time. Deleting your account destroys your encryption key, which permanently crypto-shreds the encrypted content.
- Subprocessors. Vercel, Supabase, Google Cloud, Polar (billing), a transactional email provider, PostHog and Sentry.
- Enterprise. Configurable retention, SSO, a signed DPA and an SLA are part of the enterprise tier.
Loka Note does not remove your consent obligations. You still need to tell participants and follow the rules where they are.
Try it on a real meeting and check the settings against the questions above: start at app.lokanote.com/signup
Frequently asked questions
Are AI note takers legal to use without asking participants?
Often not. Many jurisdictions require everyone's consent before a confidential conversation is recorded, and over a dozen US states enforce all-party consent, including California, Florida, Maryland, Illinois and Pennsylvania. Tell participants at the start and get agreement, and check local law for the places your attendees sit.
Do AI meeting note takers train their models on my company data?
It depends on the vendor and sometimes on the default setting. Some tools ship with model-training opt-outs switched off. Ask for a contractual commitment that your audio and transcripts are not used to train models, rather than relying on a settings page.
Can meeting transcripts be used in a lawsuit?
Stored transcripts are records, and records can be requested in litigation. Indefinite verbatim transcripts raise electronic discovery costs and can put attorney-client privilege at risk when sensitive topics are discussed. Set a retention period and keep privileged conversations out of automated recording.
How can I stop AI bots from automatically joining my calendar invites?
Turn off auto-join in the tool's settings, review which calendars are connected, and restrict which meetings a bot may enter. Then confirm with a test invite that nothing joins without a visible notice to participants.
What security certifications should an AI transcription vendor have?
SOC 2 Type II is the usual baseline. It is not enough alone. Also ask for a contractual ban on training models with your data, a clear statement of where data is stored, and a list of subprocessors.
Sources
- 1Are AI Notetakers Safe? An Honest Look at Privacy, Consent, and Data Practices [2026]fireflies.ai
- 2Your AI Notetaker Is Recording Things It Shouldn't. A 5-Minute Privacy Checkappshot.app
- 3A Zero Trust Guide to AI Note Takers | STACK Cybersecuritystackcyber.com
- 4AI Notetaker Security: The 2026 Enterprise Checklistcoommit.com
- 5AI notetaker: how it works, consent law, and limitsteamshift.io
- 6We Get Privacy — Episode 4: Assessing the Risks of AI Toolsjacksonlewis.com


