TL;DR: Five AI meeting assistants sit in your call, record the audio, and turn it into notes. They give five different answers on what happens next. Otter.ai's privacy policy says it uses "de-identified audio recordings and... transcriptions" to train its proprietary AI [1]. Fireflies says "You own your data. We don't train on it by default unlike other AI companies" [2]. Granola says it "do[es] not retain or store such recordings once the transcription is created" and trains only on de-identified data, which enterprise workspaces opt out of by default [3]. Zoom's blog says it "do[es] not use any customer audio, video, chat, screen sharing, attachments, or other communications like customer content... to train Zoom's or its third-party artificial intelligence models", and Zoom's fiscal-year-2026 SEC Form 10-K describes its federated AI as able to "dynamically select from multiple AI models, including those from OpenAI, Anthropic, and NVIDIA" [4][5]. Microsoft Learn says "Your data isn't used to train foundation models" for Microsoft 365 Copilot and Copilot Chat [6][7]. Otter is also the subject of a consolidated federal class action, In re Otter.AI Privacy Litigation, in which a judge on August 13, 2026 let claims under the federal wiretap statute, the California Invasion of Privacy Act, BIPA, and the California UCL survive a motion to dismiss [8]. None of these companies is doing the same thing. Pick the right one for what you actually need it to do.
What "Training" Means Here, and Why It Matters
When a meeting-AI assistant says it may "train" on your data, it means the transcript, and in Otter's case the audio, can be fed back into the model that powers the next meeting summary you receive. Training is different from "we logged it for debugging" or "we used it once to make your summary". Training improves the assistant for everyone tomorrow, at the cost of the conversation you thought was one-time.
Two follow-on facts are usually hidden in the same sentence. The first is whether training is opt-in (you have to turn it on) or opt-out (it is on by default and you have to find the switch). Otter's policy lists training on de-identified data as a purpose of processing [1]. Granola trains on de-identified data but Enterprise workspaces are "opted-out by default" [3]. Fireflies says "We don't train on it by default" [2]. Zoom and Microsoft both say they do not train on customer content at all [4][6][7].
The second follow-on fact is whether anyone in the assistant's supply chain (the company's own models plus any third-party LLMs it routes requests to) sees the same conversation. Zoom's federated approach sends content to OpenAI, Anthropic, and NVIDIA models to generate the answer, per Zoom's fiscal-year-2026 Form 10-K [5]. Microsoft's own Copilot documentation also names Anthropic models, which it says are "currently excluded from the EU Data Boundary and when applicable, in-country processing commitments" [6]. Whether each third-party provider separately retains or trains on the routed request is governed by its own contracts; the meeting-assistant vendor's "no training" claim does not automatically transfer to every model in the federation.
Side-by-Side Comparison
| Tool | Trains on your recordings by default? | Encryption | Who can read transcripts | Notable |
|---|---|---|---|---|
| Otter.ai | Yes, on de-identified audio and transcripts [1] | "Physical, administrative, and technical safeguards"; specific algorithm not named [1] | Otter plus categories of recipients including cloud, data-labeling, AI service providers, and law enforcement [1] | Subject of In re Otter.AI Privacy Litigation in N.D. Cal.; CIPA, ECPA and BIPA claims survived motion to dismiss Aug 13, 2026 [8] |
| Fireflies.ai | No. "We don't train on it by default unlike other AI companies" [2] | "256-bit AES encryption for meeting notes and transcripts at rest, and TLS encryption" [2] | "Meeting content remains inaccessible without explicit user consent"; Super Admin sees entire workspace [2] | "Certified for GDPR, SOC 2 Type II, and HIPAA compliance" [2] |
| Granola | On de-identified data; "Enterprise Workspace Products... opted-out by default" [3] | "All Personal Data is encrypted at rest and in transit using AWS's encrypted database system" [3] | Granola plus named vendors; workspace admins can override user preferences [3] | "We do not retain or store such recordings once the transcription is created" [3] |
| Zoom AI Companion | No. "Zoom does not use any customer audio, video, chat, screen sharing, attachments, or other communications like customer content... to train Zoom's or its third-party artificial intelligence models" [4] | Zoom platform-level encryption; specific AI-output algorithm not stated in the cited blog [4] | Zoom plus the federated LLMs it routes to per its FY2026 10-K: OpenAI, Anthropic, NVIDIA [5] | "Federated approach" lets Zoom mix its own model with third-party LLMs to generate each answer [5][9] |
| Microsoft 365 Copilot | No. "Your data isn't used to train foundation models" [6]; "Conversations from Microsoft 365 Copilot remain read-only for you and are not used to train Copilot's generative AI models" [7] | "Encryption at rest and in transit, rigorous physical security controls, and data isolation between tenants" [6] | Microsoft as data processor for organizational tenants [6] | "Prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models" [6] |
Otter.ai: Default Training, and a Federal Lawsuit
Otter.ai's Privacy Policy lists "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)" as one of the purposes for which Otter uses the data you upload [1]. The de-identification is Otter's own process. The Otter policy separately lists categories of recipients of personal information: cloud service providers, platform support providers, data labeling service providers, artificial intelligence service providers, mobile advertising tracking providers, analytics providers, payment processors, and "law enforcement agencies, public authorities or other judicial bodies" [1].
Otter is a defendant in federal litigation about how it records meetings. The consolidated class action is captioned In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal.), before Judge Eumi K. Lee [8]. The published order cites claims under ECPA, CIPA, BIPA, unjust enrichment, declaratory judgment, and the California Unfair Competition Law as surviving the motion to dismiss, alongside other claims the court dismissed [8]. No court has held that Otter broke the law.
On August 13, 2026, Judge Lee granted in part and denied in part a motion to dismiss [8]. Claims surviving the ruling include the federal Electronic Communications Privacy Act (ECPA), the California Invasion of Privacy Act (CIPA), Illinois Biometric Information Privacy Act (BIPA), unjust enrichment, declaratory judgment, and the California Unfair Competition Law (UCL) [8]. That is a pleading-stage ruling, not a finding that Otter broke the law, but it keeps Otter's training-on-third-parties default on the litigation table [8].
Fireflies.ai: "We Don't Train on It By Default"
Fireflies' security page states it directly: "You own your data. We don't train on it by default unlike other AI companies" [2]. The same page describes a "0-day retention policy" with all vendors and partners, with the explicit goal that "your meeting data is never used for AI model training" [2].
Of the pages cited here, Fireflies' is the only one that names a specific encryption algorithm. The security page describes "256-bit AES encryption for meeting notes and transcripts at rest, and TLS encryption" [2]. The page does not describe the post-meeting lifecycle of audio files or retention durations for non-Enterprise users. Fireflies is "Certified for GDPR, SOC 2 Type II, and HIPAA compliance" [2]. Meeting content "remains inaccessible without explicit user consent" unless a Super Admin is enabled for the workspace, in which case that admin gets "Full meeting access to your entire workspace" [2].
Granola: Audio Deleted After Transcription, Opt-Out Workspace Settings
Granola's privacy policy is the shortest on retention of raw audio. Under "Data Retention": "Any recordings of communications using our Services are captured only for the purposes of providing you a transcription. We do not retain or store such recordings once the transcription is created" [3]. For de-identified data, retention "may be retained indefinitely" [3].
Granola also turns the training opt-out into a structural default rather than a per-user setting. The policy summary says: "We only use de-identified data to train AI models, which you can opt-out of within your Granola account settings. Enterprise Workspace Products have admin-enforced settings and are opted-out by default" [3]. Granola's storage runs on "Amazon Web Services ("AWS") servers located in the U.S." [3].
What Granola does not allow is third-party training on your data. Under "AI Model Training": "Granola may use aggregated and de-identified data to evaluate and improve our AI systems", and "We do not allow third parties, such as OpenAI or Anthropic, to use your Personal Data for AI model training" [3].
Zoom AI Companion: "Federated" Across OpenAI, Anthropic, and NVIDIA
Zoom's stated position is a flat no-training commitment. Zoom's blog post "How Zoom's terms of service and practices apply to AI" was published on August 7, 2023 and updated on February 7, 2024, and it says: "Zoom does not use any customer audio, video, chat, screen sharing, attachments, or other communications like customer content (such as poll results, whiteboard, and reactions) to train Zoom's or its third-party artificial intelligence models" [4].
To generate summaries and answers, Zoom uses a federated AI approach. Its fiscal-year-2026 SEC Form 10-K describes it as able to "dynamically select from multiple AI models, including those from OpenAI, Anthropic, and NVIDIA" [5]. A separate March 2024 Zoom AI Research blog post describes Zoom pairing its own small language model with "Anthropic Claude-3" and "OpenAI GPT-4" [9]. NVIDIA is the third LLM partner named in the 10-K but is not named in the March 2024 research blog post.
What the public documentation does not specify is what each federated LLM provider sees, how long it sees it for, or whether the OpenAI, Anthropic, and NVIDIA inference endpoints retain or train on the routed prompts under their own policies. Zoom's "no training" claim covers Zoom and "its third-party" providers, and the FY2026 10-K's named providers are OpenAI, Anthropic, and NVIDIA [4][5].
Microsoft 365 Copilot: Foundation Models Not Trained On Your Tenant
Microsoft's posture is the most detailed, and the most restrictive by default. The Microsoft Learn article "Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat" is the authoritative document for organizational tenants, and it states: "Your data isn't used to train foundation models: Microsoft Copilot Chat uses the user's context to create relevant responses. Microsoft Copilot also uses Microsoft Graph data. Consistent with our other Copilot offers, the prompts, responses, and data accessed through Microsoft Graph aren't used to train foundation models" [6].
The Copilot Privacy FAQ is more pointed about the read-only nature of your conversation history: "Conversations from Microsoft 365 Copilot remain read-only for you and are not used to train Copilot's generative AI models" [7].
Encryption and tenant isolation are spelled out in the same Learn article: "We help protect your data with encryption at rest and in transit, rigorous physical security controls, and data isolation between tenants", with commitments including GDPR, the EU Data Boundary, and ISO/IEC 27018 [6]. Anthropic models specifically are noted as "currently excluded from the EU Data Boundary and when applicable, in-country processing commitments" [6]. Web queries to Bing are a separate flow and have their own data handling [6].
What You Can Do Before the Next Meeting
Each assistant has its own behavior, and most of the controls live in two places: the workspace admin settings and the assistant's data or training toggle. None of these controls bind the people you invited to the meeting, who may be running their own bot.
- If training matters and you control the workspace: pick an assistant whose own policy says it does not train (Zoom AI Companion, Microsoft 365 Copilot) or whose default is off (Fireflies, Granola Enterprise). Otter's privacy policy lists training on de-identified recordings and transcripts as a purpose of processing [1].
- If you are the invitee rather than the host: ask the host which bot is on the invite and whether they have turned training off. A bot running on another participant's account is subject to that participant's settings, not yours.
- For all-party-consent jurisdictions: a meeting bot may record a call without all-party consent depending on how the assistant handles the consent banner and the audio channel. If you are recording a sales call or an interview with someone outside your organization, treat the bot as a recording device under your state's wiretap law, not as a passive note-taker. A bot on a participant's account may also surface in litigation as one participant's secret recording of others on the call.
- For confidential conversations (HR, legal, medical, security incidents): do not let a meeting bot join by default. The retention and access claims above describe the documented behavior of each assistant as of October 2026, not a guarantee about any future incident, breach, or policy change. If the conversation would not be safe to leak to your vendor's staff, do not send it to the vendor's model.
- For audit-heavy environments: prefer an assistant whose third-party model list is in writing (Zoom's FY2026 10-K names OpenAI, Anthropic, and NVIDIA [5]) and whose data-residency commitment is in writing (Granola names AWS in the U.S. [3]; Microsoft Learn names encryption and EU Data Boundary commitments [6]).
The Honest Takeaway
"AI notetaker" is one product category, but the five most common assistants in it are five different products. Otter.ai trains on de-identified recordings and transcripts and is a defendant in a consolidated federal class action over how it records meetings [1][8]. Fireflies says it does not train by default and gives a specific AES-256 at rest [2]. Granola deletes the raw audio after transcription and opts Enterprise workspaces out of training by default [3]. Zoom says it does not train on customer content but routes inferences through OpenAI, Anthropic, and NVIDIA models [4][5]. Microsoft 365 Copilot says foundation models are not trained on tenant data and describes encryption and tenant isolation [6][7].
The choice that the marketing pages do not foreground is the third-party routing question. A no-training promise from the assistant vendor does not say which models handle the request. Zoom names OpenAI, Anthropic, and NVIDIA [5]; Microsoft notes that Anthropic models sit outside its EU Data Boundary commitments [6]. If that matters to you, ask the vendor which model providers process your meetings and under what terms.
All five are evolving. Each will ship another policy update and several will face another lawsuit. Recheck the policy before recording anything you would not want the vendor's subcontractors to read.
Sources
- Otter.ai Privacy Policy
- Fireflies.ai Security
- Granola Privacy Policy
- Zoom, How Zoom's terms of service and practices apply to AI (August 7, 2023; updated February 7, 2024)
- Zoom Communications, Form 10-K for fiscal year ended January 31, 2026 (SEC filing; describes OpenAI, Anthropic, NVIDIA as federated LLM providers)
- Microsoft Learn, Enterprise data protection in Microsoft Copilot and Microsoft Copilot Chat (updated August 18, 2026)
- Microsoft Support, Privacy FAQ for Microsoft Copilot
- In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal., Judge Eumi K. Lee) Order on Motion to Dismiss (August 13, 2026)
- Zoom AI Research, Zoom's federated AI approach delivers superior quality for most popular features (March 26, 2024)