Private meeting notes: keeping transcripts off other people’s servers
Last updated: July 2026
A meeting transcript is one of the most sensitive documents a business produces. It is a verbatim record of who said what — strategy, salaries, client secrets, half-formed ideas nobody meant to commit to. The convenience of AI notetakers has made it normal to hand every one of those records to a third party without much thought. This is a look at where those transcripts actually go, what “on-device by default” changes, and why consent is still part of the picture.
The quiet problem with cloud notetakers
Most AI notetakers work the same way: they capture your meeting, upload the audio, transcribe and summarize it on their servers, and keep the result in your account. It is smooth — and that smoothness hides what just happened. A recording of a private conversation now lives on a company’s infrastructure, under terms almost nobody reads.
Lawyers have started warning about this in plain language. The American Bar Association and multiple firms have flagged that cloud transcripts of privileged or confidential discussions are discoverable, may be retained indefinitely, and in some cases can be used to train the vendor’s models. A library of meeting transcripts is also a concentrated, attractive target for a breach.
Where your transcripts actually live
When you use a cloud notetaker, assume the transcript is stored server-side by default, tied to your account, and governed by a terms-of-service document you can change only by leaving. Many vendors retain recordings and transcripts until you manually delete them. Modern tools also enrich the record with metadata — names, job titles and email addresses pulled from the calendar invite — so over time the archive becomes a detailed map of your organization and its clients.
None of that is inherently malicious; it is simply what “we store it for you” means once you look closely. For a freelancer under an NDA, or anyone discussing a client’s confidential work, that is a real exposure rather than a hypothetical one.
What “on-device by default” means
The alternative is to keep the whole thing on the machine that recorded it. On-device by default means the recording, the transcription and the speaker recognition all happen locally, and no audio or text is sent anywhere unless you deliberately turn on a cloud feature.
The distinction from “bot-free” matters. Several cloud tools dropped their meeting bot in 2026, but they still upload your audio — bot-free is about etiquette; on-device is about where your data lives. The test is simple: if you disconnect from the internet, does transcription still work? If yes, the audio was never going to leave. That is a stronger privacy guarantee than any retention promise, because data that is never sent cannot be stored or leaked by someone else.
Consent is still part of privacy
Keeping notes on your own machine protects them from third parties; it does not settle your obligations to the other people in the meeting. Recording someone without their knowledge is a separate problem — around a dozen US states require all-party consent, and GDPR generally treats a recording as personal data that needs a lawful basis, usually consent. This is not legal advice, and the details depend on where everyone is.
The workable habit is consent-first: say you are recording, note it in the invite, and let people opt out. Private storage and clear consent are two halves of doing this respectfully — one protects the data, the other respects the people in it.
Keeping notes on your own machine
folo is built for the private path: it records, transcribes and recognizes speakers on your Mac, and the default is that nothing is uploaded. Summaries can run fully locally too, and there is a cloud option only if you choose it.
It is deliberately single-user and Mac-only. If what you need is a shared team workspace in the cloud, a tool like Otter or Fireflies is a better fit, and folo vs Otter.ai and folo vs Fireflies.ai say so plainly. But if your meetings involve things that should not sit on someone else’s server, keeping the transcript on your own machine — with everyone’s consent — is the straightforward way to keep them private.
Questions, answered
Are AI meeting notes a privacy risk?
They can be. Most cloud notetakers upload and store your audio and transcripts on their servers, sometimes indefinitely and occasionally to train their models. For confidential or client conversations, lawyers have warned that those stored transcripts are discoverable and a breach target.
What does “on-device by default” mean?
It means recording, transcription and speaker recognition happen on your own computer, and nothing is uploaded unless you deliberately enable a cloud feature. A quick test: if transcription still works offline, the audio never had to leave.
Isn’t “bot-free” already private?
No. Bot-free just means no visible participant joins the call. Several cloud tools are bot-free now but still upload your audio to their servers. Private means the transcript stays on your machine.
Do private notes remove the need for consent?
No. Keeping data on your machine protects it from third parties, but you still need to tell participants you are recording — required outright in all-party-consent states and generally under GDPR. Consent comes first.