How to share meeting summaries securely
Last updated: July 2026
The riskiest moment for a private conversation is often not the recording — it is the sharing. A meeting summary that travels as an open “anyone with the link” URL, or as a forwarded email that keeps getting forwarded, can outlive the reason you sent it. This is a practical guide to getting a summary to the people who need it without handing it to the people who don’t.
The quiet risk in a share link
Most notetakers make sharing frictionless with a link, and frictionless is exactly the problem. An “anyone with the link” URL grants access to whoever it reaches, indefinitely, with no idea who has opened it; some are indexable or guessable; and a link pasted into a chat or forwarded email spreads on its own. A summary of a client call or a salary discussion behind such a link is one careless forward away from the wrong inbox. The default of “share broadly, revoke never” is the opposite of what a sensitive record needs.
Share the summary, not the recording
The simplest way to reduce risk is to send less. A recipient almost never needs the raw audio or the full verbatim transcript — they need the decisions, the action items and the next steps. Sharing a concise summary instead of the recording is data minimisation in practice: it is smaller, it exposes far less, and it is what people actually read. Keep the audio and full transcript for yourself, on your own machine, and let the summary be the thing that travels.
Use channels you actually control
Once you are sharing only the summary, put it through a channel you control:
- Send the content, not a link to a live store. A pasted recap in an email or message can’t be silently re-shared from a vendor’s dashboard.
- Prefer access control over open links. Name specific recipients, and if you must use a link, make it expiring and permissioned rather than public.
- Use an encrypted or trusted channel for anything sensitive, rather than a public URL.
- Redact before you send. Strip the aside about a third party, the half-formed number, the name that does not need to travel.
What not to put in a summary you send outside
An external recap is not your private notes. Before it leaves, take out the things that were true in the room but should not travel: candid remarks about people who were not there, unconfirmed figures, internal-only context, and anything covered by someone else’s confidentiality. A good habit is to keep two versions — your full internal notes, and a leaner client-facing recap that contains only what that audience is meant to see.
Consent and who is allowed to see it
Sharing is its own processing step, not just the recording. The people in the meeting consented to being recorded; that is not automatically consent to their words being forwarded onward. Before you send, check who is genuinely entitled to see the summary, and be careful with anything that identifies a participant — under the GDPR a shared transcript is still personal data. When in doubt, share less and to fewer people. GDPR-compliant meeting recording covers the underlying obligations.
Doing it in folo
folo is built so you control the channel. Because the recording, transcript and summary live on your Mac, nothing is shared until you deliberately send it — there is no vendor dashboard quietly holding a link. A summary can be copied as Markdown to paste wherever you like, or the one-click follow-up drafts an email or a message with just the decisions and action items, so the lean recap is the thing that travels while the full record stays with you. See the export and follow-up manual for the specifics. For keeping the underlying notes private in the first place, see private meeting notes.
Questions, answered
How do I share a meeting summary securely?
Send the summary rather than the recording, use a channel you control instead of an open “anyone with the link” URL, prefer named access or expiring links, and redact anything that should not travel.
Is it safe to share an AI meeting summary by link?
Public share links are risky: they grant access to whoever the link reaches, indefinitely, and spread when forwarded. Prefer sending the content directly, or use permissioned, expiring links.
What should I leave out of a shared summary?
Candid remarks about absent people, unconfirmed numbers, internal-only context, and anything under someone else’s confidentiality. Keep full internal notes separately from the leaner recap you send outside.
Do I need consent to share a meeting summary?
Being recorded is not automatic consent to being quoted onward. Check who is entitled to see it, be careful with anything identifying a participant, and share less when unsure — a shared transcript is still personal data under GDPR.