Four of six do not say where transcription happens
For a category whose entire proposition involves sending a meeting somewhere, this is the single most relevant fact, and it is usually absent from the page that exists to answer it.
Features/What leaves your device
Every AI meeting notetaker says it takes privacy seriously. Far fewer say where your audio goes. This page collects what six of them publish, in their own words, with a link to the page each quote came from.
Last checked 9 August 2026 · maintained quarterly · corrections welcome
Where a vendor does not address a question on its own security or privacy page, this table says Not stated. That is not an accusation — it means they have not said, and we are not guessing on their behalf.
| Question | Minuted | Granola | Otter | Fireflies | Fathom | Meetily open source |
|---|---|---|---|---|---|---|
| Transcription runs | On device (Whisper) | Names Deepgram and Assembly as transcription providers | Not stated; AWS named for “compute and data storage” | Not stated | Not stated | On device (Whisper) |
| Audio leaves the device | No — never uploaded, on any plan | Not stated explicitly — see note | Not stated | Not stated | Not stated | No — “Your recordings and audio never leave your device” |
| Audio retained | Yes — kept locally, 30/90/365 days or forever, your choice | No — “doesn’t store the audio from meetings” | Not stated | Not stated | Not stated | Local only |
| Trains AI on your data | No | Yes — “Granola trains on your anonymized data” | Yes — trains “on de-identified audio recordings and on transcriptions” | No — “0-day retention policy ensures that your meeting data is never used for AI model training” | Yes, with opt-out — de-identified meeting content trains “our in-house artificial intelligence models” | No |
| Certifications | None | SOC 2 Type 2; “committed to GDPR” | Not stated on the pages checked | GDPR, SOC 2 Type II, HIPAA | Not stated on the page checked | N/A — MIT licensed |
Scroll the table sideways on a narrow screen; the question column stays put. Quotes are verbatim and nothing is paraphrased into a stronger claim than the source makes.
Transcription runs on the device via Whisper, on Windows and Android. A fully local mode runs both the transcription and the write-up on the machine, with no account and no network connection. In cloud mode the audio still never leaves — only text, the notes and the transcript, goes to the model. Recordings stay on the device with a retention you set: 30, 90 or 365 days, or forever. Keeping them is what makes click-a-line playback possible.
Source: minuted.io/security, which states the same five answers and lists every subprocessor — so this row is sourced the way the others are, rather than to a page only we can see.
Granola’s security page contains two statements that sit awkwardly together. Both are quoted here rather than resolved:
Granola uses best-in-class transcription providers (like Deepgram and Assembly)
it transcribes in real time on macOS/Windows, or after your meeting using temporarily cached audio on Mobile
A named third-party transcription provider generally implies audio reaching that provider. Granola’s page does not state that audio is transmitted, so this table records it as not stated explicitly rather than inferring an answer.
An independent audit reads it as settled, and quotes Granola directly — “we initially tried doing these locally on device, but the computation was too much and it slowed down your computer” — counting 16 subprocessors and concluding that capture is local but processing is not. That is a third-party source, labelled as such.
On training, Granola draws a line between itself and others:
We do not allow third parties (like OpenAI or Anthropic) to use your data to train their AI models. … Granola trains on your anonymized data.
Notes are stored in a US-hosted AWS VPC, encrypted at rest and in transit.
Sources: granola.ai/security and the Routines transparency audit, both read 9 August 2026.
The privacy policy is explicit that audio recordings are training material:
Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information).
Named service providers include Amazon Web Services for “compute and data storage”, plus Amplitude, Google, Stripe and Facebook. Retention periods for recordings are not stated. Otter’s security page carries marketing copy and states none of the above.
Source: otter.ai/privacy-policy, read 9 August 2026.
The clearest published stance against training of the six:
0-day retention policy ensures that your meeting data is never used for AI model training
Also 256-bit AES encryption for notes and transcripts at rest, and TLS in transit. Certified for GDPR, SOC 2 Type II and HIPAA, with a HIPAA BAA on Enterprise. Where transcription happens, and whether audio is retained, are not stated.
Source: fireflies.ai/security, read 9 August 2026.
Trains its own models on de-identified meeting content, and is the only one of the six to offer an explicit opt-out:
we may use and create de-identified data generated from Meeting Content Information to improve our Services by training, improving, and customizing our in-house artificial intelligence models … You can opt out from this use of your data in your account settings.
We do not authorize third parties (e.g., OpenAI, Anthropic, Google, etc) to use your personal information or Meeting Content Information to train their artificial intelligence models.
Retention and transcription location are not stated.
Source: fathom.ai/privacy, read 9 August 2026. Note that fathom.video/privacy redirects here.
Open source, MIT licensed, and fully local:
All processing happens locally. Your data never leaves your device.
Whisper handles transcription, with a choice of Anthropic Claude, Groq Llama or a local Ollama model for the write-up. The first two are cloud services, so “never leaves your device” holds for the local configuration. macOS and Windows, with Linux in development. Community Edition is free; Pro is from $10 per user per month billed annually.
Source: meetily.ai, read 9 August 2026.
For a category whose entire proposition involves sending a meeting somewhere, this is the single most relevant fact, and it is usually absent from the page that exists to answer it.
That is more transparent than the rest of the field, and it deserves saying even though naming them is exactly what makes Granola’s position look weaker than a competitor that stays quiet.
Otter and Fathom both train on de-identified meeting content; Granola trains on anonymised data. Fathom alone offers an opt-out.
Granola says it does not store meeting audio at all. The others do not say how long they keep it, or whether they keep it.
If you work on one of these products and something here is wrong or has changed, email hello@minuted.io and it will be corrected and re-dated.
Transcription on the device, on every plan, on Windows and Android. In local mode nothing leaves at all — no account, no network.