AI Meeting Note Privacy: What to Check Before You Record
A concrete privacy review for meeting note tools: who hears the audio, where the file goes, and how long anyone keeps it.
The privacy question for an AI meeting note tool is not whether the homepage says "private." It is whether you can point to the path of this recording: who captured it, whether it left the device, who can open the note, and when the audio is deleted.
Use the checklist on one real meeting before you turn a tool on for a team. Vendor statements below were taken from public pages on 7 October 2026. They are not a certification of Whisper Web, and this article does not claim a security audit.
Five checks that change the decision
- Capture. Does a bot join, does an app record device or system audio, or do you transcribe a file afterward? Invisible capture still needs the same consent as a bot. Wispr Flow Notetaker says it captures audio locally and that participants may not get an automatic notice, so the user has to tell them.
- Processing. On-device transcription and an upload are different. Granola's pricing table says audio is deleted after transcription. Wispr's Notetaker FAQ says meeting audio is encrypted and stored temporarily on the device and, in some cases, in cloud storage, then deleted. Whisper Web's free path processes in the browser. Unlimited uploads the file for cloud transcription.
- Retention of the note, not just the audio. Granola Basic keeps 30 days of meeting history. Business and Enterprise list unlimited history, with workspace-wide auto-deletion only on Enterprise. A deleted audio file plus a permanent transcript is still a record.
- Training. Granola lists a per-user training opt-out on every plan and a workspace-wide opt-out on Enterprise. Wispr's pricing page lists "models never trained on your data" as an enterprise control, and says you can opt out on other plans. Read the setting, then screenshot it for the review.
- Admin reach. If any employee can connect notes to Claude, ChatGPT, or another tool through MCP, the note leaves the meeting product. Granola and Wispr both advertise that connection. Decide whether it is allowed before someone turns it on.
How Whisper Web fits that list
What Whisper Web can and cannot do with the file
Use this only when the job is a recording you already have, or a microphone recording you make in the browser. Whisper Web is not a meeting bot, an enterprise meeting workspace, or a dictation layer that types into other apps.
- Free, in the browser: transcription stays on the device. Free files are limited to 200 MB and 20 minutes. A free dashboard batch accepts up to 5 files. Export the edited text as TXT, Word, SRT, VTT, or JSON.
- Unlimited, in the cloud: the published plan is US$20 per month, or US$120 per year. Files are uploaded for cloud transcription. The published limits are 10 hours or 5 GB per file, with batches of up to 50 files, saved history, and sync across devices. The pricing FAQ says those uploaded files are deleted after transcription. Cloud jobs need a network connection and start from the dashboard.
- Microphone, not system audio: the in-browser recorder asks for the microphone. It does not capture the other side of a Zoom, Meet, or Teams call. Record that audio in the meeting app or the operating system, then open the file.
- No automatic speaker names: the transcript is one continuous text. Add speaker names yourself while editing. The interview transcription page states this directly.
- First visit downloads a model: the free path needs a network connection the first time the speech model is fetched. The product FAQ says free transcription can continue offline after that download. This article does not add a new offline test, so try it on your own machine before you rely on a room with no network. Loading the website still needs a connection.
Free local processing is the option that avoids an upload, inside the 200 MB and 20 minute gates. It is not a company-wide control center. There is no SSO switch that stops a colleague from uploading a file to a different product. The older essay on privacy in speech recognition describes browser-side models. Read this checklist for the operational questions, and read that essay as background, not as a statement that every Whisper Web plan stays on the device.
For the meeting itself, the bot-free workflow is the practical sequence: consent, save a file, transcribe, export only what you will share.
Run the review on paper
- Name the meeting and the people who are not employees.
- Write the capture method: bot, device audio, system recording, or file.
- Write where the audio bytes go on the free path and on the paid path. If the vendor page is ambiguous, do not fill the gap with a guess.
- Write who can open the transcript next week, and whether an AI connector can read it.
- Transcribe one short sample on meeting transcription only after those lines are filled in. Use the dashboard for a long file only if the upload line is an accepted risk.
Limits of this checklist
A public pricing table is not a penetration test. SOC 2 or HIPAA language on a vendor page means that vendor says those programs exist for specified plans. Whisper Web's public pricing does not claim SOC 2, ISO 27001, or HIPAA. Do not borrow another product's compliance marks. Also do not treat "audio deleted" as "no record remains" if the transcript, summary, and chat history are still in the account.
Frequently asked questions
Is a bot-free tool automatically more private?
No. It can be less visible to the other participants. Privacy depends on consent, where audio is processed, and what happens to the note. A visible bot with a short retention policy can be a better control than a silent recorder that keeps notes forever.
Does local transcription remove every copy?
It removes the transcription vendor's copy only if the audio never leaves the device. You still have the original recording, the exported text, and any place you paste that text. Delete those yourself if the meeting requires it.
What should I do with a recording over 20 minutes?
On Whisper Web it cannot use the free local gate. Either cut a short excerpt for a local draft, or accept Unlimited cloud upload and the pricing FAQ's statement that the uploaded file is deleted after transcription. Keep the transcript retention decision separate.
Transcribe after the checklist, not before
For a file you are allowed to process on the device, start with meeting transcription. Move a long recording to the dashboard only when the upload is an explicit choice.
Open meeting transcriptionRelated articles
Private Meeting Transcription Without Bots: A Practical Guide
Choose a bot, a device-audio notetaker, or a recording you transcribe afterward. Then match that choice to local or cloud transcription limits.
The Future of Privacy in Speech Recognition
Browser-side speech models keep free, short transcriptions on the device. Unlimited cloud transcription is a separate path and does upload the file.
Granola AI Review: Meeting Notes Are Not the Same as a Transcript
What Granola's public plans actually include, and when a saved recording should be transcribed as a file instead.
How to Choose an Enterprise AI Meeting Note Tool
A buying checklist for teams that need shared meeting notes, and a separate path for transcribing the recording you already have.