Privacy & security

The Most Private & Secure AI Meeting Notetakers in 2026 (SOC 2, GDPR & HIPAA Compared)

We may earn a commission if you sign up through links on this page. This doesn't affect what we recommend — see our disclosure and methodology.

If your team talks about client data, health information, legal matters, or anything under an NDA, "which AI notetaker is cheapest" isn't the first question — "where does the recording go, and who can see it" is. That's a different comparison than the usual feature-and-price roundups, so here's a dedicated one: what each major AI meeting assistant actually does with your audio and transcripts, based on their own security and privacy pages, not marketing copy.

Short answer: all four tools compared here (Otter.ai, Fireflies.ai, Fathom, and tl;dv) say they do not use your meeting content to train their own or a third-party AI model by default, and all four hold SOC 2 Type II certification. Where they differ is HIPAA support, exactly how "no training" is enforced, data residency options, and how account/data deletion actually works.

Quick comparison

ToolTrains AI on your data by default?SOC 2 Type IIGDPRHIPAAData residency choiceDeletion
Otter.aiNo — de-identifies data before any model trainingYesYesYesNot specified on their security pageDeleted items purge from Trash after 30 days
Fireflies.aiNo — states "0-day data retention" with AI sub-processorsYesYesYesNot specified on their security pageUser-initiated; full data ownership per their ToS
FathomNo for third-party model training; may use de-identified data to improve its own AI (opt-out available in settings)YesYes (DPA available on request for EU/UK)YesUS-based storage; DPA for EU/UKFull deletion after account deletion, backups purged after 7 more days
tl;dvNo — anonymizes metadata and chunks/randomizes meeting segments before any AI sub-processor sees themYesYesNot stated on their security pageYes — choose EU or US processingNot detailed on their security page; see their privacy policy

Table reflects each vendor's own security/privacy pages as of this article's last fact-check (2026-09-10). Compliance claims are self-reported by each vendor; verify current status and get a signed DPA directly from the vendor before relying on this for your own compliance program.

What "SOC 2 Type II" and "GDPR compliant" actually mean here

Two quick definitions, since these terms get used loosely:

Otter.ai

Otter's privacy page states plainly that customer data is not used to train or improve its AI service providers' models, and that any data used internally for its own model improvement is de-identified first so "an individual user cannot be identified." It lists SOC 2 Type 2, GDPR, CCPA, and HIPAA on its compliance page, plus VPAT/Section 508 for accessibility. Deleted conversations move to a Trash folder and are purged after 30 days, with an option to clear them immediately. One general caveat worth knowing regardless of tool: Otter (like any call-recording AI) sits inside call-recording consent law, which varies by state and country — some US states require all-party consent to record, so check your own jurisdiction's rules before turning recording on for a call, independent of what Otter's privacy policy says.

Fireflies.ai

Fireflies' security page is unusually direct about this exact question: "We don't train on it by default unlike other AI companies," and it describes a 0-day data retention policy with its AI vendors and partners specifically to prevent meeting data being retained for training or other secondary uses. It lists SOC 2 Type II, GDPR, and HIPAA compliance, 256-bit AES encryption at rest, and TLS in transit. Fireflies also states users retain full ownership and control of their data per its Terms of Service.

Fathom

Fathom's data security center states that none of its AI sub-processors (it names Anthropic, OpenAI, and Google) are contractually permitted to train their models on Fathom users' data. It does disclose using de-identified customer information to improve its own proprietary AI — with an opt-out available in account settings, which is worth flipping if you'd rather not participate even in a de-identified form. It holds SOC 2 Type II and states HIPAA compliance and GDPR compliance, with data residency in the US and a Data Processing Agreement available on request for EU/UK customers. Account deletion removes recording data and metadata immediately, with a further 7-day window before backups are purged.

tl;dv

tl;dv's security page describes real technical steps to limit what its AI partner (it names Anthropic) can see: metadata like names, emails, and company names are anonymized before sharing, and meeting content is chunked into small segments in randomized order so a full, identifiable meeting is never reconstructable on the model provider's side. It's SOC 2 Type II certified, states GDPR compliance, and lists EU AI Act compliance — a category the other three tools compared here don't mention on their own security pages. tl;dv also lets users choose whether AI processing happens in Europe or the US, which is a genuinely useful lever for EU-based teams that the others don't clearly offer. Its security page doesn't state HIPAA certification, so healthcare teams should confirm that directly with tl;dv before relying on it for anything covering patient information.

So which one should you actually use?

For most teams, all four pass a basic security bar: SOC 2 Type II audited, no AI-model-training on your content by default, encryption in transit and at rest. Where you'd reasonably pick one over another on privacy grounds specifically:

None of this substitutes for reading the current privacy policy and, if you're in a regulated industry, getting a signed DPA/BAA directly from the vendor — self-reported compliance pages are a reasonable starting filter, not a substitute for your own legal review.


Fact-checked against each vendor's own security/privacy pages, not third-party summaries, as of 2026-09-10 (see sources below). Pricing and feature comparisons for these same tools are covered in our other guides — see "Best AI Meeting Note-Takers in 2026" and "Otter.ai vs Fireflies.ai."

Sources checked directly: