Is Your AI Notetaker Training on Your Meetings?

Published8 min read

Three of the four most common AI notetakers keep the right to train their own models on your meeting content, and the opt out, where there is one, only protects the meetings you have not had yet. This reads the current privacy policies at Otter, Granola, Fathom and Fireflies, shows why a trial is the moment you are most exposed, and lists what to ask before the first real call.

The answer for each tool, from its own policy

Fireflies says no. Its privacy policy, last updated on 28 September 2026, says it does not use personal information for AI model training, and that meeting content (audio, video, transcripts and summaries) is not used to train internal or external AI models. It also says it contractually prohibits its vendors from training on that information.

The other three keep the right to train their own models. Otter's policy lists, among the ways it uses your information, training its proprietary AI on de-identified audio recordings and on transcriptions, and the policy does not describe a way to switch that off. Granola's policy says it uses de-identified data to train AI models and that you can opt out in your account settings, with Enterprise workspaces opted out by default. Fathom's policy says that, depending on your account settings, it may create de-identified data from meeting content to train and customise its in-house models, and that you can opt out in settings.

Granola and Fathom both say they do not let third parties such as OpenAI or Anthropic train on your data. That is a real commitment, and it is also a narrower one than it sounds when you read it quickly. It is about the model company behind the product. It says nothing about the product company's own models, and for three of these four tools, the product company's own models are where the training happens.

Opting out does not reach back

Most comparison pages stop at whether an opt out exists. The more useful question is what an opt out does to meetings that were already used, and Granola is the only one of the four that answers it in writing. Its policy says that de-identified data which has been incorporated into AI models will not be removed from them, because removal may not be technically feasible without retraining the model from scratch, and that such data may be kept indefinitely.

That is an honest description of how training works, and credit to Granola for putting it in the policy. Once a model has learned from a set of examples, the examples are spread across its weights. There is no row to delete. Otter and Fathom do not address removal at all, and there is no reason to assume their models behave differently.

So the switch in settings is forward only. It stops future meetings from being used. It does nothing about the ones that went in while it was on.

The trial is when you are most exposed

Put that next to how people actually evaluate these tools. You install it on a personal plan, because nobody buys Enterprise to try something. You run it on real calls, because a notetaker tested on a dummy meeting tells you nothing. Over two weeks that might be a pricing conversation with your biggest customer, two candidate interviews, a call with your lawyer and the prep for a board meeting. You look at the settings, if you ever do, when you are deciding whether to pay.

On a plan where training is on until you turn it off, those two weeks of meetings are the ones already eligible for training by the time you find the switch, and by Granola's own account they cannot be taken back out. Granola's Enterprise default runs the other way: off unless an admin turns it on. The most protective default goes to the largest customer, and the founder trying the product alone gets the least protective one, on the calls they chose because they mattered.

The fix costs nothing. Read the training section of the privacy policy and the settings screen before the first real meeting, not after the last one. If the switch exists, flip it on day one. If it does not exist, decide whether you are comfortable before the pricing call goes through it.

What de-identified removes, and what it leaves

De-identification is the safeguard every one of these policies leans on, so it is worth being precise about what it covers. It is designed to strip information that identifies a person: names, email addresses, phone numbers, voices tied to an account. Otter's own wording is careful here. It describes training on transcriptions and adds, in parentheses, that they may contain personal information.

The sensitive part of a work meeting is usually something else. It is the discount you are about to offer, the customer who is thinking of leaving, the acquisition nobody outside the room knows about, the reason a hire fell through. None of that is personal information in the legal sense, and none of it needs a name attached to matter. A policy can de-identify a transcript thoroughly and still describe the business content of your meeting going into a training set.

That does not mean de-identified training is reckless. For many teams it is an acceptable trade for a better product. It means the word answers a question about privacy of people, and most buyers are asking a question about confidentiality of the business.

What to ask before the first real call

Ask these in writing and expect the answer to point at a sentence in the policy or the contract, not at a line on the marketing site.

Does the company train its own models on meeting content, and is that on or off by default on the plan I am buying? Can the model provider behind the product train on it? Does anyone outside the company, such as a data labelling contractor, see meeting content to build training data? Otter's policy lists data labelling providers among the vendors it discloses information to for creating training and evaluation data, so this is not a hypothetical. And if I opt out later, is anything already used removed?

If the answer to the last one is no, and for any product that has already trained on your data it will be, the timing section above is the whole story.

Where Driffle sits

Driffle's privacy policy says it does not use your content to train AI models, its own or anyone else's. There is no setting to find because there is nothing to switch off, which also means there is no trial period during which your meetings were eligible.

The reason is how it is built as much as what the policy says. Summaries, chat and search run on models served by AWS Bedrock inside Driffle's own AWS account, so prompts are not sent to a model company's own API, and AWS does not use Bedrock inputs or outputs to train models. Transcription is the one step that goes to an outside vendor, a speech to text provider working under a no training agreement and named on our subprocessor page.

The limits are worth stating as plainly. This is cloud processing, not on-device processing, so you are relying on a written commitment and an architecture, the same kind of thing you are relying on with any of the tools above. Driffle is also a Mac app for Apple Silicon only today. What it does with that audio is capture without a bot in the call, pull out the decisions and commitments, and let you ask across your meetings later with the answer pointing back to where it came from.

If you want notes from your real calls without them becoming anyone's training data, you can get the Mac app at https://driffle.ai/download.

Sources

FAQ

Does Otter train its AI on my meetings?

Its privacy policy says it trains its proprietary AI on de-identified audio recordings and on transcriptions, which it notes may contain personal information. The policy does not describe a way to opt out of that use. It also lists data labelling providers among the vendors it shares information with to create training and evaluation data.

Does Granola train on my notes?

Granola's policy says it uses de-identified data to train AI models, that you can opt out in account settings, and that Enterprise workspaces are opted out by default. It also says de-identified data already incorporated into models will not be removed, so opting out protects future meetings only.

Does Fathom train on my calls?

Fathom's policy says that, depending on your account settings, it may create de-identified data from meeting content to train and customise its in-house models, and that you can opt out in settings. It says it does not authorise third parties such as OpenAI, Anthropic or Google to train on your meeting content.

Does Fireflies train on my meetings?

No, according to its privacy policy as updated on 28 September 2026. It says meeting content is not used to train internal or external AI models and that its vendors are contractually prohibited from training on it.

If I opt out of training, is my old data removed?

Not necessarily, and usually not. Granola states that de-identified data already incorporated into its models will not be removed because removal may not be technically feasible without retraining. Otter and Fathom do not address it. Treat an opt out as protecting future meetings and set it before your first real call.

Does Driffle train on my meetings?

No. Driffle's privacy policy says it does not use your content to train AI models, its own or anyone else's. Summaries and chat run on models served by AWS Bedrock inside Driffle's own AWS account, and transcription goes to a speech to text provider under a no training agreement, listed on the subprocessor page.

Never lose the thread of a meeting again.

Driffle keeps the decisions, owners, and context from every conversation searchable when work resumes.