Does Your AI Notetaker Keep the Recording?
Most AI notetakers keep the audio. A few discard it within a minute of transcribing it. All of them keep the text, and the default is forever. This answers the question with sentences from each vendor's own documentation, separates the three different things people call recording, and gives you a ten minute check you can run during a trial instead of trusting a sales call.
The short answer
Most of them keep it. A few discard the audio within a minute of transcribing it. All of them keep the text, and unless somebody configures otherwise, they keep it forever. If you are trying to answer a question from a legal team, an IT reviewer or a client's security questionnaire, that split is the whole answer, and almost no vendor page states it in one sentence.
The confusion lives in the word itself. Recording means three different things in this market, so a tool can be truthful about one of them while your policy is worried about a different one. What follows is what four commonly shortlisted tools say in their own documentation, then the part that none of their privacy pages mention, then a check you can run yourself inside a trial.
Recording means three different things
Pulling these apart takes a minute and saves a long email thread later.
A vendor that tells you it does not record is almost always talking about the second one. Nobody is offering to skip the third, and you should not want them to, because the third one is the product you are buying.
- Audio captured. Microphone and system audio are read while the call runs. Every tool in this category does this, including the ones with no bot in the call. There is nothing to evaluate here.
- Audio retained. A file sits on a server afterwards and can be replayed, exported, produced in a legal request, or exposed in a breach. This is what a no recording policy is usually written about.
- Derived text retained. The transcript, the summary and the action items. This outlives the audio in every product mentioned below, it is indexed and searchable, and it is what a human will actually read two years from now.
What the vendors say in their own documentation
Marketing pages are written to be reassuring. Help centres are written to be operated, which makes them the better source. Four tools, quoted directly:
Two patterns, then. Fathom and Fireflies hold the media and put expiry behind the top plan. Granola drops the audio and keeps the text indefinitely until somebody sets a policy. Neither choice is dishonest. They are different products with different bills, because replayable media costs storage and answers the request to play back a moment, while a text only archive is cheap and answers the question about what was agreed.
- Fathom keeps recordings. Its retention article says a retention period is the amount of time recordings are kept before they are automatically deleted from Fathom, that any recording older than the set period will be permanently deleted, and that the feature is available only for users of the Enterprise Plan. So the media is stored, and the ability to expire it sits on the top plan.
- Fireflies meters what it stores. Its storage article says your storage is measured in total meeting minutes stored, not the number of files, and counts live meetings recorded by Fireflies, files you upload, and recordings imported from integrations, at 400 minutes on Free, 8,000 per seat on Pro and unlimited on Business and Enterprise. A product that meters stored minutes is storing the media. That is what a meter is for.
- Otter records on a press and keeps conversations. Its privacy page says Otter starts recording only when you or a meeting participant presses Record or invites Otter to your meeting, and that when you delete a conversation it moves to the Trash, which Otter empties after 30 days. Its help centre also carries an article on exporting conversation audio, and you cannot export audio that was never kept.
- Granola discards the audio and keeps the text. Its security FAQ says that once transcription is complete, the audio is deleted from its systems and any third party services. The same FAQ says notes and transcripts are retained indefinitely unless you or your admin configures a retention policy.
Dropping the audio does not shrink the thing people actually read
Here is the part the privacy pages skip. The transcript is the artifact with the long life and the wide audience. Audio is heavy, awkward to skim and rarely opened twice. Text gets indexed, pasted into Slack, quoted in a board deck and handed over in response to a request. If you picked a tool because it throws the audio away and then left transcript retention at the default, you removed the exposure that decays and kept the one that accumulates.
Which is why asking whether a vendor stores recordings is the wrong opening question in a security review. The useful version is four questions: what do you keep, for how long, who can read it, and what happens to every copy when I delete. Audio retention is one answer inside that, and usually the easiest one.
The host has a separate copy your settings do not reach
One more copy exists that your notetaker's policy says nothing about. If the meeting platform's own cloud recording or transcription was also running, that file lives in the host's account under the host's retention rules. Deleting the meeting from your notetaker does not touch it, and on a customer call or an investor call the host is not you.
So the honest picture for an external meeting is two records that age differently, and only one of them answers to the settings you control. Worth knowing before you promise a client that the call was not retained anywhere.
What Driffle does with the audio, and what it will not claim
Driffle discards it. The privacy page states that audio is transcribed in real time and discarded, that what is retained is the resulting text and the notes you write rather than the raw recording, and it puts a lifespan of under a minute on the audio stage of the pipeline. Nothing starts by itself either: no auto joining, no auto recording, no background process waiting for a calendar event. You press a button, and closing it stops capture.
The part most vendors leave vague is where the audio goes on the way to becoming text. Audio is captured on your device and streamed to a transcription vendor that returns text. The vendor registry names it: Deepgram, receiving meeting audio while a capture is running and returning text, with no calendar, profile or account data. Most tools will not tell you which speech to text service touches the audio. Ask every vendor on your shortlist and compare what comes back, because the ones who answer immediately have thought about it.
There is no on device transcription mode today, and the privacy page says exactly that, including a note that earlier copy implying otherwise described a roadmap item as though it had shipped and was corrected. Processing and the AI run in the cloud. Summaries and chat are generated by models served through AWS Bedrock inside Driffle's own AWS account, under terms that grant the model provider no training rights, so content is not sent to a model company. Transcripts and notes are encrypted at rest with AES 256 in a US AWS VPC, any segment can be edited or deleted, notes stay private until you share them, workspace admins do not see private notes, an individual note is removed immediately, and a full account deletion clears the data within 30 days including the daily encrypted snapshots, which themselves sit in a 30 day window.
The limits belong in the same paragraph as the claims. Driffle runs on Apple Silicon Macs on macOS 14.4 or later, as a direct download rather than through the Mac App Store. Intel Macs, Windows and Linux get a request form rather than a build. Pricing is still a draft, so treat any number you find elsewhere as unconfirmed.
A ten minute check on any tool in the shortlist
You do not need a vendor call for most of this. Five moves, all of which produce evidence you can forward to whoever asked you the question:
- Search the help centre, rather than the marketing site, for the word audio. If retention appears only under an Enterprise heading, you have learned which plan the control lives on.
- Try to export it. If an audio file downloads, the audio was stored. An export button is a retention disclosure that nobody thought of as one.
- Find the retention setting, note which plan it requires, and establish what the default is when nobody configures it. If the documentation does not say, ask in writing and keep the reply.
- Delete one meeting on the first day of the trial, then ask support what happened to the backups and for how long. A vague answer here is itself the finding.
- Ask which subprocessor performs the transcription and whether audio leaves the region you were told it stays in. A vendor who cannot name it has not examined the question as closely as you need.
Where this leaves you
If your policy is about replayable media, the shortlist narrows quickly and you will end up with a text only archive. If your policy is really about who can read what was said, then audio was never the important question, and transcript retention, access control and deletion are where the work sits. In both cases, collect sentences from documentation instead of assurances from a call, because a sentence in a help centre is the thing you can hold a vendor to later.
If a text only archive with the audio dropped is what you want, Driffle is a free download for Mac at driffle.ai/download.
Sources
- Retention Policies in Fathom, defining a retention period as the time recordings are kept before automatic deletion and limiting the feature to the Enterprise Plan
- Understanding storage limits, on storage measured in total meeting minutes stored and the per-plan minute caps
- Security, Privacy and Data FAQs, on audio being deleted once transcription is complete and transcripts being retained indefinitely without a retention policy
- Privacy and Security, on recording starting only when someone presses Record and on the 30 day Trash window for deleted conversations
- Export conversation audio, documenting that a conversation's audio can be exported
- Driffle privacy, on audio transcribed in real time and discarded, the pipeline retention windows, the absence of an on-device transcription mode, and deletion timelines
- Driffle vendor registry, naming Deepgram as the speech-to-text subprocessor and what it receives
FAQ
Does an AI notetaker have to record the meeting to produce notes?
No. Audio has to be captured and transcribed, but it does not have to be retained afterwards. Granola's security FAQ says the audio is deleted from its systems and any third party services once transcription is complete, and Driffle's privacy page puts a lifespan of under a minute on the audio stage and keeps only the text. What retention buys you is playback, so if you need to replay a moment or hand somebody the clip, you need a tool that keeps the media.
Which AI notetakers keep the recording?
On current documentation, Fathom keeps recordings and deletes them only when an Enterprise retention period expires, Fireflies measures your storage in total meeting minutes stored and counts live meetings it recorded along with uploads and imported recordings, and Otter documents exporting a conversation's audio, which means the audio is there. Granola states that audio is deleted after transcription. Check the docs for the plan you are actually buying at the time you buy it, because these policies change and plan gating changes more often.
If the audio is deleted, is the transcript still discoverable?
Yes. Discarding audio removes tone, voice and background conversation, not content. Granola's own FAQ states that notes and transcripts are retained indefinitely unless you or your admin configures a retention policy, and that pattern is the norm rather than the exception. If you adopted a tool for its audio handling, set the transcript retention as well, because the text is the copy with the long life and the wide readership.
Does no bot in the call mean nothing is recorded?
No, those are separate questions. A bot is about whether a participant appears in the list and who is allowed to start capture. Recording is about what is stored once the call ends. A tool with no bot reads audio on your own machine and can still keep that audio for years, and a tool with a bot can throw it away in under a minute. Ask about storage and retention regardless of what joins the call.
What should I ask a vendor in writing?
Five things. Is the audio retained, and for how long by default with no configuration. Which subprocessor performs the transcription, and in which region. How long transcripts and summaries live by default, and which plan the retention control requires. What a delete does to backups, and within how many days. Whether any of the content is used to train models, by them or by their model provider. Answers to those five, in writing, settle almost every security review at this size.