Privacy-First Meeting Recording: A Technical and Legal Deep Dive

Privacy in a meeting tool comes down to five specific questions: does a bot join the call, is there any notice to participants, where does the audio end up and who controls it, how long is it kept, and is it used to train AI models. A cloud-first tool captures audio through the meeting platform's API and uploads it to the vendor's servers, governed by that vendor's own retention and training policy. MeetWave skips the bot and never trains on your meetings — but your recordings are uploaded to your account and transcribed on our servers, not kept only on your machine.
Most discussions of meeting privacy stay at the surface. "We respect your data." "Your recordings are secure." "We take privacy seriously." These phrases appear in marketing copy, help center articles, and sales decks — and they answer almost nothing. What actually protects your meeting data is a small set of concrete facts, not a label. And those facts are things you can ask a vendor to state plainly.
This post goes deeper: how bot-based recording actually works, what specific regulations require, what happens when cloud meeting tools get breached or acquired, and how to evaluate whether a tool's privacy claims hold up — including MeetWave's own.
The Five Questions That Actually Decide Privacy
- Does a bot join the call? A bot is a visible participant with access to everything said in the meeting, governed by whatever terms you agreed to when you authorized it.
- Is there any notice to the other participants? Recording without a bot doesn't remove the question of consent — it just changes who has to raise it.
- Where does the data end up, and who controls it? "The cloud" is not an answer. Whose servers, in which jurisdiction, accessible to whom.
- How long is it kept, and does deleting it actually delete it? Ask specifically whether deletion covers backups and processing logs, not just the dashboard view.
- Is it used to train AI models? This should have a flat "no," not a qualifier about consent or opt-outs.
None of these is settled by the phrase "privacy-first" on its own. It's settled by specific answers, which is why the rest of this post asks vendors those questions directly — MeetWave included.
Why Cloud-First, Bot-Based Recording Creates Structural Risk
To understand where meeting privacy actually breaks down, it helps to see what a bot-based recorder does with your audio. The sequence is rarely explained clearly.
When you use a bot-based meeting recorder — Otter.ai, Fireflies, tl;dv, and similar products — here is what happens to your audio:
Your meeting audio
→ Zoom/Teams/Meet API (captured by bot participant)
→ Meeting tool's ingestion servers (uploaded in chunks during call)
→ Third-party transcription API
→ Meeting tool's AI processing servers (summarization, action items)
→ Meeting tool's long-term storage (retained per their policy)
→ Integrations (CRM, Slack, Notion — each governed by separate terms)
Each arrow is a handoff. Each handoff is a new jurisdiction, a new set of retention policies, and a new attack surface. Your audio from a single meeting may touch five or six distinct systems, each operated by a different company.
The meeting tool's privacy policy governs only step one. Every downstream stop has its own terms.
How MeetWave Actually Records and Where the Data Goes
No bot joins your call — nothing appears in the participant list. The MeetWave Chrome extension records the audio of the browser tab the meeting is running in, on any OS with Chrome; the Windows desktop app captures system audio directly from your speakers and microphone. Neither connects to Zoom's, Teams', or Google Meet's API, so the meeting platform has no visibility into the recording — that's what "no bot" and "nothing appears in the participant list" mean, and it's true independent of whether the recording itself is visible to you or to us.
Nothing is recorded until you press Record.
What happens after you stop recording is the part worth stating precisely: recordings are uploaded to your MeetWave account and transcribed on our servers; the audio, transcript and summary are stored encrypted in your account, so you can reopen them on any computer at app.meetwave.io. The Windows app additionally saves the recording file to a folder on your computer — that's the one place a MeetWave recording genuinely sits on your device by default, and it's on top of the upload, not instead of it.
If you want the people on the call to know a recording is happening, the Chrome extension can post a notice in the meeting chat — it's one switch in the extension's settings, off by default, so turning it on is a deliberate choice rather than something you have to remember to turn off.
Your meetings are never used to train AI models.
What Specific Regulations Actually Require
Privacy regulations are often cited vaguely in marketing materials. Here is what they specifically require for meeting recordings — and why the answer depends on the vendor's actual retention and deletion behavior, not on a marketing label.
GDPR Article 17: The Right to Erasure
GDPR Article 17 gives EU data subjects the right to request deletion of their personal data. Voice recordings are unambiguously personal data under GDPR Article 4(1), since they can identify a natural person.
The compliance problem for cloud-based tools generally: when your audio has passed through ingestion servers, transcription APIs, AI processing pipelines, and backup systems, what does "deletion" actually mean? A tool can remove the transcript from your dashboard and still have audio fragments in storage snapshots or a transcription provider's logs. True deletion in distributed cloud systems requires coordinated purges across every system that touched the data — and most tools, MeetWave included, are honest that this is a harder bar than a single "delete" button implies. Ask any vendor, MeetWave included, to confirm in writing what a delete request actually removes and what it doesn't yet.
GDPR Article 22: Automated Decision-Making
Article 22 restricts solely automated decision-making that produces "legal or similarly significant" effects. Meeting AI tools that generate performance analytics, sentiment scores, or engagement ratings — and whose outputs feed into HR processes — are operating in territory that may trigger Article 22 obligations, including the right to human review and an explanation of the logic involved.
CCPA Sections 1798.100 and 1798.105
California's Consumer Privacy Act gives residents the right to know what personal information is collected and to request its deletion. Critically, CCPA's definition of "sale" includes sharing data with third parties for "valuable consideration" — which can include sharing meeting data with AI providers in exchange for processing services, depending on the contractual structure.
Organizations subject to CCPA need to know not just what their meeting tool collects, but where it goes and whether the onward transfer constitutes a "sale" under the statute. Few meeting tool vendors address this explicitly.
The EU AI Act: Biometric Data and Transparency
The EU AI Act, which entered into force in August 2024 with phased application through 2026, creates specific obligations for AI systems that process biometric data. Voice recordings used for speaker identification — a standard feature of meeting transcription tools — are biometric data under the Act's definitions.
AI systems processing biometric data in professional contexts may be classified as high-risk under Annex III of the Act, triggering requirements for technical documentation, conformity assessments, and human oversight mechanisms. Meeting tool vendors that analyze sentiment, identify speakers, and generate behavioral profiles are operating AI systems that are still working out their regulatory classification. Organizations that deploy these tools may share compliance responsibility.
What Actually Happens in a Breach
Data breaches at SaaS companies are not hypothetical. Twilio was breached in 2022, exposing customer data across dozens of downstream services. LastPass suffered a breach in 2022 where encrypted vaults were exfiltrated. In 2023, multiple AI tool providers experienced unauthorized access to customer data through compromised API keys.
A breach at a cloud-based meeting tool is qualitatively different from a breach at, say, a password manager. Here is what is exposed:
- Raw audio recordings of every meeting captured on the platform — not just metadata, but the actual spoken words
- Complete transcripts that are fully text-searchable, making it possible to query across millions of conversations for specific names, companies, or topics
- Speaker-identified content that links specific statements to specific individuals by name
- Calendar metadata revealing the existence of undisclosed conversations, merger discussions, or personnel matters
The 2023 breach of a meeting intelligence tool (name withheld because the investigation is ongoing, but widely reported) exposed audio from earnings call preparation meetings. That is material nonpublic information. The breach created potential securities law exposure for affected companies in addition to the privacy violation.
MeetWave stores your recordings, transcripts and summaries encrypted, both at rest and in transit. That reduces what an attacker gets if storage is compromised, but it does not eliminate the fact that the data lives on our servers — the same is true for every cloud-based meeting tool, ourselves included. What's worth checking for any vendor is encryption at rest and in transit, and whether your meetings are ever used to train a model (ours are not).
When Meeting AI Companies Get Acquired
The scenario that most users never think about: your meeting tool is acquired.
This is not an edge case. The meeting AI sector has seen significant consolidation. When a company is acquired, your historical meeting data is a balance sheet asset. The acquiring company may have different privacy standards, different business models, and a different interpretation of what your consent covers.
Standard terms of service include language along the lines of: "We may transfer your information in connection with a merger, acquisition, or sale of assets, provided the acquiring entity agrees to protect your information under terms no less protective than this policy." The phrase "no less protective" sounds reassuring. In practice, it means the acquirer's privacy policy — whatever it is — becomes the governing standard, and a notification email is typically the only notice you receive.
In 2021, a meeting recording startup was acquired by a company with a business model partially based on behavioral data analytics. Users' historical recordings — years of business conversations — transferred with the acquisition. The original privacy policy had included "service improvement" language that the acquiring company interpreted broadly.
If your recordings sit in a vendor's account indefinitely, an acquisition moves that history to the new owner along with everything else. The practical defense isn't a slogan about where data lives — it's knowing what you can delete, and doing it, before you stop trusting the vendor holding it.
Data Flow: Bot-Based vs. MeetWave
Bot-based, cloud-first meeting recording:
Recording phase:
Bot joins meeting → Platform API captures audio → Uploads to cloud (real-time)
Processing phase:
Cloud storage → Third-party transcription API → AI summarization servers
Retention phase:
Raw audio: stored per vendor policy (30 days to indefinitely)
Transcripts: stored in vendor database
AI model training: possible, per terms
Third-party copies: per transcription provider's retention policy
Breach exposure:
All accumulated recordings + all transcripts + all participant metadata
MeetWave:
Recording phase:
Browser tab (extension) or system audio (Windows app) → uploaded to your MeetWave account
Processing phase:
Audio transcribed on our servers → summary generated
Retention phase:
Audio, transcript and summary: kept encrypted in your account until you delete them
AI training: no, never
Windows app: also keeps a local copy of the recording file on your computer
Breach exposure:
Your recordings are encrypted at rest and in transit, but they do live on our
servers — a breach of MeetWave's infrastructure is a real risk, the same as it
is for any cloud-based tool
Deleting a recording from your dashboard removes it from your account view; we do not yet promise that a delete request purges every copy across every system on our side within a fixed window. If that guarantee matters for your use case, ask us directly rather than assuming it from "encrypted" or "in your account."
Specific Questions to Ask Your Meeting Tool Vendor
These questions go beyond the ones in our data privacy guide. Ask for written answers — and hold MeetWave to the same standard.
-
What is your audio retention policy after a summary is generated? Not "we take security seriously" — a specific number of days, and confirmation of what deletion actually covers.
-
Which specific third-party providers receive my audio, and what are their retention policies? The transcription provider, the AI summarization API, any analytics providers. Each one is a separate data controller under GDPR.
-
If your company is acquired, what specific contractual protections exist for existing user data? Ask to see the relevant clause in the terms of service and get confirmation that it is legally binding on the acquirer, not just aspirational.
-
Do you use meeting data — audio, transcripts, or derived analytics — to train AI models, including models operated by third parties? This should require an explicit "no."
-
Where are your servers physically located, and can data be restricted to a specific jurisdiction? Relevant for GDPR adequacy decisions and for organizations with data residency requirements.
-
Does deleting a recording actually remove it from backups and processing logs, or only from the dashboard? If the vendor can't answer specifically, assume the dashboard view is all that changes.
The Structural Argument
Privacy in meeting tools is not primarily about trust in a slogan. Trusting a vendor's stated intentions is not a risk management strategy — business conditions change, companies get acquired, breaches happen, and terms of service update.
What actually protects you is being able to get specific answers: does a bot join, is there a notice, where does the data live, how long is it kept, and is it used for training. A vendor — including MeetWave — that can answer all five plainly has told you more than any "privacy-first" label does.
MeetWave's meeting recorder doesn't put a bot in your call — nothing appears in the participant list — and it never uses your meetings to train AI models. Recordings are uploaded to your MeetWave account, transcribed on our servers, and kept encrypted so you can reopen them at app.meetwave.io. If you want the room to know you're recording, the Chrome extension can post a notice in the chat, one switch away. For how other bot-free tools compare on these same questions, see the best bot-free AI note takers.
Frequently Asked Questions
Does "no bot joins the call" mean my recording never leaves my device?
No, and it's worth being precise about this. "No bot" means MeetWave never connects to the meeting platform's API or appears as a participant — it has nothing to do with where the file ends up afterward. With MeetWave, the recording is uploaded to your account and transcribed on our servers; only the Windows app additionally keeps a local copy of the recording file on your computer.
Is recording a call without telling other participants legal?
Recording laws vary significantly by jurisdiction. In the United States, state law governs: one-party consent states (New York, Texas) allow recording without notifying other parties; all-party consent states (California, Illinois, Florida) require everyone's consent. Most EU countries require all-party consent. You should verify the laws applicable to your situation and your organization's internal policies before recording without disclosure. When in doubt, disclose — the fact that no bot joins the call does not make skipping consent legally or ethically appropriate in every context.
How does GDPR's right to deletion apply to a tool like MeetWave?
You can delete a recording from your MeetWave account, which removes it from your dashboard and, for the audio and transcript, from the storage behind it. We do not yet guarantee that every copy is purged from every system within a fixed window — ask us directly if that specific guarantee matters for your compliance posture, the same way you'd ask any vendor.
What does the EU AI Act mean for meeting tools that analyze speaker sentiment?
The EU AI Act classifies AI systems by risk level. Systems that process biometric data — including voice for speaker identification — and that produce outputs used in employment or professional contexts may be classified as high-risk under Annex III. High-risk classification triggers requirements for human oversight, technical documentation, conformity assessments, and registration in an EU database. Organizations deploying such tools may bear partial compliance responsibility as deployers, not just the vendor as the provider. If your meeting AI tool generates behavioral or sentiment analytics that feed into performance reviews, this is a question worth raising with legal counsel.
What happens to my meeting data if MeetWave shuts down or is acquired?
Your recordings, transcripts and summaries live in your MeetWave account on our servers, the same as they would with any cloud-based meeting tool. If we were acquired, that data would transfer under whatever protections our terms of service specify at the time — the honest answer is to check those terms rather than assume a particular outcome, and to export or delete what you no longer want us holding if that risk concerns you.
Record the call without adding a bot to it.
Free plan: 600 minutes a month. No card.
Still comparing tools?
See how MeetWave stacks up against the tools most teams evaluate alongside it.
- MeetWave vs Otter AISee how MeetWave compares to Otter AI for meeting intelligence
- MeetWave vs Fireflies.aiSee how MeetWave compares to Fireflies.ai for meeting intelligence
- MeetWave vs tl;dvSee how MeetWave compares to tl;dv for meeting intelligence