Your AI Notetaker Is Recording Things It Shouldn't. A 5-Minute Privacy Check
TL;DR AI notetakers leak through defaults, not hackers — run a 5-minute check: which meetings to keep it out of, the 5 questions to ask whoever bought it, and the settings to fix today.
In April 2026, the popular notetaker Granola got caught: its security page said notes were “private by default,” but every note was actually shareable by a link — anyone with the URL could read your meeting transcript — and the company used your notes to train its AI unless you manually opted out (reported by The Verge, via TechBuzz, April 2026). Nobody got hacked. The default just didn’t match the word on the label.
There’s an AI bot in most of your meetings now, and you’ve almost certainly never read its settings either. So before your next call, take 3 seconds and check this one — four questions, a verdict, and the one thing to do about it. Nothing you tap leaves your browser.
Is this meeting safe to record?
Four questions about the meeting you’re about to join. Nothing leaves your browser.
Tap yes/no on each to see the verdict.
The check sorts by one rule: can you undo it? A sensitive topic frozen into a transcript can’t be un-recorded, so it goes straight to red. Recording without consent can be illegal the moment you hit record, so it gets its own warning. The rest — outside guests, unchecked default settings — are gaps you can close before recording, so they only add up to yellow. Red means damage you can’t take back; yellow means a fixable gap; green means you’ve already done the thinking most people skip.
Three conversations an AI notetaker shouldn’t be in
If the checker turned red, it’s because of this: some meetings should never become an AI transcript at all. The recurring high-risk categories:
- People matters — performance reviews, HR complaints, terminations, anything about a specific person. A frozen transcript of “what we really think about Dave” is a lawsuit waiting to be discovered.
- Legal and confidential business — contracts, M&A discussions, trade secrets, unreleased product plans. These are exactly the topics that cause the most damage when they leak (tldv, as of June 2026).
- Client and external calls where the other side didn’t agree. When someone from outside your company is on the call, they may have no idea a bot is listening — and depending on where they sit, recording them without consent isn’t just rude, it’s illegal (more on that below). Consent isn’t a courtesy here; it’s the line.
The shared thread: high stakes, real people, lasting consequences. When a meeting has those, the safe move is hands-on notes and a sanitized summary written by a human afterward — not a raw machine transcript.
The part that’s actually the law (US)
The “did everyone consent?” question isn’t just etiquette. In the US, recording a conversation is governed by state wiretapping law, and it splits two ways (recordinglaw.com AI guide, as of June 2026):
- One-party consent (most states — 37 plus DC): the person recording can consent on their own. If you’re in the meeting and you hit record, you’re generally covered.
- All-party consent (around a dozen states, including California, Illinois, Pennsylvania, Massachusetts, Florida): everyone has to agree before recording. Record without that, and it’s a crime, not a faux pas.
Two things make this trickier than “check my state”:
- The strictest state wins. If even one person on the call sits in an all-party state like California, you generally need consent from everyone, no matter where you are (recordinglaw.com, as of June 2026). On a remote team, you usually have no idea where everyone is — so the safe default is: get consent.
- A visible bot is not consent. This is the part people get wrong. A notetaker showing up in the participant list does not count as legal consent — courts are actively testing this, with pending litigation arguing exactly that an auto-joining bot with limited notice “does not constitute legally valid consent” (recordinglaw.com; Mayer Brown, as of June 2026). Consent means people were told and agreed — not that a bot icon was technically on screen.
Two more sharp edges worth knowing, both via Mayer Brown (as of June 2026):
- Voiceprints can trigger biometric law. When a notetaker identifies who said what, it may be building a voiceprint — and Illinois’ Biometric Information Privacy Act (BIPA) requires written consent before collecting biometric data like that.
- AI notes aren’t privileged. In United States v. Heppner (2026), a court held that material prepared with a consumer AI tool wasn’t covered by attorney-client privilege — reasoning, bluntly, that the AI “is not an attorney.” If you assumed your AI-summarized legal call was protected, it may not be.
I’m not a lawyer and this isn’t legal advice — laws differ by state and are shifting fast right now. But the practical takeaway is simple and safe everywhere: ask before you record. That one habit clears the consent question in every state at once.
The 5 questions to ask whoever picked the tool
You may not have chosen the notetaker, but someone did — your manager, IT, or the person who set up the workspace. These are the questions that actually matter, drawn from what privacy reviewers tell teams to ask vendors (tldv, as of June 2026):
- Where is our meeting data stored, and in which regions?
- How long are recordings and transcripts kept before they’re deleted?
- Who can access the notes by default — just the host, the whole company, anyone with a link?
- Does the vendor use our data to train its AI models? (And is opt-out on or off by default? Granola’s was off.)
- Is our data isolated, or processed in a shared system across customers?
If the answer to any of these is “I’m not sure,” that’s your finding. You don’t need to be technical to ask them — you just need to ask before the next sensitive meeting, not after.
For an organization, the baseline most guides point to is a vendor with SOC 2 Type II attestation and GDPR/CCPA compliance, with contract language stating your transcripts won’t be used to train public models (tldv; autointerviewai security guide, as of June 2026). You don’t have to verify that yourself — but knowing the words lets you ask the person who can.
Your 5-minute fix, today
You can close most of your exposure in the time it takes to make coffee:
- Open your notetaker’s settings and find default sharing. If notes are link-shareable or visible company-wide by default, change it so only you (or the host) can see them. This one setting was the entire Granola problem.
- Find the “use my data for training” toggle and turn it off. It’s often on by default and usually buried.
- Make consent a habit. A five-second “heads up, I’ve got AI notes running — everyone good?” at the top of a call covers you and the people on it.
- Learn the pause button. When a meeting drifts into something sensitive, pause recording for that stretch instead of trusting yourself to scrub it later.
None of this requires permission or budget. It’s just the stuff nobody told you to check.
The mindset that keeps you safe
Treat the notetaker like what it is: a fast assistant you’re supervising, not a silent court reporter you forgot was in the room. The danger isn’t that the AI is malicious — it’s that it’s tireless, literal, and permanent, and it will faithfully record the one sentence you’d never have written down.
Same principle as any AI tool at work: it speeds up the boring part, but you stay the one who decides what’s appropriate and signs off on where it goes. The notetaker captures the meeting. You’re still responsible for the room.
Open your notetaker’s settings right now. Check who can see your notes by default. That’s minute one.
This post was drafted with AI assistance and reviewed before publishing. The Granola incident and vendor-question framing reflect sources cited inline as of June 2026; settings and labels vary by tool and change over time, so check your own. This is general guidance, not legal advice.