Guide · for reviewers
An AI notetaker privacy checklist for IT, security and legal reviewers
Use this checklist to review any AI meeting notetaker before people at your organisation use it, whether it joins calls as a bot, records on a laptop or comes built into your meeting platform. Each section has the questions to send the vendor, what a complete answer covers and where vendors usually publish it.
Some organisations have already decided. Case Western Reserve University blocked third-party AI note-taker apps in its Zoom, Teams and Meet meetings from 12 September 2025. It said these apps often try to join future meetings by default, without the other attendees' consent, and that meeting content can go to third parties outside the university's systems (its notice, read 8 October 2026).
Tick each question as the vendor answers it. 56 questions. Your ticks stay in this browser only, if it allows that.
How to use it
- Decide the scope first: who will use the tool, and for which calls. Internal meetings, customer calls and interviews can need different answers.
- Send the questions in writing and keep the answers with the date. A published document, such as a DPA or a subprocessor list, counts for more than a sales call.
- Try the defaults on a trial account with a colleague who agrees to be recorded: what joins, what the others see, and who receives the notes.
- Review again at renewal, and when the vendor changes its terms or its AI providers.
-
Where audio, video and transcripts go
Start here, because every other answer depends on it. A notetaker may join the call as a participant, record on the user's own computer, or run inside the meeting platform, and each of these sends the conversation to a different place.
Ask
-
Retention
Recordings and transcripts tend to outlive the reason they were made. Find out how long each kind of content is kept and who can change that.
Ask
-
Who can see the recordings and notes
Many notetakers send a summary to people after the call. Check who receives it by default, because a default that suits an internal stand-up may not suit a call with a customer or a candidate.
Ask
-
Model training and AI providers
An AI notetaker usually sends transcripts to a language model, and the model may be run by another company. Ask whether anyone trains on that content, and get the answer in the contract.
Ask
-
Bots that join calls
A notetaker that joins from a person's calendar can arrive in meetings that person doesn't host, including meetings at other organisations, and keep coming back to a recurring series.
Ask
If you run Zoom, Microsoft Teams or Google Meet, Keep notetaker bots out lists the settings each platform documents.
-
Consent and notice
People on a call should know it is being recorded or transcribed, and in some places the law requires everyone's agreement. Find out what the notetaker does to tell them and what it leaves to the user.
Ask
Calls that cross borders can fall under more than one rule. Recording law by place has general information, and your lawyer has the answer for your situation.
-
Admin controls
A tool IT can't manage tends to be used anyway, on personal sign-ups. Check what an admin can set centrally and what each user can override.
Ask
-
Deletion
Deletion is only as good as the last copy. A request to remove someone's data has to reach the recording, the transcript, the notes and every copy made from them.
Ask
-
Subprocessors
The companies a vendor relies on handle your data too. Meeting content and billing details often go to different ones.
Ask
-
Security and incident history
Past incidents, and how the vendor handled them, say more than a list of badges. Ask for both.
Ask
-
Accuracy and how the notes are used
Notes written by AI can leave things out or credit words to the wrong person. That matters most when the notes feed a decision about someone.
Ask
Questions
What should an AI notetaker policy cover?
Do the notes built into Zoom, Teams or Meet need the same review?
Do notetakers that record on the user’s own computer need a review?
Who is responsible for getting consent to record?
How often should we review a notetaker again?
Can I send these questions to a vendor?
How Recordist answers it
We make Recordist, so here are its answers to the same questions, for version 0.3.10. The summary for reviewers has the longer version, written to be forwarded, and the managed settings page has what IT can enforce on the Mac computers it manages.
- Where audio and transcripts go
- Recordist is a Mac app. It records the Mac's microphone and sound output into a data folder on that Mac, transcribes there with Whisper and, with the built-in engine, writes the notes there too. Audio never leaves the Mac. Recordist doesn't encrypt these files itself, so they are encrypted at rest when FileVault is on.
- Retention
- Audio is kept 30 days by default, and each person can choose Forever, 90, 30 or 7 days, or deletion right after transcription. Delete meetings after removes whole meetings and is off by default. On managed Mac computers, MaxRetentionDays caps both.
- Who can see them
- The person using the Mac, and programs running under that macOS account. There is no account, no shared library and no link sharing, and the company that makes Recordist receives no audio, transcripts or notes. Exports are copies the person makes and sends.
- Model training
- Recordist receives no meeting content, so it has none to train on. The built-in engine runs open models on the Mac. If a person connects their own Anthropic or OpenAI-compatible key, the transcript goes to that provider under their account and its terms, and the Privacy Ledger records each request.
- Bots
- Recordist never joins a call, so nothing is added to the participant list.
- Consent
- When a call is detected, a card asks the person using Recordist "Record this meeting?", and nothing is recorded until they answer, unless they added that app to the auto-record list, which is empty by default. The Record now button in the main window starts at once. Recordist doesn't tell the other people on the call or ask them, so the user has to.
- Admin controls
- IT can enforce nine managed settings with a configuration profile from its MDM, such as keeping notes on the Mac, turning off cloud AI keys and capping retention. There is no admin console, single sign-on or account, and Recordist reports nothing back to IT.
- Deletion
- Delete meeting…, Delete audio…, Delete all my data and Remove everything and quit all work on the Mac, and there is no server copy to delete. Exports saved to a folder the person chose stay there until they delete them.
- Subprocessors
- No company receives meeting content by default, Recordist included. The app downloads its speech model, notes engine and notes model from Recordist's media host, Hugging Face, GitHub and the Ollama registry, and those downloads carry no meeting content. The privacy policy lists the processors for the website, beta requests and purchases.
- Security and incidents
- Recordist keeps no meeting content on a server. Fixes are listed in the changelog, and the security page names known issues and what to update, such as the optional gateway, which didn't check the token on its HTTP and A2A ports before version 0.1.5. Recordist has no SOC 2 report and hasn't had an independent security audit. Reports to [email protected] are acknowledged within 3 business days.
- Install and platforms
- Early builds aren't notarised by Apple yet, so macOS asks once to allow the first launch, and on managed Mac computers IT may need to allow it. Recordist needs a Mac with Apple silicon and macOS 14.6 or later. Windows and Linux next.
- Accuracy
- Notes can be wrong, and they carry a reminder to check them against the recording. The other side of a call shares one label, and in a room every voice is labelled You.
This page is general information to help with a review, and it isn't legal advice. The one outside source is the Case Western Reserve University notice linked above, read on 8 October 2026. If something here is wrong or out of date, write to [email protected] and we will correct it.