The Most Private & Secure AI Meeting Notetakers in 2026 (SOC 2, GDPR & HIPAA Compared)
We may earn a commission if you sign up through links on this page. This doesn't affect what we recommend — see our disclosure and methodology.
If your team talks about client data, health information, legal matters, or anything under an NDA, "which AI notetaker is cheapest" isn't the first question — "where does the recording go, and who can see it" is. That's a different comparison than the usual feature-and-price roundups, so here's a dedicated one: what each major AI meeting assistant actually does with your audio and transcripts, based on their own security and privacy pages, not marketing copy.
Short answer: all four tools compared here (Otter.ai, Fireflies.ai, Fathom, and tl;dv) say they do not use your meeting content to train their own or a third-party AI model by default, and all four hold SOC 2 Type II certification. Where they differ is HIPAA support, exactly how "no training" is enforced, data residency options, and how account/data deletion actually works.
Quick comparison
| Tool | Trains AI on your data by default? | SOC 2 Type II | GDPR | HIPAA | Data residency choice | Deletion |
|---|---|---|---|---|---|---|
| Otter.ai | No — de-identifies data before any model training | Yes | Yes | Yes | Not specified on their security page | Deleted items purge from Trash after 30 days |
| Fireflies.ai | No — states "0-day data retention" with AI sub-processors | Yes | Yes | Yes | Not specified on their security page | User-initiated; full data ownership per their ToS |
| Fathom | No for third-party model training; may use de-identified data to improve its own AI (opt-out available in settings) | Yes | Yes (DPA available on request for EU/UK) | Yes | US-based storage; DPA for EU/UK | Full deletion after account deletion, backups purged after 7 more days |
| tl;dv | No — anonymizes metadata and chunks/randomizes meeting segments before any AI sub-processor sees them | Yes | Yes | Not stated on their security page | Yes — choose EU or US processing | Not detailed on their security page; see their privacy policy |
Table reflects each vendor's own security/privacy pages as of this article's last fact-check (2026-09-10). Compliance claims are self-reported by each vendor; verify current status and get a signed DPA directly from the vendor before relying on this for your own compliance program.
What "SOC 2 Type II" and "GDPR compliant" actually mean here
Two quick definitions, since these terms get used loosely:
- SOC 2 Type II is an independent auditor's report confirming a company's security controls (access control, encryption, incident response, etc.) were operating effectively over a period of months — not just designed on paper. All four tools here claim it; ask any vendor for their actual report (usually available under NDA) rather than taking the badge on faith.
- "GDPR compliant" as a vendor claim usually means they offer a Data Processing Agreement (DPA) and follow standard contractual clauses for EU data transfers — it's not a certification with one universal bar the way SOC 2 is. If your organization is EU-based, ask specifically for their DPA and where processing happens, which is exactly why tl;dv's EU/US processing choice and Fathom's on-request DPA matter more than the "GDPR compliant" label alone.
Otter.ai
Otter's privacy page states plainly that customer data is not used to train or improve its AI service providers' models, and that any data used internally for its own model improvement is de-identified first so "an individual user cannot be identified." It lists SOC 2 Type 2, GDPR, CCPA, and HIPAA on its compliance page, plus VPAT/Section 508 for accessibility. Deleted conversations move to a Trash folder and are purged after 30 days, with an option to clear them immediately. One general caveat worth knowing regardless of tool: Otter (like any call-recording AI) sits inside call-recording consent law, which varies by state and country — some US states require all-party consent to record, so check your own jurisdiction's rules before turning recording on for a call, independent of what Otter's privacy policy says.
Fireflies.ai
Fireflies' security page is unusually direct about this exact question: "We don't train on it by default unlike other AI companies," and it describes a 0-day data retention policy with its AI vendors and partners specifically to prevent meeting data being retained for training or other secondary uses. It lists SOC 2 Type II, GDPR, and HIPAA compliance, 256-bit AES encryption at rest, and TLS in transit. Fireflies also states users retain full ownership and control of their data per its Terms of Service.
Fathom
Fathom's data security center states that none of its AI sub-processors (it names Anthropic, OpenAI, and Google) are contractually permitted to train their models on Fathom users' data. It does disclose using de-identified customer information to improve its own proprietary AI — with an opt-out available in account settings, which is worth flipping if you'd rather not participate even in a de-identified form. It holds SOC 2 Type II and states HIPAA compliance and GDPR compliance, with data residency in the US and a Data Processing Agreement available on request for EU/UK customers. Account deletion removes recording data and metadata immediately, with a further 7-day window before backups are purged.
tl;dv
tl;dv's security page describes real technical steps to limit what its AI partner (it names Anthropic) can see: metadata like names, emails, and company names are anonymized before sharing, and meeting content is chunked into small segments in randomized order so a full, identifiable meeting is never reconstructable on the model provider's side. It's SOC 2 Type II certified, states GDPR compliance, and lists EU AI Act compliance — a category the other three tools compared here don't mention on their own security pages. tl;dv also lets users choose whether AI processing happens in Europe or the US, which is a genuinely useful lever for EU-based teams that the others don't clearly offer. Its security page doesn't state HIPAA certification, so healthcare teams should confirm that directly with tl;dv before relying on it for anything covering patient information.
So which one should you actually use?
For most teams, all four pass a basic security bar: SOC 2 Type II audited, no AI-model-training on your content by default, encryption in transit and at rest. Where you'd reasonably pick one over another on privacy grounds specifically:
- Healthcare or anything HIPAA-scoped: Otter, Fireflies, and Fathom all state HIPAA compliance directly; tl;dv's security page doesn't, so confirm with them first if this matters to you.
- EU-based team, want data processed in-region: tl;dv is the only one of these four that lets you pick EU processing explicitly; Fathom offers a DPA on request but processes in the US.
- Want the most technically specific answer to "how do you keep the AI vendor from reading my whole meeting": tl;dv's chunking/anonymization approach is the most detailed public explanation among the four.
- Want a written guarantee your content never touches AI training, full stop: Fireflies' "0-day retention with all vendors and partners" language and Otter's "no customer data will be used to train" statement are the most unambiguous; Fathom is the one tool here that does use de-identified data for its own model by default (opt-out available), worth knowing if "default off" matters more to you than "opt-out available."
None of this substitutes for reading the current privacy policy and, if you're in a regulated industry, getting a signed DPA/BAA directly from the vendor — self-reported compliance pages are a reasonable starting filter, not a substitute for your own legal review.
Fact-checked against each vendor's own security/privacy pages, not third-party summaries, as of 2026-09-10 (see sources below). Pricing and feature comparisons for these same tools are covered in our other guides — see "Best AI Meeting Note-Takers in 2026" and "Otter.ai vs Fireflies.ai."
Sources checked directly:
- Otter.ai — otter.ai/privacy-security
- Fireflies.ai — fireflies.ai/security
- Fathom — help.fathom.video (security & data retention articles)
- tl;dv — tldv.io/features/security-commitment