Guide

The security checklist for choosing an AI note taker

Before you point a recorder at a client conversation, you need answers to about thirteen questions, and most of them are not on the vendor's marketing page. This checklist gives you each question, why it matters, and what a good answer sounds like. There is a second, shorter set near the end for the things these tools now do beyond storing a recording, because each of those creates another copy of the conversation. Then the whole checklist is answered for Noter AI, including the items where the honest answer is "no" or "not documented".

Updated September 2026

Read this first

This is general information, not legal advice. Laws change, and what applies to you depends on your country, your industry, and the contracts you have signed. If a recording involves health data, legal advice, children, financial records, or anything under an NDA, talk to a lawyer or your compliance team first.

This checklist is for one job: comparing meeting recorders as a buyer. Working through it will not make you compliant with anything. It will stop you finding out later that your client calls were kept in a country you did not expect, or used as training material. The thirteen questions are in the next table, and the rest of the page explains what a weak answer to each one looks like.

Noter AI records, transcribes and summarizes your meetings on iPhone, iPad & Android, in 60+ languages.

The checklist at a glance

Thirteen questions. Copy them into an email and send them to the vendor. The answers matter, and so does how long they take and whether a person wrote them.

These are product-mechanics questions: what the software actually does, who can touch it, and what is left behind. If what you need is the legal version, organised by GDPR article rather than by feature, the vendor questions on is AI meeting transcription GDPR compliant cover the Article 28 contract, the Article 32 measures and the Article 33 clock. The two lists are meant to be used together, one for your lawyer and one for your buying decision.

Question to askWhy it mattersWhat a good answer sounds like
Who inside your company can play back my recordings, and is that access logged?Encryption at rest does not stop staff with access opening a note.A small named group, every open logged, support needs your permission first.
Who holds the encryption keys?If the vendor holds them, encryption protects against outsiders, not insiders.An honest "we do, because the speech model has to read the audio".
Is the model provider's no-training setting switched on for my account?The app can promise no training while the model underneath is left on defaults.Named provider, no-training terms confirmed in writing, on every plan.
Which company actually runs the speech-to-text, and where is it named?The company that sold you the app rarely runs the speech model itself.A company name on a dated subprocessor page, not "leading AI providers".
Where do the backups live, and is that the same region as the live data?Backups routinely sit in a different country from the primary copy.Both regions named, and a heads-up before either one changes.
Is the audio deleted once the transcript exists, and can I shorten that clock?Audio carries tone and everything said before the meeting started.A stated audio retention period, and a setting you control.
What does deleting a note remove, and does the search index entry go with it?Full-text search and AI chat keep a derived copy of your content.Audio, transcript, summary and the index entry, in one action.
How long do deleted items sit in backups?Live deletion can be instant. Backups roll off on their own schedule.A named window, such as 30 days, and what happens in the meantime.
Can I delete the whole account from inside the app, without emailing anyone?A support queue is not a delete button, and it is not on demand.A control in the app that works the same day.
Who can open a share link, and does it expire?Public links are the most common way meeting content leaks.Links need a sign-in, expire on a date, and can be revoked.
Is your breach notification window written into the contract, or only on a policy page?A policy page can be edited on a Friday. A contract cannot.A number in hours, in the agreement you actually sign.
Is the system holding my recordings inside the scope of your SOC 2 or ISO 27001?The vendor picks the scope, so a real report can exclude your data.The document under NDA, with the scope section pointed out.
What does the app ask for on my phone, and is the local audio copy deleted after upload?Permissions, background recording and a phone-side cache are mobile-only risks.Microphone only, a visible indicator, cache cleared once upload finishes.

Encryption, and who can actually read your recordings

Start with encryption, then move past it fast, because it answers less than people think. In transit protects the audio on the hop from your phone to the server. At rest protects the stored file on the vendor's disks. Both are table stakes. Article 32 of the GDPR names encryption and pseudonymisation as example measures, then says what counts as appropriate depends on the state of the art, the cost, the nature of the processing, and the risk to people.

Here is the part vendors rarely spell out. Neither kind of encryption means the vendor cannot read your meeting. The service holds the keys, because a speech model has to see the audio to transcribe it. End-to-end encryption, where only you hold the key, would prevent that, and essentially no AI meeting tool offers it for that reason.

So the real question is access control: who can reach the plaintext, whether that access is logged, and whether support needs your permission to open a note. Dull questions, and far more revealing than the encryption line.

  • Sharing links. If the product creates a link to a note, ask whether anyone holding that link can open it. This is how meeting content leaks in practice, far more often than any attack.
  • A phone in someone else's hands. Ask whether the app itself can be locked with Face ID or a passcode. A small feature covering a large everyday risk.
  • Exported files. The moment you email a transcript as a PDF, the vendor's security stops mattering and yours starts.

Training, subprocessors, and which AI does the transcription

The training question has its own page: does an AI note taker train AI on your recordings. The short version is that the default matters more than the option, and on some products the opt-out only exists on an enterprise plan.

The question people skip is the one behind it. Your audio is almost never transcribed by the company that sold you the app. There is a speech-to-text provider, usually a separate model provider for the summary, and a cloud host underneath. Those are subprocessors, and their terms apply to your recording as much as the vendor's do.

That is not a nice-to-have. Article 28(2) says a processor cannot bring in a sub-processor without the controller's written authorisation, general or specific, and must tell the controller about intended changes so the controller can object. Article 28(4) says the sub-processor takes on the same obligations by contract, and the original processor stays fully liable if it fails. A vendor that will not name its subprocessors cannot give you that chain.

This is also where two words from every privacy policy start to matter. Under EU and UK rules the controller decides why personal data is processed, and the processor does the processing on the controller's instructions. Record a client meeting for your business and you are usually the controller, with the app as your processor, and the speech vendor underneath as a sub-processor. GDPR Article 28 puts the duty on you to use only processors that provide sufficient guarantees, under a written contract. A vendor's compliance page does not move that duty off you.

The same logic applies to telling people you are recording. That duty sits with you, not with the app, and the answer changes by country and by US state. It is covered in do you have to tell people you're recording a meeting.

  • Ask for the list by name. "Industry-leading AI providers" is not a list. You want company names and what each one does.
  • Ask whether the model provider's no-training terms are switched on, and get the answer in writing.
  • Ask what the AI chat feature indexes. Search across all your notes usually means a second copy of your content exists as embeddings, and that copy needs its own retention and deletion answers.

Where your data lives, and the cross-border question

Ask for the storage region, not the head office. A vendor registered in Berlin can run entirely on servers in Virginia.

If you are in the EU or UK and your recordings go to the US, that transfer needs a legal basis. The common route is the EU-US Data Privacy Framework, the European Commission's 2023 adequacy decision covering US companies that self-certify to it. In September 2025 the EU General Court dismissed the first direct challenge to that decision, the Latombe case, and upheld the framework. That judgment was appealed to the Court of Justice of the European Union, and the appeal had not been decided when this page was last updated, on the date shown at the foot of the page. Check the current status before you rely on it. So: the framework is valid law today, and the court that struck down both Safe Harbor and Privacy Shield is hearing the appeal. Do not build something you could not move.

If the vendor is not on the framework, the usual alternative is Standard Contractual Clauses plus a transfer risk assessment. Ask which applies to you.

Two follow-ups that catch people out. Backups often live in a different region from the primary data. And some sectors have hard residency rules, particularly public sector work, healthcare, and parts of financial services. Those differ by country, so check your own regulator.

Retention and deletion, including the backup gap

Every meeting tool runs two clocks, and vendors usually describe one. The transcript is cheap text. The audio is the sensitive artefact, because it carries tone, hesitation, and whatever was said before the meeting officially started. Find the retention sentence for audio specifically. It is often in a different paragraph from the one about transcripts.

Then ask what deletion removes. Your content exists in several shapes: the audio, the transcript, the summary and action items, and usually a search index powering full-text search and AI chat. Ask whether the index entry goes too. That is the piece most often left behind.

Backups are where honest vendors sound worse than dishonest ones. "Deleted from live systems immediately, purged from backups within 30 days" is the truth. "Deleted instantly and permanently everywhere", with no detail, usually means nobody checked.

Check you can delete the account yourself without emailing anyone. Two pages go deeper: how long you should keep meeting recordings and how to delete a meeting recording permanently.

Breach notification, and what certifications really prove

Breach notification is a chain, and you are in the middle of it. Under GDPR Article 33, a controller must notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to people's rights and freedoms. Article 33(2) requires the processor to notify the controller without undue delay. If your vendor sits on an incident for a week, your 72 hours is gone through no fault of yours. Get the commitment in the contract, in hours.

In the United States there is no single federal rule for ordinary business data. All 50 states, plus the District of Columbia, Puerto Rico, Guam and the US Virgin Islands, have their own breach notification laws, differing on what counts as personal information, what triggers a notice, and how fast it must go out. "We will notify you as required by law" means different things in different states.

Now the badges. SOC 2 is not a certification, though nearly everyone calls it one. It is an attestation report written by a CPA firm against the AICPA's Trust Services Criteria: security, availability, processing integrity, confidentiality, and privacy. A Type I report covers how controls were designed at one point in time. A Type II covers whether they actually operated over six to twelve months. Type II is the one to ask for.

ISO/IEC 27001 is a genuine certification, of an information security management system, issued by a certification body rather than by ISO itself, and strongest when that body is accredited by a national accreditation authority. The current edition is ISO/IEC 27001:2022, and organisations certified under the 2013 edition had until 31 October 2025 to transition.

What neither proves is the part that matters to you: the vendor picks the scope. A SOC 2 report can cover one system and exclude the one holding your recordings, and an ISO 27001 certificate states its own scope, which can be narrow. Ask for the document under NDA, then read the scope, the period, and the auditor's exceptions.

  • There is no such thing as HIPAA certification. The US Department of Health and Human Services does not endorse or recognise private HIPAA certifications, and holding one does not absolve anyone of their obligations under the Privacy and Security Rules. For protected health information, the question is whether the vendor will sign a Business Associate Agreement.
  • There is no general "GDPR certified" stamp either. Article 42 allows approved certification mechanisms and seals, issued against criteria approved by a supervisory authority or the European Data Protection Board, valid for up to three years. Even then, Article 42 says certification does not reduce the responsibility of the controller or the processor.
  • No certification is not automatically disqualifying for a small vendor, but it shifts the burden onto plain, specific, written answers. Vagueness plus no audit is what to walk away from.

The mobile questions most checklists miss

Most security checklists for meeting tools were written for browser software, so they skip the questions that only apply on a phone. If your recorder lives in your pocket, you can answer several of these yourself in ten minutes.

  • Which permissions does it ask for? A recorder needs the microphone. If it also wants contacts, photos, or precise location, ask why. Calendar access is reasonable if you use calendar sync.
  • What keeps running when the screen is locked? Background recording is usually a feature you want. Ask what happens on an incoming call or a low battery.
  • Is there a visible indicator? iOS shows an orange dot in the status bar whenever the microphone is in use. Useful for you, and for the person opposite you.
  • Where does the audio sit on the phone? Ask whether the local file is deleted after upload, and whether it lands in your device backup. A cached recording is only as protected as your lock screen.
  • Check the App Privacy Report yourself. On iPhone: Settings, then Privacy and Security, then App Privacy Report, and switch it on. Use the app for a week, then read Data and Sensor Access and Most Contacted Domains. It covers the last seven days and shows who the app talked to.
  • Read the store privacy labels. The App Store's App Privacy section and Google Play's Data safety section are declared by the developer, not audited line by line. A label that contradicts the written policy is worth an email.

The questions that get sharper as the tool gets smarter

Most security checklists for this category were written when an AI note taker did two things: store a recording and store a transcript. Products now do far more with the same conversation, and every extra thing they generate is another copy of it, in text, which travels more easily and attracts less attention than an audio file. These six questions are the ones that only exist because the analysis got deeper.

None of them have a single right answer. They exist so you know what you are holding before somebody asks you to account for it.

  • How many documents does one meeting become? A tool that can render the same recording several ways, as formal minutes, a short bullet summary, a sendable email, a to-do list, a report, or written in your own style, is storing that many separate documents built from one conversation. Ask whether deleting the note removes all of them or only the one on screen, and whether an older render survives after you edit the transcript.
  • What can the assistant read? Chat that answers questions about one note has a small blast radius. Chat that answers across your whole library means anyone who gets into the account can ask what was agreed with a named client, on price, over six months, and get a clean answer without opening a single note. Ask whether that index is per note or per account, whether deleting a note removes it from what the assistant can see, and whether it can be switched off.
  • Do the action items leave the building? Extracted commitments are the output most likely to be pushed somewhere else, into a task tracker, a CRM field or a mail draft. Once they land there they inherit that system's retention and that system's access list, not yours.
  • Can you cut a line out and rebuild everything from the corrected text? An editable transcript is usually sold as an accuracy feature. It is also a redaction control: it is how you strip one sentence that should never have been recorded while keeping a meeting worth keeping. It only works if re-running the summary regenerates the derived documents from the corrected transcript rather than leaving the original wording sitting inside a summary you already generated.
  • Which engine handles your languages, and where does that audio go? Speech-to-text is nearly always a third party, and coverage is uneven across languages. Ask who transcribes the languages you actually speak, whether audio containing more than one language is routed differently, and which region processes it. The transfer answer can differ by language inside a single product, and a checklist that asks only "where is the data stored" will miss it.
  • What are the speaker labels actually doing? Splitting one recording into Speaker 1 and Speaker 2 separates voices inside that file. Matching a voice against a saved profile identifies a person. The first is a convenience feature, the second is biometric identification with a different legal weight, and the marketing page rarely distinguishes them. Ask in writing which one runs.

Run the whole review in 30 minutes

You do not need a procurement process to do this well. This order surfaces problems fastest.

  1. 1Open the privacy policy and use your browser's find function on: train, machine learning, improve our services, subprocessor, retention, delete, transfer. Five minutes, and it answers half the checklist.
  2. 2Open the terms of service and search for notification, liability, indemnity.
  3. 3Look for a subprocessor page. Note whether it exists, names companies, and shows a date.
  4. 4Check for a data processing agreement you can sign, and a Business Associate Agreement if you touch US health data.
  5. 5Ask for the SOC 2 Type II report or ISO 27001 certificate, then read the scope, the period, and the exceptions. Not the logo.
  6. 6Install the app, turn on App Privacy Report on iPhone, record a throwaway meeting, and look at the domains it contacted.
  7. 7Delete that note, then delete the account. Time both, and note whether you could do it yourself.
  8. 8Email support the questions the policy did not answer. How fast and how specifically they reply is real data.
  9. 9Save a dated PDF of the policy you are relying on. Terms change.

The same checklist, answered for Noter AI

Noter AI is the app this site is about, so here is the same checklist applied to it, unflattering answers included. Everything below comes from the published privacy notice, the transparency line in this site's own footer, and the app itself. Where the notice is silent, that is said instead of filled in.

Checklist itemNoter AI's honest answer
Encrypted in transit and at restYes to both. Data is stored in Google Firestore, encrypted at rest and in transit.
Who can read your recordingsThe privacy notice states audio files are accessible only to you, and are never sold or used for marketing. It is not end-to-end encrypted, so that is a policy commitment, not a mathematical guarantee.
Trains AI on your contentNot in those words, and that gap is worth naming. The notice says audio is not sold, not shared for marketing, and not used for any purpose other than providing the service you asked for, which is a no-training commitment in substance. But the word train does not appear anywhere in it, and section 4 does reserve aggregated, anonymised usage data for fixing bugs and improving the app. Treat it as a vendor statement, not a written clause, and ask for it in writing if it matters to you.
Subprocessors namedPartly, and the published list is out of date. The notice names Google Vertex AI for processing audio and Google Firebase/Firestore for storing accounts and transcriptions. Speech-to-text itself runs on Soniox, which is credited in the AI transparency line in this site's footer but is not yet listed in the privacy notice. By this checklist's own standard, a subprocessor that only appears in a footer is not a named subprocessor list, and the notice should say it.
Data location you can chooseNo. The notice says servers are in various regions and data may be processed outside your country.
RetentionDocumented. Paid account data is kept while the account is active. For non-subscriber accounts, audio and transcriptions are deleted automatically after 90 days.
Delete a note, delete the accountYes to both, on demand. The notice states that deleting your account deletes your data immediately.
Backup purge windowNot documented as a number of days. The notice says data that cannot be deleted immediately, such as backup copies, is isolated from further processing until it can be.
Public sharing linksNot a feature. You export to PDF, Word or plain text, so the sharing and the access control are yours.
Admin console, SSO, seat managementNone. A single-user subscription, not an IT-managed deployment. No central admin can audit or revoke another person's notes.
Breach notification commitmentNot documented as a specific time commitment.
SOC 2 or ISO 27001Neither. The Google infrastructure underneath holds its own certifications, which is a different thing and should not be read as a Noter AI certification.
HIPAA Business Associate AgreementNot offered. Do not use it for protected health information.
Mobile behaviourMicrophone for recording, plus calendar access if you connect Google or Outlook calendar. Recording continues with the screen locked, and iOS shows its orange microphone indicator throughout. The phone-side cache lifetime after upload is not documented.
Documents generated per meetingUp to seven summary styles from one recording, each stored with the note. Deleting the note removes the audio, the transcript, every summary generated from it, the action items, any translation and the attached chat history.
What the AI chat can readYour whole library, not one note at a time. That is the point of it and it is also the blast radius: one signed-in session can query every meeting you have ever recorded. No per-note scoping or off switch for the cross-note search is documented, so treat the account password and the device passcode as the control.
Correcting or cutting the transcriptThe transcript is editable and re-running the summary rebuilds it from the corrected text, so a line you remove stops propagating into the derived documents. Useful as a redaction control, not a substitute for deleting the note.
Speaker labels versus voice identificationLabels separate speakers inside one recording. No stored voiceprint, no matching a voice across recordings, so this is diarisation rather than biometric identification.
  • If your organisation requires a signed DPA, a SOC 2 Type II report, or a BAA before a tool touches client conversations, Noter AI does not clear that bar today. Use something that does.
  • Where it fits is individuals and small teams who can accept cloud processing and want the notes without a bot announcing itself in the call. Recording runs from the phone with the screen locked. On the language question above, the honest answer is specific: speech-to-text runs on Soniox, transcription covers 60+ languages with detection always on, and language is tagged word by word rather than fixed for the whole recording, so there is no separate mode to switch on for a bilingual meeting. Nothing in the privacy notice describes a different engine or a different region for particular languages, so on the published information the transfer answer is the same whatever language you speak. Ask them to confirm it in writing if your review needs more than that. For a security review, that is the useful half of the answer, not the language count.
  • The cost shape is different from most of this category, and it cuts both ways on security. $9.99 a month or $49.99 a year, flat, not per seat. Per-seat pricing is the usual reason small teams share one login, and a shared login destroys the audit trail every question above depends on: you cannot say who recorded what, or whose account to close when someone leaves. One subscription per person keeps that clean. The limitation is the mirror image. There is no admin console, so there is nothing central to audit either, no way to force a retention policy across the team, and no offboarding switch. On a phone, device passcode and remote wipe are the controls you actually have.
  • Test it on a real meeting first. iOS and Android, with a free trial, so you can run the phone half of this checklist yourself.

Frequently asked questions

What should I ask an AI note taker vendor about security?

Thirteen things: who inside the company can play back your recordings and whether that is logged, who holds the encryption keys, whether the model provider's no-training setting is switched on for your account, which company actually runs the speech-to-text and where it is named, where the backups live, whether audio is deleted once the transcript exists, what deleting a note removes including the search index, how long deleted items sit in backups, whether you can delete the account from inside the app, who can open a share link and when it expires, whether the breach notification window is in the contract or only on a policy page, whether the system holding your recordings is inside the scope of the SOC 2 or ISO 27001, and what the mobile app asks for on your phone. Most are answerable from the privacy policy in five minutes.

Does SOC 2 mean an AI note taker is secure?

Not on its own. SOC 2 is an attestation report from a CPA firm against the AICPA's Trust Services Criteria, not a certification, and the vendor chooses the scope. A Type I report only covers how controls were designed at one point in time; a Type II covers whether they operated over six to twelve months, which is the one worth asking for. Read the scope, the period, and the auditor's exceptions, because a report can genuinely exclude the system your recordings live in.

Is my meeting audio encrypted end to end?

Almost certainly not, in any AI meeting tool. End-to-end encryption means only you hold the key, and a speech model cannot transcribe audio it cannot read. So these products encrypt in transit and at rest while the provider holds the keys. That protects against interception and stolen hardware. It is not a guarantee that nobody at the vendor could open your note, so judge them on access controls, logging, and retention instead.

Do I need a data processing agreement with my note-taking app?

If you record other people's personal data for your business in the EU or UK, generally yes. GDPR Article 28 says the controller must use only processors giving sufficient guarantees, under a written contract covering the subject matter, duration, nature and purpose of processing, and the processor's obligations. Article 28(2) also means the processor cannot add sub-processors without your written authorisation. Whether it applies to your exact situation is a question for a lawyer, not a checklist.

How fast does a vendor have to tell me about a data breach?

Under GDPR Article 33 the controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware, unless the breach is unlikely to risk people's rights and freedoms. Article 33(2) requires the processor to notify the controller without undue delay, which is what starts your clock. In the US there is no single federal rule for ordinary business data: all 50 states plus DC and the territories have their own laws with different triggers and deadlines. Get a number in hours written into the contract.

Is Noter AI SOC 2 or ISO 27001 certified?

No. Noter AI has no SOC 2 report and no ISO 27001 certificate, and does not offer a HIPAA Business Associate Agreement. What the privacy notice does document is that data is encrypted in transit and at rest, stored in Google Firestore, processed through Google Vertex AI, deletable by you at any time, and removed immediately when you delete your account. Two things it does not document: there is no clause using the word train, and speech-to-text actually runs on Soniox, which is credited in this site's footer but not yet listed in the notice. If your employer requires an audited vendor, that requirement is not met here.

Can I use an AI note taker for health, legal, or HR conversations?

Often not, and this is where a checklist stops being enough. Health data in the US generally needs a vendor that will sign a Business Associate Agreement, and since there is no such thing as HIPAA certification, a badge is no substitute. Legal work runs into privilege and client confidentiality. HR conversations involve information about a person who did not agree to third-party processing. Ask your legal or compliance team first, and take the notes by hand if the answer is unclear.

Let Noter AI take your meeting notes

Record, transcribe, and summarize meetings on iPhone, iPad & Android, or send a bot to Zoom, Teams, Meet, or Webex. In 60+ languages.

Related reading