How long to keep meeting recordings, and when to delete them
Most meeting audio should be gone within 30 to 90 days. The transcript and the summary can stay much longer, because they are small, searchable, and far less sensitive than the raw recording. Almost nobody plays back a Tuesday standup a year later, so keeping that audio is a cost with no matching benefit. Below is the reasoning, a sample schedule you can copy, and the handful of rules that really do name a number.
Updated September 2026
The short answer
- Default to 30 to 90 days for audio. That covers the realistic window in which someone needs to hear the exact words again. After that the transcript answers the question faster anyway.
- Keep the transcript longer than the audio, and the summary longer than the transcript. Three different assets, three different risks, three different periods. This is the single most useful idea on this page.
- There is no general law that says how long to keep a meeting recording. In the UK and EU, GDPR tells you to keep personal data no longer than you need it and leaves the number to you. Sector rules and a few company-law rules set real minimums, and those are listed further down.
- Match the period to the risk, not to the storage cost. Storage is cheap. A five-year-old recording of a heated HR conversation, sitting in a shared account, is not.
- Stop deleting the moment a dispute looks likely. A legal hold overrides your schedule. Nothing on this page beats that rule.
- Write it down on one page and actually apply it. An undocumented policy is the same as no policy when a regulator or a lawyer asks what you do.
Noter AI records, transcribes and summarizes your meetings on iPhone, iPad & Android, in 60+ languages.
Read this first: this is general information, not legal advice
This page explains how retention decisions are usually made and points at real, named rules so you can check them yourself. It is not legal advice, and it is not a compliance sign-off for your organisation.
Retention rules differ by country, by US state, by sector, and by the contracts you have signed. A rule that binds a broker-dealer in New York has nothing to do with a design studio in Berlin. A hospital, a school, a law firm, and a two-person agency all land in different places. Laws and regulator guidance also change, and this page carries a date at the top for that reason.
If a recording could end up in a dispute, a regulatory inspection, or a subject access request, get the schedule checked by a lawyer or your data protection adviser before you rely on it. That review is cheap compared with the alternative.
One more thing worth settling before retention: whether you were allowed to record at all. Consent rules vary sharply by country and by US state, and they are covered separately in do you have to tell people you're recording a meeting.
The recording, the transcript and the summary are three different things
Most retention arguments get stuck because people treat one meeting as one object. It is not. A recorded meeting produces at least three assets, and they do not deserve the same treatment.
The audio is the most sensitive and the least used. It carries tone, hesitation, side comments, the person who joined late and complained about a colleague, and the voice of everyone in the room. Voice is personal data on its own. Audio is also the largest file and the hardest to search.
The transcript is the working record. It is text, so you can search it, quote it, and redact a line from it. It still contains everything that was said, so it is not harmless, but the risk profile is lower and the usefulness is much higher.
The summary, the decisions, and the action items are the part with lasting value. Six months later, nobody wants 9,000 words. They want what was agreed, who owns it, and by when. That fits on half a page.
So the pattern that works for most teams is simple. Delete the audio early. Keep the transcript for a medium period. Keep the summary and the decisions for as long as the work they describe matters. You lose almost nothing operationally and you shrink the sensitive pile fast.
There is one caveat, and it matters. If the exact wording could ever be contested, the audio is your evidence and a transcript is a derived document with mistakes in it. That applies to disciplinary meetings, contract negotiations, and formal interviews. For those, keep the audio for the full period, or keep none of it at all and take contemporaneous written notes instead.
Why keeping everything forever is a liability, not an asset
The instinct to keep everything comes from a good place. You never know what you will need. But a growing archive of meeting audio works against you in ways that are easy to list and hard to argue with.
- Everything you hold is discoverable. In litigation, records you still have can be requested. Records you deleted on a documented schedule, before any dispute was on the horizon, generally cannot be held against you the same way. Routine deletion under a written policy is a normal, defensible practice.
- Every recording is a breach waiting for a bad day. The size of a data breach is decided by what was in the account when it happened. A team that keeps 90 days of audio has a smaller problem than one holding four years of it.
- Subject access requests get expensive. Under GDPR, a person can ask what personal data you hold about them. If that means combing through 600 recordings, someone spends a week on it. If it means 40 transcripts and a folder of summaries, it is an afternoon.
- Old audio decays into a misleading record. A recording from three years ago, with no context and half the participants gone, invites the wrong conclusion more often than it settles anything.
- Consent does not stretch forever. People agreed to a meeting being recorded. Very few of them assumed that recording would sit in a shared account indefinitely. Keeping it far past the stated purpose is exactly what the storage limitation principle is aimed at.
- Nobody can find anything anyway. Archives without a retention rule are almost always archives without a naming rule either. Volume by itself does not produce recall.
A sample retention schedule by meeting type
Copy this, then adjust it. The point is not that these exact numbers are right for you. The point is that a meeting type should decide the period, and that the audio should almost always go before the notes do.
| Meeting type | Audio | Transcript | Summary and decisions | Why this period |
|---|---|---|---|---|
| Internal standup or team sync | Delete once the transcript exists | 30 days | 1 year | Nobody replays a standup. The decisions are the only durable part. |
| Project and planning meeting | 30 days | 1 year | Life of the project plus 1 year | Context is useful while the work runs and for the post-mortem. |
| Client or sales call | 90 days | 1 to 2 years | Life of the account, plus the local claim window | Disagreements about what was promised surface late, and usually in writing. |
| Contract or vendor negotiation | Term of the contract | Term of the contract | Term plus the local limitation period | In England and Wales a simple contract claim can be brought for 6 years. US states vary. |
| Board or shareholder meeting | Delete once the minutes are approved | Delete once the minutes are approved | Signed minutes per company law, at least 10 years for UK companies | Approved minutes are the legal record. The recording is only a drafting aid. |
| HR, grievance or disciplinary | Only while the matter is open, then per your HR rule | Same as audio | Outcome letter per your HR rule | High sensitivity, and a filed claim extends preservation past any normal period. |
| Job interview | Delete after the decision, unless a candidate challenges it | Short, and tied to the hiring round | Scorecard, not a recording | US employers under EEOC rules keep personnel records at least 1 year. |
| Research or user interview | Exactly what the consent form promised | Exactly what the consent form promised | Per funder or ethics rules | Participants agreed to a stated period. That statement is the rule. |
| Medical or clinical conversation | Do not use a general meeting app for this | Not applicable | Not applicable | Clinical records sit under national and state rules and belong in a clinical system. |
Where the law names a number, and where it does not
Almost every retention question ends in "it depends", which is unhelpful, so here are named rules with real numbers. Check each one against your own situation before using it. None of these were written with AI meeting recordings in mind, and most govern the record rather than the audio.
| Rule | Who it applies to | What it actually says |
|---|---|---|
| UK GDPR and EU GDPR, Article 5(1)(e) | Anyone handling personal data in the UK or EU | The storage limitation principle. Keep personal data in identifiable form no longer than is necessary for the purpose. No fixed period is given. You set it, document it, and must be able to justify it. |
| Companies Act 2006, sections 248 and 355 | UK companies | Minutes of directors' meetings, and records of members' resolutions and general meetings, must be kept for at least 10 years. That obligation is about the minutes, not about any recording used to write them. |
| SEC Rule 17a-4 | US broker-dealers | Business communications must be preserved for at least 3 years, with the most recent 2 years kept readily accessible. |
| 29 CFR 1602.14 (EEOC) | US employers covered by Title VII and related laws | Personnel and employment records kept 1 year from the making of the record or the personnel action, whichever is later. If a discrimination charge is filed, relevant records must be preserved until final disposition. |
| 45 CFR 164.316(b)(2)(i), HIPAA Security Rule | US HIPAA covered entities and business associates | Required HIPAA documentation kept 6 years. Note the common mistake: HIPAA does not set a retention period for medical records themselves. That is state law. |
| 2 CFR 200.334 | Recipients of US federal awards, including many research grants | Award records kept 3 years from submission of the final financial report, and longer if litigation, a claim, or an audit is still open. |
| Limitation Act 1980, sections 5 and 8 | England and Wales | 6 years to bring a claim on a simple contract, 12 years on a deed. Not a retention rule, but the window many organisations use to size one. |
| Federal Rule of Civil Procedure 37(e) and the common-law duty | US federal litigation | Once litigation is reasonably anticipated, you must take reasonable steps to preserve relevant electronic records. Routine deletion has to stop for anything in scope. |
Legal hold beats your schedule, every time
A retention schedule is a peacetime rule. The moment a dispute becomes reasonably likely, it stops applying to anything connected to that dispute.
The trigger is earlier than most people expect. It is not the day you are served with papers. In US practice the duty to preserve attaches when litigation is reasonably anticipated, which can be a threatening letter, a formal grievance, a serious complaint from a client, or a regulator's first question. Deleting relevant records after that point, even on a schedule you wrote in good faith, is where organisations get into real trouble.
What a small team should actually do is short. Name one person who can call a hold. When they call it, they send a plain email naming the matter, the people involved, and the date range, and asking recipients not to delete anything in that range. Then someone checks that automatic deletion, in every tool including the meeting app, is paused for those items. Keep the email. It is the evidence that you acted properly.
Release the hold in writing too, once the matter closes. Holds that are never lifted quietly turn into keeping everything forever, which is the problem you were trying to avoid.
Write a one-page policy your team will actually follow
Long policies fail because nobody reads them. Aim for one page that a new joiner can absorb in two minutes. These are the fields worth having.
- 1List your meeting types. Four to eight is plenty. Standups, project meetings, client calls, interviews, HR, board. If a type never appears on your calendar, leave it out.
- 2Set three periods for each type, one for audio, one for the transcript, one for the summary and decisions. Copy the table above as a starting point and change what does not fit.
- 3Write one line of justification per row. This is the part regulators care about, and it forces you to notice the rows you cannot defend.
- 4Name the owner. One person per meeting type is responsible for deletion actually happening. Shared responsibility means nobody does it.
- 5Set a review rhythm. A calendar reminder on the first Monday of each quarter, with 20 minutes to clear anything past its date, beats an unread automation nobody trusts.
- 6Write the legal hold paragraph. Who can call one, how it is communicated, what pauses, and who lifts it.
- 7Say where the surviving notes live. If summaries are the long-term record, they need a permanent home outside the recording app, in a document store you already back up.
- 8Add a consent line. How people are told a meeting is being recorded, and how long you tell them it is kept. If you promise 90 days, the promise is now your rule.
- 9Date it and set a yearly review. Sector rules and privacy law both move. An undated policy looks abandoned even when it is not.
Making deletion real in a cloud app
A schedule only counts if the data is genuinely gone at the end of it. In a cloud meeting tool that takes a few checks, and they are the same checks in every app. There is more detail in where are my meeting recordings stored and in the step-by-step in how to delete a meeting recording permanently.
- Confirm deletion reaches the server, not just the screen. Delete a test note, then look for it on a second device. If it is still there, you hid it rather than removed it.
- Check whether audio and transcript delete together or separately. Some products drop the audio once transcription finishes. Others keep both until you say otherwise. This decides whether the audio-light pattern is one action or two.
- Read the backup sentence in the privacy policy. Deleted items usually persist in backups for a defined window. That is normal engineering, but you should know the number so you do not tell a client something untrue.
- Check whether deleting the account deletes the data. Closing an account and erasing its contents are not always the same operation.
- Remember exports. A PDF you emailed to a client is outside every retention control you own. Track where the notes went, not just where they started.
- Understand who else holds a copy. Speech and language model providers behind any AI note taker are subprocessors, and their handling applies to your meeting too. This is part of what GDPR compliance for AI meeting transcription asks you to check.
- Do not accept a certification claim without seeing it. If a vendor's page says SOC 2 or ISO 27001, ask for the report or the certificate. A logo is not evidence.
If you would rather keep the notes and drop the audio
This is where a tool either helps or gets in your way. The pattern that most teams settle on, short audio life and long note life, only works if the notes are good enough to stand alone once the recording is gone.
Noter AI is built around that. A recording produces a transcript with speaker labels and timestamps, an executive summary, and a list of action items with owners. You can reshape the same recording into minutes of meeting, key bullet points, an email, a to-do list, or a formal report, so the version you archive is the version you would actually read a year later. If a name or a term came out wrong, you can edit the transcript and re-run the summary so the archived note is correct before the audio goes.
For teams that work in more than one language, the same applies to the record you keep. Transcription covers 60+ languages with automatic detection, and the language is tagged word by word, so a meeting that switches between Arabic and English, or Spanish and English, comes back with both rendered properly instead of the second language arriving as phonetic nonsense. Finished notes translate into 18 languages, which matters when the archived summary has to be readable by a head office that did not attend.
Export is what makes deletion safe. PDF, Word, plain text, and rich-text copy all work, so the summary can live in your own document store while the recording lives on a short clock inside the app. Folders and search across every note's title and AI notes keep the surviving record findable.
On price, it is $9.99 a month or $49.99 a year, per person rather than per seat. That matters for retention more than it sounds. Per-seat tools push teams toward one shared account holding everyone's recordings, which is the worst possible shape for a retention policy. Here each person holds their own subscription, records from their own phone and owns their own deletions. That is five subscriptions for five people, not one shared login, which is the point.
The honest limits, stated plainly. Transcription happens in the cloud, so audio is uploaded and there is no offline mode. Data is encrypted in transit and at rest, and you can delete notes and your whole account from inside the app at any time. There is no automatic retention timer, so the schedule above is something you run, not something the app runs for you. And no certification such as SOC 2, ISO 27001, or a HIPAA business associate agreement is documented, so if your work requires one, this is not the tool for that work. You can test all of this on a real meeting during the free trial, on iOS or Android, before you commit anything sensitive to it.
Frequently asked questions
How long should you keep meeting recordings by default?
For most ordinary business meetings, 30 to 90 days of audio is enough. That covers the period in which someone might genuinely need to hear the exact words again. Keep the transcript longer, typically a year, and keep the summary and decisions for as long as the work they describe matters. Change the number upward only for meeting types where the precise wording could be contested, such as contract negotiations or disciplinary hearings.
Is there a law that says how long to keep a meeting recording?
Not as a general rule. GDPR in the UK and EU says to keep personal data no longer than necessary and deliberately does not give a number, leaving you to set and justify one. Specific sectors do have real minimums, such as three years for broker-dealer communications under SEC Rule 17a-4, and UK company law requires minutes of directors' meetings and members' resolutions to be kept for at least ten years. Those rules mostly govern the written record rather than the audio, and they vary by country and by US state, so check your own sector.
Can I delete the audio and keep the transcript?
Usually yes, and for most meetings it is the right call. The audio is the largest, most sensitive, and least used of the three assets a recorded meeting produces. The exception is any meeting where the exact wording could be disputed, because a transcript is a derived document with errors in it and the audio is the evidence. For those, either keep the audio for the full period or do not record at all.
What is a legal hold and when does it start?
A legal hold is an instruction to stop deleting anything connected to a dispute. It overrides your normal retention schedule. In US practice the duty to preserve electronic records attaches once litigation is reasonably anticipated, which can be well before a claim is filed, for example after a threatening letter or a formal grievance. Once that point is reached, deleting relevant recordings even under a documented policy can lead to sanctions.
How long should HR and disciplinary recordings be kept?
Keep them only while the matter is open, then apply your written HR rule, and delete on schedule after that. US employers covered by EEOC rules must preserve personnel records for at least one year from the making of the record or the personnel action, and if a discrimination charge is filed, relevant records must be preserved until the charge is finally resolved. Employment law differs a lot by country, so this is one of the areas most worth checking with an adviser rather than copying a number from a blog.
How long should research interview recordings be kept?
For exactly as long as your consent form and your ethics approval say, and no longer. That statement to participants is the binding rule, not a generic default. If the work is funded by a US federal award, records generally have to be kept for three years from submission of the final financial report under 2 CFR 200.334, longer if any litigation, claim, or audit is open. Where the two conflict, resolve it before you start recording, not after.
Does deleting a note in an app really delete the recording?
It should, but verify rather than assume. Delete a test note and check that it is also gone on a second device, which confirms the deletion reached the server instead of hiding the item locally. Then read the privacy policy for the backup window, since deleted items commonly persist in backups for a defined period. Also check separately whether closing your account erases its contents, because account closure and data erasure are not always the same operation.
How does Noter AI handle retention and deletion?
Transcription happens in the cloud, and recordings and transcripts are encrypted in transit and at rest. You can delete individual notes or your entire account and its data from inside the app at any time, without a support ticket. There is no automatic retention timer, so a schedule is something you apply yourself, and exporting the summary to PDF, Word, or plain text before deleting is how you keep the useful part after the audio is gone.
Let Noter AI take your meeting notes
Record, transcribe, and summarize meetings on iPhone, iPad & Android, or send a bot to Zoom, Teams, Meet, or Webex. In 60+ languages.
On your computer? Scan with your phone to get the app.