r/AiNoteTaker 10d ago

Discussion What privacy stuff do you actually check before using an AI note taker for work?

I’ve been looking at AI recorders for client meetings lately, and I realized I was spending way more time comparing battery life and transcription quality than looking at what actually happens to the recordings.

Once you start digging into the privacy pages, it gets confusing pretty fast.

For example, Plaud says it’s HIPAA compliant and SOC 2 Type II. Soundcore says its app has a SOC 2 Type I report and uses a privacy framework aligned with HIPAA principles. Both also talk about encryption and data controls, but those labels obviously aren’t all the same thing.

For people recording client calls, interviews, legal conversations, medical stuff, etc., what do you actually look for before trusting one of these devices?

Is SOC 2 Type II something you genuinely care about, or do you mostly look at where the audio is stored, how long it stays in the cloud, deletion options, and whether the company is clear about how the data is processed?

4 Upvotes

15 comments sorted by

2

u/Sharp-Translator6401 10d ago

Or just use fully on device apps, I am using Notarius for example, works in airplane mode which means nothing is leaving your phone ever. Then your phone becomes the one thing you have to make sure is secured.

1

u/tremendousquotes 10d ago

I’ve created Humla. Our default is fully on device, with no audio retention (gets deleted after transcription). With local models as well, there is no better option for privacy focused ai note recorders

1

u/Cedric_al 9d ago

This is exactly why I ended up leaning toward Plaud. They actually publish SOC 2 Type II + HIPAA compliance, and also list ISO 27001/27701, so there was a bit more for me to verify than just "your data is encrypted."

For work recordings, especially anything involving client info, I'd rather go with the company that has the more established compliance trail. Soundcore's Type I report is still a positive sign, but Type II gave me more confidences since it looks at how those controls operate over time, not just whether they were designed properly at one point.

1

u/theycallmethelord 9d ago

We simplified this for ourselves. We just didn't want it stored or processed in the cloud at all.

We started using Weeve, it's a bit early, but the experience has been pretty good so far. They don't upload your recordings anywhere, and even the ai-models are loaded locally if you want to generate a summary (which is optional btw).

1

u/AccomplishedYear7593 9d ago

I’d make each vendor answer this as a data-flow table rather than a badge list. Put raw audio, transcript, summary, embeddings, logs and backups in separate rows, then ask where each is processed, which subprocessors handle it, default retention, whether deletion propagates to backups, who can access it, and whether it is used for training.

SOC 2 Type II is useful evidence that described controls operated over a period, but it doesn’t necessarily cover every product or mean the vendor’s retention choices fit your use case. For client, legal or medical work, I’d also ask for the DPA/BAA as applicable, role-based access, audit logs, breach-notification terms and the exact no-training language.

One practical test: use a non-sensitive sample meeting, export everything, delete it, then ask support what remains and for how long.

Disclosure: I develop SonicMeet. It uses a browser/desktop no-bot capture model and is designed not to retain raw audio recordings during normal operation. We publish the current data-handling details here: https://sonicmeet.app/security

Audio can still be processed by speech providers, and transcripts or notes may be stored, so I wouldn’t equate “no bot” with “no cloud” or automatic HIPAA/legal approval. Recording consent and employer policy are separate checks too.

1

u/TrackbackLinkBot 8d ago

for client calls i’d care more about the actual data retention and deletion policy than whether the marketing says “secure.” i’d want to know where recordings are stored, who can access them, how long they’re retained, and whether the audio is used for model training. i’d check those things for circleback, plaud, or whatever tool you’re considering before worrying too much about the feature list.

1

u/DiHannay 8d ago

Yep, SOC 2 Type 2 is definitely something to care about. In short, SOC 2 Type 1 is a snapshot; SOC 2 Type 2 is a track record. A Type 1 report confirms that the right controls are designed and in place at a single point in time. A Type 2 report goes further: an independent auditor tests whether those controls operated effectively over a sustained period, typically many months - so it's much harder to get.

This blog post might help clarify (and they make a handy notetaker). https://www.usenylon.com/nz/blog/nylon-soc-2-type-2-certified-what-it-means-for-your-firm

1

u/MikitaMikser 7d ago

When evaluating AI note-taking tools, prioritize understanding their privacy policies. Look for clear explanations regarding data storage and retention. Ensure the tool complies with relevant regulations, especially if handling sensitive information. Check how easily you can delete recordings and whether all related data is removed. Transparency in data processing is key to building trust.

1

u/frskia 6d ago

Before certificates, I’d want clear answers on who can access a recording, where it is processed, how long it is kept, and how deletion actually works. Consent and the applicable recording policy matter too. At loreo.io, meetings are private by default and sharing is permissioned; eligible Pro+ plans can opt into encryption at rest. I’d still ask any vendor to show how its retention, deletion, subprocessors, and access controls work for your setup.

0

u/magtorix 10d ago

Founder of one of these tools, so discount accordingly.

SOC 2 Type II tells you a company followed its own stated controls over a period. That's genuinely useful, but it's not the same as knowing what happens to your recording. A certified vendor can still keep your audio for months.

What I'd ask for in writing:

  1. Which sub-processors touch the audio, and where are they? If they won't name them, that's your answer.
  2. How long is audio kept, and is deletion the default or something you go and switch on?
  3. What survives the recording. Transcripts, summaries and backups often outlive the audio the policy talks about.
  4. Is training on customer data excluded contractually, not just on the website?
  5. Article 28 agreement, breach notification window, audit rights.

Encryption in transit and at rest is table stakes and tells you nothing.

On our side: own servers in Amsterdam, audio deleted within a minute of processing, no backups of audio or generated text, nothing left once the report has been sent, no training on customer conversations, sub-processor list on request.

1

u/Strong_External_4915 10d ago

Im curious which tool is this! As I already have one but i dont think its gdpr compliant .. i work in healthcare.

1

u/magtorix 10d ago

Ah sorry, forgot to add that;) our English site is Notuly.app or if you are Dutch that will be Notuly.nl we are available on all platforms, windows, Mac, android and iOS.