You Don't Need a Bot in the Room to Take Compliant Meeting Notes
A meeting bot adds a third party to a confidential conversation. Recording on your own device doesn't. What that changes under GDPR, and what it doesn't change about your duty to tell people.

TL;DR
- A meeting bot joins your call in the same way that an actual participant would. That means it can keep its own copy of the recording, as well as its own retention policies and subcontractor list. You are now required to document that processor under GDPR.
- Recording on your own device doesn't add anyone. You were already in the meeting.
- A bot's "Notetaker has joined" banner isn't consent. Neither is an on-screen reminder. Both are notifications. Consent is something one person gives another, and no software can do it for you.
- So going bot-free doesn't remove your duty to tell people you're recording. It removes the third party. Those are different problems, and only one of them was ever hard.
The notetaker nobody invited
How would you feel if you saw a name you didn't recognize when you opened the calendar invite for a contract negotiation? You looked a little closer and eventually realized it wasn't a real person but an automated notetaker. Then you learned from your team that it was not actually invited to the meeting, but had been added as part of a meeting-notes service that someone had connected their calendar to.
If you work in compliance, legal, or IT security, you would probably have come across situations like these. The recording may not always be the problem. Your organization may already have systems and policies for recording meetings regularly. The first question is more basic: who exactly is participating in the conversation, and for what purpose?
The question that actually matters
Most writing about AI notetakers and compliance starts with consent law, works through a list of states, and ends somewhere vague. That's the wrong order, because consent law isn't where the difficulty is. Announcing that you're recording is a sentence you say at the start of a call. People have managed it for decades.
The difficulty is architectural. When you bring an AI notetaker into a confidential meeting, you're making a decision about who gets a copy of the conversation. Some tools answer that question by adding a participant. Others answer it by using the audio your own computer is already playing.
Those two answers have very different consequences, and almost nothing to do with consent.
What changes when a bot joins
A meeting bot is a separate account that dials into your call. It shows up in the participant list. It shows up in your meeting platform's audit log. And from the moment it connects, a company that isn't yours is processing your conversation.
What the bot brings with it
Concretely, that means:
| What the bot brings with it | Why compliance cares |
|---|---|
| Its own copy of the audio and transcript | A second location holding the conversation, outside your control |
| Its own retention policy | Deletion on your side doesn't mean deletion on theirs |
| Its own subprocessors | Their cloud host, their transcription engine, their model provider. Each one is another party |
| An entry in the participant list | Anyone reviewing the call later can see a third party attended |
| An entry in the audit log | Discoverable in litigation or an audit, and it reads as what it is |
Why that becomes paperwork
Under the GDPR, the European privacy regulation that governs how organizations handle personal data, that vendor is a processor: someone who handles personal data on your behalf. Processors aren't forbidden. They're routine. But they come with paperwork. You need a lawful basis, a data processing agreement, a record of the processing, a position on where the data sits, and an answer for every subprocessor behind them.
None of that is unusual. It's just work, and it's work you've chosen to take on the moment the bot connects.
And in a legal matter, it goes further
In a legal context it goes further than paperwork. If the meeting is a privileged discussion between a client and their counsel, a third party was present for it. Whether that affects privilege is a question for your lawyers and it varies by jurisdiction, but you'd rather not be the one raising it for the first time in a deposition. Our legal use-case page covers the confidentiality side in more detail.
What changes when you record on your own device
Now the other approach. Your computer is already playing the audio of the meeting. It has to be, or you couldn't hear it. A tool that captures that audio locally is recording something you're already receiving, as a participant, on hardware you own.
Here's the whole list of what changes about who's in the room:
Nothing.
No new account. No new participant. No entry in the platform's audit log, because no one connected. No second copy sitting on someone else's infrastructure. No subprocessor chain, because there's no processor. You were a party to the meeting before you pressed record, and you still are afterward.
This is what "bot-free" means, and it's the argument behind our bot-free page and the earlier post on self-hosted bot-free transcription. Meetily works this way: it captures system audio, so it works with Zoom, Teams, Meet or anything else, without ever joining the call.

Left: a bot in the call. Participant list: Priya, Marcus, Elena, Notetaker. The notetaker has its own account, its own copy, and its own retention policy. Right: recording on your own device. Participant list: Priya, Marcus, Elena. Nothing joined.
Neither a banner nor a reminder is consent
There is a fair objection to all this. If a bot appears in the participant list, everyone can see it. If a tool records quietly from your laptop, they can't. Doesn't the bot at least tell people what's happening?
It tells them something. It doesn't get consent.
A bot's banner is a notification
A bot's banner is a notification. "Notetaker has joined" appears on screen, and it means a third party is now in the room and processing the audio. That's useful information. It is not permission, it isn't a lawful basis for anything, and nobody in the meeting agreed to it by failing to object to a banner.
Our on-screen reminder is also a notification
Meetily's on-screen reminder is also a notification. When you start recording, Meetily shows a notice on your own screen telling you to inform everyone in the meeting that it's being recorded, with a button to confirm you've done it. You can dismiss that notice, and you can switch it off permanently in settings. It's a prompt aimed at you, the person doing the recording, not a message sent to anyone else. It doesn't announce anything on your behalf, and we're not going to describe it as though it does.
Why neither one counts
So both tools notify. Neither obtains consent, because consent is something one person gives another. It's a human act between the people in a conversation. Software can prompt you, log what you did, and remind you at the right moment. It can't stand in for you.
Which leaves the duty exactly where the law already puts it: with you, a party to the meeting you're in.
Every recording method ever invented has worked this way, banners included. Where the two approaches genuinely differ is in who ends up holding the recording afterward, and that's a separate question from consent.
What the law actually requires
Meaning first, citations after.
In the United States: one-party and all-party consent
In the United States, the rule depends on where the people in the call are. Federal law and most states use one-party consent: if you're part of the conversation, you can record it. Around twelve states use all-party consent, where everyone in the conversation has to agree, and the exact count varies by source. Nine of them appear on every published list: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington. Connecticut, Delaware and Oregon are usually counted too, with conditions.
Those conditions are the practical point, and they're the reason a tidy list of states is worth less than it looks:
- Connecticut requires all-party consent for recording phone calls, but follows one-party consent for in-person conversation under its criminal statute.
- Delaware is the most contested of the three. Its wiretap statute reads as all-party, but its courts have read the state's own one-party provision as controlling, so plenty of published lists classify it one-party.
- Oregon is the reverse of Connecticut: all-party for in-person conversation, one-party for electronic communication.
- Michigan's eavesdropping statute reads as all-party, but its courts have recognized a participant exception since 1982, so it's normally classified one-party anyway.
And if the people on your call are sitting in different states, more than one rule can apply to the same conversation at once. Check your own jurisdictions, and get it from a lawyer rather than from a vendor's blog, this one included.
In Europe: Article 13 requires notice
In Europe, GDPR Article 13 requires notice. When you collect someone's personal data, you have to tell them who you are, why you're collecting it, and how long you'll keep it. A recorded meeting is personal data. So the obligation isn't "get a signature", it's "tell people, clearly, before you start". Our GDPR compliance guide and the GDPR meeting transcription page go through what that means for recordings specifically.
The one rule that covers all of it
Say it at the start:
"I'm recording this meeting and using an AI tool to write the notes. Tell me now if you'd rather I didn't."
That one sentence is designed to address one-party consent, the substance of Article 13's notice requirement, and all-party consent in most jurisdictions, because it gives everyone the chance to object before you proceed. It takes four seconds. If someone objects, you stop, which is the point of asking.
Two caveats, because this is the part people over-read. Silence isn't the same as agreement, and some jurisdictions expect something more explicit than an unanswered announcement. And this isn't legal advice: check your own jurisdictions with a lawyer. What the sentence reliably does is put the disclosure where the law assumes it will be, with a person, at the start of the call. Most of the hard questions in this area get easier once it's simply part of how your meetings start.
So what bot-free actually removes
Put the two halves together.
Going bot-free does not remove your duty to tell people you're recording. Nothing removes that. Not a banner, not a reminder, not a checkbox in someone's terms of service.
Going bot-free removes the third party. It removes the second copy of the recording, the external retention policy, the subprocessor chain, the audit-log entry, and the processor paperwork that comes with all of it.
Which means the two things people usually merge are actually separate:
- Disclosure is a four-second sentence at the start of a call. It was never the hard part.
- Who has your data is an architecture decision you make once, and then live with.
Bot-free tools fix the second problem and leave the first exactly where it was. If anything, putting the announcement in your hands tracks how consent law already works more closely than a banner does, since the law has always assumed a person doing the telling.
Where the data sits
Two questions come up on every compliance review, so here they are directly.
What leaves the device
With Meetily, transcription runs locally, always. The audio and the transcript stay on your machine. Summaries are the part you configure: you can run a local model, in which case nothing leaves at all, or you can bring your own API key and send the transcript text to a provider you've chosen and already have a relationship with. That's a deliberate fork, and which side of it you pick is a compliance decision worth making on purpose rather than by default. The security page has the architecture.

Where it sits, for European organizations
European data residency is available on Enterprise, along with self-hosted deployment on your own infrastructure and managed compliance for GDPR, HIPAA and NIS2. If the question you're actually being asked is "can we guarantee this data never leaves the EU", that's the tier that answers it. Details are on the Enterprise page and the enterprise deployment guide, and the data sovereignty page covers where data is allowed to live.
For regulated teams generally, the government and healthcare pages cover the sector-specific requirements. Healthcare carries extra weight here, because GDPR Article 9 treats health data as a special category on top of everything above.
If you're comparing tools
If you're comparing against tools that typically join as a participant, the comparison pages lay out the differences without editorializing: Fireflies, Otter.ai and Read AI. Our earlier piece on privacy risks in AI meeting assistants documents specific incidents with sources, and the Fireflies comparison post covers the bot-free difference in practice. The full set of verticals is on the use cases page.
What to do next
If you're evaluating this for a team, the fastest way to check the claims is to run it. Meetily Community Edition is free and open source under the MIT license, and you can watch your own network traffic while it records. Meetily Pro is $10 per user per month billed annually on the current early bird price, with a 14-day trial that needs no payment details.
If you're in a regulated industry and the questions are about residency, self-hosting, SSO or managed compliance, those are Enterprise conversations. The Enterprise page has the detail and a link to book a demo.
And whichever tool you end up with, say the sentence at the start of the call.
Frequently Asked Questions
Ready to try Meetily?
Join 475,000+ users who use Meetily for private meeting transcription. No bots, privacy first. Community Edition free.
Star on GitHub (29K+) · Open source & self-hostable
Get Started with Meetily
Meetily Pro
Advanced features for individuals and teams.


