Skip to main content

You Don't Need a Bot in the Room to Take Compliant Meeting Notes

A meeting bot adds a third party to a confidential conversation. Recording on your own device doesn't. What that changes under GDPR, and what it doesn't change about your duty to tell people.

Sujith S
CTO, Product Owner, Zackriya Solutions
11 min readPrivacy & SecurityEnglish
A meeting bot adds a third party to your call. Recording on your own device does not.

TL;DR

  • A meeting bot joins your call in the same way that an actual participant would. That means it can keep its own copy of the recording, as well as its own retention policies and subcontractor list. You are now required to document that processor under GDPR.
  • Recording on your own device doesn't add anyone. You were already in the meeting.
  • A bot's "Notetaker has joined" banner isn't consent. Neither is an on-screen reminder. Both are notifications. Consent is something one person gives another, and no software can do it for you.
  • So going bot-free doesn't remove your duty to tell people you're recording. It removes the third party. Those are different problems, and only one of them was ever hard.

The notetaker nobody invited

How would you feel if you saw a name you didn't recognize when you opened the calendar invite for a contract negotiation? You looked a little closer and eventually realized it wasn't a real person but an automated notetaker. Then you learned from your team that it was not actually invited to the meeting, but had been added as part of a meeting-notes service that someone had connected their calendar to.

If you work in compliance, legal, or IT security, you would probably have come across situations like these. The recording may not always be the problem. Your organization may already have systems and policies for recording meetings regularly. The first question is more basic: who exactly is participating in the conversation, and for what purpose?

The question that actually matters

Most writing about AI notetakers and compliance starts with consent law, works through a list of states, and ends somewhere vague. That's the wrong order, because consent law isn't where the difficulty is. Announcing that you're recording is a sentence you say at the start of a call. People have managed it for decades.

The difficulty is architectural. When you bring an AI notetaker into a confidential meeting, you're making a decision about who gets a copy of the conversation. Some tools answer that question by adding a participant. Others answer it by using the audio your own computer is already playing.

Those two answers have very different consequences, and almost nothing to do with consent.

What changes when a bot joins

A meeting bot is a separate account that dials into your call. It shows up in the participant list. It shows up in your meeting platform's audit log. And from the moment it connects, a company that isn't yours is processing your conversation.

What the bot brings with it

Concretely, that means:

What the bot brings with itWhy compliance cares
Its own copy of the audio and transcriptA second location holding the conversation, outside your control
Its own retention policyDeletion on your side doesn't mean deletion on theirs
Its own subprocessorsTheir cloud host, their transcription engine, their model provider. Each one is another party
An entry in the participant listAnyone reviewing the call later can see a third party attended
An entry in the audit logDiscoverable in litigation or an audit, and it reads as what it is

Why that becomes paperwork

Under the GDPR, the European privacy regulation that governs how organizations handle personal data, that vendor is a processor: someone who handles personal data on your behalf. Processors aren't forbidden. They're routine. But they come with paperwork. You need a lawful basis, a data processing agreement, a record of the processing, a position on where the data sits, and an answer for every subprocessor behind them.

None of that is unusual. It's just work, and it's work you've chosen to take on the moment the bot connects.

In a legal context it goes further than paperwork. If the meeting is a privileged discussion between a client and their counsel, a third party was present for it. Whether that affects privilege is a question for your lawyers and it varies by jurisdiction, but you'd rather not be the one raising it for the first time in a deposition. Our legal use-case page covers the confidentiality side in more detail.

What changes when you record on your own device

Now the other approach. Your computer is already playing the audio of the meeting. It has to be, or you couldn't hear it. A tool that captures that audio locally is recording something you're already receiving, as a participant, on hardware you own.

Here's the whole list of what changes about who's in the room:

Nothing.

No new account. No new participant. No entry in the platform's audit log, because no one connected. No second copy sitting on someone else's infrastructure. No subprocessor chain, because there's no processor. You were a party to the meeting before you pressed record, and you still are afterward.

This is what "bot-free" means, and it's the argument behind our bot-free page and the earlier post on self-hosted bot-free transcription. Meetily works this way: it captures system audio, so it works with Zoom, Teams, Meet or anything else, without ever joining the call.

Side by side comparison of a meeting participant list: with a meeting bot the list shows three people plus a notetaker bot, with local recording it shows only the three people
Side by side comparison of a meeting participant list: with a meeting bot the list shows three people plus a notetaker bot, with local recording it shows only the three people

Left: a bot in the call. Participant list: Priya, Marcus, Elena, Notetaker. The notetaker has its own account, its own copy, and its own retention policy. Right: recording on your own device. Participant list: Priya, Marcus, Elena. Nothing joined.

There is a fair objection to all this. If a bot appears in the participant list, everyone can see it. If a tool records quietly from your laptop, they can't. Doesn't the bot at least tell people what's happening?

It tells them something. It doesn't get consent.

A bot's banner is a notification

A bot's banner is a notification. "Notetaker has joined" appears on screen, and it means a third party is now in the room and processing the audio. That's useful information. It is not permission, it isn't a lawful basis for anything, and nobody in the meeting agreed to it by failing to object to a banner.

Our on-screen reminder is also a notification

Meetily's on-screen reminder is also a notification. When you start recording, Meetily shows a notice on your own screen telling you to inform everyone in the meeting that it's being recorded, with a button to confirm you've done it. You can dismiss that notice, and you can switch it off permanently in settings. It's a prompt aimed at you, the person doing the recording, not a message sent to anyone else. It doesn't announce anything on your behalf, and we're not going to describe it as though it does.

Why neither one counts

So both tools notify. Neither obtains consent, because consent is something one person gives another. It's a human act between the people in a conversation. Software can prompt you, log what you did, and remind you at the right moment. It can't stand in for you.

Which leaves the duty exactly where the law already puts it: with you, a party to the meeting you're in.

Every recording method ever invented has worked this way, banners included. Where the two approaches genuinely differ is in who ends up holding the recording afterward, and that's a separate question from consent.

What the law actually requires

Meaning first, citations after.

In the United States, the rule depends on where the people in the call are. Federal law and most states use one-party consent: if you're part of the conversation, you can record it. Around twelve states use all-party consent, where everyone in the conversation has to agree, and the exact count varies by source. Nine of them appear on every published list: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington. Connecticut, Delaware and Oregon are usually counted too, with conditions.

Those conditions are the practical point, and they're the reason a tidy list of states is worth less than it looks:

  • Connecticut requires all-party consent for recording phone calls, but follows one-party consent for in-person conversation under its criminal statute.
  • Delaware is the most contested of the three. Its wiretap statute reads as all-party, but its courts have read the state's own one-party provision as controlling, so plenty of published lists classify it one-party.
  • Oregon is the reverse of Connecticut: all-party for in-person conversation, one-party for electronic communication.
  • Michigan's eavesdropping statute reads as all-party, but its courts have recognized a participant exception since 1982, so it's normally classified one-party anyway.

And if the people on your call are sitting in different states, more than one rule can apply to the same conversation at once. Check your own jurisdictions, and get it from a lawyer rather than from a vendor's blog, this one included.

In Europe: Article 13 requires notice

In Europe, GDPR Article 13 requires notice. When you collect someone's personal data, you have to tell them who you are, why you're collecting it, and how long you'll keep it. A recorded meeting is personal data. So the obligation isn't "get a signature", it's "tell people, clearly, before you start". Our GDPR compliance guide and the GDPR meeting transcription page go through what that means for recordings specifically.

The one rule that covers all of it

Say it at the start:

"I'm recording this meeting and using an AI tool to write the notes. Tell me now if you'd rather I didn't."

That one sentence is designed to address one-party consent, the substance of Article 13's notice requirement, and all-party consent in most jurisdictions, because it gives everyone the chance to object before you proceed. It takes four seconds. If someone objects, you stop, which is the point of asking.

Two caveats, because this is the part people over-read. Silence isn't the same as agreement, and some jurisdictions expect something more explicit than an unanswered announcement. And this isn't legal advice: check your own jurisdictions with a lawyer. What the sentence reliably does is put the disclosure where the law assumes it will be, with a person, at the start of the call. Most of the hard questions in this area get easier once it's simply part of how your meetings start.

So what bot-free actually removes

Put the two halves together.

Going bot-free does not remove your duty to tell people you're recording. Nothing removes that. Not a banner, not a reminder, not a checkbox in someone's terms of service.

Going bot-free removes the third party. It removes the second copy of the recording, the external retention policy, the subprocessor chain, the audit-log entry, and the processor paperwork that comes with all of it.

Which means the two things people usually merge are actually separate:

  • Disclosure is a four-second sentence at the start of a call. It was never the hard part.
  • Who has your data is an architecture decision you make once, and then live with.

Bot-free tools fix the second problem and leave the first exactly where it was. If anything, putting the announcement in your hands tracks how consent law already works more closely than a banner does, since the law has always assumed a person doing the telling.

Where the data sits

Two questions come up on every compliance review, so here they are directly.

What leaves the device

With Meetily, transcription runs locally, always. The audio and the transcript stay on your machine. Summaries are the part you configure: you can run a local model, in which case nothing leaves at all, or you can bring your own API key and send the transcript text to a provider you've chosen and already have a relationship with. That's a deliberate fork, and which side of it you pick is a compliance decision worth making on purpose rather than by default. The security page has the architecture.

Data flow comparison: with a meeting bot, audio travels to the vendor then to their cloud host, transcription engine and model provider. With Meetily, transcription stays on the device, and summaries either stay local or go to an API provider the user chooses.
Data flow comparison: with a meeting bot, audio travels to the vendor then to their cloud host, transcription engine and model provider. With Meetily, transcription stays on the device, and summaries either stay local or go to an API provider the user chooses.

Where it sits, for European organizations

European data residency is available on Enterprise, along with self-hosted deployment on your own infrastructure and managed compliance for GDPR, HIPAA and NIS2. If the question you're actually being asked is "can we guarantee this data never leaves the EU", that's the tier that answers it. Details are on the Enterprise page and the enterprise deployment guide, and the data sovereignty page covers where data is allowed to live.

For regulated teams generally, the government and healthcare pages cover the sector-specific requirements. Healthcare carries extra weight here, because GDPR Article 9 treats health data as a special category on top of everything above.

If you're comparing tools

If you're comparing against tools that typically join as a participant, the comparison pages lay out the differences without editorializing: Fireflies, Otter.ai and Read AI. Our earlier piece on privacy risks in AI meeting assistants documents specific incidents with sources, and the Fireflies comparison post covers the bot-free difference in practice. The full set of verticals is on the use cases page.

What to do next

If you're evaluating this for a team, the fastest way to check the claims is to run it. Meetily Community Edition is free and open source under the MIT license, and you can watch your own network traffic while it records. Meetily Pro is $10 per user per month billed annually on the current early bird price, with a 14-day trial that needs no payment details.

If you're in a regulated industry and the questions are about residency, self-hosting, SSO or managed compliance, those are Enterprise conversations. The Enterprise page has the detail and a link to book a demo.

And whichever tool you end up with, say the sentence at the start of the call.

Frequently Asked Questions

Yes. A meeting bot is operated by a vendor that processes personal data on your behalf, which makes that vendor a processor under the GDPR. You need a lawful basis, a data processing agreement, and a record of the processing, and you have to account for the vendor's own subprocessors. Recording locally on a device you already control doesn't introduce a processor, because no third party receives the data.
If a meeting bot vendor receives protected health information, they are a business associate under HIPAA and a business associate agreement is required before they handle it. The practical difficulty is scope: a BAA governs how the vendor handles the data, not how many of their subcontractors touch it, and it doesn't reduce the number of places the recording now exists. If patient data never reaches a vendor, there's no business associate relationship to paper over in the first place.
When a bot joins a call, it appears as a participant in your meeting platform's audit log, alongside the humans. That record shows a third party attended, is retained under your platform's policy, and is discoverable in litigation or an audit. Local recording produces no such entry, because nothing joined the meeting.
No. Your duty to tell people you're recording is set by law and by your own policies, and it doesn't change based on which tool you use. Meetily shows a notice on your own screen when recording starts, telling you to inform the other participants. You can dismiss it or switch it off in settings, and it behaves the same way on Community and Pro. It's a prompt to you, not an announcement to the meeting. Announcing is your responsibility, exactly as it is with any other recording method.
All-party consent states require everyone in a conversation to agree before it can be recorded, rather than just one participant. Federal law and most US states use one-party consent, where being a party to the conversation is enough. Around twelve states use all-party consent, including California, Illinois, Massachusetts and Washington, but the exact count varies by source because several states apply different rules to in-person conversation and to electronic communication. If participants are in different states, more than one rule can apply at once, so check your own jurisdictions with a lawyer. Announcing the recording at the start of the call satisfies the requirement everywhere.
Yes. Article 13 requires you to tell people whose personal data you collect who you are, why you're collecting it, and how long you'll keep it. A meeting recording is personal data, so participants have to be told before recording starts. Saying it out loud at the beginning of the call satisfies the substance of this. No tool can do it on your behalf.
Yes. Meetily is a botless, or bot-free, meeting recorder: it captures audio from your own system rather than joining the call as a participant. Nothing appears in the attendee list and nothing connects to the meeting, so it works the same way across Zoom, Teams, Google Meet, Discord and any other platform.
European data residency is available on Meetily Enterprise, together with self-hosted deployment on your own infrastructure and managed compliance for GDPR, HIPAA and NIS2. On Community and Pro, transcription runs locally on your device by default, so audio and transcripts don't leave the machine regardless of region. Summaries depend on the provider you configure: a local model keeps everything on-device, while bringing your own API key sends transcript text to the provider you selected.
No. Meetily holds no SOC 2 certification today, and we don't claim one. What we offer instead is architectural: transcription runs locally on your device, Enterprise can be self-hosted entirely on your own infrastructure, and the source code is MIT licensed and open to audit at github.com/Zackriya-Solutions/meetily. For organizations whose requirement is that meeting data never reaches a vendor, that's a stronger answer than a certification covering how a vendor handles data it has already received.

About the Author

S

Sujith S

CTO and Product Owner at Zackriya Solutions, which builds Meetily. Legal references are to the EU General Data Protection Regulation (2016/679) and to US federal and state wiretapping statutes. This is not legal advice.

Get started

Ready to try Meetily?

Join 475,000+ users who use Meetily for private meeting transcription. No bots, privacy first. Community Edition free.

No meeting bots
100% local transcription
Free & open source
Download Free

Star on GitHub (29K+) · Open source & self-hostable

Get Started with Meetily

Meetily Pro

Advanced features for individuals and teams.

Download

Get Meetily for Mac or Windows. Free and open source.

Download

Recent Articles