The most private AI notetaker: what to check

The most private AI notetaker is the one whose controls you can name. Privacy here is four separate decisions: training use, server storage, what joins the call, and admin governance. Most vendors blur the first two into one toggle. Wispr Notetaker keeps them as separate, named settings.

What an AI notetaker is, and what "private" means for one

An AI notetaker is software that records a meeting and turns it into notes. The words underneath it get used loosely, so it helps to separate them.

  • A transcript is the raw record of what was said, line by line, with speakers attached
  • Notes are what you wrote or marked during the meeting, in your own words
  • A readout is the summary built afterward: the TL;DR, key points, decisions, next steps
  • An assistant is the layer you can question later, either in the tool or in Claude or ChatGPT

Privacy is not one property of that stack. It is a set of separate decisions, and a vendor can be strong on one and silent on the next. Four carry most of the weight: whether your audio and transcripts are used to improve AI models, whether the content sits on a server and for how long, what joins the meeting and who knows recording is happening, and whether an admin can set the policy and keep it set.

Those are independent. A tool can store nothing on a server and still send every word through a training pipeline. A tool can promise it never trains and still keep transcripts forever.

Wispr Flow keeps the two apart under Settings, Data and Privacy: "Improve the model for everyone" governs training use, and dictation cloud storage governs where dictation data is stored and synced. Notetaker transcript retention is its own setting.

Where privacy shows up before, during, and after a meeting

The decisions above land at different moments in a meeting, which is why a single privacy page rarely answers them.

Before. The tool reads your calendar to know what is coming and who is invited. Wispr Notetaker shows the next meeting in the menu bar and reminds you right before it starts. This is where a bot-based tool would be told to join.

During. Something is capturing audio. Either a participant joins the call to do it, or the capture happens on the device of the person who pressed the button. Wispr Notetaker records on the device of the person who started it, so the participant list does not change. People should still know you are recording. Nothing joining the call does not change that.

After. Most of what you are actually deciding lands after the meeting: the transcript, the readout, the audio, how long any of it is kept, who it goes to, and whether it feeds model training. Deletion belongs here too, and it should reach every device you are signed in on, not just the one in front of you.

Questions to ask about training use and storage

Ask these four first, in order. The first two are the ones vendors most often merge, and merging them is the tell.

1. Do you use my meetings to train AI models, and what is the default?

Why it matters: a default set to allow means the answer for most of the vendor's users is yes, regardless of what the marketing page says. What a good answer sounds like: a named setting, a stated default, and a place you can change it. In Wispr Flow, the setting is "Improve the model for everyone" under Settings, Data and Privacy. It is on by default on Flow Free and Pro, and off by default on Enterprise. Off means your data is not used for model training. So the honest version is a setting you control, not a promise. If a vendor says it never trains on your data, ask them to show you the toggle.

2. Is server storage a separate setting from training use?

Why it matters: if one switch governs both, you cannot keep cross-device access while opting out of training, or vice versa. What good looks like: two controls, two descriptions. Dictation cloud storage is its own setting, separate from training use, and it covers dictation data. For meetings, transcript retention is set in Notetaker settings.

3. How long are transcripts kept, and can I pick the number?

Why it matters: "we delete when no longer needed" is not a retention policy. What good looks like: a list of intervals you choose from. Wispr Notetaker keeps transcripts indefinitely by default, or auto-deletes them after 1, 7, 30, 90, 180, or 365 days, set in Notetaker settings with notes sync on. Deleting a meeting is permanent and applies across every signed-in device, and it takes the notes, summary, transcript, and speaker-identification data with it.

4. What happens to the meeting audio after the transcript exists?

Why it matters: audio is the most sensitive artifact and the least useful one to keep. What good looks like: encryption, a short window, and automatic removal. Wispr Notetaker keeps meeting audio encrypted and only temporarily, on your device and in some cases in cloud storage, to create your transcript, let you resume a meeting, verify quality, and troubleshoot. After that limited period it is removed automatically. Wispr Notetaker does not create voiceprints or biometric profiles of you or anyone on your call.

Questions to ask about capture, location, and admin control

The remaining five decide whether the first four hold up once other people are involved.

5. Does anything join the call, and who tells the participants?

Why it matters: a bot in the participant list is a fourth party holding your audio, and it changes how people talk. What good looks like: a straight answer about parties, and a straight answer about disclosure. Wispr Notetaker records on your device, so nothing appears in the participant list and no bot joins as a separate party. Say out loud that you are recording before you start. Wispr Notetaker also keeps a consent reminder on screen the whole time it records.

6. What do sharing defaults do before I change anything?

Why it matters: most leaks are a default, not a breach. What good looks like: narrow to start, wide only on purpose. In Wispr Notetaker your notes stay private until you share them, and you decide what goes out.

7. Is my data processed where my contracts require?

Why it matters: for a European buyer this is often the whole procurement conversation. What good looks like: a plain statement of where processing happens. All Wispr Flow customer data is processed in the United States, encrypted in transit and at rest. If a vendor's answer to "is it encrypted" is one word, ask whether they mean in transit, at rest, or both.

8. Which compliance reports exist today, and how do I read them?

Why it matters: "enterprise-grade" is not an audit. What good looks like: named frameworks, a stated scope, and a way to get the report. Wispr Flow is SOC 2 Type II and ISO 27001 compliant on every plan, not gated behind an enterprise tier, and reports are available through the Trust Center. Ask every vendor whether their certification covers the notetaking product specifically or only part of the platform.

9. What can an admin lock, and can a member override it?

Why it matters: a policy any user can switch off will not hold. What good looks like: named controls, set centrally, visibly locked in the app. On Enterprise, admins set "Improve the model for everyone" to enforced for everyone or managed individually under Settings, Organization, and can set dictation cloud storage to disabled for everyone or managed individually. Enforce zero data retention is a standalone control. When an organization locks model improvement, the toggle shows off and disabled with your organization's policy named underneath it. Individual users cannot override it. Admins also opt the whole organization in or out of Wispr Notetaker.

How to score the answers you get

Read the answers side by side and grade each on evidence, not tone. A vendor who says "we take privacy seriously" and a vendor who says "the default is on, here is where to change it" are not close.

QuestionWeak answerStrong answer
Training use"We never train on customer data" with no setting shownNamed setting, stated default, changeable in-app
StorageOne privacy toggle covering everythingStorage and training controlled separately
Retention"Kept as long as necessary"Intervals you select, deletion across devices
AudioNo mention of audio at allEncrypted, short window, removed automatically
CaptureBot in the call, disclosure unaddressedParties named, disclosure responsibility stated
Encryption"Fully encrypted"In transit and at rest, stated separately
Processing locationVague global infrastructure languageNamed country, stated plainly
Compliance"Enterprise-grade security"Named frameworks, scope, report on request
GovernanceSettings live with each userAdmin-set, member-locked, named in the app

Two rows carry the most weight in practice: training use and governance. Training use decides what happens to your words. Governance decides whether that answer holds once the rest of the company is using the tool.

How Wispr Notetaker fits, and where it does not

The setup is short. Connect your calendar, and Wispr Notetaker shows the next meeting in the menu bar with a reminder right before it starts. When a meeting begins, a card offers to start the recorder. Automatic detection covers Google Meet, Zoom, Microsoft Teams, and Webex links. Recording runs on your device, and it stops on its own once the meeting ends. Names come from the calendar invite and your personal dictionary. If a speaker is unnamed, you label them once afterward and the label applies across the transcript, which matters because a wrong label carries into every summary built on it.

Now the limits.

  • Wispr Notetaker runs on Mac today, with Windows coming soon; iPhone and Android are on the roadmap
  • All Wispr Flow customer data is processed in the United States, encrypted in transit and at rest
  • Wispr Notetaker is not available on a HIPAA BAA account, and neither is Scratchpad
  • English is the supported language today, with more coming soon
  • Model training is on by default on Flow Free and Pro, so opting out is an action you take

If your security review requires a signed BAA covering meeting notes, the answer today is no. Processing happens in the United States, so buyers with a data-location requirement should raise it during contracting. Read the data controls before you decide, not after.

Who this is a good fit for, and who should wait

Good fit: a Mac team that wants meeting notes without a bot in the participant list, and an admin who can set training and storage policy once and have it hold. It also fits anyone piping meetings into Claude or ChatGPT, where the training opt-out you set still applies. Flow Free includes speaker identification, calendar and Slack connections, and the training opt-out.

Should wait: Windows-first teams, since Wispr Notetaker is Mac-only today. Anyone under a signed BAA, since Wispr Notetaker is not available on those accounts. Buyers who require data processed outside the United States, since all Wispr Flow customer data is processed in the United States today.

The product facts above come from Wispr Notetaker's public help center and privacy documentation, read in September 2026.

Defending the choice to a security team

The person who has to justify this tool is rarely the person who wanted it. So bring documents, not arguments: the SOC 2 Type II and ISO 27001 reports with the scope stated, then a screenshot of the two settings in your account, then your admin policy. Hand them over in that order, because the first answers whether controls exist and the last answers whether they hold.

Then close the loop on governance: point them at question nine above and show them the locked toggle in your own account, with your organization's policy named underneath it. A control a user can quietly switch off is not a control.

Try Wispr Notetaker on one real meeting, then run these nine questions against whatever you use today and see which answers come back with a number attached.

Frequently asked questions

What is the most private AI notetaker?

There is no single winner, because privacy is four separate decisions: training use, storage, capture, and admin governance. The most private tool for you is the one that answers each with a named setting, a stated default, and a number for retention. Grade vendors on those answers, not on their privacy page's adjectives.

Is a bot-free notetaker more private than one that joins the call?

It puts fewer parties in the room. Capture runs on the device of whoever started it, so no extra party is in the meeting holding your audio. It does not change what you owe the people on the call. Say out loud that you are recording before you start.

Can I move my notes into Claude or ChatGPT without loosening privacy?

Yes. Wispr Notetaker meetings, including notes, summaries, and transcripts, can be pulled into any AI assistant that supports MCP, and that access is included on Flow Free. Dictations are never exposed through that connection. The training opt-out is a separate setting and stays wherever you set it.

We already use another notetaker. What does switching cost us?

Your history is the thing to check first. Wispr Notetaker supports one-click import from Granola and Otter, so existing notes come with you. For other tools, run both on the same meetings and compare the readouts before you cut over.

Is Wispr Notetaker HIPAA compliant?

No. HIPAA-ready applies to Wispr Flow dictation with a signed Business Associate Agreement, and Wispr Notetaker is not available on a BAA account. If your organization operates under a BAA, treat Wispr Notetaker as out of scope for now rather than assuming platform compliance covers it.

Can I set a different retention period for different meetings?

No. Transcript retention is one account-level choice, applied to every meeting with notes sync on: keep indefinitely, or auto-delete after 1, 7, 30, 90, 180, or 365 days. If you need a shorter window for one meeting, delete that meeting directly, which removes it across every signed-in device.

Does turning off model training change what my notes look like?

No. The opt-out governs whether your data is used to evaluate, train, or improve AI models, not the quality of your transcript or summary. Changes apply right away and sync across your devices, and you can change it later under Settings, Data and Privacy.

Share this