AI-Powered Note-Taking Apps Violate User Privacy.

A few years ago, AI-powered note-taking and transcription tools were a niche productivity tool used by busy executives and media professionals. Now they’re ubiquitous. But these apps come with legal caveats that most people don’t know to look for.
First, the app can store recordings and transcripts of your meetings indefinitely after use. They can also be used for a variety of internal purposes, including model training and marketing campaigns. Second, state laws often require consent from all parties before recording a conversation. The AI that creates the notes claims that the onus is on the user of the recording app—you. Therefore, if you recorded a meeting but failed to notify the other party, they could sue you for violating their data protection rights.
That’s why many AI-powered note-taking platforms are currently facing class-action lawsuits from users who accuse them of mishandling data and transferring consent rights to users without proper information. I’ll discuss the current legal situation and steps you can take to protect your data in the future.
What is the lawsuit against Granola?
Chamberlain v. Granola, Inc. was filed on July 30, 2026, in the U.S. District Court of California by plaintiff Tarra Chamberlain, who claims she was recorded without her consent (or even knowledge) during a video call with someone using Granola. Unlike most AI-powered call recording apps, which appear as bots that must be explicitly allowed into the call, Granola is built on the principle of invisibility. According to the app’s own advertising copy, its selling point is that it runs locally on the user’s device, so “other people in the room won’t know it exists.” The plaintiff’s attorneys argue that this is a classic example of illegal eavesdropping.
Furthermore, the developers intended that no meeting participant can disable Granola except the user who has the app installed on their device. Users are also included in model training by default, so they must manually opt out if they do not want the company to save conversation recordings. Even if a user opts out of model training, this setting will not be applied to previous versions, and recordings of previous conversations will still be saved for training purposes.
In their formal complaint, the plaintiffs’ lawyers allege numerous violations of federal and state law, including the Electronic Communications Privacy Protection Act and the California Invasion of Privacy Act. Granola denies these allegations, stating that it anonymizes all training data before use and that no conversation data is shared with third parties, but the plaintiffs reject this claim.
The problem isn’t just with granola.
This isn’t the only active class action lawsuit against a company building AI-powered call recording systems in Silicon Valley. In 2025, four class action lawsuits against Otter.ai were consolidated into a single case before Judge Yumi K. Lee in the Northern District of California. Like the Granola case, this case alleges that Otter records conversations without the consent of meeting participants and then uses those recordings to train its own AI models. Justin Brewer, one of the plaintiffs in the lawsuit against Otter, claims he was recorded using the OtterPilot app during a phone call with a client, and his voice was subsequently used to train AI models without his knowledge. Although lawyers working for Otter have filed a motion to dismiss the lawsuit, a decision on it has not yet been made.
Fireflies.ai is also facing multiple class-action lawsuits for violating the Illinois Biometric Information Privacy Act (BIPA) by collecting meeting participants’ voiceprints using its speech recognition technology without obtaining consent from those involved in the recording. Read AI has not faced any lawsuits, but its app has been banned by several public and private universities, including the University of Washington , Chapman University , Tufts University , and Mississippi State University . The University of Washington’s website states: “Read AI may join, transcribe, and summarize its users’ online meetings even when users are not present,” adding that this poses significant “security and privacy risks to institutional data.”
Who is responsible for obtaining user consent for the use of AI note-taking apps?
In each of these class action lawsuits so far, the developers of AI-powered call recording apps have insisted that the responsibility for obtaining consent from other participants lies with the user, not the app company. Otter.ai specifically stated that this is spelled out in the contract new users are forced to sign, shifting the company’s responsibility for obtaining consent to the user. Therefore, if you used the app to record a conversation, Otter.ai argues that it is your responsibility to ensure that other participants are aware of and consent to the recording.
Of course, all of this relies on the terms of the user agreement you sign when creating a new account in the notes app, which is undoubtedly buried among a ton of other text that no one bothers to read. Historically, courts have frowned upon tech companies that hide behind terms of service and shift responsibility to users. But this isn’t guaranteed and remains subject to review on a case-by-case basis by the presiding judge.
On the other hand, consent from all parties isn’t a requirement for recording conversations in every US state. However, at least eleven of them , including California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, and Washington, have similar rules to protect user privacy. Depending on the circumstances of the conversation and the information disclosed, other states may also offer specific protections. Given the confusing circumstances and the lack of resolution in any of these lawsuits, it shouldn’t be assumed that you’re not responsible for obtaining consent if you use a third-party app or service. But that also doesn’t mean you should allow AI programmers to completely avoid liability.
How to Protect Your Personal Rights with AI-Powered Note-Taking Apps
There’s no denying the convenience of AI-powered transcription, and you can’t control what software other meeting participants choose to run silently. However, there are some things you can do to protect yourself from privacy breaches and compliance issues, both as a user and as another meeting participant.
-
If you decide to use an AI-powered automated note-taking system during a meeting, obtain verbal consent from all participants before starting recording.
-
Therefore, if any of the meeting participants is a resident of California, Illinois, or another state where consent from all parties is required, it should be assumed that the participants must be verbally notified and their permission sought before recording begins.
-
If you join a meeting, ask the host directly whether the conversation is being recorded or whether the minutes feature is being used, unless they have indicated otherwise in advance.
-
Before granting an AI app access to your meetings, make sure you’ve opted out of any model training or data sharing agreements in the app’s settings.
-
Depending on your region, you may have the legal right to revoke permission to access your past data by providing written notice. For example, California residents can exercise their right to erasure by contacting the company and requesting deletion of their personal data. In this case, please contact the app’s support team.
None of this can completely guarantee that you will never fall victim to privacy violations by an AI-powered meeting bot, but being mindful and attentive will increase your chances of protecting your rights. If a meeting requires disclosure of sensitive information and you are unsure whether you are being recorded by an AI app, it’s best to leave the meeting entirely and obtain written confirmation from the host before continuing.