- Privacy
- Fireflies
- Meeting notes
Is Fireflies.ai safe? The security posture, and the tier that catches people out
Fireflies holds SOC 2 Type II, does not train on your data, and enforces zero-day retention with its vendors. HIPAA coverage is Enterprise only, which is the detail that catches out solo practitioners.
Ben Claybrook 5 min read
Fireflies publishes more specific security detail than most of its competitors, and specific claims are easier to check than reassuring ones. That is a point in its favour before we look at anything else.
Everything below comes from Fireflies’ own published documentation, checked 5 September 2026.
What Fireflies commits to
- SOC 2 Type II, GDPR, and HIPAA compliance, the last one with a plan restriction covered below.
- 256-bit AES encryption for notes and transcripts at rest, TLS in transit.
- Data stored and processed in US cloud infrastructure by default, with servers on Google Cloud and databases in an AWS Virtual Private Cloud.
- “We don’t train our AI model with your data.”
- A zero-day data retention policy with all vendors that have access to user content, and signed BAAs with its LLM and speech recognition vendors prohibiting them from using customer content for training.
That last one is the strongest item on the list and it is the one most vendors do not offer. Pushing a zero-retention agreement down to your subprocessors is real work, and it closes a gap that many privacy policies leave wide open.
What the retention policy actually says
Fireflies states that “data is saved for at least 12 months.”
Read that carefully. Twelve months is the floor, not the ceiling. You can delete an individual meeting and Fireflies says the data goes “immediately and irreversibly,” and if you delete your account, “all of your meeting data will be irreversibly deleted within 30 days.” Both of those are good controls.
But absent you taking action, the default is that a transcript of your conversation lives on Fireflies’ infrastructure for a year or more. For most business meetings that is unremarkable. For a conversation you would not want to exist in written form on a third party’s servers a year from now, it is the whole issue.
The HIPAA detail that catches people out
Fireflies is HIPAA compliant and will sign a BAA. Both true.
HIPAA coverage is on the Enterprise plan only. The Free, Pro and Business plans do not include it. Enterprise is listed at $39 per seat per month billed annually, and it is where private storage, custom data retention and the signed BAA live.
This is the single most consequential thing in this post, because the people most likely to search “is Fireflies safe” are often solo practitioners: a therapist in private practice, an independent consultant handling client health information, a small clinic. Someone on the Pro plan handling PHI is not covered by a BAA, and under HIPAA that is the practitioner’s exposure, not the vendor’s.
If you handle PHI and you are not on Enterprise with a signed BAA in hand, you do not have what you think you have. We go deeper on what compliance actually requires in HIPAA and AI note takers.
The bot question
Fireflies uses a notetaker bot that joins the call and appears in the participant list. You can decline to invite it to a given meeting, and remove it if it is already there.
A visible bot is genuinely better than silent recording from a notice standpoint. Everyone in the meeting can see that something is recording, which is exactly the consent surface that is now being litigated elsewhere in this category. It is also the thing clients react to, and that reaction is information: if someone would object to a bot, they may object to the recording, and the bot is what prompted them to say so.
If you are in an all-party consent state, the bot’s presence is not the same as consent. See two-party consent states for why that list is messier than it looks.
So is it safe?
For general business use, yes, and the vendor-level controls are better than most.
The remaining question is not about Fireflies’ competence. It is that the model requires your transcripts to exist on someone else’s servers for at least a year, and your protection is the strength of a set of promises: policies, contracts, and a compliance tier you have to be paying for. Those promises are currently well kept. They are still promises, and companies get acquired, change policy, and receive legal process.
The other approach
Private Notetaker keeps the whole pipeline on your computer. Audio is captured locally, transcribed by a model on your disk, and summarised by a language model that also runs on your machine. No bot joins the call, and nothing is uploaded, so there is no retention floor to read and no compliance tier to buy into. It is a one-time $149 licence or $15 a month rather than a per-seat plan.
To be straight about what you give up: no team workspace, no shared search across an organisation, no CRM integrations, English only, and worse accuracy than Fireflies on noisy audio and heavy accents, because their models run on server hardware and ours have to fit on your laptop. Fireflies is a better product for a sales team. It is a worse fit for a conversation that should not exist on anyone else’s infrastructure.
Compare them side by side, or see the wider list of Fireflies alternatives.
All Fireflies claims quoted from its published security and pricing documentation, checked 5 September 2026. Plans and policies change, so verify before relying on this, particularly the HIPAA tier restriction.
Frequently asked questions
- Is Fireflies.ai safe to use?
- For general business use, its security posture is strong. Fireflies holds SOC 2 Type II, encrypts transcripts with 256-bit AES at rest and TLS in transit, states it does not train its models on customer data, and enforces a zero-day retention policy with the vendors that touch your content. The main caveats are that its notetaker is a bot that joins your call, and that HIPAA coverage is limited to the Enterprise plan.
- Can Fireflies AI be trusted?
- Its published commitments are specific and verifiable rather than vague, which is a good sign. It names its retention floor, its encryption, and its vendor agreements. The trust question that remains is structural rather than about Fireflies specifically: your transcripts sit on their infrastructure for at least twelve months, so you are trusting a company's future as well as its present.
- Is Fireflies AI ethical?
- The contested area in this category is consent. Fireflies uses a bot that appears in the participant list, which gives attendees visible notice, and it lets you decline to invite it or remove it mid-meeting. Whether recording a given conversation is appropriate is a decision for the person running it, not the software.
- Is Fireflies AI completely free?
- There is a free tier with limits on transcription credits and features. The plans that matter for confidential work are not free: HIPAA compliance, a signed BAA, private storage and custom data retention are Enterprise features, listed at $39 per seat per month billed annually as of September 2026.