- Privacy
- Otter
- Meeting notes
Is Otter.ai safe? What actually happens to your recordings
Otter holds SOC 2 Type 2 and encrypts everything, and it is also defending a federal wiretap case over how its notetaker joins meetings. Here is what Otter publishes, what the litigation alleges, and how to decide.
Ben Claybrook 5 min read
Otter is one of the most established AI notetakers, it publishes real security documentation, and it is currently defending a federal wiretap class action over how its notetaker joins meetings. All three of those things are true at once, which is why the question “is Otter safe” does not have a one word answer.
This post separates what Otter actually publishes from what is alleged in court, because most of what you will find searching this question blurs the two.
What Otter publishes about security
Taken from Otter’s own privacy and security page, verified 5 September 2026:
- A SOC 2 Type 2 report, plus stated alignment with GDPR and CCPA.
- AES-256 encryption, with recordings in AWS S3 using server side encryption and root keys rotated on a schedule.
- Deleted conversations move to a Trash that empties automatically after 30 days.
- Employees and support staff need explicit customer consent before accessing a transcript or recording.
That is a real security programme. If your worry is a careless startup leaving an S3 bucket open, this is not that. Otter has done the work most companies its size do.
So what is the lawsuit about?
Not a breach. Consent.
In August 2025 a California resident filed a class action alleging that the Otter Notetaker bot joins Zoom, Google Meet and Microsoft Teams calls and records participants who never agreed to it. The cases were consolidated as In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL, in the Northern District of California.
On 13 August 2026, Judge Eumi K. Lee ruled on Otter’s motion to dismiss. Several claims survived and are now heading into discovery:
- Federal Wiretap Act claim
- California Invasion of Privacy Act section 631
- Two Illinois biometric privacy claims over voiceprints
- Unjust enrichment and Unfair Competition Law claims
The court’s reasoning is the part worth reading. Judge Lee held that plaintiffs “plausibly allege that Otter independently collects, retains, and uses communications for its own commercial purposes,” which frames Otter as a potential third party eavesdropper rather than simply a tool the meeting host chose to run.
Other claims were dismissed with leave to amend, including Computer Fraud and Abuse Act and Washington Privacy Act counts, and plaintiffs withdrew several others.
This needs saying clearly: surviving a motion to dismiss is not a finding of liability. At this stage a court has decided the allegations are plausible enough to investigate, not that they are true. Otter denies wrongdoing. The case is unresolved.
Does Otter train AI on your conversations?
Otter’s security page makes two separate statements, and the difference between them is easy to miss:
- “No customer data will be used to train or improve our AI Service Provider(s).”
- Otter uses “a proprietary method to de-identify user data before training our models.”
The first promise is about OpenAI and similar vendors. The second is about Otter’s own models, and it confirms that your conversations do feed training after de-identification. Otter also states that audio and transcripts are not manually reviewed by a human.
Whether de-identified training is acceptable depends entirely on what you discuss. For a weekly standup, almost certainly fine. For a client’s acquisition terms or a patient’s history, “de-identified” is doing a great deal of load bearing work.
The question underneath all of this
Every cloud notetaker asks you to make the same bet: that the company’s policies, staff, security controls and legal posture will all hold for as long as your recordings exist on their servers.
Otter has strong policies. The lawsuit is about whether policies were the right control in the first place. A policy can be excellent and still be changed, breached, subpoenaed, or interpreted differently by a new owner. The recordings are still there.
That is the distinction between a policy promise and an architectural one. A tool that never uploads your audio has nothing to hand over, because there is no server side copy to hand over.
How to decide for your own situation
Ask three questions:
Who else is in the meeting? A bot recording your own team is a different consent question from a bot recording a client, a candidate or a patient. The Otter litigation is squarely about the second case.
What state or country are you in? Roughly a dozen US states require all parties to consent to a recording. A bot that joins and records without meaningful notice is a bigger exposure there. We cover this in more depth in our post on meeting recording consent laws.
What would it cost you if this conversation leaked in three years? If the honest answer is “very little”, cloud tools are convenient and Otter is a capable one. If the answer involves privilege, PHI, or a deal, the calculus changes.
Where Otter is genuinely the better choice
We build a competing product, so here is the honest version.
Otter is better than us if you need a shared team workspace, searchable transcripts across an organisation, real time collaborative editing, speaker identification tuned over many meetings, or languages beyond English. Its accuracy on difficult audio, heavy accents and poor microphones is also better, because it runs much larger models on server hardware than anything that fits on a laptop.
Private Notetaker does none of the team collaboration part. It is a single user desktop app that records the meeting on your machine, transcribes it there, and writes the summary with a local model. Nothing is uploaded, so nothing can be produced in discovery, breached, or used for training. That is the entire trade: you give up cloud features and multi language support, and in exchange there is no server side copy of your meetings anywhere.
If that trade sounds right, the side by side comparison is the fastest way to see what you gain and lose, and we also maintain a broader list of Otter alternatives including tools that are not ours.
Nothing here is legal advice. Court details are drawn from public filings in In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL (N.D. Cal.), and Otter’s published security documentation, both checked 5 September 2026. Litigation status changes, so verify before relying on it.
Frequently asked questions
- Is Otter.ai being sued?
- Yes. A federal class action is pending in the Northern District of California, consolidated as In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL. On 13 August 2026 the court denied Otter's motion to dismiss in part, allowing federal Wiretap Act, California Invasion of Privacy Act section 631, and Illinois biometric voiceprint claims to proceed to discovery. These are allegations that survived an early motion. No court has found Otter liable.
- Does Otter.ai use my data?
- By Otter's own account, yes, in a limited form. Its security page says Otter uses a proprietary method to de-identify user data before training its models, and separately that no customer data is used to train or improve its third-party AI providers. Those are two different promises. The first one confirms your conversations do feed model training after de-identification.
- Has Otter.ai been accused of a data breach?
- The pending litigation is about consent and recording practices, not a reported breach of Otter's systems. We are not aware of a publicly disclosed Otter data breach as of September 2026. That distinction matters: the claims concern how audio is collected and used, not whether an attacker took it.
- Is Otter a legit website?
- Yes. Otter.ai is an established company with a SOC 2 Type 2 report, published security documentation, and millions of users. Whether it is legitimate and whether it fits confidential work are separate questions, and this post is about the second one.