Transparency

AI app privacy audits, from their own documents.

Clinical privacy audits of the AI apps people run at work. Every claim is quoted from the vendor’s own policy, help center, or public record, linked and dated. Where a vendor does something well, the audit says so plainly.

5 audits · every claim sourced · re-verified on a dated schedule

Fireflies.ai

AI meeting notes · Last verified 2026-08-02

Fireflies.ai is a cloud meeting notetaker whose bot, Fred, joins the call as a participant. Everything it captures is processed in the United States, by a vendor stack whose published subprocessor list runs to 17 names, six of which would see meeting content or its derivatives, including OpenAI, Anthropic and two speech-recognition vendors. Fireflies says it never trains AI on meeting content, and one version of it is contractual, but the promise is written four times across two documents, no two of them with the same scope, and the binding one covers generative AI models only. The defaults deserve attention: the bot joins every calendar meeting with a conference link, the notification email ships off, and meetings ship viewable by anyone with the link.

Read the audit

Granola

AI meeting notes · Last verified 2026-08-02

Granola is a desktop AI notepad that captures meeting audio on your computer, and no bot joins the call. Processing is another matter: transcription and summarization run in Granola's cloud, on AWS in the United States, through five model vendors and two transcription vendors. Its Platform Terms turn Granola's own model training on by default outside Enterprise, though the opt-out is one self-serve toggle, and Granola publishes more security work than most. Against that sit no built-in two-factor authentication, indefinite retention, and a proposed class action filed July 30, 2026, not yet answered or ruled on.

Read the audit

Otter.ai

AI meeting notes · Last verified 2026-08-02

Otter.ai is a cloud transcription service. Every recording is uploaded to Otter's servers, transcribed there, and stored on AWS in the United States. Its Privacy Policy says Otter trains its own AI on de-identified recordings and transcripts, and outside the Enterprise plan no way to opt out of that training is documented. At the same time, Otter publishes real security work: a SOC 2 Type 2 report, encryption at rest, consent-gated support access, and two-factor authentication on every plan. Whether that trade is acceptable depends on what you record and for whom.

Read the audit

Superwhisper

AI dictation · Last verified 2026-08-02

Superwhisper is a dictation app that can run entirely on your device, and its own docs explain how: two independent stages, voice to text and an optional AI rewrite, each pointed at a local or cloud model per mode. The vendor promises in writing that it does not train on your data, names every cloud provider it uses, documents no sharing surface at all, and lists a SOC 2 Type II report, dated March 2026, that it says it will share under NDA. The qualifiers matter. Cloud modes exist, the flagship Super Mode reads your input field, selection and clipboard by default, and the privacy policy is dated June 2024 and no longer matches the 2026 Terms.

Read the audit

Wispr Flow

AI dictation · Last verified 2026-08-02

Wispr Flow is a cloud dictation service: audio is captured on your device, streamed to Wispr's servers in the United States and transcribed there, with no offline mode and no on-premise option. Training on your dictation is the default. Wispr's own security FAQ says audio and transcription data may be used to train its models, and that this is the default for trial and standard accounts. Privacy Mode turns that off on every plan including the free one, and Enterprise and HIPAA BAA accounts run it on by default. Against that sits a certification claim the vendor's own help center does not support.

Read the audit