Transparency
AI app privacy audits, from their own documents.
Clinical privacy audits of the AI apps people run at work. Every claim is quoted from the vendor’s own policy, help center, or public record, linked and dated. Where a vendor does something well, the audit says so plainly.
10 audits · every claim sourced · dated changelog on every audit
Fathom
AI meeting notes · Last verified 2026-08-08
Fathom trains its in-house models on de-identified data from your meetings unless you switch that off, and none of its documents state which position a new account starts in. Against that it publishes a 30-name subprocessor list, contractual no-training terms with its AI vendors, and encryption in transit and at rest.
Read the audit
Fireflies.ai
AI meeting notes · Last verified 2026-08-03
A bot joins the call, and everything it captures is processed in the United States across a 17-name subprocessor list, six of which would see meeting content. The defaults arrive at their widest.
Read the audit
Granola
AI meeting notes · Last verified 2026-08-08
Granola captures meeting audio on your computer, with no bot in the call, then transcribes and summarizes it in its own cloud. Training is on by default outside Enterprise, and the opt-out is one self-serve toggle.
Read the audit
Krisp
AI meeting notes · Last verified 2026-08-08
Used for noise cancellation alone, Krisp says no audiovisual data leaves the device. Turn on the AI Meeting Assistant and, per the Privacy Policy, recordings, transcripts and summaries may be stored on Krisp servers, auto-share ships on, and the no-training promise is split across documents that each cover something different.
Read the audit
Notion AI
AI workspace assistant · Last verified 2026-08-08
Notion states in its AI terms that it does not use your content to train the models behind Notion AI, with carve-outs for feedback and permission. The same promise is written five times across five documents, and the subject or the scope changes each time, while the binding DPA carries no training clause at all.
Read the audit
Otter.ai
AI meeting notes · Last verified 2026-08-03
Every recording goes to Otter's cloud and is stored on AWS in the United States, and outside Enterprise no way to opt out of AI training is documented. Otter also publishes real security work: SOC 2 Type 2, encryption, and 2FA.
Read the audit
Read AI
AI meeting notes · Last verified 2026-08-08
Training on your meetings is opt-out by default and the bot is built to be noticed, both documented by Read AI. Meeting reports still auto-share with everyone invited by default, and the Privacy Policy lists categories of personal information Read AI shares and sells to marketing and advertising partners while its marketing page says it sells nothing.
Read the audit
Superwhisper
AI dictation · Last verified 2026-08-03
A dictation app that can run entirely on your device, with a written no-training promise and no documented sharing surface. The qualifiers: cloud modes exist, Super Mode reads by default, the policy is dated 2024.
Read the audit
tl;dv
AI meeting notes · Last verified 2026-08-08
tl;dv promises never to train AI on customer data, and since the July 1, 2026 version that promise is a clause in the Privacy Policy itself, written more broadly than either marketing page. The gaps sit elsewhere: tl;dv's own sources state its SOC 2 status three ways, and an August 2026 researcher disclosure about meeting metadata is contested by the vendor.
Read the audit
Wispr Flow
AI dictation · Last verified 2026-08-03
Cloud dictation with no offline mode, and training on your dictation is the default outside Enterprise. Privacy Mode turns it off on every plan, free included, against a certification claim the help center does not support.
Read the audit
Method
How these audits are made.
01
The vendor’s own documents
Every audit is built from the vendor’s privacy policy, terms, help center and trust pages, plus court records and top-tier reporting where they exist.
02
Verbatim quotes, in English
Vendor language is quoted to the glyph and stays English in every locale, so you can verify the exact words against the source.
03
Every claim sourced and dated
Each claim carries a numbered reference to a document we read on a stated date. Where we could not verify something, the audit says so.
04
A dated changelog per audit
Every audit records its re-verifications and policy diffs as dated entries. When a vendor corrects something, that lands here too.
Our own audit
Last verified 2026-08-07
What leaves your Mac when you use Routines.
A directory that audits other apps owes you the same ledger for itself. This is the complete list of what Routines sends off your Mac, when it happens, and the switch that turns each flow off.
- Chat and routine prompts
Two modes, and you pick one. On Routines AI, the default for a signed-in account, the prompt goes from your Mac to getroutines.ai, authenticated by your device, and on to Anthropic under our key. We store the token count and the cost, never the prompt or the answer. On your own key, the prompt goes straight from your Mac to the provider, the key stays in the macOS Keychain, and there is no Routines server in the path.
How to switch it off
Nothing runs unprompted: if you do not start a chat or an AI routine, nothing is sent. To keep our servers out of the path entirely, add your own API key in settings.
- Meeting and dictation audio
With cloud transcription selected, audio streams to Deepgram, the hosted speech-to-text service Routines uses: a managed plan on Pro, or your own Deepgram key on Free.
How to switch it off
Choose the local Whisper model in transcription settings. Transcription then runs on your Mac, and there is no audio for anyone to train on.
- Notes, transcripts and outputs
Saved as markdown files on your Mac. They open in any editor, work offline, and carry no cloud bill and no per-minute cost.
How to switch it off
Nothing to switch off: file storage is local by design.
- Connector credentials
OAuth refresh tokens for Gmail, Calendar and Slack are stored in the macOS Keychain on your Mac, and connector calls go from your Mac to the provider directly.
How to switch it off
Disconnect the connector in settings; Routines holds no server-side copy of your tokens.
Routines does not use your recordings, transcripts, notes or prompts to train models. The language model runs either under our key, with the content passed through and not kept, or under your own key, with nothing passing through us at all. If a release changes any of these flows, this list changes with it, dated.
These audits quote each vendor’s own public documents and reputable public records. They are not legal advice, and filed lawsuits are allegations, not findings.