Transparency
AI app privacy audits, from their own documents.
Clinical privacy audits of the AI apps people run at work. Every claim is quoted from the vendor’s own policy, help center, or public record, linked and dated. Where a vendor does something well, the audit says so plainly.
10 audits · every claim sourced · dated changelog on every audit
Fathom
AI meeting notes · Last verified 2026-08-08
Fathom trains its in-house models on de-identified data from your meetings unless you switch that off, and none of its documents state which position a new account starts in. Against that it publishes a 30-name subprocessor list, contractual no-training terms with its AI vendors, and encryption in transit and at rest.
Read the audit
Fireflies.ai
AI meeting notes · Last verified 2026-08-03
A bot joins the call, and everything it captures is processed in the United States across a 17-name subprocessor list, six of which would see meeting content. The defaults arrive at their widest.
Read the audit
Granola
AI meeting notes · Last verified 2026-08-08
Granola captures meeting audio on your computer, with no bot in the call, then transcribes and summarizes it in its own cloud. Training is on by default outside Enterprise, and the opt-out is one self-serve toggle.
Read the audit
Krisp
AI meeting notes · Last verified 2026-08-08
Used for noise cancellation alone, Krisp says no audiovisual data leaves the device. Turn on the AI Meeting Assistant and, per the Privacy Policy, recordings, transcripts and summaries may be stored on Krisp servers, auto-share ships on, and the no-training promise is split across documents that each cover something different.
Read the audit
Notion AI
AI workspace assistant · Last verified 2026-08-08
Notion states in its AI terms that it does not use your content to train the models behind Notion AI, with carve-outs for feedback and permission. The same promise is written five times across five documents, and the subject or the scope changes each time, while the binding DPA carries no training clause at all.
Read the audit
Otter.ai
AI meeting notes · Last verified 2026-08-03
Every recording goes to Otter's cloud and is stored on AWS in the United States, and outside Enterprise no way to opt out of AI training is documented. Otter also publishes real security work: SOC 2 Type 2, encryption, and 2FA.
Read the audit
Read AI
AI meeting notes · Last verified 2026-08-08
Training on your meetings is opt-out by default and the bot is built to be noticed, both documented by Read AI. Meeting reports still auto-share with everyone invited by default, and the Privacy Policy lists categories of personal information Read AI shares and sells to marketing and advertising partners while its marketing page says it sells nothing.
Read the audit
Superwhisper
AI dictation · Last verified 2026-08-03
A dictation app that can run entirely on your device, with a written no-training promise and no documented sharing surface. The qualifiers: cloud modes exist, Super Mode reads by default, the policy is dated 2024.
Read the audit
tl;dv
AI meeting notes · Last verified 2026-08-08
tl;dv promises never to train AI on customer data, and since the July 1, 2026 version that promise is a clause in the Privacy Policy itself, written more broadly than either marketing page. The gaps sit elsewhere: tl;dv's own sources state its SOC 2 status three ways, and an August 2026 researcher disclosure about meeting metadata is contested by the vendor.
Read the audit
Wispr Flow
AI dictation · Last verified 2026-08-03
Cloud dictation with no offline mode, and training on your dictation is the default outside Enterprise. Privacy Mode turns it off on every plan, free included, against a certification claim the help center does not support.
Read the audit
Method
How these audits are made.
01
The vendor’s own documents
Every audit is built from the vendor’s privacy policy, terms, help center and trust pages, plus court records and top-tier reporting where they exist.
02
Verbatim quotes, in English
Vendor language is quoted to the glyph and stays English in every locale, so you can verify the exact words against the source.
03
Every claim sourced and dated
Each claim carries a numbered reference to a document we read on a stated date. Where we could not verify something, the audit says so.
04
A dated changelog per audit
Every audit records its re-verifications and policy diffs as dated entries. When a vendor corrects something, that lands here too.
Our own audit
Last verified 2026-08-31
What leaves your Mac when you use Routines.
A directory that audits other apps owes you the same ledger for itself. This is the complete list of what Routines sends off your Mac, when it happens, and the switch that turns each flow off, where one exists. Routines is a Mac app with an account behind it, so some of these flows run on our servers by default, and this list says which.
- Chat and routine prompts
Two modes, and you pick one. On Routines AI, the default for a signed-in account, the prompt goes from your Mac to getroutines.ai, authenticated by your device, and on to Anthropic under our key. Every new account starts with €5 of credit, granted once, and more is bought as a one-time top-up, so this path is funded by credit rather than a key you manage. We store the token count and the cost, never the prompt or the answer. On your own key, the prompt goes straight from your Mac to the provider, the key stays in the macOS Keychain, and there is no Routines server in the path. Signing in with ChatGPT or connecting Claude Code works the same way: those calls go from your Mac to that provider under your own account.
How to switch it off
Nothing runs unprompted: if you do not start a chat or an AI routine, nothing is sent. To keep our servers out of the path entirely, add your own API key in settings, sign in with ChatGPT, or connect Claude Code.
- What the assistant reaches while it works
A chat or routine turn can also call tools. The assistant can fetch a web page it is pointed at, and with your own keys added it can search the web with Brave or reach other services through the Maton and Windsor gateways, all directly from your Mac. If the Claude Code command line tool is installed, the assistant can hand a task to it, and that run uses whatever account Claude Code itself is signed into. Two more built-in reaches have no key and no switch: a weather lookup goes to Open-Meteo with a latitude and longitude, and saving a Reddit link to your Library fetches it from Reddit’s own public endpoint, while saving an X link goes through fxtwitter, a third-party mirror of the X API that we do not run and X does not control, because X itself serves nothing readable. If your launcher points at a supported browser and you have granted computer control, the assistant can also hand an instruction to Claude in that browser, which acts on pages under your own logins.
How to switch it off
Tools run only inside a chat or routine turn you started. Skip the optional keys and those tools stay off. Web fetching and Claude Code delegation are built in and have no switch of their own today; if we ship one, it appears here, dated.
- Meeting transcription
Meeting audio streams to Deepgram, the hosted speech-to-text service Routines uses: on the key we manage if you are on Pro or in the free trial, and on your own Deepgram key on the Free plan. There is no transcription mode to pick. With no Deepgram key in the Keychain at all, recording falls back to a local Whisper model on your Mac, and only if that model has already been downloaded; a Free account with the bundled key still in place is refused rather than transcribed anywhere.
How to switch it off
The honest answer is that there is no toggle. The one lever is removing the Deepgram key under Settings, Connections: with the slot empty, meeting transcription runs on the local Whisper model on your Mac, if you have downloaded it. Routines seeds its own key back into the empty slot the next time the app launches, so the change holds only until then.
- Dictation
Dictation is a second audio path and it is not the same as meetings. While you speak, the audio streams to Deepgram on every plan, Free included, over the key in your Keychain, which Routines seeds with its own key by default. A local Whisper model transcribes on your Mac only when that stream fails or no key is present, and only if the model has been downloaded.
How to switch it off
Do not start dictation, or remove the Deepgram key under Settings, Connections. The removed key comes back the next time the app launches, and dictation has no offline mode you can select in advance. We would rather say that than let the word offline sit next to the word dictation.
- Notes, transcripts and outputs
Notes are markdown files on your Mac, in a folder you pick, and they open in any editor. Meeting transcripts and routine outputs live in the app’s local database on your Mac, and an output becomes a markdown file only when the assistant files it into your Library. The optional external reader for hard-to-parse pages, off by default, sends a captured page’s address to Jina Reader, a third party, and stores what comes back locally.
How to switch it off
File storage is local by design. The one switch that copies content off your Mac is Cloud Sync and Backup, off by default, in the row below.
- Cloud Sync and Backup
Off by default. Turn it on and your devices share data through your Routines account: the memory vault, meeting transcripts and notes, routine definitions and their outputs, to-dos, Library items, snippets, installed skills, app settings, and connector definitions with the tokens stripped out. Health data recorded on iPhone is pulled down to the Mac on the same switch.
How to switch it off
Leave Cloud Sync and Backup off, or turn it off in settings.
- Connector credentials
OAuth tokens for Gmail, Calendar, Microsoft 365 (Outlook, read only) and Slack, and the bot tokens for Telegram and Slack apps, are stored in the app’s local database on your Mac, not in the macOS Keychain; the AI provider keys and other API keys you paste do live in the Keychain. Connector calls go from your Mac to the provider directly, and bots connect out from your Mac, so no Routines server sits in the middle.
How to switch it off
Disconnect the connector in settings; Routines holds no server-side copy of your tokens, and Cloud Sync strips tokens out of connector definitions before anything syncs.
- Your account
There is an account. Sign-in, licence state, the trial clock and the Routines AI credit balance live on our servers, and a signed-in app re-checks its entitlements about every ten minutes in the background. Your memory folder is not uploaded to it unless you turn on Cloud Sync and Backup, two rows above. This is the row that makes fully local a sentence we do not write.
How to switch it off
Sign out and the background polling stops. Pro, Teams and Routines AI all need the account; the markdown files on your Mac stay yours either way.
- Team activity, on Teams plans
If you belong to a team, the titles and outcomes of routine runs, recorded meetings and completed to-dos, plus app usage as app names, categories and durations, are sent to your Routines account for the team owner to see. It is on by default when you join a team. Titles and durations, never the notes, transcripts or prompts themselves.
How to switch it off
Turn off Share activity with your team in settings. It has no effect unless you belong to a team.
- Update checks
Shortly after launch, and every six hours, the app fetches a public release file from GitHub to see whether an update exists. The request is anonymous and carries no account data or content, and updates are verified against our signing key before they install.
How to switch it off
There is no switch for this today. If we ship one, it appears in this list, dated.
Consent and recording disclosure
Recording a meeting is a legal act, and the obligation sits with the person recording, not with the app. This is what Routines captures, what the law asks of you, and what Routines does not do for you yet.
- What Routines captures
- Nothing until you press start. When you do, Routines records two local audio streams: your microphone, and the system audio your Mac is already playing, which carries the other people on the call. No bot joins the meeting and nothing appears in the participant list. Meeting audio streams to Deepgram for transcription, on the key we manage if you are on Pro or in the free trial, or on your own Deepgram key on the Free plan. With no Deepgram key in the Keychain at all, transcription runs on a local Whisper model on your Mac, if that model has been downloaded.
- Whose consent the law requires
- In the United States the federal floor is one-party consent, and several states, California, Florida, Illinois and Pennsylvania among them, require every party to agree. Those rules turn on consent, not on whether the recorder appears in the participant list, so a silent local recorder faces the same test as a visible bot. The obligation falls on you, the person recording, not on Routines. We checked the statute text on 2026-08-10. This is general information, not legal advice.
- What you control
- You decide when recording starts, and nothing records unprompted. The one transcription lever is the Deepgram key under Settings, Connections; the meeting and dictation rows above say exactly where audio goes. Notes are markdown files in a folder you pick, and transcripts are kept in the app’s local database on your Mac, so you keep them or delete them yourself. Cloud Sync and Backup is off by default. Turn it on and your vault, your meeting transcripts and your notes are copied to your Routines account so your devices share them. Routines does not use your recordings, transcripts, notes or prompts to train models.
- What Routines does not do yet
- Routines ships no disclosure watermark, no automatic announcement in the meeting chat, and no prompt that asks the other participants for consent. Telling the people in the meeting that you are recording is your responsibility, and we recommend saying so at the start of the call. If we ship a disclosure feature, it appears in this list, dated.
Routines does not use your recordings, transcripts, notes or prompts to train models. The language model runs either under our key, with the content passed through and not kept, or under your own key or provider account, with nothing passing through us at all. If a release changes any of these flows, this list changes with it, dated. Each row is re-read against the shipping build, and the date at the top of this section is the date of that read.
These audits quote each vendor’s own public documents and reputable public records. They are not legal advice, and filed lawsuits are allegations, not findings.