Krisp privacy audit

Is Krisp safe? A privacy audit built from Krisp's own documents.

The short answer

Last verified 2026-08-08

Krisp is two products under one name. Used for noise cancellation alone, it captures nothing: the Privacy Policy states no audiovisual data leaves the device. Turn on the AI Meeting Assistant and, per the Privacy Policy, recordings, transcripts and summaries may be stored on Krisp servers and shared with named third-party inference vendors; the security page describes cloud storage as beginning once Meeting Notes is enabled and the user opts in to storing data in Krisp cloud. Krisp says customer data is not used to train AI models, but no single document makes that claim in full, and no account setting exposes it. Krisp also publishes real security work: a SOC 2 Type II attestation, PCI-DSS validation by a qualified assessor, a contractual commitment to challenge government data requests, and a timed public report of its own cross-tenant incident. [1][2][4][7][22][16][8]

What Krisp does well

  • Used for noise cancellation only, Krisp states that no audiovisual data leaves the user's device and that it does not store or have access to the content of conversations.
  • The perpetual, irrevocable, sublicensable licence in the Terms of Use covers Feedback about the product. The licence over Your Content is bounded to performing the contract, your instructions, or what law requires, and the same section states Krisp does not monitor or sell Your Content.
  • Deletion is described as a hard delete: transcripts and meeting notes are "completely wiped from Krisp’s infrastructure", and audio recorded to enable multilingual transcription is deleted from Krisp servers once the transcript exists.
  • The Data Processing Addendum commits Krisp to review the legality of any public authority's data request and to challenge it where legitimate lawful grounds exist, and certifies that it has not built and will not purposefully build backdoors.
  • Krisp's no-sale language carries no "may be considered a sale" hedge in the documents we read: its US state privacy addendum commits it not to sell or share personal information, including for behavioral advertising.
  • When one user received another user's content through its MCP API, Krisp published a timed incident report, credited the community member who reported it, and stated the fix was live in under four hours.

What deserves caution

  • No single Krisp document says the product never trains on your content. The Privacy Policy's no-training sentence is scoped to information obtained through third-party apps such as Google Workspace APIs, while the same policy lists "Improving our proprietary AI models and providing more accurate services" as a processing purpose, with consent as its legal basis.
  • There is no training control to click. No help-center article or account setting exposes an AI-training toggle at any plan tier, and the opting out Krisp describes is what it does with its own vendors, not something you do in your account.
  • Auto-share ships on, in Krisp's own words, and sends transcripts, notes and recordings to the participants on your calendar invite. The same help article flags the feature as still being gradually rolled out, so open your own Meetings page rather than assume the stated default has reached you. Krisp's help center also warns that copying a note makes it public until you unshare it.
  • The on-device framing is conditional. Krisp's AI Meeting Assistant FAQ says that in transcribe only mode, depending on the language and settings, audio may be transcribed on device or sent to Krisp servers and then deleted, and the Privacy Policy says non-English speech detected in transcribe only mode may trigger automatic recording of the audio.
  • The DPA lists "Krisp uses end-to-end encryption" as a technical measure without defining the term, in the same document that describes Krisp storing and processing meeting content on its own servers.
  • A cross-tenant exposure did occur. Krisp reported that on March 31, 2026 a user received content belonging to another user through its MCP API, and said at the time it was still reviewing whether anyone else was affected.

Training on your recordings

Denied, scope split [1][5][7]

Opt-out

No user control documented [5][7]

Where audio goes

Device, or US servers; some vendors elsewhere [1][4][6]

Encryption

In transit + at rest [1][4]

2FA

Documented for 1-seat accounts [23]

Certifications

SOC 2 Type II, PCI-DSS [4]

Krisp homepage, the AI noise cancellation and meeting assistant app this Krisp privacy and security audit covers
Krisp, accessed 2026-08-04

Quick facts

The privacy facts, at a glance.

How audio is captured
Two paths, and they behave differently. With noise cancellation alone, "NO AUDIOVISUAL DATA LEAVES THE USERS’ DEVICES", per the Privacy Policy. The AI Meeting Assistant records and transcribes instead, either from the Krisp app or through Krisp Bot, which supports Zoom, Google Meet and Microsoft Teams and joins scheduled meetings automatically when assistant@krisp.ai is added as a calendar guest. The Trust Center answers its own "How does Krisp function?" question by saying all voice audio is processed locally and that "Voice data never leaves the device, ensuring complete privacy, except when specific advanced features, such as the AI Voice Translation feature, are actively used." That exception is given by example, and the AI Meeting Assistant, which the Privacy Policy and the security page describe as storing and transmitting recordings and transcripts off the device, is not named in it. [1][19][20][5][7]
Where transcription happens
Split by language, without Krisp saying where the line falls. The AI Meeting Assistant FAQ states that in Transcribe Only mode, depending on the language and settings, audio may be transcribed entirely on device or sent to Krisp servers for transcription and then deleted, and the Privacy Policy adds that non-English speech detected in transcribe only mode may trigger automatic recording of the audio to enable multilingual transcription. The security page describes in-house speech to text on the end user's device, with Microsoft Azure generating summaries from transcripts. TechCrunch covered the 2023 beta and reported the same split these documents describe now: the audio was processed on device, but "The transcript itself is sent directly to Krisp's cloud service", with a fully on-device transcript option still to come. What these documents describe for the current Meeting Assistant is conditional on language and settings. [22][1][7][26]
Where your data is stored
The United States. Krisp states it "primarily processes and stores information in the United States", and its DPA lists the data importer at a Berkeley, California address. Per the Privacy Policy, meeting transcripts, recordings and summaries may be stored on Krisp servers when the AI Meeting Assistant is used, and the security page describes that cloud storage as beginning once Meeting Notes is enabled and the user opts in to storing data in Krisp cloud. Vendor locations are not uniformly US: the Trust Center subprocessor list gives Nebius AI a Finland location, the group affiliate Krisp LLC an Armenia location, Hotjar the EU, and Sentry, Papertrail and Typeform "USA/EU". [1][4][7][6]
AI training defaults
Krisp says customer data is not used to train its models, in two documents that each cover a different thing. The Privacy Policy's no-training sentence covers only data obtained through third-party apps such as Google Workspace APIs; the Trust Center FAQ and the AI Meeting Assistant security page carry the broader statements. The same Privacy Policy lists "Improving our proprietary AI models and providing more accurate services" as a purpose with consent as its legal basis. [1][5][7]
Retention
No fixed period for meeting content: Krisp stores recordings and meeting notes until you instruct it to delete them or delete your account. Audio recorded because non-English speech was detected is kept only for as long as generating the transcript takes. After a trial ends without a subscription, the Terms give a ninety day Post-Trial Access Period for export. [1][2]
Subprocessors
Twenty-seven on the list the DPA designates as authoritative. That list sits at trust.krisp.ai/subprocessors, a Vanta trust center that returns an empty shell to command-line fetches and renders only in a browser, which is why an earlier pass of this audit reported no list at all. Rendered in headless Chrome on 2026-08-08 it names 27 vendors with a purpose and a location for each. The ones that touch meeting content: Microsoft Azure, Anthropic PBC, Groq and Nebius AI for backend product features, AssemblyAI and Soniox for speech to text, Baseten for multi-language transcription inference, Daily for the real-time audio streaming behind live captions, ElevenLabs for voice synthesis, Google Cloud Platform for the text to speech behind AI Voice Translation, Recall.ai for meeting bots, and the group affiliate Krisp LLC in Armenia for support and maintenance. Krisp's Privacy for Humans page, last updated December 9, 2025, covers the same ground and does not match: it names Deepgram for live-caption speech to text, which the Trust Center list omits, and it omits Soniox, ElevenLabs and Google Cloud Platform, which the Trust Center list carries. No human annotation vendor is named on either. [6][3][4]
Encryption
"ALL AUDIO IS ENCRYPTED IN TRANSIT AND AT REST.", per the Privacy Policy. The DPA's technical-measures annex adds a separate line, "Krisp uses end-to-end encryption", without defining the term or describing who holds keys, in the same document that has Krisp processing and storing meeting content on its servers. [1][4]
Certifications
SOC 2 Type II and PCI-DSS, both stated in the DPA rather than on the public security page, and the SOC 2 line is worded as an examination Krisp "has undergone" rather than a certification. No ISO 27001 claim for Krisp itself appears in the documents we read, and on HIPAA the security page says the AI Meeting Assistant is designed with controls that "support HIPAA compliance" and offers Business Associate Agreements on the Business tier, without asserting a certification. No Data Privacy Framework certification is mentioned: transfers run on Standard Contractual Clauses and the UK Addendum to those clauses, which the DPA defines as the ICO's International Data Transfer Addendum, Version B1.0 (21 March 2022), not the standalone IDTA. [4][1][7]
Consent features
Thin. Krisp Bot joins as a named participant and the meeting host must authorize its entry. For Zoom meetings joined through the Krisp app, a dashboard setting can inform others that you are recording; the article says you "can activate" it and does not state which value a new account ships with. No pre-meeting consent email, click-through consent screen, or region-based recording default is documented. [19][20]
Sharing defaults
Auto-share ships on, stated plainly: "The default state of the feature is ON." It sends transcripts, notes and recordings to the participants from your calendar invite inside your workspace. The same article prints a rollout notice above that section, so the stated default has not necessarily reached every account yet. Manual shares carry View access by default, including the "Anyone with the link" option. [16]

Data flows

What leaves your Mac.

  1. Step 01

    Meeting recordings, transcripts and summaries

    Using the AI Meeting Assistant, you acknowledge Krisp may store meeting transcripts, recordings and summaries on its servers, and may share your meeting content with third-party service providers to produce AI-generated summaries, which it may also store. [1]

  2. Step 02

    Non-English audio in transcribe only mode

    When non-English speech is detected, Krisp may automatically record the audio to enable multilingual transcription. Those recordings are retained only for as long as generating the transcript takes, then deleted from Krisp servers, per the Privacy Policy. [1]

  3. Step 03

    Audio and transcripts sent to inference vendors

    Krisp names Microsoft Azure for AI-generated summaries of meeting transcripts, Anthropic, Groq and Nebius AI for the AI Meeting Assistant, AssemblyAI and Deepgram for speech to text, Baseten for transcribing audio in multiple languages, Daily.co for the real-time audio streaming behind live captions, and Recall.ai for meeting-bot infrastructure. It also names its group affiliate Krisp LLC, in Armenia, for support and maintenance. Nebius AI is listed in Finland; the rest are listed in the United States. [3]

  4. Step 04

    Calendar and contact data

    You may authorize Krisp to connect to a calendaring service or sync a contact list or address book so your meetings and connections appear in Krisp. The auto-share feature reads the meeting's calendar ID to decide who receives the recap. [1][16]

  5. Step 05

    Auto-shared recaps to meeting participants

    With auto-share on, transcripts, notes and recordings go to the participants on the calendar invite inside your workspace. On the Advanced plan, admins can extend that to participants outside the workspace. [16][18]

  6. Step 06

    Device and usage information

    Browser or mobile device, referring source, IP address or device ID, operating system, device screen size and similar technical information. [1]

  7. Step 07

    Screen recordings

    The screen recording feature asks for macOS permission to record your screen and audio the first time it runs, and the resulting recording follows the same storage path as other meeting content. [25][1]

AI training

Training defaults, in Krisp’s own words.

Krisp says it does not train on customer data. What it does not have is one document that says so about everything. The Privacy Policy's no-training sentence is fenced to information obtained through third-party apps such as Google Workspace APIs, and the same policy lists "Improving our proprietary AI models and providing more accurate services" among its processing purposes, with consent as the legal basis, without saying where that consent is given or how it is withdrawn. The broad statements sit elsewhere: on the Trust Center FAQ, which describes the noise-cancellation models as built from 20,000 noise samples and 10,000 clear voice samples, and on the AI Meeting Assistant security page, which describes Krisp opting out of training permissions with its own vendors. Which of these covers meeting audio processed by the AI Meeting Assistant is not stated in a single place. [1][5][7][3]

Please note, that no information obtained through such third-party apps or services (e.g. Google Workspace APIs) is used to develop, improve, or train generalized AI and/or ML models.
Source: Privacy Policy, "Information We Collect Indirectly", "Information from Third Parties"
Krisp is committed to user privacy and ensures that personal data is not utilized to train its AI models.
Source: Trust Center FAQ, "Does Krisp use my data to train its AI models?"
We always make sure to opt out of any data sharing or training permissions when working with third-party service providers. This ensures that neither Krisp’s data nor that of our customers is ever used for model training purposes.
Source: Security for AI Meeting Assistant, "3rd Party Data Sharing"
Krisp privacy policy receipt: the no-training sentence scoped to information obtained through third-party apps such as Google Workspace APIs
The receipt: Krisp's Privacy Policy, the fenced no-training sentence, accessed 2026-08-04

Can you opt out?

Not documented. No help-center article and no account setting exposes an AI-training toggle at any plan tier, and no support-request route for opting out is published. The opting out Krisp writes about is something it does with its own subprocessors on customers' behalf, so there is nothing in the product to turn off and nothing to verify from your own account.

Third-party AI providers

Krisp describes each inference vendor separately on its Privacy for Humans page, and the wording differs between them. Microsoft Azure, Anthropic and Groq are each described as not using customer data for their internal training purposes or for otherwise improving their services. For Nebius AI the sentence changes actor: Krisp says it has opted out of Nebius AI's use of customer data for those purposes. All of these are Krisp's descriptions of its vendors, not statements those vendors make on this page.

Sharing defaults

Who can see your notes.

The stated baseline

Krisp's Terms of Use set the floor for what it will do with your recordings and transcripts. The same clause adds a second sentence, about control rather than intent, that is worth reading alongside the first. [2]

We do not monitor, or sell Your Content for any purpose. We do not control how Your Content is processed.
Source: Terms of Use, "Our Obligations Over Your Content"

Auto-share ships on

With auto-share active, transcripts, notes and recordings go to the participants from your calendar invite inside your workspace, without a per-meeting decision. Krisp prints a rollout notice at the top of the same section, so the stated default has not necessarily reached every account yet. The mechanics carry three quirks Krisp documents: on Mac the calendar ID is only sent when you join through the Krisp notification, overlapping meetings with the same calendar ID are skipped, and a meeting already shared never gets a second recap email, so turning the feature off later does not retract what already went out. [16]

The default state of the feature is ON.
Source: Krisp Help Center, "Sharing your meetings with Krisp", "Auto-share your meetings"

Copying a note publishes it

Manual sharing offers three scopes: invite only, anyone in your Krisp team, and anyone with the link. The latter two grant View access by default. The link itself is the exposure, and Krisp's own dashboard article states the consequence plainly. [16][17]

Copying the Note makes it public. Make sure to Unshare it if you don’t intend to keep it public.
Source: Krisp Help Center, "Meetings page in account dashboard"

Admins can share your meetings outside the workspace

On the Advanced plan, External Meeting Sharing lets team admins automatically share transcripts, meeting notes and recordings of their team members' meetings with participants outside the Krisp workspace. Krisp says admins decide whose external meetings are shared and can adjust the preference at any time. Which value this admin-level feature ships with is not stated in Krisp's docs, unlike the user-level auto-share setting, whose default Krisp states outright. [18][16]

No workspace ownership-transfer clause is documented

Krisp's documents do not describe what happens to a workspace and its accumulated recordings when the account holder changes, or an admin-to-admin ownership handover. What they do carry is the general corporate clause: in a merger, acquisition, reorganization or bankruptcy, personal information may be transferred to a successor entity, purchaser or investor. Absence of a workspace clause is absence of documentation, not evidence that no such transfer can occur. [1]

Staff access controls are described, but not per recording and not visible to you

Three Krisp documents describe how staff reach customer data. The Trust Center says access is "strictly limited to a select group of key engineering leads", that access for any other engineer is case-by-case, for debugging, and "requires explicit authorization", and that all access activity is continuously monitored by automated systems. The Security for AI Meeting Assistant page says more generally that only a few security and privacy-trained engineers reach transcripts, with access limited to what their roles require; it names Role-Based Access Control, granted on a need-to-know basis, in its section covering ePHI, and describes a SIEM implemented "to track who accesses the transcripts and when" and access to stored user data only in "break-the-glass" situations by trained employees. Privacy for Humans adds that each engineer holds a unique key identifying them in Krisp's systems, that all actions are logged for two years, and that a compromised key can be expired instantly. The DPA adds confidentiality agreements, background checks and non-disclosure agreements. What none of them describes is an approval step tied to a specific customer recording, or an access log a customer can read for their own meeting. The one feature with a stronger commitment is AI Voice Translation, where the DPA states processing is fully automated and no human access or review occurs. [4][5][7][3]

Hardening checklist

Settings that make Krisp more private.

If you use Krisp and want to keep it, these are the settings worth changing, straight from the vendor’s own documentation.

  1. Step 01

    Turn off auto-share, then check what already went out

    Where

    Krisp web account dashboard > Meetings page > auto-sharing preferences.

    This is the one setting whose shipped value Krisp states outright, and the value is on. Until you change it, transcripts, notes and recordings go to the participants on your calendar invite. One qualifier Krisp prints in the same article: "This feature is being gradually rolled out, and we appreciate your patience as we complete the process." So "The default state of the feature is ON." may not have reached your account yet, which is a reason to open the Meetings page and look rather than assume either way. Two things the switch does not reach: recaps already sent are never re-sent or recalled, and on Mac the feature only fires when you joined through the Krisp notification, so the exposure is uneven rather than absent. [16]

  2. Step 02

    Use noise cancellation without the Note Taker when you want no record

    Where

    Krisp web dashboard > AI Note Taker settings, at app.krisp.ai/personal/ai-note-taker. Krisp's FAQ tells users to turn the Note Taker off before starting a call when the Krisp app is not in use, and to leave it off at all times.

    Noise cancellation alone is the only mode Krisp describes as keeping audiovisual data on the device. The moment the Meeting Assistant is on, recordings, transcripts and summaries move to Krisp servers. Which state the Note Taker ships in for a brand-new account is not stated in Krisp's docs, so check it rather than assume it. One more catch worth knowing: in transcribe only mode, detected non-English speech can trigger automatic audio recording anyway. [22][1][20]

  3. Step 03

    Switch on the recording notice for Zoom

    Where

    Krisp web dashboard > AI Note Taker settings: activate the setting that informs others you are recording.

    It is the only participant-facing consent signal Krisp documents beyond the bot appearing in the participant list, where the host must authorize its entry. No pre-meeting consent email, click-through consent screen or region-based default is documented anywhere in the help center, and Krisp's article says you "can activate" the notice without stating what a new account ships with. Recording consent stays your problem, so make the signal visible. [20][19]

  4. Step 04

    Turn on two-factor authentication

    Where

    Krisp account dashboard > Settings > Account > Two-factor authentication.

    Your meeting archive is only as private as the login in front of it, and Krisp's other documented sign-in routes are Google sign-in and emailed magic codes. The article documents 2FA for accounts with one seat and says nothing about team seats, and it does not state whether a new account starts with it on or off, so open the section and look. [23][24]

  5. Step 05

    Delete meetings you would not want stored, and know what deletion cannot split

    Where

    Hover over a passage in the transcript to delete that speech. Delete the meeting to remove its recording. For an account or all your data, email support@krisp.ai, the address Krisp's FAQ names for deletion requests.

    Krisp stores recordings and meeting notes until you tell it to delete them, so nothing ages out on its own. Deletion itself is described strongly: transcripts and meeting notes are completely wiped from Krisp's infrastructure by a hard-delete method, and no recycle-bin window is documented. The limits are structural: a recording cannot be deleted while keeping its transcript, no bulk delete is documented, and account deletion runs through email support and is irreversible. [1][22][21][7]

  6. Step 06

    On a team plan, ask your admin what External Meeting Sharing is set to

    Where

    Admin Settings > Manager View > External Meeting Sharing, on the Advanced plan.

    This is the setting your own account cannot see. It lets admins auto-share transcripts, notes and recordings of team members' meetings with people outside the workspace, and admins choose whose meetings are included. Krisp documents the feature but never states which value it ships with, so the only way to know is to ask the person who holds the switch. [18]

Policy changelog

What changed, and when.

Each entry records a dated re-verification of this audit against the vendor’s documents. Policy changes land here as dated diffs.

2026-08-08

Corrections pass. The Trust Center subprocessor list was re-read in headless Chrome, which returns the list a command-line fetch does not, and the subprocessor entry was rewritten around it: 27 named vendors, the Deepgram discrepancy between Krisp's two lists, and the non-US locations. Krisp's staff-access description was corrected after re-reading the Trust Center FAQ, the Security for AI Meeting Assistant page and Privacy for Humans. Litigation status re-checked against the court's own public case page. Also re-verified live: the auto-share rollout notice, the TechCrunch 2023 report, the DPA's UK Addendum definition, the AI Meeting Assistant FAQ's GDPR answer and Note Taker instruction, and the February 23, 2026 order. The closing Routines note was also tightened and no longer claims offline operation.

Before: no subprocessor count was published, staff access was described as gated by policy "with no approval workflow or access logging described", the docket was reported as showing discovery continuing into spring 2026, auto-share was stated as an unqualified shipped default, TechCrunch was cited for a "fully on-device" 2023 beta, and transfers were attributed to the "UK IDTA". Now: 27 subprocessors named from the Trust Center list with the Deepgram and Soniox/ElevenLabs/Google Cloud Platform mismatches called out; the three documents describing role-based access, case-by-case authorization, break-the-glass gating, a SIEM and two-year action logs are quoted, with the narrower gap (no per-recording approval, no customer-visible access log) named instead; the case is reported as in claim-construction briefing with Dkt. 117 to 119 and the vacated September 3, 2026 hearing; the gradual-rollout notice qualifies the auto-share default; TechCrunch is quoted saying the 2023 transcript went to Krisp's cloud; and transfers are attributed to the UK Addendum, Version B1.0.

2026-08-04

Audit created. Verified against the Privacy Policy (effective March 4, 2026), the Terms of Use (last updated March 4, 2026), the Data Processing Addendum (no printed effective date), the Privacy for Humans subprocessor page (last updated December 9, 2025), the Trust Center FAQ, the Security for AI Meeting Assistant page, Krisp's MCP incident post of April 3, 2026, ten help-center articles, and the public court record. Litigation status at verification: no privacy or consent suit against Krisp was found in the court records we searched, which is not proof none exists; the only case found is Sanas.AI Inc. v. Krisp Technologies, Inc., No. 3:25-cv-05666 (N.D. Cal.), a patent, trade secret and false advertising suit with Krisp counterclaims, in which the court denied Krisp's motion for judgment on the pleadings on February 23, 2026 and discovery continued through April 2026.

FAQ

Questions people ask.

Is Krisp safe to use?

It depends which half of Krisp you run. For noise cancellation alone, the Privacy Policy says no audiovisual data leaves your device and Krisp has no access to conversation content. The AI Meeting Assistant is a different service: per the Privacy Policy it may store recordings, transcripts and summaries on Krisp servers in the United States and pass content to named inference vendors. Krisp backs that with a SOC 2 Type II attestation and PCI-DSS validation, and it published a timed public report of its own cross-tenant incident within three days of the report. [1][4][3][8]

Does Krisp train its AI on my meetings?

Krisp says no, in two places. The catch is scope. The Privacy Policy's no-training sentence covers only information obtained through third-party apps such as Google Workspace APIs; the broad statements live on the Trust Center FAQ and the AI Meeting Assistant security page. Meanwhile the same Privacy Policy lists improving Krisp's proprietary AI models as a processing purpose with consent as its legal basis. Read together they do not add up to one documented promise about meeting audio. [1][5][7]

Can I opt out of Krisp AI training?

There is nothing to opt out of in your account. No help-center article or setting exposes an AI-training control at any plan tier, and no support-request route is published. The opting out Krisp describes on its security page is what Krisp does with its own subprocessors, which is a company practice rather than a control you can set or check. [5][7]

Is Krisp being sued over privacy?

No privacy or consent lawsuit against Krisp appears in the court records we searched, which is not the same as proof that none exists. One case does exist and it is commercial, not privacy: Sanas.AI Inc. v. Krisp Technologies, Inc., No. 3:25-cv-05666 (N.D. Cal.), filed July 7, 2025, alleging patent infringement, trade secret misappropriation and false advertising, with Krisp filing counterclaims of its own. These are filed allegations on both sides, not findings. On February 23, 2026 the court denied Krisp's motion for judgment on the pleadings, applying the Alice patent-eligibility framework patent by patent: a ruling on eligibility, not on infringement, invalidity on other grounds, or damages. As of August 8, 2026 the case has moved past discovery into claim-construction briefing. The court's own public case page shows Krisp's motion for leave to serve a rebuttal claim construction expert report (Dkt. 117, filed July 29, 2026) resolved by stipulated order on August 5, 2026 (Dkt. 118 and 119), with the September 3, 2026 hearing vacated. No ruling on infringement or validity has issued. Krisp's public statement is that it will "vigorously defend our innovations and set the record straight through the legal process". [11][12][10][13][14][15][9]

Has Krisp had a data breach?

Krisp disclosed one incident itself. On March 31, 2026 it was notified that a user of the AI Meeting Assistant had received content belonging to another user through its MCP API; Krisp traced it to simultaneous requests colliding, called it an unintended technical flaw rather than an attack, and published a timeline showing under four hours from report to fix. It said it was reviewing whether others were affected and would contact them. No independent report of the incident was found, and no other breach appears in the sources we checked, which is not proof that none occurred. [8]

Does Krisp sell my data?

Krisp's documents say no in three places, and none of them attaches a qualifier: the Terms state Krisp does not monitor or sell Your Content for any purpose, the Privacy Policy denies selling personal information under Nevada's NRS 603A, and the US state privacy addendum in the DPA commits Krisp not to sell or share personal information as defined under the CCPA, including for behavioral advertising. None of the documents we read carries a "may be considered a sale" qualifier. The same Privacy Policy does describe remarketing tags on Krisp's website, so read the flat denial as covering what it says: your content. [2][1][4]

Is Krisp HIPAA compliant?

Krisp's security page describes AI Meeting Assistant controls that "support HIPAA compliance", says a HIPAA Compliance Executive Summary Report is available via its Trust Center, and offers Business Associate Agreements to subscribers of the Business tier. What no document we read states is a HIPAA certification, or a flat assertion that Krisp is HIPAA compliant. Its Privacy Policy points to a separate HIPAA Privacy Notice conditioned on using Krisp to record conversations that include Protected Health Information, which is a notice about obligations rather than an assertion of compliance. The credentials Krisp claims for itself are in the DPA: a SOC 2 Type II examination it "has undergone" and PCI-DSS compliance validated by a qualified security assessor. If PHI is in scope for you, that is a contract conversation, not a settings question. [7][1][4]

Does Krisp say it is GDPR compliant?

It does, flatly. Krisp's AI Meeting Assistant FAQ answers "Are Krisp Meeting Notes GDPR compliant?" with "Krisp Meeting Notes are GDPR compliant. We collect and process personal data based on your consent.", and names dpo@krisp.ai for exercising GDPR rights. That is an unqualified self-declaration, and no audit, certification or supervisory-authority finding is cited for it, which makes it a stronger claim than the wording Krisp uses about HIPAA on its security page, where the controls only "support HIPAA compliance". The contractual machinery behind it is in the DPA: Standard Contractual Clauses for EU transfers and the UK Addendum for UK ones. [22][7][4]

Who can see my Krisp meetings?

More people than you might set by hand. Auto-share ships on, subject to a gradual rollout Krisp flags in the same article, and sends transcripts, notes and recordings to the participants on your calendar invite. Copying a note makes it public until you unshare it, and link and team shares grant View access by default. On the Advanced plan, admins can auto-share team members' meetings with people outside the workspace. Inside Krisp, access to customer data is described as limited to a select group of key engineering leads, granted to other engineers only case by case with explicit authorization, monitored by a SIEM, and logged per engineer for two years; Role-Based Access Control on a need-to-know basis is named in the section covering ePHI. What is not described is an approval step for a specific recording, or an access log you can read for your own meeting. [16][17][18][4][5][7][3]

Sources

Every claim, receipted.

Every claim on this page maps to one of these documents. Dates are when we last read each one.

  1. [1]

    Krisp Privacy Policyaccessed 2026-08-04

    Effective March 4, 2026. Several passages, including the noise-cancellation and AI Meeting Assistant clauses, are printed in full capitals; quotes here reproduce them as written.

  2. [2]

    Krisp Terms of Useaccessed 2026-08-04

    Last updated March 4, 2026. Contains both the Feedback licence and the separate, narrower "Your Content" licence.

  3. [3]

    Krisp: Privacy for humansaccessed 2026-08-08

    Last updated December 9, 2025. Names inference and speech-to-text subprocessors with a stated purpose and location for each, plus the "Who Has Access to What Within Krisp?" section on per-engineer keys and two-year action logs. Its vendor list does not match the Trust Center list.

  4. [4]

    Krisp Data Processing Addendum (PDF)accessed 2026-08-08

    The document carries no printed effective or last-updated line, so it is dated by access date only. Annex II holds the certifications and technical measures; Schedule B holds the US state privacy addendum.

  5. [5]

    Krisp Trust Center: FAQaccessed 2026-08-08

    Undated. A Vanta trust center: it returns an empty shell to command-line fetches, so it was rendered in headless Chrome. Carries the no-training answer, the "How does Krisp function?" answer, and the employee-access answer.

  6. [6]

    Krisp Trust Center: Subprocessorsaccessed 2026-08-08

    Undated. The list the DPA designates as authoritative. Same Vanta shell problem as the FAQ, so it was rendered in headless Chrome on 2026-08-08, when it showed "1-10 of 27 results" and an "All subprocessors" section naming 27 vendors with a purpose and a location for each. A dated screenshot of the full rendered list is kept as an archival receipt.

  7. [7]

    Krisp: Security for AI Meeting Assistantaccessed 2026-08-08

    Undated. Carries the third-party data sharing statement, the hard-delete description, the HIPAA compliance section with the Role-Based Access Control and SIEM language, the break-the-glass access description, and the description of in-house speech to text running on the end user's device.

  8. [8]

    Krisp blog: Krisp MCP Incident Communicationaccessed 2026-08-04

    Published April 3, 2026, about an incident reported to Krisp on March 31, 2026. Vendor self-report; no independent account of the incident was found.

  9. [9]

    Krisp blog: Krisp Statement on Sanas Lawsuitaccessed 2026-08-04

    Published July 31, 2025. Krisp's own response to the filed claims.

  10. [10]

    Justia: Sanas.AI Inc. v. Krisp Technologies, Inc., No. 3:25-cv-05666, Document 72 (N.D. Cal. 2026)accessed 2026-08-08

    Order of February 23, 2026 denying Krisp's Rule 12(c) motion for judgment on the pleadings. The order works through the Alice patent-eligibility framework patent by patent, so it decides eligibility, not infringement, invalidity on other grounds, or damages.

  11. [11]

    U.S. District Court, N.D. Cal.: Sanas.AI Inc. v. Krisp Technologies, Inc., No. 3:25-cv-05666-RSaccessed 2026-08-08

    The court's own free public case page, live rather than a snapshot. Recent filings shown on the access date: Dkt. 118, a stipulation with proposed order dated 08-05-26 re Dkt. 117, and Dkt. 119, an order signed 8/5/2026 by Judge Richard Seeborg granting in part and denying in part Dkt. 118 and vacating the 9/3/2026 hearing.

  12. [12]

    PacerMonitor: Sanas.AI Inc. v. Krisp Technologies, Inc. (3:25-cv-05666), California Northern District Courtaccessed 2026-08-08

    Commercial docket mirror, page-stamped "Docket last updated: 08/06/2026". Used only for the filing date of Dkt. 117, Krisp's motion for leave to file or serve a rebuttal claim construction expert report, which it dates July 29, 2026. The court's own page names Dkt. 117 but does not date it.

  13. [13]

    GovInfo: Sanas.AI Inc. v. Krisp Technologies, Inc., No. 3:25-cv-05666 (N.D. Cal.)accessed 2026-08-04

    Official record. Latest entry seen: a discovery-letter order signed April 1, 2026.

  14. [14]

    Justia Dockets: Sanas.AI Inc. v. Krisp Technologies, Inc., No. 3:25-cv-05666accessed 2026-08-04

    Docket header: filed July 7, 2025, Northern District of California. The page states the docket was last retrieved on May 14, 2026, so it is a snapshot rather than a live status.

  15. [15]

    PR Newswire: Sanas.AI Inc. Adds Newly Issued Patents and False Advertising Claims to U.S. Lawsuit Against Krisp Technologies (September 23, 2025)accessed 2026-08-04

    Press release issued by the plaintiff's counsel. Describes the claims as filed, not as adjudicated.

  16. [16]

    Krisp Help Center: Sharing your meetings with Krispaccessed 2026-08-08

    The only Krisp article we found that states a shipped default outright: "The default state of the feature is ON." The same section opens with a rollout notice: "This feature is being gradually rolled out, and we appreciate your patience as we complete the process."

  17. [17]

  18. [18]

    Krisp Help Center: Manager Viewaccessed 2026-08-04

    Advanced plan, admin settings. Documents External Meeting Sharing without stating which value it ships with.

  19. [19]

    Krisp Help Center: Krisp Botaccessed 2026-08-04

    Zoom, Google Meet and Microsoft Teams only. Inviting the bot mid-meeting discards any prior transcription and recording.

  20. [20]

  21. [21]

    Krisp Help Center: FAQ about Krisp Recording featureaccessed 2026-08-04

    States that a recording cannot be deleted separately from its meeting. Its storage figures differ from those in the recording article.

  22. [22]

    Krisp Help Center: AI Meeting Assistant FAQaccessed 2026-08-08

    Covers the Transcribe Only mode language split, partial transcript deletion, support@krisp.ai as the deletion contact, and the unqualified "Krisp Meeting Notes are GDPR compliant" answer. Does not state what the Note Taker ships as for a new account.

  23. [23]

    Krisp Help Center: Two-factor authentication for your Krisp accountaccessed 2026-08-04

    Scoped in the article header to accounts with 1 seat; team-seat availability is not addressed.

  24. [24]

    Krisp Help Center: Getting started with Krisp SSOaccessed 2026-08-04

    SAMLv2 with automatic user provisioning. Every SSO article we read is scoped to Krisp's Call Center AI plan.

  25. [25]

  26. [26]

    TechCrunch: Krisp expands from noise canceling to on-device transcription (March 28, 2023)accessed 2026-08-08

    Describes the 2023 transcription beta. It reports the transcription agent running on device but adds that "The transcript itself is sent directly to Krisp's cloud service", with a fully on-device transcript option still to come, so it is not a report of a fully on-device product.

This audit quotes Krisp’s own public documents and reputable public records. It is not legal advice, and filed lawsuits are allegations, not findings.

Related audits

How Routines handles the same data

Routines, the app behind this audit, handles the same job differently: meetings are recorded without a bot joining the call, and your notes are markdown files on your Mac that open in any editor. No cloud bill and no per-minute costs. All transparency audits