Read AI privacy audit

Is Read AI safe? A privacy audit built from Read AI's own documents.

The short answer

Last verified 2026-08-04

Read AI is a cloud meeting assistant. Audio and video are captured in the call, processed by Read AI, and stored encrypted in the AWS us-east-1 region in Northern Virginia, with meeting content sent on to Anthropic and OpenAI, both named on Read AI's subprocessor list. Contributing your meetings to model training is opt-out by default, which Read AI states plainly in three places, and any participant can remove the bot mid-call. Two things need reading closely: reports auto-share with everyone invited by default, and the Privacy Policy's state-law table lists personal information Read AI shares and sells to marketing and advertising partners while its marketing page says it sells nothing. [1][2][3][4][5][6][8][22]

What Read AI does well

  • Contributing your meeting content to Read AI's models is opt-out by default. The Privacy Policy puts the mechanism in a named Customer Experience Program you opt in to, and two help articles repeat that the default is opt-out.
  • Any meeting participant, including people with no Read AI account, can remove the bot mid-call by typing "opt out" in the chat, and Read AI states all data measured is then deleted.
  • The bot is designed to be noticed: in web mode it appears in the participant list, may post a chat message naming who invited it, and Read AI's CEO is on record refusing to make it quieter.
  • The two LLM subprocessors are named, not hidden behind a generic "AI providers" line. Anthropic and OpenAI are listed for "Augmentation of Meeting Data", under a data processing agreement Read AI describes as zero re-use and zero retention.
  • Encryption is published with specifics, not just asserted: TLS 1.2 in transit and AES-256 at rest, alongside a SOC 2 Type 2 report and EU, UK and Swiss Data Privacy Framework certification.
  • Deletion is described as hard deletion. Read AI states account and report deletion is immediate, permanent and cannot be undone, and that its own support agents cannot delete an account on your behalf.

What deserves caution

  • Automatic sharing is the shipped default: Read AI's help center states the default and recommended setting is to share reports with everyone invited to the meeting.
  • Read AI's two documents on selling data do not agree. Its marketing page says it does not sell your data to anyone; the Privacy Policy's state-law section says it shares and sells categories of personal information to marketing and advertising partners. Meeting Information is carved out of targeted advertising absent your consent, per the same policy, but the two statements are never reconciled.
  • The Read Score analyzes facial and verbal elements of every attendee to infer reactions and engagement, and Read AI separately states it uses audio and visual information to infer demographic characteristics. The words biometric, voiceprint and faceprint appear nowhere in the Privacy Policy. For EU and UK users the score excludes video and facial elements, per that policy.
  • Desktop and mobile capture removes the consent surface. With no bot in the call, the "opt out" chat command does not work, and Read AI states the person running the capture is responsible for telling participants and collecting consent.
  • The Terms grant Read AI a worldwide, sublicensable license to use, modify, analyze and create derivative works from your User Content. No clause states that license ends when you delete the content. It is worth crediting what is not there: the words perpetual and irrevocable do not appear in that grant.
  • HIPAA is listed with a checkmark on the Trust Center, but the underlying help article gates the BAA to annual Enterprise+ customers who have set up SAML authentication and domain capture first.

Training on your meetings

Opt-out by default [1][6][7]

Opt-out

A settings checkbox, path undocumented [6][7]

Where audio goes

Read AI cloud, AWS us-east-1 [6][4]

Encryption

TLS 1.2 + AES-256 [6]

2FA

Through your SSO provider only [6]

Certifications

SOC 2 Type 2 [6][3]

Read AI homepage, the cloud AI meeting notes and meeting assistant service this Read.ai privacy audit covers
Read AI, accessed 2026-08-04

Quick facts

The privacy facts, at a glance.

How audio is captured
Bot-based in web mode: Read AI joins Zoom, Microsoft Teams and Google Meet calls from a connected calendar, appears in the participant list, and may post a chat message naming who invited it. A desktop and mobile local-capture mode also exists, where no bot joins the call at all. Read AI states the bot only attends after a user creates an account, connects a calendar and has settings in place for it to join: "In no instance does Read join random meetings." Read AI states the bot can only join Zoom, Microsoft Teams and Google Meet. [17][5][6][14]
Where transcription happens
In Read AI's cloud. Meeting content is passed to Anthropic and OpenAI, both listed as subprocessors for "Augmentation of Meeting Data" in the United States. No on-device transcription path is documented in any Read AI document we read. [4][6]
Where your data is stored
AWS us-east-1, Northern Virginia. Per the help center, "data captured is stored encrypted at rest within the AWS us-east-1 datacenter in Northern Virginia USA", and another location is a sales conversation for large group purchases. The Trust Center's AWS entry adds "EU/Canada available on request". [6][4]
AI training defaults
Opt-out by default, per Read AI, through a named Customer Experience Program you opt in to. Read AI states about 10 to 15 percent of users join it. Separately, the Terms of Service license your User Content to train AI/ML models, and say the Privacy Policy controls where the two conflict. [1][2][7]
Retention
The Privacy Policy caps audio and video at "in no case for longer than 2 years", and says paid-account data is kept until you stop paying or ask for deletion. The help center frames retention as user-set: with playback storage off, no audio or video is retained beyond what producing the report needs. Custom retention policies are Enterprise+ and apply to all past, current and future reports. [1][6][12]
Subprocessors
22 listed, including AWS, Anthropic, OpenAI, Databricks, Microsoft Teams, Tavily, Google Analytics, Mixpanel and Stripe, all located in the United States. The page carries no effective or last-updated date. No human annotation or transcription-review vendor appears on it. [4]
Encryption
Per the help center: "Read encrypts all data in transit with HTTPS with TLS 1.2, and encrypts all data at rest with AES-256." No end-to-end encryption is claimed in any document we read, which follows from the product: Read AI processes raw meeting content on its servers. [6][3]
Certifications
SOC 2 Type 2, per Read AI, plus a flat "Read AI is GDPR compliant" in its help center and a Data Privacy Framework self-certification for the EEA, Switzerland and the UK in the Privacy Policy. HIPAA carries a checkmark on the Trust Center but a BAA is offered only on annual Enterprise+ with SAML and domain capture configured. No ISO 27001 claim appears in any document we read. [3][6][1]
Consent features
In web mode the bot is visible in the participant list, may announce itself in chat with the name of whoever invited it, and any participant can type "opt out". If Read AI posted an opt-out link instead, the chat command does not work and the link must be clicked. In desktop and mobile mode neither works, because no bot is in the call. No region-specific default consent behavior is documented. [17][15][6]
Sharing defaults
Automatic by default: "the default/recommended setting is to automatically share reports with everyone that was invited to the meeting", per the help center. The workspace-wide Team Report Access setting defaults to Admin, the most restrictive of its three levels, per the same help center. Which value the workspace Link Access dropdown ships with is not stated in Read AI's docs. [8][11][12]

Data flows

What leaves your Mac.

  1. Step 01

    Meeting audio and video

    Captured in the call, processed by Read AI, and stored encrypted at rest in AWS us-east-1. If audio and video playback is disabled, Read AI states it deletes the underlying recording automatically after the report is generated. [6][12]

  2. Step 02

    Meeting content sent to third-party models

    Anthropic and OpenAI are listed as subprocessors for "Augmentation of Meeting Data" in the United States, under an agreement Read AI describes as including zero re-use and zero retention. [4]

  3. Step 03

    Calendar, Gmail and Google Workspace content

    The Google integration covers event titles, descriptions, dates and guest lists; Gmail messages including subject, body, recipients, senders and metadata; and Google Docs, Drive and Chat content. The Privacy Policy also states Workspace data "may be transferred to third party AI tools in connection with the Services". [1]

  4. Step 04

    Inferred affect, engagement and demographics

    The Read Score uses audio and visual information to score affect and behavior, and Read AI states it also infers demographic characteristics and a user's role in the meeting. For users in the EU and UK the score excludes meeting video and facial elements. [1]

  5. Step 05

    Device, network and location telemetry

    Hardware model, operating system version, mobile network, IP address, unique device identifiers, hashed email address, browser type, app version, access times, pages viewed and links clicked, plus approximate location from calendar invitations and from your IP address. [1]

  6. Step 06

    Marketing and advertising disclosures

    The Privacy Policy's state-law table maps identifiers, commercial information, internet activity, employment information and inferences to "Marketing and advertising partners". Meeting Information is excluded from targeted advertising unless you consent, per the same section. Google Analytics and Mixpanel are listed subprocessors. [1][4]

  7. Step 07

    Report distribution to participants and tools

    Generated reports are shared out by your Report Sharing settings, whose documented default is everyone invited to the meeting. The Microsoft Teams subprocessor entry lists "raw and summarized content and content extractions including key questions, action items, and other generated content". [8][9][4]

AI training

Training defaults, in Read AI’s own words.

Read AI describes training on your meeting content as opt-out by default and enableable by you, not as a prohibition. The Privacy Policy locates the mechanism in a named Customer Experience Program you opt in to, and its help center says opting in "requires manually going to the settings page and checking a box to contribute data to improve the product". Two things sit alongside that default. The Terms of Service separately license your User Content to train AI/ML models, and state that the Privacy Policy controls where the two conflict. And one unconditional prohibition does exist, but it is narrow: it covers only data collected via Google Workspace APIs, and only generalized or non-personalized models. The Trust Center's one-line summary, "No training of models on your data by default", is accurate about the default and silent about everything above. [1][2][3][4][6][7]

The default is to opt-out, but users have a choice to opt-in to contributing their data into our models.
Source: Security & Privacy Overview, "Does Read use customer data to train AI model?"
As part of your account settings, Read offers a Customer Experience Program that you may opt-in to. This program allows Meeting Information and connected data (email, messages) to be used for the purpose of improving the features of our Service. You may choose to opt-in or opt-out at any time, via your account settings.
Source: Privacy Policy, "Your Choices" > "Customer Experience Program"
Read AI may use your User Content to train, develop, and improve its artificial intelligence and machine learning technologies ("AI/ML Models").
Source: Terms of Service, 4(b) "Use of User Content"
Read AI privacy policy clause describing the Customer Experience Program you opt in to for model training
The receipt: Read AI's Privacy Policy, the Customer Experience Program clause, accessed 2026-08-04

Can you opt out?

Nothing to do for the default itself: Read AI states you are opted out until you act. Opting in is described as a checkbox on the settings page, and Read AI says roughly 10 to 15 percent of users join. The exact settings tab and the on-screen label of that checkbox are not stated in any Read AI document we read, and no plan tier is attached to the control, so it should not be assumed to be an Enterprise feature. No admin-level or domain-wide training exclusion is documented either: the only control described anywhere is the individual one.

Third-party AI providers

Read AI's subprocessor list names Anthropic and OpenAI for "Augmentation of Meeting Data" and states that "All subprocessors are bound by a restrictive Data Processing Agreement that includes zero re-use and zero retention." That is Read AI's summary of its own contracts: the page publishes no text or link substantiating it, and the Data Processing Addendum itself sits behind a request-access gate on the Trust Center, so it could not be read for this audit.

Sharing defaults

Who can see your notes.

The stated baseline is sharing, not privacy

Read AI does not describe reports as private by default. Its help center says the opposite, in the article about making them private. [8]

Read's meeting reports are designed to be shared with others, and the default/recommended setting is to automatically share reports with everyone that was invited to the meeting.
Source: Help Center, "How do I make my meeting reports private?"

Where the automatic audience is set

Account Settings > Report Sharing decides who a new report goes to, split into internal and external participants who were invited to the meeting. Per report, the Access & Distribution tab offers Editor, Viewer and None for each group. One catch Read AI documents: if your primary email is from a public service like Gmail, the internal option is disabled and every participant is treated as external. [9][10]

Anyone else who adds the bot gets their own copy

Setting both participant groups to None does not close the report. Read AI states that other people who add Read to the same meeting receive editor access automatically and can apply their own sharing settings on top of yours. [10]

Please be aware that if other people also add Read to the meeting, they will automatically get editor access and may apply their own sharing settings as well. Therefore just setting internal and external participants to "None" is not enough to guarantee that nobody else will receive access to your report [...]
Source: Help Center, "How does sharing upcoming meetings from the Calendar page work?"

Workspace settings outrank the per-report switch

The "Make report private" toggle sets both internal and external participant access to None and blocks others from adding Read to that meeting, but Read AI states it "will not prevent team sharing if enabled via the Team Report Access Workspace setting". Team Report Access has three levels, Admin, Manager and User, and Read AI states the default and recommended one is Admin. It cannot be toggled per meeting in advance, only removed from a report after it has been generated. [8][11]

Staff access is least privilege, logged and expiring

Read AI states that only certain internal technical staff may be granted temporary permission to access production systems, to resolve operational issues or when a user grants permission through a support ticket, and that in all cases access permissions are logged and subject to both audit and automatic expiration. [6]

Your employer cannot have your data deleted without you

Read AI refuses third-party deletion requests, including from corporate IT, and points them back at the account holder: "Due to our privacy and security policy, we are not able to delete accounts or meeting reports at the request of a third party." Its stated reason is that Read is a service provider and the data belongs to the user. Deletion of a report you do not own goes through Read AI's Account and Privacy Center instead. [6][18]

Hardening checklist

Settings that make Read AI more private.

If you use Read AI and want to keep it, these are the settings worth changing, straight from the vendor’s own documentation.

  1. Step 01

    Decide which meetings the bot joins at all

    Where

    Account Settings > Meeting Recording > Auto-Join Preferences. Per meeting: toggle "Add Read?" off on your Calendar page.

    With "Auto-join meetings" turned off, Read AI states it is off by default for all of your meetings. Three catches from Read AI's own docs. The submenu name is inconsistent between articles, with the same setting also routed through Account Settings > Meeting Assistant > Join Preferences. The lead time to switch a meeting off is given twice and differently: "at least 15 minutes before the meeting starts" in one article, "a few minutes before" in another. And turning your own bot off does not stop anyone else's. [13][15][16][6]

  2. Step 02

    Change who reports go to before you record anything

    Where

    Account Settings > Report Sharing, then set internal and external participant access. Per report: the Share and Access buttons on the Calendar page, "Access & Distribution" tab, Editor / Viewer / None.

    This is the setting the flagship default sits in: Read AI documents automatic sharing with everyone invited as the default and recommended value. Setting both groups to None narrows your own distribution but, per Read AI, does not guarantee the report stays closed, because other people who add Read to the same meeting get editor access of their own. [8][9][10]

  3. Step 03

    Know which opt-out actually works in the room you are in

    Where

    In web mode, type "opt out" in the meeting chat, or click the opt-out link if Read AI posted one.

    Read AI states the chat command will not work when an opt-out link was provided, in which case only the link does. In desktop and mobile capture mode neither works, because there is no bot in the call to receive them, and Read AI puts the duty to inform participants on whoever is running the capture. One more gate to know about: if a host has installed the Read AI Zoom app or connected their Zoom account, Read AI states the admit-to-meeting request does not appear, because Zoom has already issued it a token. [17][15][16]

  4. Step 04

    Cut what is stored, and check the direction it applies in

    Where

    Retention controls are in Account Settings, where transcript storage can be limited or disabled while summaries, action items and insights still arrive. Workspace admins control "Audio and Video Playback" under Workspace Settings > Meeting Insights.

    The Privacy Policy's ceiling on audio and video is two years, so anything shorter has to come from these controls. Read AI documents two opposite behaviors here that are easy to mix up: the playback setting applies only going forward and cannot be changed retroactively for an existing report, while the Enterprise+ retention policy "will apply to all past, current and future reports in your workspace". Read AI also warns that with playback disabled it deletes the underlying recording automatically once the report is generated. [1][7][12]

  5. Step 05

    Log in through an identity provider that enforces a second factor

    Where

    Sign in with Microsoft, Google or Zoom SSO instead of a username and password. SAML single sign-on and SCIM provisioning require a Workspace on the Enterprise+ plan.

    Read AI states that 2FA "can be set at the SSO level but is not enforced at via username/password" (its typo), so a password account carries no second factor of Read AI's own. Standard OAuth SSO is available to all users regardless of plan, per Read AI. SAML plus domain capture are also the two prerequisites Read AI names before it will sign a HIPAA BAA. [6][20][21]

  6. Step 06

    Delete it yourself, and know what deletion reaches

    Where

    Log in and delete your account or a report you own; Read AI states support agents cannot do it for you. Reports owned by someone else go through Read AI's Account and Privacy Center. Workspace admins can wipe Ask Read chat history for every member under Workspace Settings > Settings > Ask Read.

    Read AI describes deletion as immediate, permanent and impossible to undo, and no trash bin or grace-period window is documented anywhere in its help center. One limit is written into the account-deletion article itself: "Unless you belong to a Workspace, all of the meeting reports owned by your account will also be immediately deleted." What happens to those reports when you do belong to a Workspace is not stated. [18][6][19]

Policy changelog

What changed, and when.

Each entry records a dated re-verification of this audit against the vendor’s documents. Policy changes land here as dated diffs.

2026-08-04

Audit created. Verified against the Privacy Policy (last updated June 29, 2026), the Terms of Service (last updated February 26, 2026), the undated Trust Center and its undated 22-entry subprocessor list, the undated read.ai/privacy page, 16 help-center articles, one vendor article carrying a CEO statement, and the public court record. Litigation status at verification: no privacy or consent suit naming Read AI as a defendant was found in the court records searched, and as of August 4, 2026 Read AI appears in a competitor's consolidated class action only as a comparator, not as a party.

FAQ

Questions people ask.

Is Read AI safe to use?

It depends on who else is in the room. The training and consent defaults go right here: training is opt-out, the bot is visible, and any participant can eject it. The defaults that go wide are about distribution, not training. Reports auto-share with everyone invited to the meeting, other people who add Read to the same call get editor access of their own, and everything is processed and stored in Read AI's United States cloud. Set Report Sharing before your first recorded meeting, not after. [8][10][6]

Does Read AI train its AI on my meetings?

Not unless you turn it on, per Read AI. Its help center states "The default is to opt-out", and the Privacy Policy puts the mechanism in a Customer Experience Program you opt in to through account settings. Read the scope, though: this is a default, not a ban. The Terms of Service grant Read AI a license to use your User Content to train AI/ML models, with the Privacy Policy controlling where they conflict, and the only unconditional no-training promise in the documents covers data collected via Google Workspace APIs and generalized models only. [6][1][2]

How do I opt out of Read AI's AI training?

You start opted out, per Read AI, so there is nothing to switch off for the default itself. Opting in is a checkbox on the settings page, which Read AI describes but never names or locates precisely, and no Read AI document we read attaches that control to a plan tier or gives admins a workspace-wide version of it. If you need proof of your own account's state, the setting is the only place it is visible. [6][7]

Is Read AI being sued over privacy?

No suit naming Read AI as a defendant on privacy, wiretap or consent claims was found in the court records we searched, which is not the same as proof none exists. Read AI does appear in one federal case, but as a comparator: the consolidated class action against a rival, In re Otter.AI Privacy Litigation in the Northern District of California, cites Read AI as a company that lets any participant stop a recording. Those are allegations against that rival, not findings, and not claims about Read AI. As of August 4, 2026 the matter is at the pleading stage. Read AI's own Terms also require individual arbitration and waive class actions (with a written opt-out window in the Terms themselves), which is designed to keep US claims off a public docket. [23][2]

Has Read AI had a data breach?

No breach of Read AI's systems is documented in any court record, regulator filing or major-outlet report we checked. That is an absence of findings, not proof that nothing happened. Read AI's own security claims (SOC 2 Type 2, TLS 1.2 in transit, AES-256 at rest) are vendor statements about controls, and controls are not incident history either. No regulator action naming Read AI turned up in the sources we checked. [6][3]

Does Read AI sell my data?

Read AI's own documents answer this two different ways, so this audit quotes both. Its marketing page says "we don't sell your data to anyone - period." Its Privacy Policy, in the state-privacy-law section, says "we share and sell the following categories of personal information to the following categories of third parties" and its table names "Marketing and advertising partners" as the recipient for every listed category: identifiers, commercial information, internet activity, employment information and inferences. The reconciling detail is scope: the same policy says Meeting Information is not shared for targeted advertising unless you consent. The marketing page does not carry that limitation. [5][1]

Is Read AI HIPAA compliant?

The Trust Center lists HIPAA with a checkmark, which reads as unconditional. The help article behind it is conditional: Read AI states it can offer a BAA to support HIPAA compliance, but only for users on an annual Enterprise+ plan, and only after SAML authentication and domain capture are set up for the workspace. A self-serve or Pro account is not covered by that. Where Read AI holds an independently checked credential it names it, a SOC 2 Type 2 report, and no ISO 27001 claim appears anywhere in its documents. [3][6]

Who can see my Read AI meeting reports?

By default, everyone invited to the meeting, per Read AI's help center. Beyond that: anyone else who adds Read to the same call gets editor access automatically and can re-share; a workspace-wide Team Report Access setting can grant a team visibility that a per-report privacy toggle does not override; and Read AI staff can reach production systems under a least-privilege policy with logged, audited, automatically expiring access. [8][10][11][6]

Sources

Every claim, receipted.

Every claim on this page maps to one of these documents. Dates are when we last read each one.

  1. [1]

    Read AI Privacy Policyaccessed 2026-08-04

    Last updated June 29, 2026.

  2. [2]

    Read AI Terms of Serviceaccessed 2026-08-04

    Last updated February 26, 2026. Carries the User Content license (4(b)), the Agentic Features clause (Section 3) and the arbitration and class-action waiver (Section 16).

  3. [3]

    Read AI Trust Centeraccessed 2026-08-04

    Carries no document date; the "Updated" string on the page belongs to a live control-monitoring feed. The Data Processing Addendum, SOC 2 report and BAA are listed but gated behind a request-access flow, so none could be read for this audit.

  4. [4]

    Read AI Trust Center: Subprocessorsaccessed 2026-08-04

    22 entries. No effective or last-updated date appears anywhere on the page. The page is JavaScript-rendered: a plain HTTP fetch returns an empty shell, so it was read with a rendering fetch tool.

  5. [5]

    Read AI: Privacy First Meeting Measurementaccessed 2026-08-04

    Undated marketing page. Carries the "we don't sell your data to anyone - period" claim, the bot-join FAQ and the in-meeting opt-out description.

  6. [6]

    Read AI Help Center: Security & Privacy Overviewaccessed 2026-08-04

    Shows "Updated" with no date rendered.

  7. [7]

    Read AI Help Center: What does Read AI do with my dataaccessed 2026-08-04

    Shows "2 months ago Updated" with no absolute date.

  8. [8]

    Read AI Help Center: How do I make my meeting reports private?accessed 2026-08-04

    The one article that states a shipped sharing default in Read AI's own words.

  9. [9]

  10. [10]

  11. [11]

  12. [12]

    Read AI Help Center: What are all of the settings and permissions available with Workspaces?accessed 2026-08-04

    Carries the Meeting Insights, Auto-Join and Enterprise+ retention sections.

  13. [13]

  14. [14]

    Read AI Help Center: What meetings does Read join when I connect my calendar?accessed 2026-08-04

    States Read joins Zoom, Microsoft Teams and Google Meet only. The default value of the auto-join sub-options is not stated in the article.

  15. [15]

    Read AI Help Center: How to Stop or Opt Out of a Read AI Recordingaccessed 2026-08-04

    Gives the lead time as "at least 15 minutes before the meeting starts".

  16. [16]

    Read AI Help Center: How to Turn Off Read AIaccessed 2026-08-04

    Gives the same lead time as "a few minutes before" and describes the Zoom token that skips the admit request.

  17. [18]

  18. [19]

    Read AI Help Center: Using Ask Read to search your meetings and connected appsaccessed 2026-08-04

    The list of exactly which connected apps Ask Read reads did not survive extraction and is not restated here.

  19. [20]

  20. [21]

  21. [22]

    Read AI: How to Stop Read AI from Joining My Meetingsaccessed 2026-08-04

    Undated vendor article. Carries a statement attributed to CEO and co-founder David Shim: "We've rejected requests to make Read AI less noticeable. We'd rather have an awkward moment now than lose trust later." Not independently confirmed by a third-party outlet.

  22. [23]

    CourtListener: Consolidated Class Action Complaint, In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 (N.D. Cal.)accessed 2026-08-04

    Filed December 5, 2025. Read AI is not a party; it is named at paragraph 84 as a comparator. Everything in the document is a filed allegation against the defendant, not a finding.

This audit quotes Read AI’s own public documents and reputable public records. It is not legal advice, and filed lawsuits are allegations, not findings.

Related audits

How Routines handles the same data

Routines, the app behind this audit, handles the same job differently: meetings are recorded without a bot joining the call, and your notes are markdown files on your Mac that open in any editor. No cloud bill, no per-minute costs, and it works offline. All transparency audits