tl;dv privacy audit

Is tl;dv safe? A privacy audit built from tl;dv's own documents.

The short answer

Last verified 2026-08-04

tl;dv is a cloud meeting recorder operated by Tldx Solutions GmbH, a German company. A bot joins your calls, and the recording, transcript and summary are stored on tl;dv's servers, which its Privacy Policy says sit primarily in the European Economic Area. The vendor's promise never to train AI on customer data is stated plainly, but it lives on two marketing pages in two different wordings, and the Privacy Policy that actually governs processing carries no training clause at all. Several other claims also land differently in different tl;dv documents: the SOC 2 report type, the hosting providers, and how long free recordings are kept. [1][2][3][4][17][22][23]

What tl;dv does well

  • EU hosting is the stated baseline. The Privacy Policy says all personal data collected through the platform is primarily processed and stored in facilities located in the European Economic Area, and names one exception: part of the AI service, depending on the AI hosting location you select.
  • The Terms take no license over your content. No license grant covering user recordings, transcripts or notes appears anywhere in them, and none of the usual perpetual, irrevocable, sublicensable or royalty-free wording appears in the document.
  • Staff access is consent-gated in writing. The Privacy Policy states that tldx does not access your recordings and transcriptions at any time unless you personally share access with individual employees for technical assistance, and that only the items you granted access to are reachable.
  • The sale-of-data sentence is flat and unhedged: "We will not sell the collected data to other companies." No US state-law carve-out sits next to it in either legal document.
  • Consent is a shipped feature, not just a disclaimer. An add-on requests recording consent from external invitees before the bot joins, and if consent is declined the bot is not allowed into the meeting room, per tl;dv's own documentation.
  • Deletion is documented as immediate and final: tl;dv states it keeps no backups nor fallbacks and that a deleted recording cannot be recovered, and account deletion is a single self-serve click-path in settings.

What deserves caution

  • The no-training promise is absent from the Privacy Policy. The May 22, 2026 version was read in full on August 4, 2026 and contains no training clause; the promise appears only on the Security Commitment page and the homepage, worded two different ways. The document that governs processing is silent on it.
  • tl;dv's own sources disagree on its SOC 2 report. The Security Commitment page says Type II; a tl;dv blog post says Type 1. The same page's badge strip also reads "EU US PRIVACY SHIELD", a framework name the Privacy Policy never uses when it describes transfers.
  • Encryption is described three ways. The Privacy Policy's encryption clause covers connections only; the homepage's security section claims AES-256 at rest and, in the paragraph carrying the no-training promise, "end-to-end encryption." Neither legal document repeats the end-to-end claim, and the Privacy Policy's own staff-access clause describes tl;dv granting support employees access to stored recordings when you share them, an access model inconsistent with keys only the customer holds.
  • The documents disagree about where data sits. The Privacy Policy's hosting section names Google Cloud and AWS; its own subcontractor table adds Hetzner and Wasabi, and the help center offers an AI hosting region in France with Mistral, a vendor the subcontractor table does not list.
  • No two-factor authentication is documented in any tl;dv source read for this audit. SSO is described as Enterprise-only, but only in vendor comparison blog posts, not in the help center or either legal document.
  • Free-plan retention is stated two ways by the same vendor: three months in both the Privacy Policy table and the help-center article, six months in tl;dv's comparison blog posts.

Training on your recordings

Never, per tl;dv [3][4]

Where that promise lives

Marketing pages, not the policy [3][1]

Where recordings go

tl;dv cloud, EEA; AI in US or France [1][7]

Encryption

In transit in the policy, at rest on the homepage [1][4]

Two-factor authentication

Not documented [3][7]

Certifications

SOC 2, type stated two ways [3][22]

tl;dv homepage, the cloud AI meeting recorder and note taker this tl;dv privacy audit covers
tl;dv, accessed 2026-08-04

Quick facts

The privacy facts, at a glance.

How audio is captured
Bot-based by default: a tl;dv bot joins calendar meetings and can be denied entry or removed like any other participant. A bot-free desktop recording mode exists. The bot waits 10 minutes, caps recordings at 3 hours, skips events marked all day, and does not work with webinars. [11][12][13][15]
Where transcription happens
In tl;dv's cloud. The Privacy Policy says all personal data is primarily processed and stored in EEA facilities, with one stated exception: part of the AI service, which runs in the region you select. No on-device transcription path is described in any document. [1][7]
Where your data is stored
Google Cloud and AWS, per the Privacy Policy's hosting section, with the database in a Google Virtual Private Cloud. The subcontractor table in the same policy also names Hetzner and Wasabi as hosting, infrastructure and storage providers; the hosting section does not mention either. [1]
AI training defaults
"No customer data is used to train the AI," per the Security Commitment page, and the homepage says the same thing in stronger words. The Privacy Policy, read in full on August 4, 2026, carries no training clause; its only AI passage discloses where summaries are generated. [3][4][1]
Retention
Recordings and transcripts: three months for free accounts, until account deletion for paying ones, per the Privacy Policy table and the help center. Logs and site analytics are kept 10 days. Support ticket data: "This data is not deleted. A request may be made." Free recordings move to archive after 3 days. [1][17][18]
Subprocessors
15 named entries in a table inside the Privacy Policy; no standalone dated subprocessor page exists. The AI provider row names Anthropic and Google Vertex. No human annotation or data-labelling vendor is disclosed anywhere, and Mistral, offered as an AI hosting region in the help center, does not appear in the table. [1][7]
Encryption
In transit: "All connections to Tldx Solutions GmbH are encrypted using the SSL protocol," with HTTP redirected to HTTPS. The Privacy Policy states no at-rest encryption clause; the AES-256 at-rest claim appears on the homepage instead. End-to-end encryption is claimed on the homepage only; neither legal document repeats it, and the policy's consent-gated staff-access clause describes vendor-side access to stored recordings. [1][4]
Certifications
SOC 2 is claimed as "Type II" on the Security Commitment page and as "Type 1" in a tl;dv blog post. ISO 27001 is attributed to the hosting providers, not to tl;dv. No HIPAA claim appears in the Privacy Policy, the Terms, the Security Commitment page or the homepage. The Vanta-hosted Trust Center returned no readable content to non-browser fetching. [3][22][1][5]
Consent features
The bot joins as a visible participant, and tl;dv states recording is not designed to run silently. An add-on can request consent from external invitees and blocks the bot if consent is declined. Bot-free recording carries no automated notice, and tl;dv puts that duty on the user. [7][24][15]
Sharing defaults
Two access levels per meeting, "Anyone with the link" and "People with access", plus per-person Admin, Editor and Viewer roles and whole-domain sharing with a wildcard address. Which value a new account or a new team ships with is not stated in tl;dv's docs. [8][7][9]

Data flows

What leaves your Mac.

  1. Step 01

    Meeting video, audio and transcripts

    Uploaded to tl;dv and stored on its infrastructure. The policy names Google Cloud and AWS in its hosting section and Google Cloud, Hetzner and Wasabi in its subcontractor table. [1]

  2. Step 02

    Transcript excerpts sent to an LLM provider

    To generate summaries and other derived content, limited portions of meeting transcripts are processed by large language models, either in the US or in France, depending on the AI hosting location set in your preferences. [1][7]

  3. Step 03

    Calendar events

    Auto-record reads your calendar to decide which meetings the bot joins, and rules can match on invitee email domains. The Privacy Policy's table of collected data categories does not list calendar data as its own category. [11][1]

  4. Step 04

    Email addresses of people who never signed up

    The Privacy Policy lists, as a collected category, the "Email address of people not subscribed but are participants in a meeting where the solution would be used", retained for 5 years or upon deletion request. [1]

  5. Step 05

    Usage analytics and logs

    IP address, geographic location, browser and version, operating system, referral source, visit duration, pages viewed and navigation paths. Retained 10 days, described as non-nominative. Mixpanel, Cloudflare and Sentry are the named analytics subcontractors. [1]

  6. Step 06

    Account, billing and support data

    Email, name and profile image URL, plus credit card, billing email and billing address, processed with Stripe and kept until account deletion. Support conversations go to Intercom and Sentry, and support ticket data is not deleted unless requested. [1]

AI training

Training defaults, in tl;dv’s own words.

tl;dv states that it does not train AI on customer data. Read the sourcing precisely: that promise appears on the Security Commitment page and, in different words, on the homepage. The Privacy Policy, whose current version is dated May 22, 2026 and which was read end to end on August 4, 2026, contains no training clause of any kind. Its only AI passage is a processing-location disclosure. So the strongest statement tl;dv makes about training sits in marketing copy rather than in the document that governs how it processes your data. [1][3][4][7][23]

No customer data is used to train the AI.
Source: Security Commitment page, "Trusted and Secure Generative AI"
Your recordings and transcripts are yours (not ours). And we'll never, ever use them to train AI. Ever.
Source: Homepage, "Your data, always kept private and secure"
tldx may use large language models provided by Anthropic via Google Cloud Vertex AI to generate written summaries or other derived content.
Source: Privacy Policy, section 8, "Is your data sent outside the European Union?"
tl;dv Security Commitment page stating that no customer data is used to train the AI, the training clause this tl;dv privacy audit quotes
The receipt: tl;dv's Security Commitment page, the no-training sentence, accessed 2026-08-04

Can you opt out?

Not documented, and on tl;dv's telling not needed: no per-account or per-workspace AI-training toggle appears anywhere in the help center, and the claim is written as a platform-wide policy rather than a setting. The nearest control is a different thing entirely, the AI hosting location at Preferences > AI hosting location, which chooses the processing region and vendor rather than whether training happens. Which region a new account starts on, and which plans include that setting, are not stated in tl;dv's docs.

Third-party AI providers

Per the Privacy Policy's subcontractor table, the AI providers are Anthropic and Google Vertex, and section 8 names Anthropic models reached via Google Cloud Vertex AI. The help center adds a second option, Mistral in France, which the subcontractor table does not list. tl;dv states on its homepage that it anonymizes all metadata and processes meetings in randomized, small chunks. tl;dv's comparison blog asserts, in a feature table, a "BAA with LLM providers" and a "0-day data retention" policy with its vendors; no agreement or policy document backing either table cell is published, and neither claim appears in the Privacy Policy or the Terms.

Sharing defaults

Who can see your notes.

Two access levels, set per meeting

Every recording carries an overall access level, and tl;dv describes the private one as a choice you make rather than a state you start in. [8]

People with access - You choose specific people who can view the meeting, or give no one access to keep the meeting entirely private.
Source: Help Center, "How to share meeting recordings", "Change who has access to your meeting"

Link sharing is public, and domain sharing is wide

The other level, "Anyone with the link", makes a meeting entirely public and viewable without signing in, though tl;dv notes it will not be indexed by search engines. Access can also be granted to an entire company at once by entering a wildcard domain such as *@company.com. Adding someone emails them; removing someone does not notify them, per the same article. [8]

Team defaults publish recordings quietly

Admins define rules at Your Team > Admin Controls > Recording Settings that decide whether a meeting is shared with teammates, added to the workspace library, or kept private. Two things travel with those rules: tl;dv states the setting triggers no notification email when a new recording is published, and team settings do not override the privacy rules of Team Admins themselves. [9][7]

Changes only ever apply forward

tl;dv states that whichever team settings you change apply moving forward only and do not apply retroactively. So tightening a default leaves everything already recorded on the terms it was recorded under, and the back catalogue has to be fixed meeting by meeting. [20]

Who controls the workspace, and who cannot leave it

Team Admins can override account preferences set by a Team Member, and only another Billing Group Admin can demote a Billing Group Admin. tl;dv states organizations cannot be deleted. Account transfer needs tl;dv's prior written permission, except through a documented bereavement and power-of-attorney path that can transfer or migrate ownership to another user. [21][2]

tl;dv staff access, described twice

The Privacy Policy gates staff access on you sharing items with a support member. The Terms state the same promise with a different trigger, access only upon specific request by the user who created the recording. Both are consent-gated; the two documents word the trigger differently. [1][2]

Tldx Solutions GmbH does not access your recordings and transcriptions at any time, unless you personally share access with individual employees for technical assistance.
Source: Privacy Policy, section 6, "What personal data is collected?"

Hardening checklist

Settings that make tl;dv more private.

If you use tl;dv and want to keep it, these are the settings worth changing, straight from the vendor’s own documentation.

  1. Step 01

    Decide which meetings the bot joins, before it joins one

    Where

    Preferences > Auto-record calendar events: "All meetings", "Internal meetings" or "External meetings". Finer rules live under Auto-record, with the Is, Is not and At least one is conditions on invitee domains. For a whole team: Your Team > Admin Controls > Recording Settings tab > Auto Record meetings.

    tl;dv's docs do not state which value a new account starts on, or whether auto-record starts enabled, so check yours; the preferences article recommends keeping it enabled for all meetings, which is a recommendation, not a stated shipped default. Three traps from the same docs: a domain you type is only accepted after pressing Enter or comma, accounts registered on a public email domain such as gmail.com cannot use the internal-only or external-only filters at all, and team auto-record rules do not override the rules of Team Admins themselves. [7][11][10]

  2. Step 02

    Turn on consent requests for external guests

    Where

    Preferences > Auto-request recording consent (GDPR Add-on).

    With it on, tl;dv asks everyone who does not share your email domain for consent, and if consent is declined the bot is not allowed into the meeting room. A separate Consent Collection flow is documented as replacing the calendar meeting link with a consent link; that article could not be retrieved in full for this audit, so verify its behaviour in-product before relying on it. Neither mechanism covers bot-free recording, where tl;dv states notifications may not appear automatically and it is your responsibility to inform participants. [7][14][15]

  3. Step 03

    Set the team privacy default, then fix the back catalogue by hand

    Where

    Your Team > Admin Controls > Recording Settings tab > Default Recording Privacy.

    This is where a workspace decides whether recordings are shared with teammates, added to the library, or kept private. Which of those a new team starts on is not stated in tl;dv's docs. Two limits ride along: the change applies moving forward only and does not apply retroactively, and team settings do not override the privacy rules of Team Admins, who set their own in Personal Preferences. [9][20]

  4. Step 04

    Audit who is on each recording, and treat removals as silent

    Where

    Open the meeting > sharing menu: set the overall level to "People with access", then review the per-person Admin, Editor and Viewer roles.

    The alternative level, "Anyone with the link", makes the meeting viewable without signing in, and a wildcard domain entry hands access to everyone at a company. tl;dv notifies people by email when you add them, and its docs state people are not notified when you remove their access, so removal alone is not a way to tell someone the recording is off limits. [8]

  5. Step 05

    Delete what you would not want kept, and expect it to be final

    Where

    Meeting thumbnail > 3-dot button > Delete. For the whole account: tldv.io/app/settings/personal-settings/profile > "delete account".

    tl;dv states it keeps no backups nor fallbacks and that once a recording is deleted it cannot be recovered, and no trash or undo window is documented. Trimming is equally one-way: each recording can be trimmed once and the removed parts cannot be recovered. On the free plan, recordings are stored three months and then deleted in batches on the 1st of the month, with an email 4 weeks before and downloads enabled for the affected recordings. [16][19][17]

  6. Step 06

    If the data has to stay in Europe, set the AI region and read the subcontractor table

    Where

    Preferences > AI hosting location: France with Mistral, or the US with Anthropic.

    The Privacy Policy says everything is hosted in the EEA except part of the AI service, which follows this setting, and that transfers rely on standard data protection clauses adopted or approved by the European Commission. tl;dv's docs do not state which region a new account starts on. Note also that Mistral does not appear in the Privacy Policy's subcontractor table, and that the Security Commitment badge strip reads "EU US PRIVACY SHIELD", a name the Privacy Policy itself never uses for transfers. [7][1][3]

Policy changelog

What changed, and when.

Each entry records a dated re-verification of this audit against the vendor’s documents. Policy changes land here as dated diffs.

2026-08-04

Audit created. Verified against the Privacy Policy (current version published May 22, 2026), the Terms of Service (effective May 18, 2026), the undated Security Commitment page, the undated homepage, 15 help-center articles, and three tl;dv blog posts cited only where a claim appears nowhere else. The Vanta-hosted Trust Center at trust.tldv.io returned no readable content to non-browser fetching, so nothing on it is cited here. Litigation status at verification: no lawsuit, regulator action or breach disclosure naming tl;dv or Tldx Solutions GmbH was found in the court records, regulator channels and reporting searched for this audit, which is not the same as proof that none exists.

FAQ

Questions people ask.

Is tl;dv safe to use?

It depends on what you record and how much weight you put on where a promise is written. tl;dv keeps data in the EEA by default, takes no license over your recordings, gates staff access on your consent, and ships a consent-request add-on. Against that, its strongest privacy claims sit on marketing pages rather than in the Privacy Policy, and several of its own documents disagree with each other on encryption at rest, SOC 2 type, hosting providers and free-plan retention. For routine internal meetings that is a normal cloud trade. For regulated or confidential conversations, get the claims into a contract first. [1][2][3]

Does tl;dv train AI on my meetings?

tl;dv says no. Its Security Commitment page states "No customer data is used to train the AI," and its homepage says recordings and transcripts are yours and will never be used to train AI. The gap worth knowing is where those sentences live: the Privacy Policy, read in full on August 4, 2026, contains no training clause at all, so the promise is a marketing-page statement rather than a policy term. [3][4][1]

Can I opt out of tl;dv AI training?

There is nothing documented to opt out of. No AI-training toggle appears in the help center, and tl;dv frames the no-training claim as a platform-wide policy rather than an account setting. The closest control is the AI hosting location in Preferences, which selects the processing region and provider, US with Anthropic or France with Mistral, and does not describe itself as a training control. Which region a new account starts on is not stated in tl;dv's docs. [7][3]

Is tl;dv being sued over privacy?

No lawsuit naming tl;dv, tldv.io or Tldx Solutions GmbH was found in the court records and search sources checked for this audit, including CourtListener-targeted searches and German-language searches for the company, which is registered in Aachen. That is an absence of records in the places searched, not a clearance. tl;dv itself publishes a blog post about recording-consent lawsuits filed against other meeting assistants; those are filed allegations against other companies and say nothing about tl;dv. [6]

Has tl;dv had a data breach?

No breach disclosure by tl;dv and no third-party report of a breach were found in the sources checked for this audit, which is not the same as proof that none occurred. tl;dv does publish a vulnerability-reporting route through privacy@tldv.io and its Trust Center. Note that the Trust Center itself could not be read by non-browser fetching, so whatever it discloses about incidents is outside what this audit could verify. [3][5]

Does tl;dv sell my data?

The Privacy Policy says "We will not sell the collected data to other companies." That is the whole statement: unlike policies written for US state privacy laws, it carries no definition-based carve-out for sharing that might count as a sale. The policy does list the third parties data reaches for the service to work, including analytics, support, payment and AI providers. [1]

Is tl;dv SOC 2 certified or HIPAA compliant?

On SOC 2, tl;dv publishes both answers. The Security Commitment page says it is SOC 2 compliant with a Type II report; a tl;dv blog post says it has a Type 1 report. Those describe different levels of assurance, and the audit cannot resolve which is current from public documents. On HIPAA, no claim exists: the word appears in none of the Privacy Policy, the Terms, the Security Commitment page or the homepage. ISO 27001 is attributed to the hosting providers rather than to tl;dv itself. If either matters, ask for the report and the effective dates directly. [3][22][1][5]

Who can see my tl;dv recordings?

You and whoever the access level lets in. A meeting set to "Anyone with the link" can be viewed without signing in; a wildcard domain entry admits everyone at a company; and a team default set by an admin can publish new recordings to teammates or the workspace library without sending anyone a notification email. tl;dv staff are outside that circle by policy unless you share an item with support. Which values a new account and a new team start on is not stated in tl;dv's docs, so check yours rather than assuming private. [8][9][1]

Sources

Every claim, receipted.

Every claim on this page maps to one of these documents. Dates are when we last read each one.

  1. [1]

    tl;dv Privacy Policyaccessed 2026-08-04

    States "Current version published: May 22nd, 2026." Read end to end for this audit: the document contains no AI-training clause, and its subcontractor table (section 7.2) is the only subprocessor disclosure tl;dv publishes. A search-index snippet referencing an "AI Model Training" heading could not be located in the live document, so no claim here rests on it.

  2. [2]

    tl;dv Terms of Serviceaccessed 2026-08-04

    States "Current version published: May 18th, 2026"; the footer restates "Effective as of May 18, 2026." Read end to end: no license grant over user content appears in it, although the text refers once to "the licenses above" with no such clause preceding it.

  3. [3]

    tl;dv Security Commitment pageaccessed 2026-08-04

    The page carries no effective or last-updated date, so its claims cannot be dated from the page itself. Carries the SOC 2 Type II claim, the no-training sentence and the trust badge strip including "EU US PRIVACY SHIELD".

  4. [4]

    tl;dv homepageaccessed 2026-08-04

    Undated marketing page. Its quotes were captured through a page-reading tool rather than from raw HTML, so they carry a lower confidence tier than the Privacy Policy, Terms and Security Commitment page, all three of which were read in full.

  5. [5]

    tl;dv Trust Center (Vanta-hosted)accessed 2026-08-04

    A JavaScript-rendered application that returned only the string "tl;dv Trust Center" to non-browser fetching. Cited here only for the fact that its contents could not be read, never for a claim.

  6. [6]

    tl;dv Imprintaccessed 2026-08-04

    Company registration data: Tldx Solutions GmbH, Aachen, Germany, HRB 23730 (Amtsgericht Aachen).

  7. [7]

    tl;dv Help Center: Understanding and setting your preferencesaccessed 2026-08-04

    Carries the AI hosting location, auto-record scope, auto-send and default recording privacy sections. The article prints no date.

  8. [8]

  9. [9]

  10. [10]

  11. [11]

  12. [12]

    tl;dv Help Center: How to stop tl;dvaccessed 2026-08-04

    States that the Chrome extension and desktop app do not control whether tl;dv is automatically invited to meetings, and carries the account-deletion click-path.

  13. [13]

  14. [15]

  15. [16]

  16. [17]

    tl;dv Help Center: How long do you keep my recordings?accessed 2026-08-04

    States three months of storage on the free plan, and unlimited storage on Pro. It names no other tier, so what Business and Enterprise accounts get is not stated there.

  17. [18]

  18. [19]

  19. [20]

    tl;dv Help Center: Managing your team in tl;dvaccessed 2026-08-04

    Carries the non-retroactivity sentence for team settings changes.

  20. [21]

  21. [22]

    tl;dv blog: GDPR compliant meeting assistants you can actually trustaccessed 2026-08-04

    Vendor-authored marketing content, not a policy document. Cited only because it states a SOC 2 Type 1 report, which contradicts the Type II claim on tl;dv's own Security Commitment page.

  22. [23]

    tl;dv blog: tl;dv vs. Read.aiaccessed 2026-08-04

    Vendor-authored comparison content. Cited only for claims that appear nowhere in the legal documents: SAML SSO on the Enterprise plan, a six-month free-plan retention figure that conflicts with both the Privacy Policy table and the help center, and the feature-table cells asserting a "BAA with LLM providers" and a "0-day data retention" policy with vendors.

  23. [24]

    tl;dv blog: AI and Privacy, What Teams Need to Know About AI Notetakers in 2026accessed 2026-08-04

    Vendor-authored marketing content. Cited only for tl;dv's description of its own bot as visible in the call and not designed to record silently.

This audit quotes tl;dv’s own public documents and reputable public records. It is not legal advice, and filed lawsuits are allegations, not findings.

Related audits

How Routines handles the same data

Routines, the app behind this audit, handles the same job differently: meetings are recorded without a bot joining the call, and your notes are markdown files on your Mac that open in any editor. No cloud bill, no per-minute costs, and it works offline. All transparency audits