The Bot Was Never the Problem: What the Otter Ruling Means for Every Other AI Notetaker
Short answer - what should you actually take from this?
- If you use a notetaker at work, the three questions that matter are: who else gets commercial use of the audio, who does your vendor say is responsible for participant consent (Otter's own litigation position was: you are), and can the vendor actually delete your data once it's been baked into a model.
- If you're choosing a tool, "does it send a bot?" is not the question. Granola's invisibility is what the complaint against it complains about.
- If you're in an all-party-consent state, the numbers are why this is class-action-shaped: California Penal Code § 637.2 sets damages at $5,000 per violation or three times actual damages, whichever is greater - and says outright that you don't need to have suffered actual damages to sue.
- Nothing here is proven. Surviving a motion to dismiss means "plausible enough to continue," not "liable." Every company named below denies the claims.
- I am not a lawyer and this is not legal advice. It's a careful read of published legal coverage and of four companies' own privacy policies, with links, so you can go check my work.
Bias, loudly, before I start: I make Humla, a Mac notetaker that competes with most of the companies in this post. A post like this is EXTREMELY convenient for me. That's precisely why I've tried to write it as a post about a structural problem rather than a list of people to be frightened of, and why there's a whole section near the bottom about how the same problem lands on my app too. (It does. It's not a flattering section. I wrote it anyway.)
What happened on 13 August, briefly
I did the long version already, so, quickly.
Four class actions filed against Otter in 2025 got consolidated into In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL (N.D. Cal.), before Judge Eumi K. Lee. Otter moved to dismiss. On 13 August the court granted that in part and denied it in part - CIPA, federal wiretap, Illinois BIPA, unjust enrichment and unfair competition all survived; the computer-fraud claims, the Washington Privacy Act claim and most common-law privacy claims did not (National Law Review, 17 August 2026).
Otter's whole defence was: we're a tool. The host is holding us. We're not some separate entity listening in, we're the notepad.
The court didn't buy it, and the reason is the entire point of this post. Otter looked like a third party because it "independently collects, retains, and uses communications for its own commercial purposes," including to improve its products and its machine-learning models.
Six words. For its own commercial purposes. Not "because a bot was in the room." What it DOES with what it heard.
I read that, thought "huh, neat, that's a nice tidy angle for the review," filed it, and moved on.
Then I found the Granola case and had to rewrite my entire mental model in a coffee shop.
Okay so watch what happens when you take the bot away
Chamberlain v. Granola, Inc., No. 3:26-cv-07926 (N.D. Cal.), filed 30 July 2026. Fourteen days BEFORE the Otter order (Barnes & Thornburg LLP, 13 August 2026).
Granola is the poster child for bot-free. There is no participant called "Granola" in your Zoom. It grabs the audio at the endpoint, on the laptop of the person using it, which is exactly the architecture that two solid years of "no bot joins your call" marketing - mine included, repeatedly, with feeling - has been holding up as the considerate option.
Sued anyway.
And here's the part that made me put my coffee down: per the complaint's framing, the missing bot isn't the defence. It's the aggravating factor. A visible bot in the participant list is at least a thing a human being can see and object to. An endpoint recorder is invisible to everyone in the meeting except the one person running it.
I have written the sentence "no bot ever joins your call" on a marketing site. I still believe it's better! I think it's less rude, less disruptive, and it doesn't put a robot's name in front of your client. But I had quietly filed it under "and therefore more respectful of the other people," and a plaintiff's lawyer has now filed it under "and therefore harder to notice," and I can't actually prove my filing is the right one.
(Sourcing note, because I care about this and you should too: the most detailed write-up of that complaint I could find sits on the marketing blog of a COMPETING notetaker. Which is not a neutral narrator. Neither, obviously, am I. So the caption, court, docket and filing date above come from a law firm's client alert instead, and for what Granola actually does I went to Granola's own policy rather than anybody's characterisation of it. Coming up in two sections.)
Same alert lists two more, both against Fireflies:
| Case | Court | Filed |
|---|---|---|
| In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 | N.D. Cal. | Four suits, Aug-Sept 2025, consolidated |
| Chamberlain v. Granola, Inc., No. 3:26-cv-07926 | N.D. Cal. | 30 July 2026 |
| Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 | C.D. Ill. | 18 December 2025 |
| Parrinello v. Fireflies.AI Corp., No. 3:26-cv-02479 | N.D. Cal. | 2026 |
Bot. No bot. Bot. Bot.
The pattern does not sort by architecture, is my point. It sorts by something else.
What they actually have in common
Strip out the venues and the statute numbers and every one of these is the same two-part story.
Part one: somebody's speech got captured without them agreeing to it. Part two, and this is the half that survives a motion to dismiss: the vendor then used it for itself.
The Otter complaints allege it "uses conversations to train AI models" (Troutman Amin, November 2025). And the genuinely interesting thing about that allegation is that nobody had to dig for it. Otter says so. Out loud. In its privacy policy, effective 16 June 2026: "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)."
Now here's Granola's own privacy policy, effective 24 July 2026, which is six days before it got sued:
"We only use de-identified data to train AI models, which you can opt-out of within your Granola account settings. Enterprise Workspace Products have admin-enforced settings and are opted-out by default."
I'm going to say the unpopular thing, as the competitor, in public: on paper that is BETTER than Otter's. There's a documented off switch. Enterprise defaults the right way round. Granola also says it doesn't keep the audio at all - "We do not retain or store such recordings once the transcription is created." When I read Otter's policy for the review I went hunting for an equivalent training opt-out and couldn't find one documented anywhere. Granola documents one.
Credit where it's due, sincerely, no notes.
And it got sued anyway.
Which is the thing I actually want to talk about, and it took me embarrassingly long to see it.
Meet the Account Holder
My last post ended on the Fourth Attendee - the model that learns from your meeting, in the room, absent from the participant list. This one is about the only person in that room who gets a vote about it.
The Account Holder is a wonderful character. Truly. The Account Holder clicked accept. The Account Holder has SETTINGS. The Account Holder can toggle model training off, pick a retention window, upgrade to the enterprise tier where it's off by default, delete a conversation and watch it purge from trash after thirty days. Every consent mechanism, every opt-out, every admin control in this entire product category is issued, exclusively, to the Account Holder.
The Account Holder is also, structurally, the one person in that meeting whose privacy was never at risk.
They knew. They pressed the button. They're fine.
Everybody else - your client, the candidate, the contractor, the colleague who dropped in for nine minutes to answer one question and then left - has no account, has never read the policy, has no toggle, and could not tell you which of the fourteen notetakers currently on the market is turning their voice into training data this afternoon.
The opt-out is real. It's just been installed in the wrong person.
That's not a Granola problem or an Otter problem. It's the shape of the entire category, mine very much included, and it's why "but we have an opt-out" doesn't dispose of a claim brought by someone who was never offered one.
And Otter's litigation position made the geometry explicit. If you use one of these tools at work, this is the paragraph to actually worry about: Otter argued that the account holder - the customer, you, the person reading this - carries the responsibility for getting third-party consent under its terms. The plaintiffs' response was that this obligation is "neither intuitive nor prominent but instead buried in a policy that few participants ever see" (ZwillGen, 30 July 2026).
Whoever turns out to be right about that, notice the shape of it.
Your vendor's defence strategy involves pointing at you.
The one you can't undo
Of everything I read this week, the sharpest practical line comes from Barnes & Thornburg's checklist for companies. Among the things they say to evaluate in a vendor contract: data use for model training, deletion rights, and whether vendors can actually delete data after it's been incorporated into AI models.
Sit with that one for a second.
Retention windows, a trash that empties after thirty days, a delete button, a DSAR process - all of that operates on records. Rows. Files. Things with a location.
A model that has already trained on the transcript is not a record. There's no row to drop. There's nothing to point the delete button at.
"De-identified" is carrying an enormous amount of weight in both of the policies I quoted, and neither company describes the method. So when you're evaluating one of these tools, "can I delete my data" and "can I delete my data from the model" are two completely different questions, and only one of them has a comforting answer.
What to actually do about it
Here's where a competitor's blog post says "or you could just use my app!" I will say that, further down, because I'd like you to and I'm not going to pretend otherwise.
But realistically most of you are not switching tools this quarter, so here's the list from the actual law firm rather than the list from the guy with something to sell (Barnes & Thornburg, 13 August 2026):
- Inventory what's actually running, shadow IT included. Somebody on your team installed a notetaker in 2024 and has never once mentioned it to anybody.
- Review your SSO and app-access permissions, so a tool one person authorised isn't quietly spreading sideways through the org.
- Write the policy down: which tools are approved, what notice gets given, what consent looks like in each jurisdiction you operate in.
- Read the vendor contract for model-training use, deletion rights, and the un-deletable-model problem above.
And then one from me, which is not on any law firm's list because it is not a legal control and no lawyer would dignify it: just say it out loud.
"I've got a notetaker running, shout if you'd rather I didn't."
One sentence. Top of the call. It doesn't make anything lawful that wasn't lawful, it doesn't substitute for whatever consent your jurisdiction actually requires, and it completely solves the SOCIAL version of this problem - which, let's be honest, is the version you're overwhelmingly more likely to actually experience. Nobody is suing you. Someone might be quietly annoyed at you, and that one costs you the relationship.
The properly legal version, if you want it: is it legal to record client calls, two-party consent, and GDPR and meeting recordings for the EEA. Norwegian readers get their own post, because Norwegian criminal law draws this line somewhere genuinely different and it surprised me when I looked it up.
Right. Where my own app sits in all this
I'm not going to tell you Humla is legally safer, because I don't know that, and neither does anybody else, and the honest reason nobody has tested us in court is that we are small. That's a fact about our size. It is not a fact about our virtue.
What I can say is structural. The specific thing Judge Lee's reasoning turned on - a vendor independently collecting, retaining and using your conversations for its own commercial purposes - is a thing we don't do. Recording and transcription can run entirely on your Mac. We receive no audio, no transcripts, and we train nothing on your meetings, because there is no pipeline here that could. You don't have to take that on faith either, since the whole app is MIT-licensed and sitting on GitHub waiting to embarrass me.
Now the less flattering half:
- Use a cloud transcription provider and a third party gets your audio. Point Humla at OpenAI, Deepgram or Groq and you have handed the recording to a company with its own retention terms. I've read all three end to end (OpenAI, Deepgram, Groq) and they differ a LOT. Bring-your-own-key moves the decision to you. It doesn't delete the decision.
- Turn on Cloud sync and we hold your notes. That is a service holding your data, same category as everyone above, and the honest answer for anyone who cares at this level is to self-host the sync server or not sync at all.
- We do send two anonymous counters now, during first-run setup, disclosed on screen before anything leaves, and off entirely for every install that existed before the feature did. They count whether setup finished. They contain nothing from any meeting - but "we send literally nothing" would be a lie, and I would rather write this bullet myself than have somebody find it in the source and write it for me.
- And none of this solves the Account Holder problem either. Humla hands you the controls, exactly like everybody else. The person across the table still didn't get a vote. The only difference is that with nothing leaving the machine, there's less for them to have needed a vote about.
The thing I keep circling back to
Two years of marketing in this category - and I mean MY marketing, I have receipts, I linked one above - has been an argument about the bot. Bot bad. No bot good. Look how considerate our capture architecture is, look at our nice quiet endpoint recorder.
And then a judge in San Jose read these products and cared about something else entirely. Not who was in the room. Who got to keep what was said in it.
Meanwhile the plaintiffs' bar has gone and filed against the polite bot-free one too, which fairly strongly suggests the distinction the whole market has been selling on was never the distinction that mattered.
The Fourth Attendee doesn't need to join your call. It never did. It just needs somebody in the room to have clicked accept on its behalf - and that person, conveniently, is the only one it ever asks.
Case names, dockets and dates come from published law-firm client alerts dated 24 November 2025, 30 July 2026 and 13 August 2026, all linked above. I did not read the underlying complaints or orders; CourtListener 403s. Vendor quotes are from Otter's and Granola's own live policy pages, effective 16 June 2026 and 24 July 2026, checked 25 August 2026. The § 637.2 figure is quoted from the California legislature's own text. Every allegation described here is unproven and denied. I am not a lawyer, this is not legal advice, and if this affects you commercially you want a real one.