Notetaker: privacy and security overview

Last updated: September 1, 2026

Available on: Mac

What Notetaker captures during a meeting, where that data is processed and stored, how long each part is kept, and who can see it. Written for anyone evaluating Notetaker in a security or privacy review.

Formal documentation — the SOC 2 report, Data Processing Addendum, subprocessor list, and policy suite — is available through the Wispr Trust Center at https://trust.wispr.ai.


How Notetaker captures a meeting

Notetaker records from the Wispr Flow app on your own Mac, capturing your microphone and your computer's system audio locally and streaming both to Wispr's servers for transcription.

  • No bot joins the call. There is no Wispr participant in your Zoom, Teams, or Google Meet session, so other participants see no bot, no join notification, and no automatic in-meeting recording indicator.

  • Capture quality depends on your device. Local capture means Notetaker works with any meeting platform, but it hears only what reaches your Mac's microphone and speakers.

  • Transcription happens in the cloud. Notetaker does not transcribe on-device, so an internet connection is required. If the connection drops mid-meeting, audio is held on your device and transcribed once you reconnect.

Important: Because there is no bot and no automatic notice, any notification to participants has to come from you. See Consent and participant notice.


Where meeting data is processed and stored

  • Location: all customer data is processed in the United States. Wispr does not operate regional processing in the EU, EEA, or Asia-Pacific.

  • In transit: encrypted using TLS 1.2 or higher.

  • At rest: encrypted using AES-256, with keys managed in AWS KMS and rotated every 90 days.

  • Access controls: role-based access following least privilege, with MFA enforced on internal systems.

  • International transfers: the Data Processing Addendum incorporates the EU Standard Contractual Clauses, with a UK Addendum available.


How long each piece of a meeting is kept

A meeting is stored as several separate pieces, kept for different lengths of time.

Data

Where it lives

How long it is kept

Uploaded meeting audio

Wispr's servers

Deleted once processing finishes, whether it succeeded or failed — minutes, not days.

Local copy of the audio

Your Mac

About 24 hours after the meeting finalizes.

Transcript

Wispr's servers and the recording device

Indefinitely by default; deleted with the meeting or when a retention window expires.

Title, notes, and Flow Summary

Wispr's servers

Until you delete the meeting; transcript retention does not remove them.

Calendar event data

Wispr's servers

No time-based deletion. See Calendar data.

How the local audio copy affects Resume

The local copy is what makes Resume possible. Once it expires after about 24 hours, Resume disappears.

Setting a transcript retention window

The default is Never delete: transcripts persist for the life of the account. To change it, open Settings from the Wispr Flow menu bar icon, select Data and Privacy, and set Notetaker transcript retention to 1, 7, 30, 90, 180, or 365 days.

Shortening the window permanently deletes transcripts older than the new limit, from both your devices and Wispr's servers, within 24 hours. It cannot be undone. Enterprise administrators can set this policy org-wide, which supersedes and locks each member's own control.

The Local data storage control on the same settings page governs desktop dictation only, not Notetaker meetings.


Who can see a meeting

A meeting is private to the person who recorded it until they share it. The two sharing levels grant different access.

  • A share link grants the Summary only. This applies to every link, including one restricted to everyone at your domain; the Transcript tab stays locked.

  • An email invitation grants the Summary and the full Transcript. Only the meeting owner can send one, and recipients are always view-only.

  • Removing an invitation locks the Transcript tab the next time that person opens the note.

  • Deleting a meeting is permanent and applies across every device, removing the notes, summary, transcript, and all associated speaker-identification data.

  • Automatic sharing is opt-in and off by default. When on, calendar attendees who did not decline become email-invited recipients, which grants them the full transcript. Enterprise administrators can disable external sharing or restrict it to your own domain.


Calendar data

Connecting a calendar is optional; it exists to match recordings to events, name participants in 1:1 meetings, and power meeting reminders. Google Calendar is the only calendar Notetaker connects to today.

  • What is sent: event title, start and end time, a conference URL derived from the event, colour, recurrence identifier, and attendees. Location text is parsed to find a meeting link and is not retained.

  • What comes back to the app: attendee display names only. Attendee email addresses and the event description are never returned to the client.

  • How long it is kept: no time-based expiry. Cancelled or stale events are marked inactive rather than removed. Deleting your Wispr Flow account removes it.

  • How access is granted: each person authorizes their own calendar through Google's consent screen, so an administrator cannot connect calendars on someone's behalf.

  • How to revoke: disconnect the calendar in Wispr Flow, or revoke Wispr Flow's access from your Google account settings. Disconnecting clears calendar data from your devices; notes already linked to an event keep the event details they captured.


AI processing and subprocessors

Transcription and summarization both run in Wispr's cloud, and both involve third-party AI providers operating as subprocessors under the Data Processing Addendum.

  • The authoritative list of authorized subprocessors is published at https://trust.wispr.ai and incorporated by reference into Annex III of the DPA. Wispr provides at least 10 days' prior written notice before adding a subprocessor.

  • Meeting summaries are generated by a third-party AI provider. Retention and training terms differ by provider and are documented in the subprocessor material available under NDA through the Trust Center.

  • Pre-meeting briefs draw on your own calendar event, your history with the attendees, and — only where you have separately connected Gmail or Slack — recent messages with them. There is no third-party data enrichment. The brief is generated from a prompt that includes attendee email addresses and the event description.

  • Model training: Wispr does not use customer content to train its models without consent. On Enterprise plans, model training is off for the whole organization and is not member-configurable.


Consent and participant notice

Under Wispr's Master Services Agreement, the customer holds the rights, permissions, and consents needed to record, monitor, or transcribe the content they process through the service. You obtain whatever notice or consent your jurisdiction and internal policy require, including from participants who are not Wispr Flow users. Wispr does not obtain consent from participants on your behalf.

  • Recording and consent laws vary by state and by country. Check with your legal team if you are unsure what applies.

  • Notetaker shows an in-app reminder above the composer for the duration of every recording, reading "Always get consent when transcribing others."

  • Enterprise administrators can require a consent confirmation before recording starts. With it enabled, a member must click Consent obtained or the recording does not begin. It is off by default.


Controls for administrators

Enterprise administrators manage these at https://admin.wisprflow.ai, under Settings → Organization.

  • Notetaker availability — enabled or disabled org-wide, with no per-member setting. Disabling hides the feature without deleting anything; re-enabling restores past meetings and preferences.

  • Transcript retention policy — set org-wide, superseding and locking each member's control.

  • Consent confirmation — require members to confirm consent before recording.

  • Note sharing — disallow external sharing, or restrict shared links to your own domain.

  • Connector access — control whether members can connect Google Calendar, Gmail, Slack, and Notion.


FAQs

Does a bot join our meetings, and will participants know they are being recorded?

No bot joins, and participants receive no automatic notification. Telling participants is the recorder's responsibility — see Consent and participant notice.

How long do you keep our meeting audio?

See How long each piece of a meeting is kept. The durable record of a meeting is its transcript and summary, not its audio.

Are transcripts deleted automatically?

Not by default. See Setting a transcript retention window.

If someone shares a meeting link outside our company, what can the recipient see?

The Summary only. Full transcript access requires an email invitation from the meeting owner — see Who can see a meeting.

Is our meeting content used to train AI models?

See AI processing and subprocessors for Wispr's position and for third-party subprocessor terms.

Can we use Notetaker under our HIPAA BAA?

No configuration change unblocks it — see What Notetaker does not support.

Do you have to connect a calendar to use Notetaker?

No. Notetaker records ad-hoc and in-person meetings without any calendar connection. See Calendar data for what the connection adds.

Where do we get your SOC 2 report, DPA, and subprocessor list?

All of it comes through the Wispr Trust Center at https://trust.wispr.ai. Some documents are released under NDA. Support cannot email these directly, so the Trust Center is the fastest route.


What Notetaker does not support

  • HIPAA workloads. Notetaker is unavailable and recording is blocked while a HIPAA Business Associate Agreement is in place, for either an individual account or an organization. Dictation and the rest of Wispr Flow are unaffected, and a BAA remains available for those.

  • Windows, iOS, and Android. Notetaker is Mac-only today.

  • Calendars other than Google. Outlook, Microsoft 365, and iCloud calendars cannot be connected.

  • Offline transcription. Audio recorded offline is held on your device and transcribed once you reconnect.


Still need help?

For a formal security questionnaire, a penetration test summary, certification status, or contractual terms, request access through the Wispr Trust Center at https://trust.wispr.ai. Enterprise customers can also reach their account contact for platform assessment questions.