Notetaker: privacy and security overview
Last updated: October 7, 2026
Available on: Mac and Windows.
Notetaker uses cloud processing for meeting transcripts and summaries. Review consent, retention, sharing and access before you record or share a meeting.
What Flow captures, and consent
With your permission, Flow captures microphone and system audio and sends it to Wispr. It hears only audio available to your computer; no bot joins the call. If your connection drops, recording continues locally and the full recording is transcribed once connectivity returns, so the live transcript can have gaps.
Obtain recording permissions, notices and consent yourself, including for participants who don't use Flow. Bot-free recording does not notify participants, and Wispr's confirmation asks you, not them — optional notices and confirmations do not collect participant consent, so do not assume a notice was sent. Requirements vary by jurisdiction and policy; consult your legal team.
Important: If consent is withdrawn, delete the whole meeting — segment-level deletion is unavailable.
Processing and security
Protection: Data is encrypted in transit and at rest with managed, regularly rotated keys, and internal access uses least-privilege role-based controls with multi-factor authentication.
Location and international transfers: The Data Processing Addendum (DPA) incorporates EU Standard Contractual Clauses, and a UK Addendum is available; confirm individual subprocessors' locations and transfer terms in the current DPA and subprocessor materials.
AI processing: Cloud transcription and summarization involve third-party AI providers acting as subprocessors under the DPA, whose retention and training terms differ.
Training: Wispr does not use customer content to train its models without consent.
Request the SOC 2 report, DPA, subprocessor list and security documents through the Wispr Trust Center; some require an NDA.
Retention and deletion
Data | Retention |
Uploaded meeting audio | Kept 7 days after upload, then deleted; your account may delete it as soon as processing finishes. |
Local meeting audio | Copies expire 7 days after the file was last written by default; account windows can differ. |
Transcript | Kept indefinitely unless a retention window expires or you delete the meeting. |
Title, notes and Flow Summary | Kept until you delete the meeting, unaffected by transcript retention. |
How meeting audio is deleted
Wispr does not store the live audio stream. Flow deletes the original audio once the upload is prepared, then the uploaded copy when its window ends; recordings that don't reach Wispr are sent again automatically. Clearing uploaded audio also attempts deletion for transcription, and saved transcripts remain. Expired local copies are deleted. These deletion schedules still apply under organization restrictions or with a signed HIPAA Business Associate Agreement (BAA).
How an expired transcript is removed
When a transcript's retention window ends, Flow removes it right away, including when you have edits that haven't finished saving. Your title, notes and Flow Summary for that meeting are kept, and anything you are typing is left untouched.
Warning: Retention deletes meeting audio and transcript-derived speaker names; the meeting itself remains. Once a transcript is deleted, Flow cannot display it or resume that meeting, even with local audio. Deleting a meeting removes access to it, its notes and summary across devices, deletes transcripts and speaker-identification data, and ends shared access.
Who can see a meeting
Email invitations: Summary and Transcript by default. Removing an invitation removes Transcript access, and invited-only notes disappear from the recipient's apps.
Owners: Keep access despite sharing-content restrictions or disabled sharing.
Names and emails: Only owners and invitees see recipient emails, and anonymous visitors cannot see the owner's email.
Revoking: Full revocation permanently invalidates the link and removes all recipients; narrowing visibility keeps invitees.
Auto-shared calendar notes: When Flow adds the notes link to a calendar invite, attendees are invited and your chosen visibility — for example "Anyone with the link" or your company — is kept. Notes with no share setting yet are shared with invited people only.
Recurring Google Calendar events: If a notes link from a past occurrence ends up on upcoming occurrences you organize, Flow removes it, so the link stays only on the meeting that has notes. Pre-meeting "taking notes" notices and the rest of your event description are left as they are.
Warning: Copying the link of a note you haven't configured applies "Anyone with the link" unless your default or organization narrows it. Invitation emails contain summary previews that revoking access cannot retract.
The owner's organization governs sharing, even across organizations: public links, named internal and external recipients, internal recipients only, or sharing disabled. Organizations that have not set a policy allow public links. Disabling sharing preserves notes and links, and re-enabling restores the links. If owners leave their organization, colleagues lose team-link access while owner and invitee access remain.
Optional calendar access
Each person authorizes their calendar separately; on Mac and Windows you can connect Google Calendar or Outlook/Microsoft Calendar. Flow collects titles, times, conference links, colors, recurrence details, attendees and agendas or descriptions. Location text supplies meeting links but is not kept. Google connections also store attendee names and photos, including from recent meetings at the time you connect.
To remove calendar data:
Open Settings → Connectors.
Disconnect your calendar. This clears calendar data and stored attendee names and photos from your device, stops updates, and attempts to revoke access with the provider.
Existing notes keep the event details already captured. You can also revoke access in the provider's settings. Signing out clears calendar data from the device, and deleting your Flow account removes calendar data.
Organization restrictions and HIPAA
A signed personal or organization HIPAA BAA blocks recording. An organization BAA enforces Zero Data Retention and turns off data sharing and cloud storage while active; dictation remains available. Personal BAAs take precedence over organization restrictions — use "Open Settings" for Data and Privacy. If an organization restriction applies to you, contact your admin.
Still need help?
Contact your admin or Wispr Support with your platform, the exact message and the steps you tried if:
A retention change keeps failing after you try again.
Recording or sharing stays blocked and you cannot tell which restriction applies.