The Bot Was Never the Problem: What the Otter Ruling Means for Every Other AI Notetaker
Short answer - what should you actually take from this?
- If you use a notetaker at work, the three questions that matter are: who else gets commercial use of the audio, who does your vendor say is responsible for participant consent (Otter's own litigation position was: you are), and can the vendor actually delete your data once it's been baked into a model.
- If you're choosing a tool, "does it send a bot?" is not the question. Granola's invisibility is what the complaint against it complains about.
- If you're in an all-party-consent state, the numbers are why this is class-action-shaped: California Penal Code § 637.2 sets damages at $5,000 per violation or three times actual damages, whichever is greater - and says outright that you don't need to have suffered actual damages to sue.
- Nothing here is proven. Surviving a motion to dismiss means "plausible enough to continue," not "liable." Every company named below denies the claims.
- I am not a lawyer and this is not legal advice. It's a careful read of published legal coverage and of four companies' own privacy policies, with links, so you can go check my work.
Bias, loudly: I make Humla, a Mac notetaker that competes with most of the companies in this post. A post like this is extremely convenient for me, which is exactly why I've tried to make it a post about a structural problem rather than a list of people to be scared of - including a section on where Humla sits in the same problem, because it does.
What actually happened on 13 August
Short version, because I wrote the long one already.
Four class actions filed against Otter in 2025 got consolidated into In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL (N.D. Cal.), before Judge Eumi K. Lee. Otter moved to dismiss. On 13 August 2026 the court granted that motion in part and denied it in part: the CIPA, federal wiretap, Illinois BIPA, unjust enrichment and unfair-competition claims survived, while the computer-fraud claims, the Washington Privacy Act claim and most common-law privacy claims went out (National Law Review, 17 August 2026).
Otter's central defence was that it's just a tool the meeting host is holding - an extension of the person who pressed record, not a separate party listening in. The court didn't buy it, and the reason it gave is the whole point of this post. Otter looked like a third party because it "independently collects, retains, and uses communications for its own commercial purposes," including to improve its products and its machine-learning models.
Read that again with a highlighter on the last six words. The thing that made Otter a third party is not that it was in the room. It's what it does with what it heard.
So watch what happens when you remove the bot
Here's the test case, and it's almost too neat.
Chamberlain v. Granola, Inc., No. 3:26-cv-07926 (N.D. Cal.), filed 30 July 2026 - fourteen days before the Otter order (Barnes & Thornburg LLP, 13 August 2026).
Granola is the poster child for bot-free. There is no participant called "Granola" in your call. It captures audio at the endpoint, on the laptop of the person using it, which is precisely the architecture that "no bot joins your call" posts (mine included, several times) have been holding up as the considerate option for two years.
It got sued anyway. And per the complaint's framing, the absence of the bot isn't the defence - it's the aggravating factor. A visible bot in the participant list is at least a thing people can see and object to. An endpoint recorder is invisible to everyone except the person running it.
I want to be careful about my sourcing here, because the most detailed write-up of that complaint I could find is on the marketing blog of a competing notetaker, which is not a neutral narrator and neither am I. The case caption, court, docket and filing date above come from a law firm's client alert. For what Granola itself says it does, I went to Granola's own policy rather than to anyone's characterisation of it. More on that in a moment.
Meanwhile, the same alert lists two more:
| Case | Court | Filed |
|---|---|---|
| In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 | N.D. Cal. | Four suits, Aug-Sept 2025, consolidated |
| Chamberlain v. Granola, Inc., No. 3:26-cv-07926 | N.D. Cal. | 30 July 2026 |
| Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 | C.D. Ill. | 18 December 2025 |
| Parrinello v. Fireflies.AI Corp., No. 3:26-cv-02479 | N.D. Cal. | 2026 |
Bot, no bot. Bot, no bot. The pattern doesn't sort by architecture.
What the complaints actually have in common
Strip out the venue and the statutes and you get the same two-part story every time. Part one: somebody's speech was captured without their agreement. Part two - and this is the part that survives a motion to dismiss - the vendor then used it for itself.
The Otter complaints allege it "uses conversations to train AI models" (Troutman Amin, November 2025). And they're not making that up, which is the genuinely interesting thing. Otter says so itself, in its privacy policy effective 16 June 2026: "training our proprietary AI technology on de-identified audio recordings and on transcriptions (which may contain Personal Information)."
Now Granola's own privacy policy, effective 24 July 2026 - six days before it was sued: "We only use de-identified data to train AI models, which you can opt-out of within your Granola account settings. Enterprise Workspace Products have admin-enforced settings and are opted-out by default."
I'll say the unpopular thing: on paper, that's better than Otter's. There's a documented off switch, enterprise defaults the right way, and Granola also states it doesn't keep the audio - "We do not retain or store such recordings once the transcription is created." When I read Otter's policy I went looking for an equivalent training opt-out and couldn't find one documented. Granola documents one. Credit where it's due.
And it still got sued. Which brings us to the actual problem, and it's the one nobody's product page has solved.
Meet the Account Holder
My last post ended on the Fourth Attendee - the model that learns from your meeting, present in the room but absent from the participant list. This post is about the only person in that room who gets a say about it.
The Account Holder is a wonderful character. The Account Holder clicked accept. The Account Holder has settings. The Account Holder can toggle model training off, choose a retention window, upgrade to the enterprise tier where it defaults off, and delete the conversation so it purges from trash in thirty days. Every consent and control mechanism in this entire product category is issued to the Account Holder.
The Account Holder is also, structurally, the one person in the meeting whose privacy was never at issue. They knew. They pressed the button.
Everybody else - your client, the candidate, the contractor, the colleague who joined for nine minutes to answer one question - has no account, has never seen the policy, has no toggle, and in most cases has no idea which of the fourteen notetakers on the market is currently turning their voice into training data. The opt-out is real. It's just installed in the wrong person.
That's not a Granola problem or an Otter problem. It's the shape of the whole category, and it's why "we have an opt-out" doesn't dispose of a wiretap claim brought by someone who was never offered it.
Otter's litigation position made the geometry explicit, and if you use one of these tools at work this is the paragraph to actually worry about. Otter argued that the account holder - the customer, you - bears the responsibility for getting consent from third parties under its terms. The plaintiffs' answer was that this obligation is "neither intuitive nor prominent but instead buried in a policy that few participants ever see" (ZwillGen, 30 July 2026).
Whoever's right about that, notice what it means for you. Your vendor's defence strategy involves pointing at you.
The one you can't undo
Of everything I read this week, the sharpest practical point comes from Barnes & Thornburg's checklist. Among the things they tell organisations to evaluate in vendor contracts: data use for model training, deletion rights, and whether vendors can actually delete data after it's been incorporated into AI models.
Sit with that one. Retention windows, trash that empties after thirty days, a delete button, a DSAR process - all of that operates on records. A model that has already trained on the transcript isn't a record. There's no row to drop. "De-identified" is doing a lot of load-bearing work in these policies, and neither Otter nor Granola describes the method.
So when you evaluate one of these tools, "can I delete my data" and "can I delete my data from the model" are two different questions, and only one of them has a reassuring answer.
What to actually do
This is the part where a competitor's blog post says "or you could use my app," and I will, further down, because I'm not going to pretend I don't want that. But the honest answer is that most of you aren't switching tools this quarter, so here's the list from the law firm rather than the list from me (Barnes & Thornburg, 13 August 2026):
- Inventory what's actually running, including shadow IT. Somebody on your team installed a notetaker in 2024 and never mentioned it.
- Review SSO and app-access permissions, so a tool one person authorised isn't quietly propagating across the org.
- Write down a policy: which tools are approved, what notice gets given, and what consent looks like in each jurisdiction you operate in.
- Read the vendor contract specifically for model-training use, deletion rights, and the un-training problem above.
And one from me, which costs nothing and is not in any law firm's checklist because it isn't a legal control: say it out loud. "I've got a notetaker running, shout if you'd rather I didn't." One sentence, at the top of the call. It doesn't make anything lawful that wasn't, it doesn't replace the consent your jurisdiction actually requires, and it solves the entire social version of this problem, which is the version you're far more likely to actually experience.
The legal version, if you want it properly: is it legal to record client calls, two-party consent, and GDPR and meeting recordings if you're in the EEA. Norwegian readers, there's a separate post because Norwegian criminal law draws the line in a genuinely different place.
Where Humla sits, since I brought it up
I'm not going to tell you Humla is legally safer, because I don't know that and neither does anyone else. Nobody has tested us in court, which is a fact about our size and not about our virtue.
What I can say is structural. The specific thing Judge Lee's reasoning turned on - a vendor independently collecting, retaining and using your conversations for its own commercial purposes - is a thing we don't do. Recording and transcription can run entirely on your Mac. We receive no audio, no transcripts, and we train nothing on your meetings, because we have no pipeline that could. That's not a policy promise you have to take on faith either, since the whole app is MIT-licensed and readable.
Now the parts that are less flattering, because a post about other people's disclosures should probably contain some of my own:
- If you use a cloud transcription provider, a third party gets your audio. Point Humla at OpenAI, Deepgram or Groq and you've handed the recording to a company with its own retention terms. I've read all three end to end (OpenAI, Deepgram, Groq) and they differ a lot. Bring-your-own-key moves the decision to you; it doesn't delete it.
- If you turn on Cloud sync, we hold your notes. That's a service holding your data, same category as everyone above, and the honest answer for anyone who cares at this level is to self-host the sync server or not sync at all.
- We do send two anonymous counters now, during first-time setup, disclosed on screen before anything is sent, off for every install that predates the feature. They count whether setup completed. They contain nothing from any meeting - but "we send literally nothing" would be a lie, and I'd rather write this sentence than have you find it in the source.
- None of this solves the Account Holder problem either. Humla gives you the controls, same as everyone else. The person across the table still didn't get a vote. The difference is only that with nothing leaving the machine there's less for them to have needed a vote about.
The thing I keep coming back to
Two years of marketing in this category, mine very much included, has been an argument about the bot. Bot bad, no bot good, look how considerate our capture architecture is.
A judge in San Jose read the same products and cared about something else entirely: not who was in the room, but who got to keep what was said there. And the plaintiffs' bar has now filed against the polite bot-free one too, which suggests the market's favourite distinction was never the one that mattered.
The Fourth Attendee doesn't need to join your call. It never did. It just needs somebody in the room to have clicked accept on its behalf - and that person, conveniently, is the only one it ever asks.
Case names, dockets and dates come from published law-firm client alerts dated 24 November 2025, 30 July 2026 and 13 August 2026, linked above; I did not read the underlying complaints or orders, and CourtListener 403s. Vendor quotes are from Otter's and Granola's own live policy pages, effective 16 June 2026 and 24 July 2026 respectively, checked 25 August 2026. The § 637.2 damages figure is quoted from the California legislature's own text. All allegations described here are unproven and denied. I am not a lawyer, this is not legal advice, and if this affects you commercially you want a real one.