Same meeting. Different data rules.
Otter, Fireflies and Fathom: compare their published rules for AI training and retained meeting records before you invite an assistant.
Three tools. Different boundaries.
Published commitments and controls—not verified implementation. Read each source for its scope.
On smaller screens, scroll the table sideways to compare all three questions.
| Service | Provider’s own model training | Third-party AI processing | Stored records and plan controls |
|---|---|---|---|
| Otter | The general privacy policy describes training on de-identified audio and transcriptions that may contain personal information. Enterprise has a separate default exclusion; see below. Read Otter source 1 | Otter says its AI service providers do not train on customer data or store data sent through their API. That statement is distinct from Otter’s own training. Read Otter source 2 | Enterprise custom retention can target the full conversation, audio/video, or transcript. Deleting only the media or transcript can leave other outputs accessible. Read Otter source 4 |
| Fireflies | Its current policy says meeting content is not used to train internal or external AI models. The policy separately excludes business-customer User Content from its scope; applicable agreements still matter. Read Fireflies source 5 | Its zero-retention commitment concerns vendor processing. Meeting data sent to an external AI tool through MCP follows that tool’s policies instead. Read Fireflies source 7 | The dedicated auto-delete guide labels this an Enterprise feature and says the setting applies to future meetings, not existing ones. Verify entitlement and historical records separately. Read Fireflies source 8 |
| Fathom | Its policy permits in-house training using de-identified meeting data depending on account settings, with an opt-out. We did not verify your toggle or its default. Read Fathom source 9 | The same policy says third parties are not authorized to train their models on personal information or meeting content. Processing and training are different uses. Read Fathom source 9 | Organization-wide retention is documented as Enterprise-only and requested through support. Do not assume a Free or Premium account includes that control. Read Fathom source 10 |
What is established.
A training exclusion is not a deletion schedule. A vendor’s AI processor is not the same as an external tool you connect. This comparison reads public documentation, not your account settings or a negotiated contract. It covers these three services, not the whole market; no product receives a privacy score or endorsement.
Otter: the Enterprise distinction is material.
Otter’s Enterprise admin guide says workspaces are excluded from model training by default, enforced through the Enterprise agreement and configuration. Opting in requires contacting the account manager. Do not extend that statement to a personal or other-plan account without confirming the terms that apply.
Its retention guide distinguishes deleting a full conversation from deleting only selected record types. Ask which setting is enabled, what survives, and whether preservation requirements affect deletion.
Source 3: Otter: Enterprise Admin Controls Overview ↗Fireflies: zero vendor retention does not mean zero stored meetings.
Fireflies describes recordings, transcripts and summaries that remain accessible through its service. The zero-retention statement addresses vendor processing; it does not mean your meeting never becomes a stored record.
Its auto-delete guide describes an Enterprise control for future meetings. Its newer team-settings overview also lists auto-delete, without assigning that individual control a plan. Confirm availability in your workspace rather than infer it from a general settings page. External AI connections require a separate review.
Source 6: Fireflies: Team Settings ↗Fathom: disconnecting a calendar is not deleting the account.
Fathom’s policy says an unused account and its personal information remain unless the account is actively deleted. It describes an effort to delete recordings and personal information within 30 days of an account-deletion request, without guaranteeing that timeframe and subject to retention required by law.
For team, business and enterprise accounts, the policy directs deletion requests to the customer administrator. Stopping use, removing a calendar connection, deleting one recording and deleting an account are different actions.
Source 9: Fathom: Privacy Policy ↗Where we stand.
Our position: the useful answer names the record, the purpose, the recipient and the lifetime. “We don’t train on your data” answers only part of that. These are published provider claims, not findings from an audit. An unresolved detail is a question to verify, not evidence that a company is doing something wrong.
Ask the next question.
- Which exact plan, workspace agreement and AI feature cover this meeting?
- Can the provider train its own models? Can an AI processor? Which setting or contract supports the answer?
- Which records are saved, and what remains if only the recording or transcript is deleted?
- Who can open a recap, including administrators, link recipients and connected applications?
- Does the retention rule cover existing meetings as well as future ones?
- What can participants choose before recording begins, and who handles an objection?
Check one ordinary meeting before trusting the workflow.
Use an approved, non-sensitive test meeting. With the workspace administrator, identify the recording, transcript and summary; check sharing settings, connected apps and the configured retention scope. Record the plan, evidence, review date and unanswered questions in your approved system.
Ask support to clarify any missing plan entitlement, default setting, backup-deletion timing or treatment of data already used for training. This public-document review does not settle those details. Check preservation requirements before deleting workplace records.
Share the question and a public source in the PrivacyAF community. Keep recordings, names, client information and internal screenshots out of the discussion.
Before we invite the assistant: which account is recording, who gets the outputs, and what is our verified retention rule for each record?
This starts a discussion. It does not establish consent or satisfy every local legal requirement.
Educational commentary. Sources and services can change. This brief does not establish legal compliance, product safety or misconduct. No affiliation or endorsement. Suggest a correction.