Five notetakers, one sortable column: who keeps a copy of the call.
By Fazit
Search “Fathom vs Fireflies vs Otter vs tl;dv vs Granola” and you get feature grids: transcription accuracy, integrations, free-tier minutes, pricing. In 2026 those columns have converged so hard they no longer sort anything. Every tool on the shortlist writes a clean summary, pulls action items, and drafts a follow-up. So sort on the one column a security reviewer actually reads: after the call ends, who is holding a copy of your conversation? Add that column and the list reorders, because four of these five keep a durable artifact on infrastructure you do not control.
The features are a tie, so stop sorting on them
Fathom, Fireflies, Otter, tl;dv, and Granola all produce good notes. Model quality is a commodity input now, and the note-quality gap between the leaders is small and shrinking. A comparison that ranks these tools on summary quality is ranking noise. The honest version of this comparison concedes the tie on output and moves to the pipeline that produced it.
Every notetaker is a data pipeline with one liability attached: the durable artifact of your conversation that outlives the meeting. That artifact is what gets subpoenaed, breached, trained on, or inherited in an acquisition. So the question that sorts the list is not “how good is the note.” It is “what copy of the raw conversation still exists tomorrow, and who controls it.”
AUDIO LEAVES DEVICE? TRANSCRIBED AT COPY THAT SURVIVES THE CALL Fathom yes, upload vendor cloud recording kept in cloud Fireflies yes, bot vendor cloud recording + voiceprint Otter yes, upload vendor cloud recording + trained model tl;dv yes, bot vendor cloud video recording Granola yes, stream 3rd-party APIs note; raw audio deleted after Fazit no on device note; audio never written
Five rows create a copy on someone else's infrastructure. One does not. Everything below is why each row reads the way it does, and the single angle where Fazit wins each matchup outright.
Fathom
Strength vs Fazit. A genuinely generous free tier, a polished experience across Zoom, Meet, and Teams, and the enterprise checkboxes buyers ask for: SOC 2 Type II, HIPAA, SSO. It is cross-platform where Fazit is Apple Silicon only. If cost and device coverage are the binding constraints, Fathom is the honest pick and Fazit is not for you.
Fatal weakness. The recording lands in Fathom's cloud, stored in AWS data centres in the US and Canada, and de-identified meeting data is used by default to improve Fathom's own in-house models unless you go into settings and opt out. Default-on training against a retained corpus is the weakness: the artifact exists, and the burden is on you to find the toggle that limits what happens to it.
Where Fazit wins decisively. There is no server-side recording to inherit. Nothing was stored, so nothing changes hands when the cap table does. The acquisition risk is not mitigated, it is absent.
Fireflies
Strength vs Fazit. The deepest integration ecosystem on the shortlist: CRM field sync, Slack, unlimited-transcription tiers, conversation analytics. For a revenue team that wants pipeline automation rather than just notes, Fireflies is stickier than anything Fazit offers.
Fatal weakness. Fireflies faces biometric-privacy litigation in Illinois, including Cruz v. Fireflies.AI Corp. filed December 2025, alleging voiceprint collection without consent. Its recording bot is now flagged by Google Meet as a third-party security risk that can be blocked from joining the call. A centralized store of voiceprints is precisely the asset BIPA-style statutes were written to govern.
Where Fazit wins decisively. No voiceprint is extracted, no bot needs to be admitted or gets flagged, and there is no central store of meeting data to breach, because there is no central store at all.
Otter
Strength vs Fazit. Fast real-time transcription, a searchable company-wide archive, a long track record, and aggressive pricing. If meeting notes are meant to be a shared knowledge base for a whole org, Otter has scale on its side that a local, single-user tool does not.
Fatal weakness. Otter is the defendant in a federal class action, Brewer v. Otter.ai, alleging it recorded conversations without all-party consent and trained its speech models on user recordings. A motion to dismiss was argued in May 2026 and is under submission. Otter is simply the litigated version of the risk the entire cloud category carries: a recording, retained, used to train.
Where Fazit wins decisively. You cannot train a model on a recording that was never created. Fazit's audio lives in a RAM ring buffer and is consumed by an on-device model, so there is no recording to subpoena, leak, or feed into a training set.
tl;dv
Strength vs Fazit. Strong recording and playback UX, coaching and conversation analytics, and EU-headquartered positioning that reads well to European buyers who specifically want a video artifact of every call to review later.
Fatal weakness. A video recording is more data than an audio one, not less, and it is still a visible-bot cloud recorder. Free-tier recordings auto-delete after three months, which is a retention limit, not a privacy guarantee, and despite the EU branding tl;dv is described as still working toward full GDPR compliance. Cloud recording under an EU flag is still cloud recording.
Where Fazit wins decisively. For a European regulated professional, a pipeline that transcribes in volatile memory and never writes an audio file to a sound carrier is a materially stronger legal position than a promise of compliant storage. Under German law, §201 StGB, “never created” and “created then deleted” are different legal facts. That argument is laid out in Why “Never Records” Is Not Marketing.
Granola
Strength vs Fazit. Granola is the one tool here that shares Fazit's instinct: no bot in the room, capture the audio your own device already hears, and do not retain it. It is SOC 2 Type II, the notes are excellent, and on privacy it is genuinely better than every bot-based tool above. If Fazit did not exist, Granola would be the right answer on this list.
Fatal weakness. Granola is bot-free, but it is not on-device transcription. To turn audio into text it streams your call to third-party services, Deepgram, AssemblyAI, OpenAI, and Anthropic, and deletes the raw audio after transcription. Your conversation still transits the public internet to those subprocessors. Deletion is a promise about what happens after the audio arrives on someone else's server, not a guarantee that it never arrived.
Where Fazit wins decisively. Fazit's speech model runs on the device. Audio is captured into a fixed-size RAM ring buffer, a local model consumes a snapshot, and the note is written to your Obsidian vault as Markdown. The audio never leaves the machine, so there is no subprocessor to list, no transfer mechanism to disclose, and no “deleted after transcription” step to trust, because there is no transcription server to delete it from.
The reorder, stated plainly
On features, this is a five-way tie and you should pick on price and platform. On the column that survives a security review, the list collapses into three tiers. Fathom, Fireflies, Otter, and tl;dv keep a recording, so the copy of your conversation exists on their infrastructure and inherits every risk that infrastructure carries: subpoena, breach, training, acquisition. Granola sits one tier better, holding no long-term recording but still routing your raw audio through four external services before deleting it. Fazit sits one tier beneath all of them, because the audio was never eligible to be sent. There is nothing to delete and no one else holding a copy.
Every note Fazit writes carries audio_retained: false in its frontmatter, not as a compliance checkbox but as a description of the execution path. That is the whole comparison. The summary is a tie. The copy is the decision.