Removing the bot removed the warning too.

By Kyle Nelson, Founder, Fazit

On 30 July 2026 a proposed class action was filed against Granola in the Northern District of California. The core allegation is not that Granola recorded badly. It is that the thing everyone liked about it, that no bot appears in the call, is the same thing that left the other participants with no way to know a recording was happening. We compete with Granola, so read the rest with that in mind. Nothing here has been decided by a court.

The filing

The case is Chamberlain v. Granola, Inc. and Granola Labs Ltd., brought by a Florida resident on behalf of a proposed nationwide class and a California subclass. It was reported by Computerworld, by Robinson & Cole in the National Law Review on 6 August, and by PPC Land, which published the docket details.

CHAMBERLAIN v. GRANOLA, INC. AND GRANOLA LABS LTD.

court      U.S. District Court, Northern District of California
docket     3:26-cv-07926-EMC
filed      30 July 2026
plaintiff  Tarra Chamberlain, Florida; proposed nationwide
           class plus a California subclass

counts     1  intrusion upon seclusion (common law)
           2  Electronic Communications Privacy Act
           3  California Penal Code s 631  (interception)
           4  California Penal Code s 632  (all-party consent)
           5  Computer Data Access and Fraud Act
           6  Unfair Competition Law
           7  unjust enrichment

status     complaint only. Nothing has been decided on any
           count. No public response from either defendant.

We have since read the filing itself rather than the coverage of it. Every line in that box is confirmed against Document 1, the 38-page class action complaint, as posted on CourtListener and checked on 9 August 2026: the caption, the court, the docket number, the 30 July filing date, and all seven claims for relief in the order they are pleaded. Dockets move; if you are relying on this for anything that matters, pull the case yourself.

What the complaint alleges

The complaint opens by calling the product “spyware”, and its second paragraph is the one worth reading twice: it argues that Granola’s design is contrary to most notetakers on the market, where the software is made known at the start of the meeting and participants often have the option to boot or kick it out. That is the plaintiff’s theory in one line. The bot was the notice, and removing it removed the notice.

From there it splits into two claims, and they are worth keeping apart because only one of them is about architecture.

The notice claim. Granola captures microphone and system audio on the account holder’s machine rather than sending a bot into the meeting. The complaint alleges that this leaves every other participant with no indication that a recording is running, and it frames that as an intentional design decision rather than a gap, quoting Granola’s own marketing line that other people in the room will not know it is there. That is the hinge of the whole case: the same sentence reads as a feature in a product page and as intent in a pleading.

The training claim. The complaint alleges that meeting contents were used by default to train models on the Free and Business plans unless the account holder found and disabled the setting. This one we can partly check without waiting for a court, because it describes a documented default rather than a hidden practice: when we read Granola’s own security FAQ on 1 August for our subprocessor write-up, it described anonymised training as on by default for Free and Business with an opt-out in settings, and org-wide enforcement available only on Enterprise. The complaint’s description of the setting and Granola’s description of the setting agree. What is contested is whether a disclosed default is the same as consent, and whether the people whose voices were in the room ever had a setting at all.

What it does not establish

A complaint is one party’s account, filed to survive a motion to dismiss. It proves nothing. Four things are worth stating plainly:

  • No court has ruled on any count. Not on interception, not on consent, not on training.
  • Granola has not answered publicly. We found no public response from either defendant as of 9 August 2026, and Computerworld reported that the company did not respond to a request for comment. A defendant has weeks to answer a complaint, so silence at this stage is procedure, not concession. There is a side of this we have not heard.
  • These theories are slow and genuinely contested. The parallel consolidated class action against Otter has been at the motion-to-dismiss stage for around a year with no merits ruling, which is the realistic timescale here too. We wrote that case up in Is Otter.ai Safe? and the same caution applies.
  • Damages numbers in a complaint are a demand, not an award. The filing asks, under California Penal Code section 637.2(a), for the greater of $5,000 per violation or three times actual damages, plus restitution and disgorgement. Multiplied across a proposed class, that figure is what makes these cases large on paper. It is not money anyone has been ordered to pay.

The part that applies to us too

It would be convenient to write this up as a cloud problem. It is not one, and pretending otherwise would be the same move the complaint is criticising.

Fazit is bot-free. There is no bot in your call, which means there is no automatic marker telling the other person that notes are being taken, which is precisely the absence the complaint is built on. A local model does not fix that. If the legal theory in this case succeeds, it will be about whether the other party knew and agreed, and that question has the same answer for an on-device notetaker as for a cloud one: it depends entirely on whether the person running it said something out loud.

So the honest version of our position is narrower than the marketing version. On-device processing does not make consent go away, and we are not going to tell you it does. What it changes is everything downstream of consent.

WHAT AN ON-DEVICE ARCHITECTURE DOES AND DOES NOT ANSWER

                              cloud notetaker   on-device
was the call intercepted?     contested         contested
did everyone consent?         contested         contested
is there a third party
  in the audio path?          yes               no
is there a recording to
  retain or produce?          yes               none created
can the vendor train
  on the contents?            a setting         nothing to train on

The top two rows are the lawsuit. Architecture does not touch them. The bottom three are the rows where it decides the outcome rather than argues about it: Fazit holds call audio in a RAM ring buffer and never writes it to disk, so there is no recording to retain, subpoena, back up, or feed to anything. That is described in full in the architecture write-up, and it is a claim about what the software does, not a claim about what a court would say.

What to actually do on Monday

Independent of which tool you use, and independent of how this case turns out:

  • Say it out loud. One sentence at the top of the call that you are taking AI-assisted notes, and wait for an audible yes. In a two-party-consent state such as California, that sentence is doing real work. More on the rules in is it legal to record client calls.
  • Go and look at your training setting. Not what you remember choosing, what it says today, and which plan tier controls it.
  • Find out how long transcripts live. Retention defaults are usually indefinite unless someone configured otherwise.
  • Ask where the audio goes before it becomes text. Bot-free is a statement about the meeting UI, not about the data path, which is the whole argument of bot-free is not the same as private.

None of this is legal advice, and we are not lawyers. If your calls are privileged, clinical, or fiduciary, the retention and consent questions are worth twenty minutes with someone who is.

The category spent two years competing on removing the bot. This filing is the first serious argument that removing the bot removed something the other participant was relying on. Whatever happens to these seven counts, that argument is not going away, and the answer to it is a sentence you say at the start of the call rather than a feature anyone can ship.

FAQ

Is Granola being sued?

Yes. A proposed class action, Chamberlain v. Granola, Inc. and Granola Labs Ltd., was filed on 30 July 2026 in the U.S. District Court for the Northern District of California, docket 3:26-cv-07926-EMC. It brings seven counts including the federal Electronic Communications Privacy Act and California Penal Code sections 631 and 632. All seven are confirmed against Document 1, the complaint itself. The allegations are unproven, no court has ruled on any of them, and we found no public response from either defendant as of 9 August 2026.

What does the Granola lawsuit actually allege?

Two things. First, that because Granola captures microphone and system audio without sending a bot into the call, other participants are given no notice that they are being recorded, and that the complaint treats this as a deliberate design choice rather than an oversight, quoting Granola marketing to the effect that other people in the room will not know it is there. Second, that meeting contents were used by default to train AI models on the Free and Business plans unless the account holder turned that setting off.

Does the lawsuit mean Granola is unsafe to use?

No court has found that. A complaint is one side’s account of the facts, and the parallel case against Otter.ai has been at the motion-to-dismiss stage for roughly a year without a ruling on the merits. What the filing does establish is that the consent question around bot-free capture is now being litigated rather than debated, which is a reason to check your own disclosure practice regardless of which tool you use.

Does an on-device notetaker avoid this problem?

Only part of it. The interception and consent counts turn on whether the other person knew and agreed, and running the model locally does not answer that question. Fazit is bot-free too, so it puts no marker in the call either, and the obligation to tell the other person sits with the user in both cases. What changes is the rest: with no audio leaving the machine there is no third party in the chain, no server-side recording to retain or produce, and no contents for a vendor to train on.

What should I do if I use a bot-free notetaker?

Say out loud at the start of the call that you are taking AI-assisted notes, and get an audible yes, particularly with anyone in a two-party-consent state such as California. Check whether your tool’s training setting is on by default and what plan tier controls it. Check how long transcripts are retained and whether that is configurable. None of this is legal advice, and if the calls are privileged or clinical the retention question is worth a conversation with your own counsel.

Related reading: the Granola alternatives field guide, who processes your Granola audio, the Otter class action, and on-device vs. cloud notetakers. If it fits your practice, early access pricing is live. Security teams: source access for independent review is available on request — hello@re-entry.ai