Is Otter.ai safe? The lawsuit against it turns on one question: who consented?
By Fazit
“Is Otter.ai safe” has two different answers depending on who is asking. For the account holder, Otter is a mature product with normal enterprise security controls. For everyone else on the call, safety depends on facts most participants never see: where the recording goes, how long it lives, and what it trains. A consolidated federal class action now argues that second group never agreed to any of it.
Last updated August 1, 2026. Case status checked against public reporting on that date.
What the lawsuit actually alleges
The consolidated case, In re Otter.AI Privacy Litigation, alleges that Otter’s meeting bot recorded private conversations without the consent of every participant, in violation of federal and California wiretap law. Four putative class actions were filed against Otter between August and September 2025, starting with Brewer v. Otter.ai in the Northern District of California, and were consolidated in late 2025 before Judge Eumi K. Lee as No. 5:25-cv-06911.
The core allegations, and they are allegations, not findings:
- OtterPilot, the bot that joins Zoom, Teams, and Meet calls, recorded meetings that included people who never signed up for Otter and never consented to being recorded.
- California Penal Code section 632 makes it unlawful to record a confidential communication without the consent of every party. California is an all-party consent state, and the complaint leans on that plus the federal Wiretap Act.
- Otter allegedly used meeting recordings to train its speech-recognition and AI models. Otter’s own privacy policy states that it trains on de-identified audio; the complaint argues the consent behind that training was never obtained from non-users, and questions how robust the de-identification is.
The theory is worth pausing on, because it is not about a bug or a breach. The complaint attacks the default operating model of a cloud notetaker: the vendor, not the participants, ends up holding the conversation, and only one participant clicked “agree.” Our earlier post on the AI notetaker legal risk walked through why that structure creates exposure for the user, not just the vendor. This case is that argument, filed.
Primary sources: the docket at CourtListener, a plain-language explainer at Recording Law, and coverage of the industry stakes at UC Today.
Where the case stands in 2026
As of August 2026 the case sits at the motion-to-dismiss stage, and no court has found Otter’s practices lawful or unlawful. Otter moved to dismiss, arguing that no unlawful interception occurred and that the plaintiffs had not plausibly pleaded the elements of their wiretap and privacy claims. The motion was argued before Judge Lee on May 20, 2026, a further in-person hearing was set for July, and no ruling has issued as of this writing.
IN RE OTTER.AI PRIVACY LITIGATION, SO FAR
Aug 2025 Brewer v. Otter.ai filed, N.D. Cal.
Sep 2025 three more putative class actions follow
Late 2025 consolidated before Judge Eumi K. Lee
(No. 5:25-cv-06911)
May 2026 motion to dismiss argued
Jul 2026 further in-person hearing
Today no ruling. Nothing decided, either way.Three outcomes are possible from here, and each one matters beyond Otter:
- Dismissal would signal that notifying participants is enough to defeat wiretap claims. Every cloud notetaker would relax.
- Survival past the motion would open discovery into how OtterPilot handles consent and what actually happens to audio inside Otter’s training pipeline. Expect settlements across the category if that happens.
- A settlement before ruling would resolve nothing legally and leave the consent question hanging over the whole bot-based category.
What Otter actually does with your audio
Otter is a cloud recorder: audio is captured, uploaded to Otter’s servers, stored as a recording plus transcript, and retained until the account holder deletes it. That is not an accusation, it is the product working as designed. The pieces that matter for the safety question:
- Recording and transcript live in Otter’s cloud, tied to the account holder. Other participants have no account, no dashboard, and no delete button. We wrote about how one-sided that is in the delete problem.
- Training happens on de-identified audio. Otter discloses this in its privacy policy. De-identification of voice data is doing a lot of work in that sentence: your voice is arguably identifying on its own, which is exactly the thread the Fireflies plaintiffs pull on under Illinois law.
- Auto-join and auto-share are the sharp edges. OtterPilot follows the account holder’s calendar into meetings, and post-meeting summaries can be emailed to participants automatically.
Two public incidents show the failure mode better than any policy analysis. In 2022, a journalist reported that Otter sent a survey asking about the purpose of a specific interview he had recorded with a Uyghur activist, a jarring reminder that a human-readable record of a sensitive conversation existed on a vendor’s server. In late 2024, an engineer named Alex Bilzerian left a Zoom call with venture investors; OtterPilot stayed, kept transcribing, and then emailed everyone the transcript, including the investors’ candid post-meeting discussion of their deal. The deal died.
Neither incident is a hack. Both are the designed behavior of persistent cloud capture meeting ordinary human sloppiness. That is the risk category to evaluate, and it applies to every vendor whose answer to “where does the audio go” is “our servers.”
Safe for whom? The question the reviews skip
For the account holder, Otter is reasonably safe in the way any established SaaS product is: SOC 2, encryption in transit and at rest, enterprise controls. The safety gap is on the other side of the table.
"IS OTTER SAFE?" DEPENDS ON WHICH SEAT YOU'RE IN
account holder everyone else on the call
consented? yes, clicked it allegedly never asked
holds the record? dashboard access no account, no access
can delete it? yes no delete button existsThe people actually carrying risk:
- The participants who never consented. In all-party consent states (California, Illinois, Florida, and roughly a dozen others), recording them without agreement is the user’s legal problem, not Otter’s marketing problem. Our guide to recording client calls legally covers where the lines are.
- The user’s own clients. If your client work is confidential, a transcript on a third-party server is a record you cannot fully control, subject to subpoena, breach, and retention policies you did not write.
- The user, eventually. The Otter plaintiffs are meeting participants suing over the tool a counterparty used. If the case survives dismissal, “my notetaker did it” is not looking like a strong defense.
So the honest answer to “is Otter.ai safe” is: define safe. Against outside attackers, about as safe as any established cloud vendor. Against the structural risks, retention, training, discoverability, consent, it is exactly as exposed as its architecture requires it to be.
If you keep using Otter, tighten these settings
You can meaningfully reduce Otter’s blast radius in about ten minutes, and if you use it, you should. The high-leverage moves:
- Turn off auto-join. Settings, then the calendar and auto-join options. The bot following your calendar into every meeting is how transcripts of meetings you barely remember end up existing.
- Turn off auto-share. The Bilzerian transcript reached the room because sharing was automatic. Make sharing a decision, not a default.
- Ask for consent, every time, on the record. One sentence at the top of the call. In all-party states this is not etiquette, it is the legal requirement.
- Set a retention policy and actually delete. Old transcripts are pure liability. Business plans allow retention rules; free accounts require manual hygiene.
- Check the training toggle. Review whether your workspace allows Otter to use your recordings for model improvement, and turn it off if your plan exposes the control.
All of that helps. None of it changes the architecture: the call still leaves the room, and the record still lives on servers you do not control.
The alternative the lawsuit cannot touch
There is a version of this product category that has no recording to litigate over, because the audio is never stored at all. That is the design decision Fazit is built on:
- Audio is processed in a fixed-size ring buffer in RAM on your Mac, continuously overwritten during the call, never written to disk, never uploaded. The architecture is documented in Why “Never Records” Is Not Marketing.
- Transcription and summarization run on-device on Apple Silicon. There is no vendor cloud, so there is nothing to subpoena, breach, retain, or train on. No audio ever reaches us, and the note is stamped
audio_retained: false. - What survives the call is one Markdown note in your Obsidian vault. Your file, on your disk, in your control.
- Nothing joins the meeting. No bot in the participant list, no lingering transcriber after you leave the call.
To be precise about the claim: consent norms still apply to note-taking, and being open about capture is still right. But the specific thing the Otter plaintiffs are suing over, a stored recording of their voices on a vendor’s server, put to uses they never agreed to, structurally cannot exist here. You cannot leak, subpoena, or train on audio that was overwritten in RAM before the call ended.
If you are comparing tools on this axis, we scored the major notetakers by what happens to your audio in the 2026 buyer’s guide and the Granola alternatives roundup, and the full Fazit security posture is at getfazit.com/security.
FAQ
Is Otter.ai safe to use in 2026?
For the account holder, Otter has standard enterprise security and no known major breach. The open risk is legal and structural: a pending consolidated class action alleges its bot recorded meeting participants without all-party consent, and its architecture stores recordings and transcripts in the cloud, where they are subject to retention, subpoena, and training-use questions. No court has ruled on the allegations yet.
What is the Otter.ai lawsuit about?
In re Otter.AI Privacy Litigation, consolidated in the Northern District of California in late 2025, alleges that OtterPilot recorded private meetings without the consent of every participant, violating the federal Wiretap Act and California’s wiretap statutes, and that Otter used recordings to train its AI models without adequate consent. Otter denies the claims and has moved to dismiss; the motion was argued in May 2026 and remains undecided as of this writing.
Does Otter.ai train its AI on my conversations?
Otter’s privacy policy states that it trains its models on de-identified audio recordings. The pending litigation disputes whether participants consented to that use and how effective the de-identification is. If your workspace exposes a training opt-out, use it.
Can other people delete an Otter transcript of a meeting they were in?
No. The recording and transcript belong to the account holder. Non-users on the call have no account, no access, and no deletion mechanism, which is one of the structural complaints in the litigation and the subject of our post on deleting AI notetaker data.
Is there an AI notetaker that does not record at all?
Yes. On-device notetakers like Fazit process audio in memory on your own machine, transcribe locally, and keep no audio at all: nothing is written to disk and nothing is uploaded. The output is a text note in your own files, so there is no stored recording to consent-litigate, breach, or subpoena in the first place.