All posts

Five AI notetakers, ranked by where your recordings actually land

Every AI notetaker claims GDPR compliance. Far fewer will tell you which continent your customer calls are stored on. Here's what the vendors publicly claim, and the questions that test it.

Granola logoFathom logotl;dv logoJamie logoCircleback logo

Five tools

Tool Review

Every AI notetaker on the market says it’s GDPR compliant. The claim is nearly free to make, and on its own it tells you almost nothing, because GDPR compliance is a posture you can hold while storing every one of your sales calls on a server in Virginia under Standard Contractual Clauses.

For a DACH company recording customer conversations, one question decides most of the shortlist: where does the audio physically land, and who is allowed to learn from it? This is a comparison built around that question.

How this comparison was made, and its limits

Read this part before the table, because it changes how much weight to put on it.

Everything below comes from vendors’ own public documentation and marketing pages, checked in July 2026. We have not audited anyone’s infrastructure, and neither has any blog post you’ll find ranking these tools.

That matters more than usual here, because this category is unusually polluted. Search for “GDPR AI notetaker” and most of the top results are comparison posts published by the notetaker vendors themselves, each concluding that the correct answer is the vendor who wrote it. We used those sources, because they’re often the only public statement available, and we’ve marked which claims come from a competitor rather than the vendor.

So treat this as a shortlist and a set of questions, not a verdict. The four questions at the bottom are the part you actually take into procurement.

The distinction that matters more than the brand

Before the individual tools: notetakers split into two architectures, and the split has consequences.

Bot-based tools join your call as a visible participant. Everyone sees “Fathom Notetaker has joined”. The audio goes to the vendor’s servers to be recorded and transcribed.

Device-based tools capture audio locally on your machine, with nothing joining the call. Your customer sees a normal meeting.

Device-based sounds automatically better for privacy, and partly it is: less obtrusive, no third party sitting visibly in a client conversation. But local capture does not mean local processing. In most cases the audio or the transcript still travels to a cloud model to be summarised, so the residency question survives intact. Do not let “no bot joins your call” be read as “nothing leaves your laptop”, because those are different claims and vendors are sometimes relaxed about which one they’re making.

There’s also a consent dimension that DACH teams care about disproportionately, and it is not a GDPR question. It is a criminal one.

Up to three years imprisonment, or a fine, for recording the non-publicly spoken word without authorisation.

§ 201 StGB, Verletzung der Vertraulichkeit des Wortes. It applies to the individual who did the recording, not to the company, and no data processing agreement cures it.

This is why “the bot is annoying, let’s use the silent one” is a worse trade in Germany than it looks. A visible bot is, awkwardly, a consent prompt: everyone on the call can see that recording is happening, and consent can be inferred from continuing. Silent local capture removes that signal and puts the entire burden of disclosure on whoever set it up, while raising the stakes of getting it wrong from a fine to a criminal provision.

None of which makes device-based tools unusable. It makes the announcement mandatory rather than polite: say at the start of the call that you are recording, wait for the answer, and note it. Teams that build that into the meeting opener stop having the problem. Teams that rely on a line in the calendar invite have not solved it.

Beyond the individual, there is the works council. In Germany, recording and evaluating employee conversations is generally co-determined under § 87 BetrVG, so a tool rolled out across a sales team is a topic for the Betriebsrat before it is a topic for procurement.

The five

Granola

Device-level capture, no participant joins the call. Granola states SOC 2 Type 2 certification as of July 2025, GDPR compliance, that audio is deleted immediately after transcription, and that its third-party AI providers are contractually prohibited from training on customer data. Pricing runs from a free tier through roughly $14 per user per month for Business, with Enterprise above $35.

The gap: EU data residency. Granola’s own comparison content does not claim it, and material circulating in mid-2026 indicates it isn’t offered. For a lot of DACH buyers that ends the conversation regardless of how good the product is, and Granola is a genuinely good product.

Pick it if residency is not a hard requirement and you want the least intrusive capture experience available.

Fathom

Joins as a visible participant and records, transcribes and summarises. SOC 2 Type 2, GDPR compliance, and contractual prohibitions on sub-processors training on customer data. Pricing sits around $15 to $29 per user per month depending on tier.

Fathom is refreshingly direct about the thing others bury: all data is stored in the United States. No EU residency option. Stating that plainly is worth some credit, and it’s also a clean disqualifier if your answer to “where is this stored” has to be “in the EU”.

Pick it if you’re a US-facing team, or an EU team that has genuinely worked through SCCs and a transfer impact assessment with your DPO rather than assuming they’re a formality.

tl;dv

tl;dv states that it hosts data on EU servers and claims GDPR, SOC 2 and EU AI Act compliance, with AI processing that can be run in either the EU or the US. It’s positioned heavily at sales teams, with CRM write-back as the main draw.

The EU-or-US processing toggle is the detail to pin down in writing, because a tool where residency is a configurable option is a tool where residency can be configured wrong. Ask which setting is the default, whether an admin can change it per user, and whether you get told when it changes.

Pick it if you want EU hosting from a mature sales-focused product and you’re willing to verify the processing region as a contract term rather than a settings toggle.

Jamie

Explicitly built as an EU-hosted notetaker. Transcripts and generated notes stored on European servers, with EU residency stated as available across every plan rather than gated behind an enterprise tier. Device-based capture, no bot.

Note the sourcing: much of the public detail comes from Jamie’s own comparison content, which also happens to rank Jamie first. The residency claim is central to their positioning, which is a reason both to take it seriously and to get it in the DPA.

Pick it if EU residency is your binding constraint and you’d rather buy from a vendor whose whole product is built around it than bolt it onto a US tool.

Circleback

Well-liked for the quality of its summaries and its action-item extraction, which is the thing most notetakers are mediocre at.

On residency: the claim in circulation is that Circleback hosts in the US with no EU or German option. We found that stated on a competitor’s blog, which is exactly the kind of source that deserves a caveat, so verify it directly before you either buy or reject on that basis.

Pick it if output quality is your priority and residency isn’t binding. Verify first either way.

Side by side

ToolCaptureEU residencyTraining on your dataRough price
GranolaDevice, no botNot claimedProviders contractually barredFree / ~$14 / $35+
FathomVisible botNo, US storage statedSub-processors contractually barred~$15–29
tl;dvBotYes, EU servers claimedVerify in DPAVaries by tier
JamieDevice, no botYes, claimed on all plansVerify in DPAVaries by tier
CirclebackDeviceReported US-only, unverifiedVerify in DPAVaries by tier

Otter and Fireflies both hold SOC 2 Type 2 and both use a joining bot. Otter mentions data residency options, which is worth chasing if you’re already committed to it. Neither is built around the EU question, and for this particular decision that shows.

What we’d actually tell a DACH client

If EU residency is a hard requirement, and for most Mittelstand companies recording customer calls it is, the shortlist is Jamie or tl;dv. Jamie if residency is the point and you want it to be the vendor’s whole identity. tl;dv if you also need CRM write-back and sales-team features, with the processing region nailed down in the contract.

If residency is genuinely not binding, Granola is the nicest product in the group to actually use, and the absence of a bot in client calls is a real advantage rather than a marketing line.

What we would not do is pick on summary quality and handle residency later. Summary quality across all five is good enough and converging fast. Residency is architectural, it doesn’t change because you asked nicely, and discovering it in month four means migrating a year of recorded customer conversations.

One more thing that’s easy to miss: the notetaker is rarely the last stop. The transcript usually flows onward into a CRM, a summariser, a follow-up drafter. Every hop is another processor and another line in your records of processing activities. Picking an EU-hosted notetaker and then piping every transcript into a US chat product with a personal account undoes the whole exercise, and it is the single most common version of this mistake we see.

The four questions to take into procurement

Ask these in writing, and keep the answers.

  1. In which country is meeting audio stored, and in which country is it processed by your AI models? Two questions in one sentence, because the answers are often different and vendors answer whichever is more flattering.
  2. Will you sign an Article 28 DPA, and does it name every sub-processor including model providers? A DPA with an unnamed “AI partner” in it is not a DPA you can defend.
  3. Is our content excluded from model training, including your sub-processors’, and is that in the contract rather than the marketing page? Marketing pages get edited without notice. Contracts don’t.
  4. What’s your deletion process and how long does it actually take? “Deleted immediately” and “removed from backups within 90 days” are both true statements about the same system.

If a vendor can’t answer these in writing within a week, that’s your answer.

Getting the tool right is the easy half. If you want the transcripts to actually do something afterwards, feeding your CRM, triggering follow-ups, updating deal records without anyone copying and pasting, book a strategy call.

Frequently asked questions about AI notetakers and GDPR

Does GDPR compliance mean my data stays in the EU?

No. GDPR permits transfers outside the EU under mechanisms like Standard Contractual Clauses paired with a transfer impact assessment. A vendor storing data in the US can be GDPR compliant. If you want EU-only storage, that’s a separate requirement called data residency and you have to ask for it by name.

Do I need consent from everyone on the call?

In practice you disclose recording and give people a way to object, and in Germany you should assume a works council will want a say if employees are recorded systematically. The exact basis depends on your setup and your jurisdiction, so this is one to run past your data protection officer rather than a blog post. What matters technically is that your tool makes disclosure easy rather than silent.

Is a device-based notetaker safer than a bot?

Safer for meeting hygiene, not automatically safer for data protection. Local capture usually still means cloud processing. Ask where the transcription and summarisation run, not just where the recording starts.

What about Microsoft Teams and Zoom’s built-in AI notes?

They inherit your existing tenant’s residency configuration, which for many EU companies is already sorted, and that’s a genuine advantage worth weighing. The trade is feature depth and cross-platform coverage. If everything you do is in one platform, start there before buying a fifth tool.

How do I check whether a vendor trains on my data?

Read the DPA and the sub-processor list rather than the privacy page. The pattern to look for is a contractual prohibition that extends to sub-processors, since the model provider behind the product is usually a different company from the one selling you the notetaker.


Sources: § 201 StGB, Verletzung der Vertraulichkeit des Wortes, § 87 BetrVG, Mitbestimmungsrechte, AI Act Article 50 transparency obligations.

Related reading