Founder notes

Why I Stopped Trusting AI Meeting Notes in the Cloud

Weeve author portrait

Stefan Weiss

I used to run every meeting through a cloud notetaker. Fundraising calls, legal reviews, partnership talks: as a consultant and then a founder, my week was a stack of conversations I could not afford to forget. The tools helped. That is what made the problem hard to see.

The moment it changed was not dramatic. I was preparing for a fundraising call, the kind where every sentence is confidential, and I realized I did not actually know where the recording of my last one had gone. Which server. Which country. Which subprocessor. I had signed up for convenience and inherited a supply chain.

The tools worked. That was never the problem.

Let me be fair, because the tools deserve it. Granola writes clean notes without sending a bot into the call. Jamie does botless capture across platforms and treats privacy more seriously than most. tl;dv fits async teams well, and its security commitments are published and specific. I tested them properly and got real value from all three.

If your meetings are internal and your data can live in a vendor's cloud, tools like these are good answers. Nothing in this piece says otherwise.

Then I read the privacy policies

I spent an evening actually reading what I had agreed to. Not the marketing pages, the policies.

They were better than I feared and worse than I needed. Granola states that it trains on anonymized customer data to improve its product, unless you find the setting and opt out. Jamie states that it does not train on customer data at all, and deletes audio after transcription. tl;dv states plainly that customer recordings and transcripts are never used to train AI. Three tools, three different answers to a question most users never ask.

And here is the thing: these are the good ones. The careful ones, with real policies worth reading. Even at their best, the structure is the same. The meeting leaves the room, gets processed on infrastructure you do not control, and your protection is a policy rather than an architecture.

That distinction became the whole decision for me. A policy is a promise: it can be updated, acquired, subpoenaed, or quietly revised in a changelog nobody reads. An architecture is a fact. If the audio never leaves the device, there is no retention schedule to check, no training question to opt out of, and no subprocessor list to audit, because there is no copy to govern. You do not have to trust anyone with data they never receive.

There was a smaller moment that stuck with me too. A notetaker bot joined one of my calls before the other person did, and sat there, named and visible, waiting. My counterpart joined, saw it, and paused. The meeting changed shape before it began. People talk differently when something is listening, and they are right to.

What people kept telling me

Once I started asking, the same conversation repeated itself. Companies wanted meeting intelligence. Their compliance teams, their clients, or their own judgement blocked the cloud version of it. A lawyer cannot casually route privileged calls through a third party. A therapist cannot explain a subprocessor list to a client. An IT lead does not want one more vendor holding recordings of the company's internal thinking.

The pattern was always the same tension: the value was obvious, and the data path was the blocker. Nobody wanted less AI. They wanted the same intelligence without the trip.

The counterargument I take seriously

Cloud notetakers are not a mistake, and pretending otherwise would be dishonest. Shared team workspaces, mobile apps, live captions, CRM integrations: these genuinely require a cloud, and teams that live in them get real value. Vendor security is real too. SOC 2 audits, encryption, EU residency options: serious companies do serious work here.

And the local answer has costs. Weeve runs on the Mac only. The summary arrives after the call, not during it. There is no shared cloud workspace, because a shared cloud workspace is exactly the thing we chose not to build. If your work needs Windows, mobile capture, or live team co-editing, a cloud tool serves you better today, and you should use one.

The question is not whether cloud notetakers are good. It is whether a confidential conversation should ever become someone else's data. For my meetings, the answer stopped being yes.

So we built the one that stays on the Mac

Weeve is the tool I wanted on that fundraising call. Local speech recognition, speaker diarisation, and local summary generation, all running on the Mac itself. No bot joins the call, because Weeve captures the Mac's own audio. Nothing uploads, because there is nothing to upload to. The recording, the transcript, and the summary live on the machine the meeting happened on, and that privacy is the default, not a setting.

Ask before you record; that duty never goes away. What changes is the answer when someone asks where the recording goes. With a cloud tool, the honest answer is a diagram. With Weeve, it is a sentence: it stays on this Mac.

I still admire what the cloud tools do. I just stopped believing that a confidential conversation should have to travel to be remembered.

A meeting you can trust your tools with is a meeting where people can actually talk. Download Weeve and keep the conversation in the room it happened in. If you are not on a Mac, the browser transcriber keeps a recording inside the tab.