Product updates

Why Weeve Is GDPR-Compliant by Default

Weeve author portrait

Stefan Weiss

Why Weeve Is GDPR-Compliant by Default

Yes. Weeve is GDPR-compliant by default, because your meeting content never leaves your Mac. There is no cloud processing step, so there is no sub-processor holding your recordings, no cross-border transfer to justify, and no retention policy to write for content sitting on someone else's server. Weeve is built in Amsterdam by a Dutch company, so the vendor sits inside the EU as well as the data.

We hear the same question in almost every serious sales conversation, usually from someone doing a security review: "okay, but what does local-first actually mean?"

It's a fair question. Every meeting tool on the market now calls itself private. Most of them mean something narrow: your recording is encrypted while it travels to a server, and maybe encrypted while it sits there.

That's real security. It is not the same thing as local-first, and the gap between the two is exactly where GDPR gets complicated for most vendors.

What "local-first" literally means

When you record a meeting in Weeve, here is what happens. The audio is captured on your Mac. The transcript is generated on your Mac, using Apple's on-device MLX framework.

Speaker detection runs on your Mac. The summary is written on your Mac. At no point does the recording, the transcript, or the summary get sent to a server, ours or anyone else's.

No cloud AI provider is ever in the loop. No bot joins your call to capture it in the first place.

That wasn't always the case. Weeve used to offer an optional setting that let you connect your own Anthropic, Google, or OpenAI account and route summarisation through the cloud. It was off by default, and almost nobody turned it on, which told us people were choosing Weeve specifically because they didn't want a cloud model touching their meetings.

We removed the option in April 2026. [1] There is no cloud path for your meeting content today, on or off, and no setting that brings one back. Once the models are downloaded, Weeve works with no internet connection at all.

That's the part worth being precise about, because "local-first" gets used loosely across this category. For us that's simply how the system is built. There's no setting to flip and no policy that could quietly change in a future update. It's the only path the data has.

The question underneath the question

The people asking about local-first are usually asking something more specific, even if they don't phrase it that way. A pattern we hear often, from IT leads and privacy-conscious operators alike: they already trust one system of record, often a coding or AI assistant they've vetted internally. They're wary of adding a second tool into the loop that touches the same sensitive conversations without the same scrutiny.

They want to know if it trains on the audio, where the files actually sit, whether they're anonymized before anyone else's model sees them. And if the content is going to end up back in a tool they already trust anyway, why it needed to pass through a third party's servers first.

That reaction makes sense in a category where "private" has been used to mean a dozen different things, most of which still involve your meeting leaving the building.

The GDPR questions this architecture removes

GDPR compliance for a cloud meeting tool is a real, substantial piece of work, and the vendors doing it properly deserve credit. It usually means data processing agreements with every sub-processor in the chain under Article 28 [2], a documented legal basis for each cross-border transfer under Chapter V [3], a retention and deletion policy someone has to actually enforce, and a clear answer to who could be compelled to hand your data over and under which country's law.

Done well, that's a thick binder of documentation, mapped article by article, often broken out country by country because the details shift depending on where your team sits.

Weeve mostly sidesteps that binder. There's nothing on the other side of it to solve.

If your meeting audio and transcript never leave your laptop, there's no sub-processor to sign a DPA with for that data, because there's no processor. There's no cross-border transfer question, because nothing crossed a border. There's no retention policy to write for content sitting on a server we don't have.

The compliance argument is a consequence of an architecture decision we made before compliance ever entered the conversation. We thought your meetings should not leave your machine to begin with.

What still leaves the device, and why

Running a software business means some data has to leave the device, and it's worth being precise about what that is so the claim doesn't fall apart the moment someone checks.

Your account email and sign-in code, so we know it's you.

Your subscription status, so we know which plan you're on.

A monthly usage counter, so we can enforce plan limits.

Anonymous version checks, so the app knows when to update.

None of that is your meeting content. All of it is the ordinary account and billing data any subscription software needs, handled under the same rules as any other SaaS vendor's account layer, DPA included where one is needed.

That's the boundary of the claim. The part of GDPR that gets genuinely hard is sensitive conversation content moving through third-party infrastructure, and your meetings never enter that infrastructure in the first place.

What this means if you're the one doing the review

If you're evaluating Weeve for your team, the practical upshot is this: for the meeting content itself, there's no subprocessor to list, no cross-border transfer mechanism to review, no "where does the audio actually live" question to chase down with a vendor's support team.

That part of your due diligence gets short, because the architecture leaves less to verify in the first place.

That's the whole case: where the data goes, and where it doesn't.

How to check whether any AI notetaker meets GDPR

  • Where is the audio processed? Ask in writing. "Encrypted in transit and at rest" is a different answer from "never sent". Only the second one removes the transfer question.

  • Who are the sub-processors for meeting content? If there is a list, every name on it needs an Article 28 agreement and a transfer basis under Chapter V.

  • Does the vendor train on your meetings? Ask whether de-identified content is excluded, and whether the opt-out is self-serve or needs an account manager.

  • Where is the vendor established? An EU-established vendor removes the Chapter V question for the account layer as well as the content.

FAQ

Is Weeve a GDPR-compliant AI notetaker for EU companies?

Yes. Meeting audio, transcripts and summaries are produced and kept on your own Mac, so for that content there is no processor, no cross-border transfer and no retention policy on our side. Weeve is also built in Amsterdam by a Dutch company, so the vendor is EU-established, which matters for the account and billing layer that every subscription tool has.

Can I use Weeve to record client calls in Europe?

Yes, and the recording stays on your machine. Consent is a separate obligation and it does not go away because the processing is local. Recording rules differ across the Netherlands, Germany and the rest of the EU, and in many places every participant has to agree. Local processing makes the answer you give them shorter, not optional.

Do I need a data processing agreement with Weeve?

Not for your meeting content, because we never receive it. For the account layer, the email address, subscription status and usage counter described above, a DPA applies in the ordinary way, the same as with any subscription vendor.

Does Weeve train AI models on my meetings?

No, and there is nothing to train on. No copy of your recording, transcript or summary reaches a server, so there is no de-identified extract to opt out of and no sub-processor list to audit.

Does Weeve work without an internet connection?

Once the models have downloaded on first run, yes. Recording, transcription, speaker detection and summarisation all run on your Mac with no connection at all. A connection is needed for sign-in, billing, updates and the usage counter.

Where is Weeve's data stored?

Your meeting content is stored on your Mac and nowhere else. The account data described above is held by our subscription infrastructure under the usual agreements.

The easiest processing to defend at a review is the processing that never happened.

If you would rather test that than take it on trust, Weeve's free Starter plan covers 10 recordings a month on a Mac, with the transcript and summary written on the device. It is Mac only and needs Apple Silicon with macOS 14 or later. On any other machine, the browser transcriber processes a file inside the tab without uploading it.

If you would rather test that than take it on trust, Weeve's free Starter plan covers 10 recordings a month on a Mac, with the transcript and summary written on the device. It is Mac only and needs Apple Silicon with macOS 14 or later. On any other machine, the browser transcriber processes a file inside the tab without uploading it.

Sources

[1] Weeve, "How Weeve stays private by default." https://getweeve.io/blog/how-weeve-stays-private-by-default

[2] Regulation (EU) 2016/679 (GDPR), Article 28, Processor. https://gdpr-info.eu/art-28-gdpr/

[3] Regulation (EU) 2016/679 (GDPR), Chapter V, Transfers of personal data to third countries or international organisations (Articles 44–49). https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504