VendorScore · AI meeting notetaker · Data-access posture

Can Fireflies.ai read your meeting recordings and notes?

A plain-language answer from Fireflies' security page, privacy policy, DPA and Knowledge Base. Fireflies and its AI vendors process your meetings in plaintext.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): Fireflies and its AI vendors process your recordings and transcripts in plaintext under vendor-managed encryption; staff access needs your permission.

42 / 100 overall

Scored configuration: Fireflies Enterprise: Private Storage / bring-your-own-storage (BYOS), Transcript/Summary-Only mode (no audio/video retained), custom retention, Rules Engine, SSO/SCIM.

Default (lower tiers) setup scores lower: vendor-managed keys, with no Private Storage, audio-free mode or custom retention.

Report confidence: Medium-low. Fireflies' subprocessor list (Trust Center) renders only via JavaScript and couldn't be read.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Fireflies.ai's public documentation:

  • Fireflies' subprocessor list (Trust Center) renders only via JavaScript; we couldn't read it on Fireflies' site and don't repeat names from third-party copies.
  • Marketing language overstates: Fireflies calls server-side encryption 'end-to-end encryption', and VendorScore doesn't verify its GDPR marketing claims.
  • Participant-notification behaviour isn't documented in the pages we read; auto-join can be set to 'All meetings with web-conf link', and the Super Admin role can view all meetings, including those marked 'Only Me'.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Fireflies.ai data access, AI training, GDPR and residency

Can Fireflies.ai read your meeting recordings and notes?

Yes, by design (with controls): Fireflies and its AI vendors process your recordings and transcripts in plaintext under vendor-managed encryption; staff access needs your permission. VendorScore rates Fireflies.ai 42/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Fireflies Enterprise: Private Storage / bring-your-own-storage (BYOS), Transcript/Summary-Only mode (no audio/video retained), custom retention, Rules Engine, SSO/SCIM.

Is Fireflies.ai end-to-end encrypted?

No. A Fireflies Knowledge Base page describes "AES 256-bit encryption for data at rest and TLS 1.2+ for data in transit" as end-to-end encryption, but that's server-side and transport encryption, not E2EE: Fireflies and its AI vendors process your recordings and transcripts in plaintext. We found no customer-managed key option. Enterprise Private Storage lets you keep transcripts, audio and summaries in a bucket you own, but Fireflies must read and write it, and processing stays on Fireflies' US servers.

Can Fireflies employees access my meetings?

Only with your permission, per Fireflies: "Internally, our teams do not have access to your meeting content by default. Any access requires your explicit permission, typically granted for support-related purposes only." Public docs don't describe staff-access logging. Inside your own organization, the Enterprise Super Admin role can bypass meeting privacy restrictions, including for meetings marked 'Only Me'.

Does Fireflies.ai train AI on my meetings?

Fireflies says no. Its privacy policy states: "We do not use personal information for AI model training and we contractually prohibit our vendors from using this information for their own model training." Its Knowledge Base says meeting content is never used to train any AI models. The wording isn't fully consistent: the security page says "We don't train on it by default", and the DPA lets Fireflies create de-identified data to improve its products.

Is Fireflies.ai GDPR compliant? Where is the Fireflies DPA?

VendorScore doesn't certify compliance; Fireflies.ai publishes a DPA at https://fireflies.ai/data-processing-agreement. The DPA (last updated 2026-03-06) incorporates SCCs and the UK IDTA, gives a 30-day objection window for new subprocessors, and allows one audit a year at your expense.

Who are Fireflies.ai's subprocessors, and do AI vendors see my meetings?

Fireflies' DPA points to the Trust Center list at https://trust.fireflies.ai/subprocessors as the operative list. That page renders only via JavaScript, so we couldn't read the list content. Fireflies' own docs name OpenAI and Anthropic, plus unnamed transcription providers, as processors of meeting content under zero-retention, no-training agreements.

Can I keep Fireflies.ai data in the EU?

Only storage, and only partly. Enterprise Private Storage (BYOS) lets you choose where data is stored, but Fireflies says "Data is processed on Fireflies' servers in the U.S."

Compare Fireflies.ai

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (fireflies-ai.md), evidence dated 2026-10-07.