VendorScore · AI meeting notetaker · Data-access posture

Can Granola read your meeting notes?

A plain-language answer from Granola's security page, Help Center and Data Processing Addendum. Granola doesn't keep audio, but it and its AI providers process transcripts and notes in plaintext.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): Granola and its transcription and AI providers process meeting audio and notes in plaintext; audio isn't stored, transcripts are kept indefinitely by default.

43 / 100 overall

Scored configuration: Granola Enterprise: model training off by default (admin-enforced), transcript auto-deletion set via the account manager, automated chat message or Granola Watermark required by admins.

Default (non-Enterprise) setup scores lower because anonymized training is on until you opt out; the report estimates Overall ~42.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Granola's public documentation:

  • Granola's Trust Center (full subprocessor list, certifications) is JavaScript-only and couldn't be read from the vendor; we don't repeat names or counts from third-party copies.
  • No encryption algorithm, key-management or staff-access detail is published.
  • The DPA's training clauses (§8.B and §8.C) conflict.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Granola data access, AI training, GDPR and residency

Can Granola read your meeting notes?

Yes, by design (with controls): Granola and its transcription and AI providers process meeting audio and notes in plaintext; audio isn't stored, transcripts are kept indefinitely by default. VendorScore rates Granola 43/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Granola Enterprise: model training off by default (admin-enforced), transcript auto-deletion set via the account manager, automated chat message or Granola Watermark required by admins.

Is Granola encrypted? Does Granola store my meeting audio?

Granola says notes are stored in a US-hosted AWS VPC, "encrypted at rest and in transit", but publishes no algorithm, TLS version or key-management detail, offers no customer-managed keys and makes no E2EE claim. It doesn't keep audio: "Once transcription is complete, the audio is deleted from our systems and any third-party services." Transcripts and notes are retained indefinitely unless you or your admin set a retention policy; individuals can auto-delete transcripts after 1 day to 1 year.

Can Granola employees read my meeting notes?

Public docs don't say: Granola publishes no staff-access policy, consent gate or access logging. Workspace admins "cannot view your private notes". Meeting audio goes to Deepgram and Assembly for transcription, and notes go to OpenAI and Anthropic for AI features.

Does Granola train AI on my meetings?

It depends on your plan, and Granola's documents don't agree. Its model-training page says: "By default, Granola may use anonymized data to improve our services… You can opt out of model training at any time." Enterprise users have model training turned off by default, and admins can enforce that; Granola says it can't guarantee anonymised data wasn't used before you changed the setting. The DPA conflicts: §8.B says Granola may use aggregated, de-identified information unless opted out, while §8.C says Granola does not use your Personal Data to train or improve its AI models and refers to users who choose to opt in. We report both and don't resolve them. Granola says OpenAI and Anthropic may not train on your data.

Is Granola GDPR compliant? Where is the Granola DPA?

VendorScore doesn't certify compliance; Granola publishes a DPA at https://docs.granola.ai/help-center/policies/data-processing-addendum. It gives at least 10 days' prior notice before adding or replacing a subprocessor, then 30 days to object, with EU/UK SCCs; custom DPAs aren't available. Its training clauses conflict (see the training question).

Who are Granola's subprocessors? Which AI providers see my meetings?

Granola's full subprocessor list is in its Trust Center at https://trust.granola.ai/, a JavaScript app, so we couldn't read the list content and don't repeat names from third-party copies. Granola's own security page names Deepgram and Assembly (transcription), OpenAI and Anthropic (AI) and AWS (hosting).

Can I keep Granola data in the EU?

No. Granola says: "We do not offer EU, UK, or other regional data residency at this time." All data is on AWS in the US.

Compare Granola

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (granola.md), evidence dated 2026-10-07.