VendorScore · AI meeting notetaker · Data-access posture

Can Otter.ai read your meeting transcripts?

A plain-language answer from Otter's Privacy & Security page, Terms of Service (DPA in Appendix 1), subprocessor list and Help Center. Otter holds the encryption keys.

Get the full 5-dimension PDF — join the waitlist

Evidence dated 2026-10-07, public docs only, not legal advice.

Short answer

Yes, by design (with controls): Otter's cloud processes your audio and transcripts in plaintext with Otter-managed keys; staff need your explicit consent to open specific conversations.

48 / 100 overall

Scored configuration: Otter Enterprise workspace: AI model training off by default, admin-locked Notetaker auto-join, pre-meeting recording notifications, 'Remove audio recordings', custom retention, SSO/SCIM.

Default (non-Enterprise) setup scores lower: de-identified AI training is on, and admin auto-join and audio controls are absent.

Report confidence: Medium.

Higher = more customer control / less inherent vendor read access for the scored configuration. A strong SOC 2 doesn't mean the vendor can't read your data.

Last reviewed: · Evidence date: (score, key findings and FAQ) · Sources

Key findings

Where public evidence is thin

Our report flags these gaps in Otter.ai's public documentation:

  • otter.ai/security and otter.ai/dpa now render a sign-in page; the DPA was verified as Appendix 1 of the Terms of Service.
  • Otter publishes no customer-managed keys, key-hierarchy detail or TLS version.
  • Consent is the user's responsibility under Otter's Terms; auto-join is per-user unless admins lock it, and audio is retained unless 'Remove audio recordings' is on.

In the full PDF

Get the full 5-dimension PDF — join the waitlist

PDFs aren't for sale yet. Join the waitlist and we'll email yours when it's ready. No calls.

FAQ: Otter.ai data access, AI training, GDPR and residency

Can Otter.ai read your meeting transcripts?

Yes, by design (with controls): Otter's cloud processes your audio and transcripts in plaintext with Otter-managed keys; staff need your explicit consent to open specific conversations. VendorScore rates Otter.ai 48/100 overall from public documentation (evidence dated 2026-10-07). Scored configuration: Otter Enterprise workspace: AI model training off by default, admin-locked Notetaker auto-join, pre-meeting recording notifications, 'Remove audio recordings', custom retention, SSO/SCIM.

Is Otter.ai encrypted? Does Otter offer customer-managed keys?

Otter stores data in AWS S3 with server-side encryption (AES-256) and says "It encrypts the key itself with a root key that it regularly rotates." We found no customer-managed key, BYOK or EKM option, and Otter doesn't publish its TLS version. There's no E2EE: audio is processed in Otter's cloud for transcription, summaries and AI chat.

Can Otter.ai employees listen to my recordings?

Only with your consent, per Otter: "Otter requires explicit consent from the customer prior to Otter employees and customer support team accessing your transcript and/or audio recording to troubleshoot a product issue." Its security measures add admin approval and logged production access. An annotation subprocessor (Research Transcriptions) handles training and evaluation data.

Does Otter.ai train AI on my meetings?

Not on Enterprise by default: "By default, Enterprise workspaces are opted out of AI model training." Enterprise workspaces can opt in through their account manager. Outside Enterprise, Otter says it de-identifies user data before training its models, automatically and without human review of recordings, and its Terms allow aggregated or de-identified data to be used for machine learning.

Is Otter.ai GDPR compliant? Where is the Otter DPA?

VendorScore doesn't certify compliance; Otter.ai publishes its DPA as Appendix 1 of its Terms of Service at https://otter.ai/terms-of-service. It incorporates SCC Module 2 and the UK Addendum and gives you 30 days to object to new subprocessors. The Terms make users "solely responsible" for giving notice to, and getting consent from, the people they record.

Who are Otter.ai's subprocessors, and which see my meetings?

Otter's list (effective 2026-03-31) includes AWS (core storage), Google Cloud Platform and Crusoe (cloud), Anthropic and OpenAI (AI; Otter says no Customer Data is used to train or improve their models and neither stores Customer Data sent through the API), Research Transcriptions (annotation), and Zendesk, Intercom and Crescendo (support). The list is published at https://otter.ai/subprocessors.

Can I keep Otter.ai data in the EU?

Public docs don't offer it. We found no EU hosting option, and listed subprocessors, including AWS storage, show the United States as entity country.

Compare Otter.ai

All comparisons

Sources

Every URL cited on this page. Score, key findings and FAQ: VendorScore report (otter-ai.md), evidence dated 2026-10-07.