Asset 20 8 2
Does AI recommend your business? Run the free check →

Join 15,000 business owners, marketers and entrepreneurs. The Sunday newsletter you'll be annoyed only arrives once a week.

Article

The AI Notetaker Sitting In On Your Client Calls Might Be Breaking Your NDA

Straight answer: if an AI notetaker like Otter, Fireflies, Fathom or Read AI is joining your client calls, it is recording, transcribing and often storing that conversation on a third-party server, and most small business owners have never checked whether that breaks an NDA, a client contract, or GDPR. This is not a scare story about AI taking over. It is a very boring, very fixable admin problem that almost nobody has fixed.

The bot that joined my call uninvited

Three weeks ago I was on a strategy call with a prospective client, a founder I'd worked with once before through a mutual connection. Two minutes in, I noticed the little icon in the corner of the Zoom window: "Fathom Notetaker is recording this meeting." Nobody had asked me. Nobody had asked the founder's business partner either, who was also on the call and looked just as surprised as I was when I pointed it out.

We paused. The founder had no idea the bot had been auto-added, it turned out it was set up by an assistant who'd enabled it for every calendar invite as a default a month earlier. That transcript, unless someone deleted it, is still sitting on a server somewhere, containing a conversation where I discussed a client's unreleased product launch by name.

I went back and checked my own last fifteen client calls that month. Nine had some kind of AI notetaker present. Four of those nine, nobody on the call had said a word about it out loud.

Why this is different from "we're recording this call for training purposes"

Recorded calls used to sit on one company's server, under one company's data policy, usually deleted after 90 days. That's what most NDAs and data processing clauses were written around a decade ago.

An AI notetaker is a different animal. The transcript often gets:

  • Stored on the notetaker company's own servers, not yours or your client's
  • Fed into a searchable database tied to the person who installed the bot, so a former employee or ex-contractor can sometimes still search old meeting transcripts after they've left
  • Summarised by a large language model, which means a second AI system has processed your confidential conversation, not just recorded it
  • Automatically shared to a Slack channel or synced to a CRM, sometimes to people who were never on the call at all

None of that is hidden or malicious. It's just the default setting on tools that were built for speed, not for confidentiality. Nobody sat down and asked "should this transcript of a client discussing their finances be searchable by three other people in this Slack workspace?" It just happens because the integration was switched on once and forgotten.

The uncomfortable bit nobody in the AI-for-business world wants to say out loud

Most of the advice online about AI notetakers is written by the companies selling them, so it's all "save four hours a week" and never "here's what you're agreeing to when you click accept." The truth is that plenty of small business owners have signed NDAs promising to keep client information confidential, then quietly let an AI tool record, transcribe and store every one of those conversations without checking the notetaker's own terms of service, retention policy or server location. It's not dishonesty. It's just nobody's job to check, so nobody does.

What to check before your next call

You don't need a lawyer for this, though if you're handling sensitive client data, a proper contract review is worth the money. For most small businesses, this is a twenty-minute job:

  1. Find out which notetaker you're using. Ask your team. If more than one person books calls, you might have two or three different tools running, each with its own policy.
  2. Read the retention setting, not the marketing page. Most tools let you set transcripts to auto-delete after 30, 60 or 90 days. Most are set to "keep forever" by default.
  3. Check where the servers are. If you have UK or EU clients and your notetaker stores data in the US with no UK data processing addendum, that's a GDPR problem waiting to surface, particularly if a client ever asks you directly.
  4. Check who else can see the transcript. Some tools auto-share to every calendar attendee's workspace. If your client's competitor happens to share a Slack instance with someone on the call (rarer than it sounds, but it happens in small industries), that's now a live risk.
  5. Turn off auto-join by default. Set it so the bot only joins when you specifically add it, not every meeting on your calendar.

I did this audit for my own business in an afternoon. It took longer to find the settings menu in each tool than it did to change anything.

The simple policy that solves 90% of this

You don't need a fifteen-page document. A one-page policy, shared with your team and mentioned to clients where relevant, covers most of it:

  • State out loud, at the start of any call, whether a bot is recording. Not a tiny icon in the corner, an actual sentence.
  • Set every notetaker to delete transcripts automatically after a fixed period, not indefinitely.
  • Turn off any auto-sharing to channels or CRMs that weren't agreed in advance.
  • For anything covered by an NDA, either turn the bot off entirely or get written confirmation from the client that they're fine with it.
  • Review who has access to old transcripts every time someone leaves the business.

If this feels like more admin than your business has time for, that's exactly the kind of gap an AI implementation coach is useful for, someone who sits down with you once, sets the policies and settings up, and then it's done rather than being a nagging worry every time a new client joins a call.

What this has to do with marketing and trust, not just legal risk

Here's the part that gets missed. Trust is the actual product you're selling as a consultant, a coach, an agency, or any small business that works closely with clients. Look at how brands that have built genuine trust do it: Airbnb's marketing strategy is built almost entirely on trust signals, because the entire business model depends on strangers trusting strangers. A client who finds out, weeks later, that an AI bot recorded a sensitive conversation without them being told isn't going to sue you. They're just quietly not going to refer you to anyone, and they're not going to book the next call.

Work with me

Want AI doing the heavy lifting in your marketing?

I build the systems that handle the boring 80 percent, so you get your week back. Done properly, with the human kept in.

The same logic applies to how you handle their data everywhere else. If you're collecting client information through email sequences, the same carelessness that lets a notetaker auto-join a call is often the same carelessness that lets a Mailchimp list sit unsegmented with three years of client data nobody's audited. It's the same muscle: treating data handling as a one-off setup rather than an ongoing responsibility.

What to use instead, if you want the benefit without the risk

You don't have to give up AI notetaking altogether. A few practical swaps:

  • Use a notetaker with a clear, short retention window (30 days, not indefinite) and check that setting every quarter, not just once.
  • For sensitive calls, take your own notes the old way, or ask the client directly before the call starts, "is it alright if I record this."
  • If you need to capture lead information rather than confidential discussion, something like an interactive calculator on your website captures useful, structured information from a prospect without ever needing to record a conversation at all, worth thinking about for early-stage enquiries where you don't need a call yet.
  • Build the habit Joe Pulizzi talks about in his own approach to business, treating trust and consistency as the actual asset, not the content itself. I wrote about the business lessons from Joe Pulizzi a while back, and the same principle applies here: the boring, consistent, slightly unglamorous habits are what protect a business long term, not the clever tool.

Where this is heading

More calls will have AI notetakers on them next year, not fewer. Zoom, Teams and Google Meet are all building the functionality directly into the platform, which means soon it won't even be a separate app someone chose to install, it'll be a checkbox that's on by default for everyone. That makes this more urgent, not less. The businesses that get ahead of it now, with a one-page policy and a genuine habit of saying "just so you know, I'm recording this," will look careful and professional. The ones that don't will find out the hard way, usually from a client who mentions it once, politely, and then never books another call.

Frequently asked questions

Is it illegal to use an AI notetaker without telling the other person on the call?

In the UK, recording a call you're part of is generally legal even without consent, but sharing or storing that recording, especially with third-party AI processing, can breach data protection rules and almost certainly breaches most standard NDAs and confidentiality clauses. The legal risk sits less in the recording itself and more in what happens to the transcript afterwards.

Which AI notetaker is safest for client calls?

There's no single "safest" tool, it depends entirely on your settings. Any notetaker (Otter, Fireflies, Fathom, Read AI or the built-in ones in Zoom and Teams) is fine if you set a short retention period, turn off unnecessary auto-sharing, and are transparent with the people on the call. The tool matters less than the settings.

Should I turn off AI notetakers for all client calls?

Not necessarily. For routine calls it's a genuine time saver. For anything covered by an NDA, involving unreleased information, or where a client hasn't explicitly agreed to it, turn it off or ask first. A quick verbal check at the start of the call solves most of the risk in under ten seconds.

What should a small business AI meeting policy include?

A short, usable policy covers four things: announce recording out loud at the start of every call, set transcripts to auto-delete after a fixed short period, switch off unnecessary auto-sharing to channels or CRMs, and review who has transcript access whenever someone leaves the team. That's enough for most small businesses.

Related reading: AI Notetakers on Client Calls: The Etiquette Nobody Has Agreed On Yet and The AI Meeting Notetaker Problem Nobody Warns You About.

If you want the full breakdown, here is everything I know about AI marketing.

Published and maintained by the Lilach Bullock team, covering marketing, AI and business growth.
Your buyers are asking AI who to use. Does it say you?

See for free whether ChatGPT, Claude, Perplexity, Gemini and Google name you, and get the plan to become the answer.

Check my AI visibility →
Sundays only

Get the Sunday newsletter.

One email a week. AI experiments, marketing tactics, and the workflows Lilach is building right now in her own business.

Subscribe free

Let’s get your marketing running on AI.

Book a free 30-minute call

We figure out what you need, where AI fits in, and what working together would look like.

Book the call →

Or take the 30-second calculator

You’ll see the hours and the money quietly leaking out of your week, and the three workflows worth building first.

Take the calculator →

Or grab the free AI resource library

Prompt packs, templates, checklists, and swipe files. The exact tools I build for paying clients. Yours, free.

Get the library →
Keep reading

More from the blog.