I Read the Terms of 13 AI Note-Takers. Nine Make Consent Your Problem. Zero Indemnify You.
Aug 15, 2026 · 7 min read · by Jordan Kwan
TL;DR: I read the published terms of 15 named meeting-AI products on August 15, 2026 and got a readable document for 13 of them. Nine of those 13 contain a clause making the customer solely responsible for obtaining recording consent from the other people in the meeting. Zero of the 13 indemnify that customer against a privacy or wiretap claim. So if your AI note-taker records someone who did not consent, the contract you already agreed to points at you. This is a reading of published documents, not legal advice.
Meeting AI is sold on frictionlessness. No bot, no announcement, nothing for anyone to object to. The legal documents underneath that pitch run the other direction, and they are public, so I read them. Fifteen products were on my list: Granola, Otter, Fireflies, Fathom, tl;dv, Read AI, Avoma, Gong, Chorus, Sembly, Krisp, Circleback, Spinach, Grain and Zoom AI Companion. Thirteen served me a readable document. Sembly publishes its terms as a PDF that returned unreadable binary to my fetcher, and I could not locate a resolving terms URL for Chorus under ZoomInfo, so both are excluded from every number below rather than guessed at.
What do the contracts actually say?
Nine of the 13 put the consent duty on you in writing, and several of them are unusually direct about it.
Otter's terms of service at section 9.2: "You acknowledge and agree that you are solely responsible for providing any notices to, and obtaining consent from, individuals in connection with any recordings as required under applicable law." The same section notes that "the laws regarding the notice and notification requirements of such recorded conversations vary by location."
Fathom makes it a warranty you give: "you have obtained the required consent of every meeting participant to record each call before the call begins." Fireflies, under a heading called Consents and Third-Party Rights, says "you must ensure that each meeting participant consents to recordings." tl;dv: "you are responsible for collecting consents from all participants in the meeting prior to starting the recording."
The rest phrase it as compliance rather than consent, with the same destination. Krisp requires you to comply with "laws requiring you to provide proper notifications and to obtain proper consents from your online meeting guests." Grain at 2.10: "You are responsible for compliance with all recording laws." Avoma goes further and makes you responsible for other people: "You agree to comply, and you will require your Meeting participants or Call receivers to comply, with all applicable laws regarding the privacy of communications." Read AI obliges you to give end users notice of Read AI's own privacy policy. Zoom assigns compliance "as the Host or Phone Host."
Zoom was also the only one of the 13 whose terms documented an in-product announcement to the other participants: "You will receive a notification (visual or otherwise) when recording is enabled. If you do not consent to being recorded, you can choose to leave the recorded session." That sentence is doing work no other contract in my sample does.
Who indemnifies whom?
This is where the sample stops being uneven and becomes unanimous. Across all 13 readable documents, not one vendor indemnifies the customer against a privacy or wiretap claim.
The indemnities that exist run one of three ways. Some are purely one-directional toward the vendor: Otter, Fireflies, tl;dv, Read AI and Zoom all require you to defend them, and Otter's and Fireflies' clauses name privacy rights explicitly as a category you are covering them for. Some are reciprocal but carved down to intellectual property: Gong, Avoma, Krisp and Spinach will defend you against a patent, copyright or trademark claim, and nothing else. Fathom's vendor-side indemnity is IP-only and, per its terms, does not apply to the free edition at all. Krisp's document explicitly disclaims liability arising from the practices of third-party integrations.
And two documents contain no indemnification clause whatsoever. Grain's terms have none. Circleback's have none either.
So the structure is consistent across products that compete with each other: the duty is assigned downward, the protection is not extended back up. If a participant sues over a recording, the vendor's paperwork has already answered the question of whose problem that is.
Which vendors say nothing at all?
Four of the 13 have no recording-consent clause in the document I read: Granola, Circleback, Spinach and Gong. That absence is not a protection. It means the allocation of that risk is not addressed in the terms you accepted, which is a different and less predictable position than Otter's blunt one, not a better one.
Granola deserves a specific caveat. The document I could reach was its Application Terms of Service, which contains neither a consent clause nor an indemnity clause. Granola also publishes separate Platform and User terms that I did not read in this pass, so treat that row as incomplete rather than as a finding about the company.
What is actually being litigated?
Several of these products are defendants in active federal cases. Every one of them is pending. No court has ruled on the merits of any of them, and every characterization below is an allegation.
The National Law Review's survey of these cases lists Chamberlain v. Granola, Inc., No. 3:26-cv-07926 (N.D. Cal., filed July 30, 2026), in which the complaint alleges capture from Google Meet, Zoom and Microsoft Teams without notification to other participants. Fireflies faces alleged Illinois Biometric Information Privacy Act claims over voiceprints in Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 (C.D. Ill., Dec. 18, 2025), and a second action, Parrinello v. Fireflies.AI Corp., No. 3:26-cv-02479.
The furthest along is In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL (N.D. Cal.), four suits consolidated in late 2025 with a consolidated complaint filed December 5, 2025. It alleges violations of California Penal Code sections 631 and 632 and the federal Wiretap Act. A motion to dismiss was heard on May 20, 2026 and remained undecided as of that source's most recent update. Otter denies unlawful interception and argues its assistant acts as a tool of the meeting host rather than as an independent eavesdropper. That defense, if accepted, is the same theory as the consent clause: the host is the actor.
One number I am deliberately not publishing is how many US states require all-party consent. It is commonly given as anywhere from 11 to 13, published lists disagree, and I did not fetch a statute compilation I would stand behind. The only statutes I saw named in the documents I actually read were the California and Illinois provisions above. If a post hands you a state count without a citation, it is repeating someone else's memory.
What does this not prove?
It does not prove any vendor broke a law, because no court has said so yet. It does not prove these clauses are enforceable, since a contract between you and a vendor cannot bind a third party who was recorded and has their own claim. And a missing clause is missing from the document I read, not necessarily from every document a given company publishes.
What it does establish is narrower and harder to argue with. On the evidence of the vendors' own published terms, the consent obligation is contractually yours at nine of 13 products, and the financial exposure is yours at all 13. If you are choosing between these tools, the useful comparison is not the summary quality, it is whether the product announces itself to the room, because that is the only variable in this entire mess you control. It also fits the pattern I found when I went looking for accuracy numbers these vendors publish, which is that the documentation gets thin exactly where the buyer's risk gets thick. The same asymmetry shows up in what browser extensions declare about their own data collection: the disclosure exists, it is just pointed away from you.
Written by Jordan Kwan, founder of Reachium.
I build Reachium, the LinkedIn outreach platform behind the tactics you just read. Same brain, live product.
See what Reachium does ↗