Back to Articles
    Operations & Management

    Granola vs. Fireflies vs. Otter

    Every major AI notetaker has now been sued over how it captures other people's voices. For a nonprofit whose meetings involve clients, patients, students, or survivors, the differences between these tools are not about summary quality. They are about who consented, where the recording lives, how long it stays there, and whether a model was trained on it. Here is how the three most common options actually compare on the dimensions that carry risk.

    Published: August 13, 202614 min readOperations & Management
    Comparing AI meeting notetakers for nonprofit client privacy

    Most nonprofit staff arrive at this question backwards. Someone tries a meeting assistant on a team check-in, the summaries are genuinely good, and within a few weeks the tool has quietly migrated into case conferences, intake calls, and conversations with families. Nobody made a procurement decision. The tool was chosen for how it handled a staff meeting and is now handling protected information, which is a very different job with a very different risk profile.

    The market has since made this harder to ignore. Otter.ai was hit with a federal class action in August 2025 alleging its notetaker recorded participants who never consented. Fireflies.ai was sued in March 2026 under Illinois biometric law over voiceprints collected from meeting participants. Granola, which built its entire brand on the fact that no bot joins your call, was sued in July 2026 precisely because participants were never told anything was running. Three tools, three different architectures, three lawsuits alleging the same underlying failure: the person whose voice was captured was not the person who agreed to the terms.

    None of this means meeting AI is off limits for nonprofits. It means the choice deserves a real evaluation, and that the evaluation should be organized around client risk rather than feature lists. A tool that is perfect for a development team's funder calls may be indefensible in a family services program, and the reverse is also true. The right answer for many organizations is not one tool but a clear rule about which meetings can be captured at all, followed by a tool choice that fits the meetings that survive that rule.

    This article compares Granola, Fireflies, and Otter on the four dimensions that determine whether a nonprofit can defend the decision later: how the tool announces itself to participants, where recordings and transcripts are stored and for how long, whether the vendor will sign a Business Associate Agreement, and what happens to your content by default with respect to model training. It also covers the parts none of these tools solve, which is where most of the real work sits. If you have not yet written the underlying rules, start with our guide to AI notetakers in nonprofit meetings and treat this comparison as the procurement step that follows.

    Client Privacy Is Three Separate Problems, Not One

    Vendors talk about privacy as a single property that a product either has or lacks, usually evidenced by a SOC 2 report. That framing is not useful for a nonprofit, because the three things that can go wrong are independent of each other and a tool can be strong on one while being weak on the others. Separating them is the fastest way to cut through marketing claims.

    The first problem is capture. Did every person in the conversation know it was being recorded, and did they agree? This is a legal question governed by state law and it does not care how good the vendor's encryption is. The second problem is custody. Once the words exist as text, who holds them, in whose account, for how long, and who can pull them back out later through a subpoena, a link shared by mistake, or a departing employee's inbox. The third problem is downstream use, meaning whether your client's words become training data or evaluation data for someone else's model.

    A nonprofit can fail any one of these while passing the other two. Granola's architecture is the clearest illustration: by not sending a bot into the call it removes the visible warning that other participants rely on, which weakens capture, while its handling of raw audio is comparatively strong. Fireflies takes the opposite posture, announcing itself with an obvious bot but building a deeper data pipeline around what it hears. Neither is simply better. They fail differently, and which failure you can tolerate depends on who is in the room.

    Capture

    Did everyone know and agree?

    Governed by federal and state wiretap law, not by vendor security. The relevant question is whether the tool makes its presence obvious to people who are not your staff, and whether your process captures their agreement before anything starts.

    Custody

    Where does it live, and for how long?

    Transcripts are records. They are discoverable, they can be shared by link, and they persist long after the meeting mattered. Default retention on most of these tools is indefinite, which is a decision your organization should be making rather than inheriting.

    Downstream use

    Does it become training data?

    Training defaults frequently differ by pricing tier, with the protective setting reserved for enterprise plans. Content absorbed into a model cannot be pulled back out, which makes this the one mistake with no remedy after the fact.

    The Consent Problem Is a State Law Problem

    Federal law under the Electronic Communications Privacy Act generally permits recording when one party to the conversation consents, which is why so many products were designed around the assumption that the meeting host's agreement is sufficient. State law is where that assumption breaks. Roughly a dozen states require all parties to consent before a conversation can be recorded, including California, Florida, Illinois, Pennsylvania, Washington, Massachusetts, Maryland, Montana, New Hampshire, Delaware, Connecticut, and Oregon, with Connecticut and Oregon applying different rules to phone calls and in-person conversations. The state-by-state breakdown at Recording Law is a reasonable starting reference, though it is not legal advice and the classifications shift.

    For a nonprofit this is more complicated than for a company with a single office, because your meetings routinely cross state lines. A video call with a board member in Illinois, a program director in Texas, and a family in California is subject to the strictest rule in the room, and you may not know where everyone is sitting. The practical consequence is that all-party consent should be your operating standard everywhere, not just in the states that require it. Building two workflows and asking staff to remember which applies is a policy that will fail on a busy Tuesday.

    Illinois adds a second layer that catches people by surprise. The Biometric Information Privacy Act regulates voiceprints as biometric identifiers, requiring written consent and a published retention schedule before collection. This is the basis of the Fireflies case, where the complaint alleges the tool collected and stored voiceprints of participants who never created accounts, never agreed to terms of service, and never signed anything, as summarized in Jackson Lewis's analysis of the case. Voice separation and speaker labeling, the features that make transcripts readable, are exactly what create this exposure. If you serve or employ anyone in Illinois, this belongs in your evaluation.

    What none of this means is that verbal disclosure at the top of a call is enough on its own. It is the minimum, and it works reasonably well for staff and board meetings. For any conversation where a client's own information is the subject, consent should be documented in the same place you document everything else about that client, which is your case management system, not a checkbox in a meeting tool. A person who is receiving services from you is not in a position to freely decline a recording that their caseworker has already started, and a consent process that ignores that power dynamic is a formality rather than a protection.

    The bot is doing more work than you think

    The visible participant that Fireflies and Otter drop into a call is widely treated as an annoyance. Legally it is a feature. It gives every person in the meeting an unmistakable signal that something is capturing the conversation, and it creates a moment where anyone can object before the substance begins.

    Bot-free tools remove that signal entirely. That is convenient, and it is also why Granola's marketing language about other people not knowing the tool is there was quoted back at the company in the complaint against it. If you adopt a bot-free tool, you have taken on the disclosure job the bot used to do, and you need a process that reliably performs it.

    What the Three Lawsuits Actually Tell You

    It would be easy to read a wave of litigation as a reason to avoid the whole category, and easy in the other direction to dismiss it as the ordinary cost of doing business for fast-growing software companies. Neither reading is much use. The value in these cases is that they show precisely which design decisions attract legal attention, which lets you evaluate any tool, including ones not covered here, against the same criteria.

    The Otter case, filed in the Northern District of California in August 2025 and later consolidated, centers on the gap between host consent and participant consent. The named plaintiff had no Otter account and joined a call where the notetaker was running. Coverage from NPR and legal analysis at the National Law Review lay out the theory: permission was sought from the meeting host and treated as permission from everyone. For a nonprofit, that is the exact pattern of a caseworker enabling a notetaker on a call with a client.

    The Fireflies case, filed in the Northern District of Illinois in March 2026, is not about recording at all. It is about voiceprints, and the claim that biometric identifiers were extracted from participants without the written consent Illinois law requires. This matters because it survives disclosure. A participant can know a recording is happening and still have a claim if their voice was converted into a biometric identifier and retained without notice.

    The Granola case, filed in July 2026 in the Northern District of California, closes the loop. It alleges that the bot-free design deprived participants of any notice at all, and separately that captured content was used for model training by default. Reporting on the complaint notes the company's own privacy documentation acknowledges that data incorporated into a model cannot subsequently be extracted, a point that should end any internal debate about whether training defaults are a minor setting. Taken together, the three cases say that disclosure, biometric handling, and training defaults are each independently sufficient to create liability, and that a tool passing on two of them is not safe.

    Granola: Quiet by Design, Which Cuts Both Ways

    Granola runs as an application on your own laptop and listens through the system audio rather than joining the call as a participant. You type shorthand notes during the meeting and the tool enriches them afterward, which produces output that reads like something a person wrote rather than a machine summary. Staff who have tried several notetakers often prefer it, and the preference is legitimate. The workflow genuinely fits how people take notes.

    The privacy picture is more mixed than the local-first framing suggests. Granola does not retain raw audio after transcription, which is a meaningful advantage over tools that keep recordings indefinitely. But transcription and summarization run in Granola's cloud infrastructure in the United States rather than on your machine, so the words leave your laptop regardless of where the app is installed. Transcripts are stored indefinitely by default. And on model training, the protective default applies only at the enterprise tier, currently listed around thirty-five dollars per user per month; free and business users are opted in unless someone changes the setting. You can review the current terms directly in Granola's published privacy policy, which is worth doing because these details change.

    The disclosure gap is the real issue for nonprofit use. Because nothing appears in the participant list, a client, a family member, or a job applicant has no way to know they are being transcribed unless a person tells them. In a staff or leadership context where everyone has been briefed on the tool, that is manageable. In any conversation with someone outside the organization, you are relying entirely on a human remembering to say something, every time, under time pressure. That is a thin control to place between your organization and a wiretap claim.

    Where it fits

    • Internal staff meetings, planning sessions, and one-on-ones where every participant knows the tool is in use
    • In-person conversations where a bot cannot join anyway and audio retention is a concern
    • Organizations that want a notetaker without a visible participant appearing in funder or partner calls

    Where it does not

    • Any conversation with clients, patients, students, or applicants, where silent capture is the core risk
    • Programs on free or mid-tier plans, where training opt-out is not the default and must be actively managed
    • Situations requiring centralized administrative control over what individual staff members capture

    Fireflies: The Strongest Compliance Story, With Conditions

    Fireflies joins calls as a visible participant, transcribes, and pushes structured output into other systems. Its orientation is toward being a data pipeline rather than a notepad, which is why it appears most often in organizations that want meeting content flowing automatically into a CRM or a project tracker. That orientation is also the source of both its strongest privacy features and its biggest exposure.

    On the compliance side, Fireflies offers the clearest path of the three for organizations handling protected health information. The company publishes a Business Associate Agreement and states that it has signed BAAs with its own downstream speech recognition vendors so that meeting content is not stored on their systems or used to train their models. It also operates a zero data retention arrangement with those AI vendors for meeting content. This is a genuinely more mature posture than a general assurance that data is secure.

    The conditions matter as much as the features. HIPAA coverage is limited to enterprise customers, and the BAA takes effect only when Private Storage is enabled. A program running on a lower tier, or an individual staff member using a personal account, sits entirely outside whatever agreement your organization signed. This is the single most common way nonprofits end up out of compliance without realizing it: the agreement exists, and the person actually recording the client conversation is not covered by it. Any rollout needs an account audit alongside the contract, which is the same discipline covered in our guide to shadow AI use on personal accounts.

    The biometric exposure remains the open question. The Illinois complaint targets speaker identification, which is a core Fireflies capability and not something you can turn off while keeping the product useful. Until that litigation resolves, nonprofits with Illinois staff, clients, or board members should treat voiceprint collection as an unresolved risk and factor it into where the tool is permitted.

    Where it fits

    • Health-adjacent programs that need a signed BAA and are willing to fund the enterprise tier
    • Development and partnership teams that want meeting content routed into a CRM without manual entry
    • Organizations that want a visible bot as a built-in disclosure mechanism

    Where it does not

    • Small organizations that cannot reach the enterprise tier where the compliance features actually live
    • Anywhere Illinois biometric law applies, until the voiceprint litigation is resolved
    • Teams that will not maintain the integration hygiene a data pipeline requires, since every connected system inherits the content

    Otter: Deepest Transcription, Heaviest Configuration Burden

    Otter is the most familiar of the three to nonprofit staff, partly because it has been available through TechSoup and partly because its live transcription is the strongest in the category. For accessibility purposes that matters a great deal. Real-time captions in a community meeting or a board session are a service to participants, not just a convenience for the notetaker, and Otter does that job well.

    Otter can be configured to handle protected health information, but only after a BAA is executed, and the burden of getting the configuration right sits with you. The controls that matter include disabling public and link-based transcript sharing, enforcing two-factor authentication and single sign-on, managing whether the notetaker auto-joins calendar events, and setting a retention period rather than accepting the default. Each of those is a place where an unconfigured account leaks. Link-based sharing in particular is worth attention, because a transcript link forwarded outside the organization does not respect any of your other controls.

    Auto-join deserves its own decision. The feature that makes Otter feel effortless, having the assistant appear in every meeting on your calendar, is the feature most likely to put it in a conversation where it does not belong. A caseworker's calendar contains both team meetings and client appointments. Auto-join does not distinguish between them, and the staff member who forgets to disable it before a sensitive call has made a mistake that the tool encouraged. For any program touching client information, auto-join should be off at the organizational level and enabling it should require a deliberate action.

    The consolidated litigation against Otter is the most advanced of the three, which cuts in two directions. It means the company is under the most pressure to change its consent flows, and it also means the practice being challenged has been running the longest. If your organization has been using Otter for years across client-facing work, the retention question is not hypothetical. There may be a substantial archive of transcripts whose consent basis nobody can now reconstruct, which is a cleanup project rather than a procurement one.

    Where it fits

    • Accessibility use cases where live captions genuinely serve the people in the room
    • Public meetings, webinars, and recorded trainings where the content is intended to be shared
    • Organizations that need verbatim transcripts rather than summaries, for accuracy or for the record

    Where it does not

    • Any deployment where nobody owns the configuration, since the defaults are the risk
    • Calendars that mix internal meetings and client appointments, unless auto-join is centrally disabled
    • Staff working from personal accounts, which fall outside any organizational BAA entirely

    The Comparison That Matters

    Feature comparisons of these tools are easy to find and mostly unhelpful for this decision, because they rank summary quality and integration counts. The table below is organized instead around the questions a board member or an auditor would ask. Pricing figures reflect publicly listed rates as of August 2026 and change frequently, so treat them as a rough sense of tier rather than a quote.

    QuestionGranolaFirefliesOtter
    Visible to participants?No. Runs on the laptop, no bot appearsYes. Joins as a participantYes. Joins as a participant
    Where processing happensVendor cloud in the US, despite local captureVendor cloud, with private storage option at higher tiersVendor cloud
    Raw audio retained?Deleted after transcriptionRetained per account settingsRetained per account settings
    Default transcript retentionIndefiniteIndefinite, configurableIndefinite, configurable
    BAA available?Enterprise onlyEnterprise only, requires Private StorageYes, must be executed before any PHI
    Training opt-out by defaultEnterprise only. Free and business tiers opted inStates customer data is not used to train modelsContested in litigation. Verify current terms
    Voiceprint exposureLower, no speaker biometric focusSubject of active Illinois BIPA litigationSpeaker identification in use
    Rough entry pricingFree tier, around $14 per user monthly for businessAround $10 to $18 per user monthly for proFree tier capped at 300 minutes, around $17 for pro
    Nonprofit pricingNot publicly offeredCheck current nonprofit terms directlyHas been available through TechSoup

    Note: Prices may be outdated or inaccurate.

    Read down the BAA row and the training row together and a pattern emerges that should shape your budget conversation. On all three tools, the protections a nonprofit actually needs are gated behind the most expensive tier. The cheap plan that a program manager can expense is structurally the least protective one, which means the real cost of using meeting AI on client work is the enterprise price multiplied by everyone who touches client conversations. If that number does not fit the budget, the honest conclusion is that meeting AI does not belong in that program yet, not that the free tier will do. Our discussion of AI tool budgets and per-employee spending covers how to frame that tradeoff for a finance committee.

    Decide Which Meetings Qualify Before You Decide Which Tool

    The most useful thing a nonprofit can do in this space costs nothing and involves no vendor. Sort your recurring meetings into tiers based on what is said in them, and decide at the tier level whether AI capture is permitted at all. Doing this first turns the tool question into something manageable, because most organizations discover that the meetings where they actually want a notetaker are not the ones carrying the risk.

    A workable structure has four tiers. Open meetings, including public forums, webinars, and recorded trainings, where transcription is a benefit and often an accessibility improvement. Internal meetings, where everyone present is staff or a board member operating under your policies. External professional meetings with funders, vendors, and partners, where disclosure is required but the content is not sensitive. And protected conversations involving clients, patients, students, applicants, personnel matters, or legal advice, where the default is no capture and any exception is approved individually rather than by category.

    That fourth tier does most of the work. If protected conversations are simply excluded, the remaining question is which tool best serves the other three, and the answer can reasonably be a mid-tier plan rather than an enterprise contract. If you decide protected conversations should be included, then you are in a different procurement entirely, one that requires a BAA, a documented consent process built into intake, a defined retention period, and a named owner. Board executive sessions raise their own set of issues around privilege and discovery, which we covered separately in AI notetakers in board meetings.

    Questions to answer before signing anything

    Work through these with the program leads who will actually use the tool, not just with IT

    • In which states do our staff, clients, and board members sit, and does that put us under all-party consent or biometric rules?
    • Which of our meeting types will this tool touch, and have we explicitly excluded the ones involving protected information?
    • Does the plan we can afford actually include the BAA, retention controls, and training opt-out, or are those enterprise features?
    • What is our retention period, who enforces it, and what happens to transcripts when a staff member leaves?
    • How will a participant who objects be accommodated, and does declining actually stop the capture?
    • If we received a records request or a subpoena tomorrow, could we produce a complete list of what exists?

    The Setup Work Is the Same Whichever Tool You Pick

    Whatever you choose, the configuration determines most of your actual exposure. Vendors ship defaults tuned for adoption rather than for caution, and a nonprofit that installs any of these tools and leaves the settings alone has effectively chosen the least protective option available on its plan. The following work takes an afternoon and matters more than the comparison above.

    Start with retention, because it is the setting with the longest tail. Indefinite storage is the default nearly everywhere, and it converts a convenience into a growing archive of discoverable records. Pick a period tied to why you need the transcript at all. Notes that inform a case record should live in the case record and be deleted from the meeting tool once transferred. Notes from a planning session rarely need to survive the quarter. If you have not thought through who holds these records and under what terms, our article on data retention policies for AI meeting notes works through the governance side in detail.

    Then close the sharing paths. Disable public and link-based transcript sharing, which is the most common route by which a sensitive summary ends up somewhere unintended. Turn off calendar auto-join at the organizational level. Require single sign-on so accounts can be deprovisioned when someone leaves, and audit for personal accounts already in use, which is where most of the uncontrolled capture actually lives. Finally, check the training setting on every account rather than trusting a single organizational toggle, since these defaults vary by tier and are sometimes reset when plans change.

    Settings to change on day one

    • Set an explicit retention period instead of accepting indefinite storage
    • Disable public and link-based transcript sharing
    • Turn off calendar auto-join organization-wide
    • Opt out of model training on every account, not just the admin one
    • Enforce single sign-on and two-factor authentication

    Process to build around it

    • A scripted disclosure staff read at the start of any external call
    • Documented consent in the case record for any client conversation, not in the meeting tool
    • A named owner responsible for the account inventory and settings review
    • A clear list of meeting types where capture is prohibited outright
    • Coverage for volunteers and contractors, who are outside your HR policies

    What None of These Tools Solve

    There is a category of problem that no configuration and no contract addresses, and it is worth naming before you finish the evaluation. The first is the difference between consent and free consent. A client who is receiving housing assistance, immigration support, or food from your organization is not a peer negotiating terms. When a caseworker says a notetaker is running and asks if that is alright, the answer is almost always yes, and that yes carries very little information about whether the person was comfortable. Designing around this means offering a genuine alternative, making the non-recorded path equally easy, and accepting that some conversations should not be captured regardless of what anyone agrees to.

    The second is the chilling effect on the conversation itself. People disclose less when they know they are being transcribed, and the disclosures they withhold are disproportionately the ones that matter: substance use, immigration status, domestic circumstances, informal income. A notetaker that produces a beautifully organized summary of a conversation in which the client said less than they otherwise would has made your program worse while appearing to make it more efficient. This cost is invisible in any evaluation that measures only transcript quality.

    The third is accuracy across the people you actually serve. Speech recognition performs unevenly across accents, dialects, speech differences, and multilingual conversation, and it degrades further with background noise of the kind common in shelters, clinics, and community spaces. A transcript that quietly mishears a client and then becomes the basis for a case note is a documentation error that propagates. Any use of transcripts as a source for client records needs human review of the output, which is the same discipline required when turning case notes into outcomes data.

    The fourth is people outside your policies. Volunteers, contractors, consultants, pro bono professionals, and partner staff all join your meetings and may bring their own notetakers, running on their own accounts under terms you have never read. Your carefully configured enterprise deployment does nothing about a volunteer's personal Otter account transcribing a client meeting. Extending your rules to unpaid and non-employee participants requires a different mechanism than an employee handbook, which is the subject of our volunteer AI policy guide.

    Conclusion

    If you are choosing today, a defensible default for most nonprofits looks like this. Use a visible-bot tool for meetings with people outside the organization, because the bot performs a disclosure job that a busy staff member will eventually forget to perform. Use whichever tool your staff actually like for internal meetings, where everyone present knows the rules and the content is not protected. Keep all three away from client conversations unless you have an executed BAA, a consent process documented in the case record, a defined retention period, and someone whose job it is to check that those things are still true in six months.

    The three lawsuits point at the same lesson from three directions. Otter's case is about treating host permission as everyone's permission. Fireflies' case is about extracting something from a voice that the speaker never agreed to give. Granola's case is about the absence of any signal at all. In each, the person harmed was not the customer. That is the structural feature of this whole product category, and it is why a nonprofit cannot delegate the consent question to a vendor no matter how good the compliance documentation looks.

    It is also worth holding onto the reason this technology is appealing in the first place. Nonprofit staff spend enormous amounts of time on documentation that no one reads, and a tool that gives an hour back to a caseworker is delivering that hour to the people they serve. The goal is not to refuse the benefit. It is to take it in the settings where it costs nothing, and to be honest about the settings where the cost is borne by someone who never got a vote.

    Start with the meeting tiers, not the tool. Once you know which conversations are eligible, the procurement question gets much smaller, the budget question gets much clearer, and the answer to what happens when a client asks whether the recording can be turned off becomes something you can say out loud without hesitating.

    Need Help Choosing Safely?

    We help nonprofits evaluate AI tools against the risks that actually apply to their programs, then get the policy and configuration right before rollout.