Vendor review
Does your AI notetaker send your meetings to a third-party AI provider?
Published August 16, 2026 by Stillnote
Almost every AI meeting notetaker produces its summary by sending your transcript to a model run by somebody else. That is not a scandal, it is just how most of them are built. But it is the single most useful question to ask in a vendor review, because the answer is a checkable fact rather than an adjective. Stillnote's answer is none: both models run strictly self-hosted and offline on your own Mac.
If you have ever filled in a security questionnaire, you know the shape of this. Somewhere near the middle there is a line asking you to list every subprocessor and every third-party AI or machine-learning service that touches customer data, with the plan tier for each. It is a boring question and it is the right one, because "private," "secure," and "enterprise-grade" are all things a vendor can say about an architecture that still transmits your conversation to a model provider.
There are only two architectures, and they are easy to tell apart
Strip away the marketing and an AI notetaker is doing two model-shaped jobs: turning audio into text, and turning text into a summary. Each one either runs on a machine you control or on a machine somebody else controls.
- API-based: the app sends your audio or transcript to a model provider over the network, the provider runs inference, and the result comes back. Your conversation leaves your device and enters a third party's systems, however briefly.
- Self-hosted and offline: the app downloads open-weight models once, then runs them locally. There is no inference-time network call, so no provider ever receives the data, and nothing has to be promised about how they handle it.
Both are legitimate engineering choices. They are not, however, the same risk, and no contractual term converts one into the other. This is worth saying plainly because the distinction usually gets flattened into a single word, private, that both architectures claim with a straight face.
A no-training clause is not the same as not sending
The most common answer to "is my data used for training?" is a zero-retention or no-training agreement with the model provider. Those are genuinely valuable and you should want them. They are also a promise about what happens to your data after it arrives.
Transmission and retention are separate questions and a good review asks both. If a transcript is transmitted, then the provider's access controls, breach history, subpoena exposure, and sub-processor list are now part of your risk surface, no matter how immediately they delete it afterwards. If the transcript is never transmitted, that entire surface does not exist for you to assess.
Stillnote's answer, and where it is written down
Stillnote uses no third-party AI provider or generative AI service of any kind. The speech-to-text model and the summarization model are open-weight models downloaded once to your Mac and then run strictly self-hosted and offline. There is no inference-time API call to any model provider, no prompt or transcript is transmitted to one, and no data is returned to any provider for training, retraining, fine-tuning, or evaluation.
That claim is published rather than merely stated here. Section 4.3 of the Stillnote privacy policy discloses the self-hosted and offline model processing explicitly, and section 4.4 carries the affirmative Limited Use statement covering data received from Google APIs. Section 4.1 lists the exact Google Calendar scopes Stillnote requests and why each is necessary, which is the same class of question in a different suit.
A published policy is a better artifact than a sales answer for a simple reason: it is the same document for every reader, it is dated, and changing it leaves a trace.
Four questions that make the answer checkable
Whichever tool you are evaluating, including this one, these four turn a claim into something you can confirm or disprove:
- Which third-party AI providers do you use, and at what plan tier? A vendor who cannot answer this quickly has not thought about it. 'None' and a named list are both good answers. A pause is not.
- Does your published privacy policy explicitly disclose self-hosted or offline processing? If the architecture is local, the policy should say so in words, not imply it.
- Does the app produce a summary with the network disconnected? Turn off Wi-Fi and take a two-minute meeting. Local inference keeps working. API-based inference cannot.
- What leaves the device, and can I watch it? Open Activity Monitor or a network monitor during a recording and see for yourself. This is the only one of the four that does not depend on anybody telling you the truth.
The last two are the useful ones, because they do not require trust. They require about five minutes.
Why this question keeps coming from lawyers and investors
The people who ask it first are usually the ones whose conversations carry other people's confidences: lawyers under professional secrecy obligations, investors discussing a company that is not theirs to discuss, clinicians, and anyone whose meetings routinely include material that is not merely sensitive but somebody else's to protect. For them the relevant question is not whether a vendor is trustworthy. It is whether the vendor is in the room at all.
Stillnote is built so that the answer is no. It records through your Mac's own audio rather than joining the call as a bot participant, and both models run on your machine, so there is no third party in the room and no bot in the attendee list. Because you are recording, obtaining any consent your participants or jurisdiction require is still your responsibility.
Third-party AI providers and meeting notes: common questions
Does my AI notetaker send my meeting to a third-party AI provider?
It depends entirely on where the model runs. If a tool generates summaries by calling a model API, your transcript is sent to that provider to be processed. If a tool runs open-weight models on your own machine, nothing is sent anywhere. The question to ask a vendor is not whether they are private, it is which AI providers they use and at what plan tier, because that answer is a fact rather than a promise.
Which third-party AI providers does Stillnote use?
None. Stillnote uses no third-party AI provider or generative AI service of any kind. Both models it relies on, the speech-to-text model and the summarization model, are open-weight models downloaded once and then run strictly self-hosted and offline on your Mac. There is no inference-time API call to any model provider.
Is my meeting data used to train an AI model?
Not in Stillnote. Because inference happens entirely on your device, no transcript or prompt ever reaches a model provider, so there is no path by which it could be used for training, retraining, fine-tuning, or evaluation. This is disclosed in section 4.3 of the Stillnote privacy policy.
Does a zero-retention or no-training agreement mean my data is not sent?
No. A zero-retention or no-training term is a contractual promise about what a provider does with data after it arrives. It is worth having, and it is a different thing from the data never being transmitted at all. Both can be reasonable choices, but they carry different risk, and a diligence questionnaire usually asks about transmission, not only retention.
How can I verify a notetaker's claim rather than trust it?
Ask for three things in writing: the list of third-party AI providers and plan tiers, whether the privacy policy explicitly discloses self-hosted or offline processing, and whether the app still produces a summary with the network disconnected. The last one you can test yourself in about a minute.
Keep reading
This guide describes how Stillnote works and how to evaluate AI notetakers at a category level. It does not assert specifics about any other tool's internal implementation, and product details can change, so confirm any vendor's current architecture with that vendor. Nothing here is legal advice. Stillnote is a native macOS app on Apple Silicon, made by LeapVision Technologies Inc.