Reviewed by Jonathan West · Updated Aug 13, 2026

Is Granola AI Safe?

What Granola does with your meeting data, the consent lawsuit, and how to lock it down.

Reviewed by Jonathan West · Updated Aug 13, 2026

Granola is reasonably safe on the technical basics, but its default settings and silent-capture model create real privacy risk you have to manage. Data is encrypted and the company holds a SOC 2 Type 2 report, yet training on your data is on by default on Free and Business plans.

This guide is general information, not legal advice. If your team records meetings, consult qualified counsel about your specific situation and local law.

Below, we cover how Granola handles your data, what the current lawsuit alleges, and a concrete checklist to lock the tool down before anyone on your team relies on it.


How Granola Handles Your Data

Granola stores your notes and transcripts in a US-hosted AWS environment, encrypted at rest and in transit. It says it does not keep raw meeting audio: on Mac and Windows it transcribes in real time, and on mobile it caches audio briefly, then deletes it.

The company holds a SOC 2 Type 2 report, which means an independent auditor reviewed its security controls over time. It also states that third-party AI providers such as OpenAI and Anthropic are never allowed to train on your data.

So the plumbing is solid. The risk is not the encryption. It is the default settings that decide who can use your content and who knows they are being recorded.

It helps to separate two questions. First, is your data secure from outsiders? On that front, encryption, US storage, and a SOC 2 report are reassuring. Second, who inside the loop can use your content, and did everyone on the call agree to be recorded? That second question is where Granola needs your attention.

  • Notes and transcripts encrypted at rest and in transit (US AWS)
  • Raw audio not retained after transcription
  • SOC 2 Type 2 report; no third-party training on your data

Worried about consent and data training before you roll out Granola? Layer3 Labs audits meeting-capture tools for privacy and compliance risk.

Book a Consultation

The Training-data Default

By default on Free and Business plans, Granola may use anonymized data to improve its own models, and you have to turn that off. The switch lives in Settings, Preferences, then Data and sharing, under the option to use your data to improve models for everyone.

This is opt-out, not opt-in. If you install Granola and never touch the setting, your meeting content can feed model improvement. For calls with client names, deal terms, or personal data, that is a meaningful exposure.

The Enterprise plan flips this. Model-training opt-out is on by default for the entire organization, so no individual has to remember. That is the single biggest safety reason to choose Enterprise for a team.

On Free and Business, training on your data is ON until you turn it off. Change it in Settings before your first real meeting.

Why Silent Capture Is the Core Risk

The bigger safety question is not storage, it is consent. Granola captures your device audio without joining the call as a visible bot, so the other people may never know a tool is recording.

Bot-based tools announce themselves by appearing in the participant list. Granola removes that signal, which is convenient for you and a blind spot for everyone else on the call.

That shifts a legal duty onto you. In many places, recording a conversation without proper consent can break wiretap or privacy law. The silent model does not exempt you from telling people.

In our AI workflow audits for teams rolling out meeting-capture tools, the failure mode we see most is treating the tool as if it handles consent. It does not. Silent capture makes disclosure a habit you have to build, and habits fail quietly until someone objects.


What the Chamberlain V. Granola Complaint Alleges

A proposed class action, Chamberlain v. Granola, Inc., No. 3:26-cv-07926, was filed in the Northern District of California on July 30, 2026. It is early-stage, and none of the allegations have been proven.

The complaint alleges that Granola records people without their consent through silent capture, and that it uses captured communications for AI model training by default. The core federal theory rests on the Electronic Communications Privacy Act, the federal wiretap statute.

The plaintiffs face real hurdles. Federal wiretap law generally allows recording when one party consents, and the tool's own user is that party. The Ninth Circuit also reads the exception for a criminal or tortious purpose narrowly, which makes the federal claim harder to win.

Because the case is at an early stage, there are no rulings to rely on and no findings of wrongdoing. The point for a buyer is not to predict the outcome. It is to recognize that regulators and courts are now looking hard at silent capture and default data use, and to set your own practices accordingly.



Encryption, Storage, and Admin Controls

For teams, the safety tools you want live on the Enterprise plan. Enterprise adds single sign-on, admin controls over sharing and API access, org-wide auto-deletion, and usage analytics.

Retention is a detail worth checking. By default, notes and transcripts are kept indefinitely unless an admin sets a retention policy. Enterprise plans let you configure auto-deletion periods for transcripts.

Sharing needs attention too. Notes shared by link have been criticized for reaching more people than users expect, so restrict sharing defaults before you distribute anything sensitive.

Think about where transcripts flow next. Integrations and the MCP connector can push notes into other apps and AI assistants, which is powerful and also widens the surface area for your data. Map those connections before you turn them on, and grant only the ones you actually need.

  • Enterprise: SSO, admin sharing and API controls, usage analytics
  • Default retention is indefinite unless an admin sets a policy
  • Review link-sharing defaults before sharing sensitive notes

How to Lock Granola Down: A Checklist

You can use Granola far more safely by changing a handful of settings and habits before your first real meeting. Work through this list as an admin, not just as a user.

None of these steps are hard on their own. The risk comes from skipping them, because the defaults lean toward convenience. Treat the checklist as a one-time setup ritual, then revisit it whenever Granola ships new features or your team grows.

  • Turn off training: Settings, Preferences, Data and sharing, disable using your data to improve models for everyone
  • On a team, standardize a spoken or written disclosure that a note taker is capturing the call
  • Get affirmative consent from all parties, especially in all-party consent states like California
  • For teams, choose Enterprise so training opt-out and auto-deletion apply org-wide
  • Set a retention policy instead of keeping transcripts indefinitely
  • Restrict link sharing and review who can access notes
  • Keep sensitive meetings off the tool until your consent process is solid
  • Document your policy and confirm it with qualified counsel
Granola can be used safely, but only if you change the defaults. Out of the box, it favors convenience over consent.

Frequently Asked Questions

  • It is technically sound, with encryption and a SOC 2 Type 2 report, but the training default and silent capture create real risk. It is safe only if you change the defaults and disclose recording to participants.
  • By default on Free and Business plans, anonymized data may improve Granola's own models until you opt out in Settings. Third parties like OpenAI and Anthropic are never allowed to train on it, and Enterprise turns training off org-wide by default.
  • Granola captures audio silently with no visible bot, so other participants may not know. The Chamberlain v. Granola complaint alleges this records people without consent, though nothing is proven. You are responsible for disclosure.
  • It depends on where you and the other participants are. Many states require all-party consent for recording. This is general information, not legal advice, so consult qualified counsel about your situation.
  • Turn off model training in Settings, disclose recording and get consent, restrict link sharing, set a retention policy, and use the Enterprise plan for org-wide controls. Keep sensitive calls off the tool until your process is solid.
  • No. Granola transcribes in real time on desktop, or from briefly cached audio on mobile, then deletes the audio. It stores the transcript and your notes, encrypted at rest and in transit.

Deploying Granola without a consent problem

Layer3 Labs runs AI workflow audits that set consent, retention, and training defaults correctly before your team records a single call. Book a free AI workflow audit and we will build a compliant meeting-capture setup for your stack.

Book your free AI workflow audit