Flocci Technologies Open dashboard

Where do AI notetakers store your recordings?

Direct answer

Cloud notetakers store recordings, transcripts and derived summaries on the vendor’s own infrastructure, typically in the region their plan specifies, under retention rules tied to your tier. Some enterprise plans add region choice or on-premise storage. A self-hosted bot stores everything on your server instead — no vendor copy exists.

The four questions worth asking a vendor

Where is the data physically stored, and can we choose? How long is it retained by default, and does deletion remove the derived data — summaries, embeddings, search indexes — or only the media file? Is our content used to train or improve models, and is that opt-out or contractual? Who inside the vendor can access a recording, and is that access logged? Reputable vendors answer all four in writing. The answers differ enormously by plan tier, which is the detail marketing pages leave out.

Why derived data is the part people forget

Deleting a recording is not the same as deleting what was learned from it. Transcripts, summaries, search indexes and analytics usually live in separate systems with their own lifecycles, and a “delete meeting” button often removes the media while leaving the derived record. For meetings covering hiring, compensation, client contracts or legal exposure, that gap is the entire risk — it is where a recording you believe is gone can still be retrieved.

The self-hosted answer

When you run the bot, all four questions collapse into your own policy. Donna records to disk on the server you control, stores the transcript and report in your own database, and reaches speech recognition and analysis over API with keys you hold. Deletion is your retention job, access is your authentication, and there is no vendor copy to ask about — which is why teams under client or regulatory scrutiny choose this shape.

Related questions

Do cloud notetakers train on my meetings?

Most now state that they do not train on customer content by default, but the guarantee’s strength varies by plan and jurisdiction. Read the data-processing terms rather than the marketing page, and check whether it is a contractual commitment or a settings toggle.

What data leaves the building with Donna?

Only what the analysis needs: audio chunks go to the speech-recognition API and the transcript goes to the analysis API, on keys you control. Recordings, transcripts and reports are stored on your infrastructure.

Does self-hosting satisfy GDPR or DPDP obligations?

It removes a third-party processor and cross-border transfer from the picture, which simplifies the assessment considerably — but compliance is a programme, not a deployment model. Keeping the data in your own perimeter makes the rest of the work tractable; it does not do the work.

Put Donna in your next meeting

Access is open — sign in with your Google account and she’s in your dashboard in minutes. Rolling out to a whole team, or want a hand with the server setup? We’re glad to help.