Recording and the law
Local notes are private. Recording is still your call.
Steno records and transcribes on your computer and never uploads audio. That settles who can hear your meetings. It doesn't settle whether you may record the people in them. This page explains what the law asks of you, country by country and situation by situation, and what to say before you press Record.
There is no Steno server, so the claims now aimed at cloud notetakers have nobody to reach.
Whether you may record a call depends on where you and the others are. In Germany, Switzerland, France and a dozen US states, everyone must agree.
Remembering who spoke is biometric data. For work, get explicit consent before you name someone's voice in Steno.
Not legal advice. Laws change and courts read them differently; check with a lawyer before you rely on a row here for work. Last reviewed 4 October 2026.
Tell people. It is the one step that works everywhere.
Consent rules differ, but a clear notice at the start is enough in most places and the right first step in all of them.
- 1Say it at the start.
One sentence before the first agenda item covers most calls. People who stay after hearing it have agreed in most places that allow implied consent.
- 2Put it in the invite for outside guests.
Silence on a call is weak consent from someone who doesn't know you. A line in the invite, or a yes in the chat, is better.
- 3Ask for a yes where everyone must agree.
Germany, Switzerland, France and the all-party US states. If a participant is in one of them, the strict rule applies to the whole call.
- 4If someone says no, stop.
Stop the recording. Once Steno has finished processing, delete the meeting and any note it exported, and take notes by hand for the rest of the call.
- 5Keep less.
For work calls, let Steno delete audio after processing, and use a local summary model for anything confidential.
Quick note before we start: I record this call on my computer to take notes. The recording stays on my machine. Tell me now if you'd rather I didn't.
Kurz vorab: Ich zeichne das Gespräch auf meinem Rechner auf, um Notizen zu machen. Die Aufnahme bleibt auf meinem Gerät. Sag gern jetzt, wenn du das nicht möchtest.
I take notes with Steno, which records the call on my computer. The recording stays with me. Reply if you'd rather I didn't record.
Who has to agree?
The question each row answers: may one person on the call record it without telling the others? Where people sit in different places, follow the strictest rule among them.
- Germany
- Everyone must agree
- § 201 StGB makes recording non-public speech a crime, private use included. Live transcription that never stores audio is arguably outside it; no court has decided.
- Switzerland
- Everyone must agree
- Art. 179ter StGB: a participant who records a non-public conversation without the others' consent commits an offence.
- France
- Everyone must agree
- Art. 226-1 Code pénal covers words spoken in private. Purely professional calls are a grey area.
- Austria
- You may record
- A participant may record. Passing the recording on without consent is an offence (§ 120 StGB).
- UK, Netherlands, Italy, Spain
- You may record
- A participant may record for their own use. Sharing it or using it for work falls under the GDPR.
- US, federal law
- You may record
- The Wiretap Act needs one party's consent. States can be stricter, and many are.
- California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, Washington
- Everyone must agree
- All parties must agree. California allows $5,000 per violation in civil claims and reaches callers outside the state; Florida and Pennsylvania treat it as a felony. A call across states follows the strictest one.
- Connecticut, Delaware, Michigan, Nevada, Oregon
- Depends
- Different rules for phone calls and in-person conversations, or disputed readings. Treat them as all-party.
- Canada
- You may record
- Criminal Code s. 184 needs one party's consent. Work use falls under PIPEDA or provincial law.
- Australia
- Depends
- By state. Victoria, Queensland and the Northern Territory let a participant record; New South Wales, Western Australia, South Australia, Tasmania and the ACT need consent, with narrow exceptions.
- Japan, Brazil, India
- You may record
- A participant may generally record. Work use falls under APPI, LGPD and the DPDP Act.
“You may record” covers capturing a call you take part in. Publishing or sharing the recording is a separate question almost everywhere, and work use brings in data protection law on top.
Three sets of rules.
Recording law decides whether you may capture the call. Data protection law decides what you may do with the transcript. Biometric law covers the voice profiles Steno uses to recognise speakers. Keeping everything local helps with the second and third, and does nothing for the first.
A stored file is what most statutes call a recording. Steno writes audio to disk before it transcribes, so this applies every time you press Record.
For work, you are the controller under the GDPR and similar laws: you need a reason, people have to be told, and they can ask for a copy or for deletion. Purely private use is exempt in the EU.
Steno remembers voices so it can name speakers in the next meeting. A voice profile that identifies a person is biometric data under GDPR Art. 9 and Illinois' BIPA, the strictest category: explicit, often written, consent.
A cloud model is a third party, which matters under data protection law and again for client confidentiality and legal privilege. A local model keeps the text on your machine.
What changes with context.
The more your notes are for work, and the more people you record who don't know you, the more the law asks.
Recording law still applies. Recording a friend in Germany or California without asking is unlawful even though nobody else ever hears it. Data protection law does not apply to purely private use in the EU.
Freelancers, founders and team leads are the controller for their notes. Tell people what you record and why, delete when someone asks, and get explicit consent before you name a person's voice in Steno.
Write a policy before the first install. In Germany a works council has a say in tools that can monitor staff (BetrVG § 87). In Illinois, plaintiffs argue that a company enabling voice recognition can be liable under BIPA alongside the vendor.
Professional secrecy rules restrict sending client material to an outside provider, and a US court has held that documents a client made on their own with a consumer AI service were not privileged. Use a local summary model, or none.
What the notetaker cases say.
Every case so far targets a cloud service. Each one still shows which design choices draw claims, and which of them apply to a recorder that runs on your own computer.
Wiretap, California privacy and BIPA claims go ahead. Otter can be a third-party eavesdropper because it keeps and uses recordings for its own purposes.
For StenoThere is no Steno server, so no vendor receives the call. A cloud summary model you pick does receive the transcript text. Your own duty to the people on the call is unchanged.
The first major suit against a bot-free notetaker. It argues that recording from the user's computer, invisible to everyone else, was a design choice to avoid disclosure. No ruling yet.
For StenoSteno captures audio the same way. Telling people yourself is what closes that gap.
BIPA claims based on speaker recognition alone: voiceprints of people without an account, no written consent, no published retention policy.
For StenoSteno's voice profiles are voiceprints too, kept on your computer. BIPA binds companies, so a company deploying Steno carries this.
Documents a defendant produced with a consumer AI service were not protected by attorney-client privilege.
For StenoYour summary model is the third party here. For privileged conversations, use a local model.
The 2026 Digital Omnibus moved the high-risk obligations, which include some biometric identification, to December 2027. Emotion recognition at work has been banned since February 2025.
For StenoSteno does no emotion recognition. Whether matching voices of people in a meeting counts as high-risk identification is disputed.
What Steno doesn't do for you.
Steno is a tool you run, not a service that takes on your duties. These are the parts it leaves to you today.
- It doesn't tell anyone.
- No bot joins, nothing beeps, no notice reaches the other side. Saying it is your job.
- It keeps audio until you say otherwise.
- New installs keep recordings forever. Settings → Recording deletes them after processing or after a number of days, with a per-meeting override.
- Voice profiles outlive meetings.
- Deleting a meeting removes its recording, transcript, summary and tasks. The people Steno knows, their voice profiles and any files you already exported stay. There is no button yet to forget one person's voice.
- It compares every voice.
- Each meeting's speakers are matched against the people Steno knows, and there is no switch to turn that off. A voice profile only grows when you confirm a name.
- It can't discard a recording on Stop.
- Stopping always runs processing, including the summary and the export. Delete the meeting afterwards if someone asked you not to record.
- It doesn't record consent.
- Steno has no field for who agreed. Keep that in your notes or your calendar.
Sources · reviewed 4 October 2026
- In re Otter.AI Privacy Litigation, order of 13 Aug 2026 (FindLaw)
- Otter.ai as third-party eavesdropper (National Law Review)
- The Granola class action (Barnes & Thornburg)
- Lessons from the Fireflies.AI lawsuit (Epstein Becker Green)
- BIPA suits against AI notetakers (Amundsen Davis)
- United States v. Heppner (Proskauer)
- EU AI Act omnibus agreement (Gibson Dunn)
- Speaker identification and data protection (Ailance)
- KI-gestützte Meeting-Transkription und § 201 StGB (Werning)
- KI-Transkription und § 201 StGB (unternehmensstrafrecht.de)
- Call recording laws by US state, 2026
The case summaries and the German rows rest on these sources. The other countries are general summaries of their statutes, not checked against recent case law. Found something wrong? Open an issue and it gets fixed here.