Granola, the AI meeting-notetaking app built around recording calls without adding a visible bot, is facing a proposed federal class action accusing it of secretly intercepting participants’ conversations and using the resulting material for AI model training by default. The complaint, filed July 30 in the U.S. District Court for the Northern District of California, puts a legal problem squarely on a product feature Granola has marketed as an advantage: other people in the meeting may not know the tool is running. PPC Land first reported the case, Chamberlain v. Granola, Inc. and Granola Labs Ltd., brought by Florida resident Tarra Chamberlain on behalf of a proposed nationwide class and California subclass. The suit alleges violations of the federal Electronic Communications Privacy Act, California’s Invasion of Privacy Act, California’s computer-data-access law, and common-law privacy rights, among other claims. Granola had not publicly responded to the allegations as of August 2.
This is an allegation, not a ruling. But Granola’s own current documentation confirms the factual design choice at the center of the dispute: its desktop app captures a user’s microphone and system audio locally, does not join a call as a bot, and leaves consent to the customer using the product. Its documentation also says anonymized data on Free and Business plans may be used for Granola’s own model improvements unless users opt out.
For Windows administrators and IT teams, the important point is more immediate than the lawsuit’s final outcome: “no stored recording” is not the same thing as “no recording risk.” If audio is captured and sent for real-time transcription, the alleged interception has already happened before the vendor deletes an audio cache or reduces the conversation to a transcript.

A video conference laptop displays audio analytics beside cloud security graphics, legal documents, and a gavel.The bot-free design is the legal pressure point​

Granola’s product works differently from meeting assistants that appear in Zoom, Teams, or Google Meet as a named attendee. Its software runs on the user’s device and captures microphone input plus the computer’s system audio. The result is a transcript and AI-generated notes without a bot appearing in the participant list or triggering the familiar platform-level recording warning.
Granola presents that approach as a privacy and usability benefit. Its support material says no additional attendee is visible to other participants, while its product marketing has explicitly promoted “no bot” and “no notification” as characteristics of its meeting assistant. The company says the design avoids turning a live conversation into a performance for a conspicuous recording agent.
The complaint argues that this is precisely the problem. It alleges Granola’s design permits a participant to transcribe a conversation without notifying everyone else in the call, including people who have no Granola account, no contractual relationship with the company, and no practical way to know their words are being captured.
Granola’s own consent documentation makes a critical distinction that should concern Windows deployments. It says users are responsible for obtaining consent where the law requires it and recommends consent regardless of legal obligation. The automated consent-message feature described in that documentation is currently limited to Zoom on macOS; Granola says it has paused Google Meet support while it works on a replacement. Its documentation does not describe an equivalent automatic meeting-chat notification for the Windows desktop app.
That leaves a Windows user with the product’s core capability — capture of system audio across meeting platforms — but without the documented macOS-and-Zoom automated notice mechanism. A company cannot treat a general employee reminder to “follow applicable law” as a technical control. It is a policy instruction handed to the person with the least incentive to interrupt a sales call, interview, customer escalation, or executive meeting.

Real-time transcription does not erase the interception question​

Granola says it does not retain meeting audio after transcription. On desktop, the company says it transcribes in real time and stores the transcript and notes rather than an enduring audio file. On mobile, it says audio is cached temporarily during transcription and then deleted.
That may reduce the damage from a breach involving a stored audio archive. It does not necessarily answer the statutes cited in the complaint. California Penal Code section 632, for example, addresses intentional recording of confidential communications without the consent of all parties; the core dispute will include whether the conversations at issue were “confidential,” what consent was required, and whether Granola can be treated as responsible for the customer’s act of recording.
The complaint also invokes California Penal Code section 631, which covers certain forms of interception and use of communications, as well as the federal wiretap law. Those claims will face difficult questions: whether Granola is merely a service provider acting for a participating user, whether the application acquired the communication contemporaneously enough to constitute interception, and which jurisdiction’s consent rule applies when participants are scattered across states or countries.
But Granola’s “we delete the audio” answer is aimed at a different question — post-call retention. The legal exposure alleged here begins during the call, at the moment the app captures system audio and routes it for transcription. In practical security terms, deleting the original after the transcript is produced does not undo the disclosure of the conversation to Granola, its transcription infrastructure, or any downstream AI processing covered by the service.
The distinction is especially relevant for Teams users. Microsoft Teams can present its own recording or transcription notices when Teams-native features are used, but a locally installed application capturing Windows system audio operates outside that normal in-meeting disclosure path. A tenant’s Teams recording policy does not automatically prove that an endpoint-level notetaker disclosed itself to call participants.

The model-training setting exposes people who cannot opt out​

The recording allegation is only half of the case. PPC Land reports that Chamberlain’s complaint also challenges Granola’s use of captured data to improve its own models, saying that model training is enabled by default on Free and Business plans and requires a user-level opt-out.
Granola’s current security and privacy documentation supports the broad outline of that policy. It says anonymized data on Free and Business plans may be used to improve Granola’s services; users can disable the setting in their preferences. The company also says third-party AI providers such as OpenAI and Anthropic are contractually prohibited from training on Granola customer data.
That distinction is meaningful but incomplete. Preventing OpenAI or Anthropic from training on meeting content does not prevent Granola from using de-identified material for its own training or product-improvement work. For organizations that adopted Granola on the assumption that “our data is not used to train AI,” the relevant question is whose AI the policy excludes.
Granola says enterprise customers are opted out of model training by default and that Enterprise administrators can set the policy organization-wide. Business-plan customers do not receive the same control: Granola’s documentation says each user must opt out individually. That makes a user’s privacy preference dependent on every individual employee finding and changing the setting, even though the conversations can involve customers, job candidates, suppliers, lawyers, consultants, and other people outside the workspace.
The alleged consent gap becomes wider for those non-users. A person speaking on a call may have no Granola account and no ability to see a workspace’s data setting, turn off model training, or request that a user disable transcription before a meeting begins. The complaint’s most durable theory may rest there: an account holder can at least be offered a setting, while the people whose voices the account holder records cannot.
Granola acknowledges another practical limitation in its FAQ: after an opt-out is changed, it cannot guarantee that anonymized data was not used before the setting changed. That is not unusual for machine-learning systems, where previously incorporated data may be difficult or impossible to isolate without retraining. Yet it means opt-out is a forward-looking control, not a way to claw back conversations already processed under the default.

The dispute arrives as Granola pushes deeper into business workflows​

Granola is no longer a small personal productivity app operating at the edge of enterprise IT. In March, the company announced a $125 million Series C financing at a $1.5 billion valuation; TechCrunch independently reported the round and Granola’s expansion from an individual note-taking tool toward an enterprise AI product. Granola has also publicly named customers including Vanta, Gusto, Thumbtack, Asana, Cursor, Lovable, Decagon, and Mistral AI.
That growth changes the stakes. A tool used quietly by one executive presents a compliance problem. A tool integrated with calendars, Slack, Notion, HubSpot, Affinity, Attio, Zapier, and internal knowledge workflows can turn one undisclosed transcript into a broader data-governance issue.
Granola says notes are private by default and that customers choose whether to share them. Its documentation offers private, company-only, and anyone-with-the-link sharing options, while Enterprise administrators can set maximum sharing permissions. Those are sensible controls, but they are downstream controls. They govern who can access notes after a transcript exists, not whether everyone whose words became the transcript was told at the start.
For a company using Granola alongside Microsoft 365, the risk chain can run from a Teams or Zoom call on a managed Windows PC to an AI-generated note, then to Slack, a CRM record, a Notion page, a public link, or an external automation. The organization may have retention labels, sensitivity labels, eDiscovery controls, and data-loss-prevention rules around Teams and SharePoint while missing the locally installed endpoint tool that captured the conversation first.

Windows administrators need controls before a court supplies them​

The Granola case does not establish that every bot-free notetaker is unlawful. Consent law varies by state and country, workplace policies differ, and the complaint still must survive the early procedural stages of federal litigation. What it does establish is that invisible capture cannot be treated as a harmless implementation detail.
Organizations that permit Granola or similar apps should inventory them as recording and transcription tools, not as ordinary note-taking software. That means identifying managed and unmanaged installations, checking whether Windows endpoints can capture system audio, determining which plans are in use, and confirming whether model-training opt-out is centrally enforceable or left to individual users.
They should also require an affirmative meeting-notice workflow that works on every supported platform. Granola’s documented automated notice feature is not a substitute for such a policy on Windows because it is described as a macOS Zoom feature, with Google Meet support paused. Teams and Zoom hosts should know when a participant is using endpoint-level transcription, and customer-facing teams should be prohibited from using hidden capture on calls where the company cannot ensure disclosure.
The lawsuit’s immediate consequence is not a verdict against Granola. It is a warning that the industry’s preferred alternative to visible meeting bots — software quietly recording system audio from a participant’s device — moves disclosure, consent, and model-training accountability from the platform into the hands of each employee. For IT departments, that is a control failure waiting to become a legal one.

References​

  1. Primary source: ppc.land
    Published: 2026-08-01T11:53:36+00:00
  2. Related coverage: docs.granola.ai
  3. Related coverage: docs.granola.ai
  4. Related coverage: jobs.granola.so
  5. Related coverage: granola.ai
  6. Related coverage: jobs.granola.so
  7. Related coverage: granola.ai
  8. Related coverage: speechmark.co
  9. Related coverage: hedy.ai
  10. Related coverage: techcrunch.com
  11. Related coverage: techcrunch.com
  12. Related coverage: seedtable.com
  13. Related coverage: listennotes.com
  14. Related coverage: premieralts.com
  15. Related coverage: founded.com
  16. Related coverage: europealternatives.com
  17. Related coverage: tech.eu
  18. Related coverage: thenextweb.com
  19. Related coverage: siliconangle.com