Granola, the AI meeting-notetaking app built around recording calls without adding a visible bot, is facing a proposed federal class action accusing it of secretly intercepting participants’ conversations and using the resulting material for AI model training by default. The complaint, filed July 30 in the U.S. District Court for the Northern District of California, puts a legal problem squarely on a product feature Granola has marketed as an advantage: other people in the meeting may not know the tool is running.
PPC Land first reported the case, Chamberlain v. Granola, Inc. and Granola Labs Ltd., brought by Florida resident Tarra Chamberlain on behalf of a proposed nationwide class and California subclass. The suit alleges violations of the federal Electronic Communications Privacy Act, California’s Invasion of Privacy Act, California’s computer-data-access law, and common-law privacy rights, among other claims. Granola had not publicly responded to the allegations as of August 2.
This is an allegation, not a ruling. But Granola’s own current documentation confirms the factual design choice at the center of the dispute: its desktop app captures a user’s microphone and system audio locally, does not join a call as a bot, and leaves consent to the customer using the product. Its documentation also says anonymized data on Free and Business plans may be used for Granola’s own model improvements unless users opt out.
For Windows administrators and IT teams, the important point is more immediate than the lawsuit’s final outcome: “no stored recording” is not the same thing as “no recording risk.” If audio is captured and sent for real-time transcription, the alleged interception has already happened before the vendor deletes an audio cache or reduces the conversation to a transcript.
Granola’s product works differently from meeting assistants that appear in Zoom, Teams, or Google Meet as a named attendee. Its software runs on the user’s device and captures microphone input plus the computer’s system audio. The result is a transcript and AI-generated notes without a bot appearing in the participant list or triggering the familiar platform-level recording warning.
Granola presents that approach as a privacy and usability benefit. Its support material says no additional attendee is visible to other participants, while its product marketing has explicitly promoted “no bot” and “no notification” as characteristics of its meeting assistant. The company says the design avoids turning a live conversation into a performance for a conspicuous recording agent.
The complaint argues that this is precisely the problem. It alleges Granola’s design permits a participant to transcribe a conversation without notifying everyone else in the call, including people who have no Granola account, no contractual relationship with the company, and no practical way to know their words are being captured.
Granola’s own consent documentation makes a critical distinction that should concern Windows deployments. It says users are responsible for obtaining consent where the law requires it and recommends consent regardless of legal obligation. The automated consent-message feature described in that documentation is currently limited to Zoom on macOS; Granola says it has paused Google Meet support while it works on a replacement. Its documentation does not describe an equivalent automatic meeting-chat notification for the Windows desktop app.
That leaves a Windows user with the product’s core capability — capture of system audio across meeting platforms — but without the documented macOS-and-Zoom automated notice mechanism. A company cannot treat a general employee reminder to “follow applicable law” as a technical control. It is a policy instruction handed to the person with the least incentive to interrupt a sales call, interview, customer escalation, or executive meeting.
That may reduce the damage from a breach involving a stored audio archive. It does not necessarily answer the statutes cited in the complaint. California Penal Code section 632, for example, addresses intentional recording of confidential communications without the consent of all parties; the core dispute will include whether the conversations at issue were “confidential,” what consent was required, and whether Granola can be treated as responsible for the customer’s act of recording.
The complaint also invokes California Penal Code section 631, which covers certain forms of interception and use of communications, as well as the federal wiretap law. Those claims will face difficult questions: whether Granola is merely a service provider acting for a participating user, whether the application acquired the communication contemporaneously enough to constitute interception, and which jurisdiction’s consent rule applies when participants are scattered across states or countries.
But Granola’s “we delete the audio” answer is aimed at a different question — post-call retention. The legal exposure alleged here begins during the call, at the moment the app captures system audio and routes it for transcription. In practical security terms, deleting the original after the transcript is produced does not undo the disclosure of the conversation to Granola, its transcription infrastructure, or any downstream AI processing covered by the service.
The distinction is especially relevant for Teams users. Microsoft Teams can present its own recording or transcription notices when Teams-native features are used, but a locally installed application capturing Windows system audio operates outside that normal in-meeting disclosure path. A tenant’s Teams recording policy does not automatically prove that an endpoint-level notetaker disclosed itself to call participants.
Granola’s current security and privacy documentation supports the broad outline of that policy. It says anonymized data on Free and Business plans may be used to improve Granola’s services; users can disable the setting in their preferences. The company also says third-party AI providers such as OpenAI and Anthropic are contractually prohibited from training on Granola customer data.
That distinction is meaningful but incomplete. Preventing OpenAI or Anthropic from training on meeting content does not prevent Granola from using de-identified material for its own training or product-improvement work. For organizations that adopted Granola on the assumption that “our data is not used to train AI,” the relevant question is whose AI the policy excludes.
Granola says enterprise customers are opted out of model training by default and that Enterprise administrators can set the policy organization-wide. Business-plan customers do not receive the same control: Granola’s documentation says each user must opt out individually. That makes a user’s privacy preference dependent on every individual employee finding and changing the setting, even though the conversations can involve customers, job candidates, suppliers, lawyers, consultants, and other people outside the workspace.
The alleged consent gap becomes wider for those non-users. A person speaking on a call may have no Granola account and no ability to see a workspace’s data setting, turn off model training, or request that a user disable transcription before a meeting begins. The complaint’s most durable theory may rest there: an account holder can at least be offered a setting, while the people whose voices the account holder records cannot.
Granola acknowledges another practical limitation in its FAQ: after an opt-out is changed, it cannot guarantee that anonymized data was not used before the setting changed. That is not unusual for machine-learning systems, where previously incorporated data may be difficult or impossible to isolate without retraining. Yet it means opt-out is a forward-looking control, not a way to claw back conversations already processed under the default.
That growth changes the stakes. A tool used quietly by one executive presents a compliance problem. A tool integrated with calendars, Slack, Notion, HubSpot, Affinity, Attio, Zapier, and internal knowledge workflows can turn one undisclosed transcript into a broader data-governance issue.
Granola says notes are private by default and that customers choose whether to share them. Its documentation offers private, company-only, and anyone-with-the-link sharing options, while Enterprise administrators can set maximum sharing permissions. Those are sensible controls, but they are downstream controls. They govern who can access notes after a transcript exists, not whether everyone whose words became the transcript was told at the start.
For a company using Granola alongside Microsoft 365, the risk chain can run from a Teams or Zoom call on a managed Windows PC to an AI-generated note, then to Slack, a CRM record, a Notion page, a public link, or an external automation. The organization may have retention labels, sensitivity labels, eDiscovery controls, and data-loss-prevention rules around Teams and SharePoint while missing the locally installed endpoint tool that captured the conversation first.
Organizations that permit Granola or similar apps should inventory them as recording and transcription tools, not as ordinary note-taking software. That means identifying managed and unmanaged installations, checking whether Windows endpoints can capture system audio, determining which plans are in use, and confirming whether model-training opt-out is centrally enforceable or left to individual users.
They should also require an affirmative meeting-notice workflow that works on every supported platform. Granola’s documented automated notice feature is not a substitute for such a policy on Windows because it is described as a macOS Zoom feature, with Google Meet support paused. Teams and Zoom hosts should know when a participant is using endpoint-level transcription, and customer-facing teams should be prohibited from using hidden capture on calls where the company cannot ensure disclosure.
The lawsuit’s immediate consequence is not a verdict against Granola. It is a warning that the industry’s preferred alternative to visible meeting bots — software quietly recording system audio from a participant’s device — moves disclosure, consent, and model-training accountability from the platform into the hands of each employee. For IT departments, that is a control failure waiting to become a legal one.
This is an allegation, not a ruling. But Granola’s own current documentation confirms the factual design choice at the center of the dispute: its desktop app captures a user’s microphone and system audio locally, does not join a call as a bot, and leaves consent to the customer using the product. Its documentation also says anonymized data on Free and Business plans may be used for Granola’s own model improvements unless users opt out.
For Windows administrators and IT teams, the important point is more immediate than the lawsuit’s final outcome: “no stored recording” is not the same thing as “no recording risk.” If audio is captured and sent for real-time transcription, the alleged interception has already happened before the vendor deletes an audio cache or reduces the conversation to a transcript.
The bot-free design is the legal pressure point
Granola’s product works differently from meeting assistants that appear in Zoom, Teams, or Google Meet as a named attendee. Its software runs on the user’s device and captures microphone input plus the computer’s system audio. The result is a transcript and AI-generated notes without a bot appearing in the participant list or triggering the familiar platform-level recording warning.Granola presents that approach as a privacy and usability benefit. Its support material says no additional attendee is visible to other participants, while its product marketing has explicitly promoted “no bot” and “no notification” as characteristics of its meeting assistant. The company says the design avoids turning a live conversation into a performance for a conspicuous recording agent.
The complaint argues that this is precisely the problem. It alleges Granola’s design permits a participant to transcribe a conversation without notifying everyone else in the call, including people who have no Granola account, no contractual relationship with the company, and no practical way to know their words are being captured.
Granola’s own consent documentation makes a critical distinction that should concern Windows deployments. It says users are responsible for obtaining consent where the law requires it and recommends consent regardless of legal obligation. The automated consent-message feature described in that documentation is currently limited to Zoom on macOS; Granola says it has paused Google Meet support while it works on a replacement. Its documentation does not describe an equivalent automatic meeting-chat notification for the Windows desktop app.
That leaves a Windows user with the product’s core capability — capture of system audio across meeting platforms — but without the documented macOS-and-Zoom automated notice mechanism. A company cannot treat a general employee reminder to “follow applicable law” as a technical control. It is a policy instruction handed to the person with the least incentive to interrupt a sales call, interview, customer escalation, or executive meeting.
Real-time transcription does not erase the interception question
Granola says it does not retain meeting audio after transcription. On desktop, the company says it transcribes in real time and stores the transcript and notes rather than an enduring audio file. On mobile, it says audio is cached temporarily during transcription and then deleted.That may reduce the damage from a breach involving a stored audio archive. It does not necessarily answer the statutes cited in the complaint. California Penal Code section 632, for example, addresses intentional recording of confidential communications without the consent of all parties; the core dispute will include whether the conversations at issue were “confidential,” what consent was required, and whether Granola can be treated as responsible for the customer’s act of recording.
The complaint also invokes California Penal Code section 631, which covers certain forms of interception and use of communications, as well as the federal wiretap law. Those claims will face difficult questions: whether Granola is merely a service provider acting for a participating user, whether the application acquired the communication contemporaneously enough to constitute interception, and which jurisdiction’s consent rule applies when participants are scattered across states or countries.
But Granola’s “we delete the audio” answer is aimed at a different question — post-call retention. The legal exposure alleged here begins during the call, at the moment the app captures system audio and routes it for transcription. In practical security terms, deleting the original after the transcript is produced does not undo the disclosure of the conversation to Granola, its transcription infrastructure, or any downstream AI processing covered by the service.
The distinction is especially relevant for Teams users. Microsoft Teams can present its own recording or transcription notices when Teams-native features are used, but a locally installed application capturing Windows system audio operates outside that normal in-meeting disclosure path. A tenant’s Teams recording policy does not automatically prove that an endpoint-level notetaker disclosed itself to call participants.
The model-training setting exposes people who cannot opt out
The recording allegation is only half of the case. PPC Land reports that Chamberlain’s complaint also challenges Granola’s use of captured data to improve its own models, saying that model training is enabled by default on Free and Business plans and requires a user-level opt-out.Granola’s current security and privacy documentation supports the broad outline of that policy. It says anonymized data on Free and Business plans may be used to improve Granola’s services; users can disable the setting in their preferences. The company also says third-party AI providers such as OpenAI and Anthropic are contractually prohibited from training on Granola customer data.
That distinction is meaningful but incomplete. Preventing OpenAI or Anthropic from training on meeting content does not prevent Granola from using de-identified material for its own training or product-improvement work. For organizations that adopted Granola on the assumption that “our data is not used to train AI,” the relevant question is whose AI the policy excludes.
Granola says enterprise customers are opted out of model training by default and that Enterprise administrators can set the policy organization-wide. Business-plan customers do not receive the same control: Granola’s documentation says each user must opt out individually. That makes a user’s privacy preference dependent on every individual employee finding and changing the setting, even though the conversations can involve customers, job candidates, suppliers, lawyers, consultants, and other people outside the workspace.
The alleged consent gap becomes wider for those non-users. A person speaking on a call may have no Granola account and no ability to see a workspace’s data setting, turn off model training, or request that a user disable transcription before a meeting begins. The complaint’s most durable theory may rest there: an account holder can at least be offered a setting, while the people whose voices the account holder records cannot.
Granola acknowledges another practical limitation in its FAQ: after an opt-out is changed, it cannot guarantee that anonymized data was not used before the setting changed. That is not unusual for machine-learning systems, where previously incorporated data may be difficult or impossible to isolate without retraining. Yet it means opt-out is a forward-looking control, not a way to claw back conversations already processed under the default.
The dispute arrives as Granola pushes deeper into business workflows
Granola is no longer a small personal productivity app operating at the edge of enterprise IT. In March, the company announced a $125 million Series C financing at a $1.5 billion valuation; TechCrunch independently reported the round and Granola’s expansion from an individual note-taking tool toward an enterprise AI product. Granola has also publicly named customers including Vanta, Gusto, Thumbtack, Asana, Cursor, Lovable, Decagon, and Mistral AI.That growth changes the stakes. A tool used quietly by one executive presents a compliance problem. A tool integrated with calendars, Slack, Notion, HubSpot, Affinity, Attio, Zapier, and internal knowledge workflows can turn one undisclosed transcript into a broader data-governance issue.
Granola says notes are private by default and that customers choose whether to share them. Its documentation offers private, company-only, and anyone-with-the-link sharing options, while Enterprise administrators can set maximum sharing permissions. Those are sensible controls, but they are downstream controls. They govern who can access notes after a transcript exists, not whether everyone whose words became the transcript was told at the start.
For a company using Granola alongside Microsoft 365, the risk chain can run from a Teams or Zoom call on a managed Windows PC to an AI-generated note, then to Slack, a CRM record, a Notion page, a public link, or an external automation. The organization may have retention labels, sensitivity labels, eDiscovery controls, and data-loss-prevention rules around Teams and SharePoint while missing the locally installed endpoint tool that captured the conversation first.
Windows administrators need controls before a court supplies them
The Granola case does not establish that every bot-free notetaker is unlawful. Consent law varies by state and country, workplace policies differ, and the complaint still must survive the early procedural stages of federal litigation. What it does establish is that invisible capture cannot be treated as a harmless implementation detail.Organizations that permit Granola or similar apps should inventory them as recording and transcription tools, not as ordinary note-taking software. That means identifying managed and unmanaged installations, checking whether Windows endpoints can capture system audio, determining which plans are in use, and confirming whether model-training opt-out is centrally enforceable or left to individual users.
They should also require an affirmative meeting-notice workflow that works on every supported platform. Granola’s documented automated notice feature is not a substitute for such a policy on Windows because it is described as a macOS Zoom feature, with Google Meet support paused. Teams and Zoom hosts should know when a participant is using endpoint-level transcription, and customer-facing teams should be prohibited from using hidden capture on calls where the company cannot ensure disclosure.
The lawsuit’s immediate consequence is not a verdict against Granola. It is a warning that the industry’s preferred alternative to visible meeting bots — software quietly recording system audio from a participant’s device — moves disclosure, consent, and model-training accountability from the platform into the hands of each employee. For IT departments, that is a control failure waiting to become a legal one.
References
- Primary source: ppc.land
Published: 2026-08-01T11:53:36+00:00
Granola sued for recording meetings without consent to train AI models
Filed July 30 in California, the complaint says Granola hides its notetaker from participants by design, a practice raising wiretapping questions for marketers.ppc.land
- Related coverage: docs.granola.ai
Models & training - Granola Docs & Help Center
How Granola uses your data for AI model training. Opt out, workspace controls, and data usage transparency.docs.granola.ai - Related coverage: docs.granola.ai
Security, Privacy & Data FAQs - Granola Docs & Help Center
Answers to common questions about Granola's security practices, data storage, privacy controls, GDPR compliance, and enterprise features.docs.granola.ai - Related coverage: jobs.granola.so
- Related coverage: granola.ai
Is it safe to record meetings with AI tools? A buyer's safety checklist for 2026 | Granola
Recording meetings with AI tools is safe when you choose vendors that prioritize privacy through architecture, not just policy.www.granola.ai - Related coverage: jobs.granola.so
AI Meeting Assistant - Without the Bot | Granola
Meet Granola, an AI meeting assistant that works without a bot. Capture meetings locally, create editable notes, and act on every conversation.jobs.granola.so - Related coverage: granola.ai
Is your organization ready for an enterprise AI notetaker? Readiness assessment | Granola
Enterprise AI notetaker readiness requires assessing research volume, compliance obligations, and IT infrastructure before vendor selection.www.granola.ai - Related coverage: speechmark.co
Does Granola Save Your Recordings? — Speechmark
No — Granola deletes meeting audio once transcription finishes, while transcripts and notes sync to its cloud. What that means for replay and privacy.
www.speechmark.co
- Related coverage: hedy.ai
- Related coverage: techcrunch.com
Granola raises $125M, hits $1.5B valuation as it expands from meeting notetaker to enterprise AI app | TechCrunch
Granola's valuation jumped from $250 million to $1.5 billion with this round, and it has added more support for AI agents after users previously complained.techcrunch.com - Related coverage: techcrunch.com
VCs love using the AI meeting notepad Granola, so they gave it $20M | TechCrunch
Granola's notepad app has become a popular tool among venture capitalists who use it to record meetings and augment notes using AI technology. That madetechcrunch.com - Related coverage: seedtable.com
Granola Funding Rounds | Seedtable
Granola has raised 192.3M USD across 4 funding rounds — latest: Series C (125.0M USD) in Mar 2026. Full history with stages, dates, investors and valuations on Seedtable.seedtable.com - Related coverage: listennotes.com
Granola raised $125 million Series C at a $1.5 billion valuation: Sam Stephenson, Co-founder
00:21:44 - Granola has just raised a $125 million Series C at a $1.5 billion valuation, becoming one of Europe’s newest AI unicorns, after spreading from VCs a…www.listennotes.com - Related coverage: premieralts.com
Granola Valuation 2026: $1.5B | Private Company Worth
How much is Granola worth? Current valuation: $1.5B | Total funding raised: $192.3M | 2 funding rounds | Latest: Later Stage VC | Industry: Business/Productivity Software. Track Granola valuation history, funding timeline, and implied market value from secondary transactions.www.premieralts.com - Related coverage: founded.com
- Related coverage: europealternatives.com
Granola raises $125M Series C | Europe Alternatives | Europe Alternatives
London-based Granola raised $125M in a Series C led by Index Ventures at a $1.5B valuation.europealternatives.com
- Related coverage: tech.eu
Granola raises $125M at $1.5BN valuation - Tech.eu
The funding round increases Granola's valuation from $250m last year to $1.5bn.tech.eu - Related coverage: thenextweb.com
London’s Granola raises $125M to turn meeting recordings into enterprise AI infrastructure
Granola, the London-based AI meeting app that records conversations without dropping a bot into the call, has raised $125 million in a Series C round led by Danny Rimer at Index Ventures, with participation from Mamoon Hamid at Kleiner Perkthenextweb.com - Related coverage: siliconangle.com
Granola raises $125M at $1.5B valuation for its AI note-taking app - SiliconANGLE
Granola raises $125M at $1.5B valuation for its AI note-taking app - SiliconANGLE
siliconangle.com