← Blog

Is Fireflies.ai GDPR-Compliant? Where Your Meeting Recordings Actually Go

    Fireflies.ai can be used in a GDPR-compliant way, with a Data Processing Agreement and the right configuration. But by default it stores and processes meeting data in the United States, and its EU option is enterprise-only and covers storage rather than processing. For a European team that needs meeting data under EU jurisdiction end to end, that gap is the whole story.

    Here is what Fireflies' own documentation says, what it gets genuinely right, and where the sovereignty problem actually sits.

    Where Fireflies stores and processes your data

    Fireflies' own help documentation is direct: "By default, your data is stored and processed in Fireflies' secure cloud infrastructure in the United States (AWS and GCP)." Its security FAQ adds that servers run on Google Cloud and the database sits in a Virtual Private Cloud on AWS. Data is encrypted with AES-256 at rest and TLS in transit.

    There is an EU option, but read it carefully. On the Enterprise plan, Fireflies offers Private Storage, and its documentation states that with it "your data will be stored in the EU, but processed in the US." So the recording still travels to the US to be processed, even when the storage bucket sits in Europe. Storage residency is not processing residency, and under GDPR it is the processing and access that determine jurisdiction, not only where the bytes rest.

    For everyone below Enterprise, both storage and processing are in the US by default.

    Give Fireflies credit: it does not train on your calls

    It would be easy to attack Fireflies on training. It would also be wrong, and a post that overstates loses trust.

    Fireflies' privacy policy says plainly that it does not use personal information to train AI models and that it contractually prohibits its vendors from using the data for their own model training. It describes zero data retention for meeting content, meaning audio, video, transcripts, and summaries are not stored by third-party vendors after processing, not accessed once the service completes, and not used to train internal or external AI models. It publishes SOC 2 Type II, GDPR, and HIPAA (via a BAA on Enterprise) claims, and offers a public DPA.

    That is a genuinely responsible posture on training and retention. So the argument against Fireflies for a sovereignty-minded European buyer is not "they train on your calls." It is jurisdiction and consent.

    So why is it still a sovereignty problem?

    Fireflies.ai Corp. is a US company, and its privacy policy states it processes and stores personal information on servers located in the United States and other countries. Transfers out of the EU rely on the EU-US Data Privacy Framework, which Fireflies self-certifies, plus Standard Contractual Clauses.

    Those are valid mechanisms, but they do the same thing they do for every US vendor: they legitimise moving your data to the US, where it becomes reachable under US law. A self-certification is a company claim, and Data Privacy Framework adequacy remains politically contested after Schrems II. A provider that never moves the data out of the EU does not depend on any of that holding.

    This is exactly the distinction our GDPR-compliant AI meeting assistant comparison scores: data residency for both storage and processing, Article 28 DPA terms, transfer impact assessments, and no-training obligations. A tool can be excellent on retention and training and still leave your data under US jurisdiction.

    The consent problem travels with the bot

    Fireflies joins Zoom, Google Meet, and Microsoft Teams as a bot participant. If any single participant has it enabled, the bot joins and records the entire call, everyone on it included. Fireflies also offers a bot-less desktop recorder, which removes even the visible participant that would otherwise signal to the room that recording is happening.

    In Germany and much of the EU that is a live legal issue, not a preference. Recording the non-public spoken word without the consent of all participants can be a criminal matter, and deploying a notetaker that records employees can trigger works-council co-determination. We cover exactly what that requires in AI notetaker consent in Germany. A tool that records first and asks later puts the consent burden entirely on you.

    The EU alternative

    If the requirement is EU jurisdiction for storage and processing, the fix is a sovereign provider, not an enterprise add-on that half-solves it. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction on infrastructure you can point to. No US processing. No training on your data. The bot joins Microsoft Teams and Google Meet through an EU-only pipeline, and the integrations fit how your team already meets.

    Fireflies gets a lot right, especially on training and retention. For a European team that has to answer for where meeting data is processed and how consent is captured, "stored in the EU, processed in the US" is the sentence that decides it.

    Frequently asked questions

    Is Fireflies.ai GDPR-compliant?

    Fireflies offers a Data Processing Agreement, self-certifies under the EU-US Data Privacy Framework, and holds SOC 2 Type II. You can use it under GDPR with the right paperwork. But by default it stores and processes meeting data in the United States, so European data is transferred to US jurisdiction unless you meet specific enterprise conditions.

    Where does Fireflies.ai store meeting data?

    By Fireflies' own documentation, data is stored and processed in the US by default, on Google Cloud servers with a database in an AWS Virtual Private Cloud. EU data residency is available only on the Enterprise plan, and even then it moves storage to the EU while processing still happens in the US.

    Does Fireflies.ai train AI on my meetings?

    No. Fireflies' privacy policy states it does not use personal information to train AI models and contractually prohibits its vendors from doing so, with zero data retention for meeting content after processing. Its published no-training posture is genuinely strong. The GDPR question with Fireflies is jurisdiction and consent, not model training.

    What is an EU-sovereign alternative to Fireflies.ai?

    A sovereign EU meeting assistant keeps recording, transcription, storage, and processing inside EU jurisdiction, not just storage. Numi runs its meeting bot on Microsoft Teams and Google Meet through an EU-only pipeline, with no US processing and no training on your data.

    Numi keeps meeting data in the EU for both storage and processing, with no US processing and no training on your data, so residency and sovereignty finally line up.

    Get Early Access