tl;dv is the most European-looking notetaker in the category. It is a German company, it stores meeting data in EU data centres, and it says it does not train AI on your content. Those are real strengths, and it is a genuinely more sovereign starting point than a US-hosted tool. But its own documents show the caveat behind the EU marketing: its AI providers are US-owned, most of its subprocessors are US companies, and it offers a setting that moves transcript processing to the United States. For a buyer who chose tl;dv specifically to keep data out of US jurisdiction, that gap is worth understanding.
Here is what tl;dv gets right, where the US exposure actually sits, and what a fully sovereign alternative looks like.
Give tl;dv credit: the EU storage claim is real
A post that overstates the case loses trust, so start with what tl;dv gets right. Its security page states that "all our data centers are located in Europe," and names Google Cloud, AWS, Hetzner, and object storage on Wasabi. Its privacy policy locates that infrastructure more precisely, in "Google Cloud data centers, including in Germany," "Wasabi Technologies data centers, including in Germany," and "Hetzner Online data centers, including in Germany and Finland."
The company behind it is European too. tl;dv is operated by Tldx Solutions GmbH, a German limited company registered in Aachen, not a US firm with a European sales page. And on the question that sinks most notetakers, training, tl;dv is clean: its privacy policy states it "does not use Customer Content, including meeting recordings, transcripts, notes, files, or other data processed through the Services, to train, fine-tune, or improve foundation models, large language models, or other generative AI models."
So on storage residency, corporate domicile, and training, tl;dv is meaningfully ahead of the US-hosted notetakers we have looked at in Otter.ai and Fathom. If your bar is "European storage and no training," tl;dv clears it.
Where the US exposure actually sits
Data sovereignty is not decided by where the bytes rest. It is decided by who can reach the data and under whose law. That is where tl;dv's own subprocessor list complicates the EU picture.
The subprocessors named in tl;dv's privacy policy are predominantly US-headquartered companies: the infrastructure and object storage (Google Cloud, Wasabi), payment (Stripe), analytics and monitoring (Mixpanel, Cloudflare, Sentry), support (Intercom), and CRM and workflow tools (HubSpot, Paragon). Most relevant of all, the AI providers tl;dv names are Anthropic and Google's Vertex AI platform, and its security page confirms "we partner with Anthropic." Both are US-owned companies.
This matters because US-owned processors can be compelled to produce data under US law, such as the CLOUD Act, regardless of where the server sits. Storing data in a Frankfurt data centre operated by a US cloud provider does not, on its own, place that data beyond the reach of US legal process directed at the provider. EU regulators have been explicit that data residency and legal jurisdiction are two different questions. tl;dv answers the first well; the second is where the US subprocessors reintroduce exposure.
The US processing option, in tl;dv's own words
There is one more line in tl;dv's privacy policy that a sovereignty buyer should read closely. For AI features, tl;dv states that "limited portions of meeting transcripts may be processed either: within the European Union (e.g. Google Cloud regions located in the EU), or within the United States of America depending on the AI hosting location that you select in your account's preferences," and that these US transfers are covered by "standard data protection clauses adopted or approved by the European Commission."
Read plainly, that means tl;dv can process your meeting transcripts in the US when the account is set to a US AI hosting region. Its security page confirms the choice exists: "you can now choose where your AI is hosted, Europe or the US." The transfer safeguard is Standard Contractual Clauses, the same mechanism every US-hosted tool relies on.
This is not a hidden trapdoor. tl;dv discloses it, and an EU-configured account keeps that processing in Europe. But it does mean the "EU tool" framing rests on configuration, and that the underlying AI capability is delivered by US-owned providers under SCC-based transfers rather than by an EU-owned AI stack.
Data residency answers "where is the data stored." Data sovereignty answers "whose law can reach it." A tool can store everything in Germany and still route it through US-owned processors that sit under US jurisdiction. tl;dv is strong on residency; the open question is sovereignty.
So, is tl;dv GDPR-compliant?
Used with a Data Processing Agreement and an EU AI hosting setting, tl;dv can be operated in a GDPR-compliant way. It markets itself as GDPR-compliant, its data centres are in Europe, and it commits in writing not to train on your data. For many teams that is enough.
The honest caveat is the one its marketing does not lead with. GDPR compliance and full data sovereignty are not the same standard. You can be GDPR-compliant while relying on US-owned subprocessors under Standard Contractual Clauses, because SCCs are a lawful transfer mechanism. What SCCs cannot do is remove your data from the reach of US law. For a buyer in a regulated sector, or a DACH organisation that adopted tl;dv precisely to avoid US jurisdiction, the subprocessor roster is the thing to check against your own transfer impact assessment. Our GDPR-compliant AI meeting assistant comparison scores exactly this: residency for storage and processing, subprocessor jurisdiction, Article 28 DPA terms, transfer impact assessments, and no-training obligations.
The fully sovereign alternative
If the requirement is not just European storage but European jurisdiction end to end, the difference is whether there is a US-owned processor anywhere in the chain. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction on infrastructure you can point to, with no US AI provider in the loop and no training on your data. The meeting bot joins Microsoft Teams and Google Meet through an EU-only pipeline, and the integrations fit how your team already meets.
tl;dv is a good product and an honest step up from the US-hosted notetakers. For a team that chose it for sovereignty, the question is not whether it stores data in Europe. It does. The question is whether US-owned providers in the processing chain leave your meetings reachable under a jurisdiction you were trying to leave behind.