← Blog

Otter vs Fireflies vs Fathom vs tl;dv: an EU Data-Sovereignty Comparison

    Most AI notetaker comparisons rank features: transcript accuracy, summary quality, CRM sync, price. This one ignores all of that and asks a single question a European buyer has to answer first. Where does your meeting data go, and whose law can reach it once it gets there. Judged on sovereignty rather than features, Otter, Fireflies, Fathom, and tl;dv separate cleanly, and the tool that wins on features is rarely the one that wins here.

    Below is the matrix, then what each row means, then the honest bottom line, including where all four fall short of full sovereignty.

    The sovereignty matrix

    Every cell below is drawn from each vendor's own privacy policy, security page, or Data Processing Agreement. Where a vendor offers a genuinely responsible posture, the table says so.

    Criterion Otter.ai Fireflies.ai Fathom tl;dv
    Company domicile US US US Germany (Aachen)
    Storage residency US (AWS) US default; EU on Enterprise only US EU (Germany, Finland)
    Processing residency US US (even with EU storage) US EU default; US optional setting
    AI subprocessor jurisdiction US (OpenAI, Anthropic, Google) US US (Anthropic, OpenAI, Google) US-owned (Anthropic, Google Vertex AI)
    Trains own AI on your data Yes (de-identified) No Yes (de-identified, opt-out) No
    EU transfer mechanism DPF + SCCs DPF + SCCs DPF + SCCs SCCs
    Public DPA Yes Yes Yes On request
    Consent model Bot records all participants Bot plus bot-less recorder Bot records all participants Bot records all participants

    Sources: each vendor's privacy policy, security page, and DPA, current as of July 2026. "DPF" is the EU-US Data Privacy Framework; "SCCs" are Standard Contractual Clauses. Subprocessor jurisdiction reflects the corporate ownership of the named AI providers, which determines legal reach even when data is stored in the EU.

    Reading the matrix: three tiers, not four tools

    The four tools do not spread evenly. They fall into three tiers.

    US-hosted, trains on your data: Otter and Fathom. Both store and process everything in the US, both send meeting content to US AI vendors, and both state they train their own in-house AI on de-identified meeting content. Fathom at least offers an opt-out; Otter's training runs by default. For a European buyer, these are the furthest from sovereign. We traced each in detail in where does Otter.ai send your meeting data and Fathom is free, but where does your meeting data go.

    US-hosted, does not train: Fireflies. Fireflies deserves credit. Its privacy policy is clear that it does not train on your calls and contractually stops its vendors from doing so, and it publishes a DPA, SOC 2 Type II, and zero-retention terms. The sovereignty problem is jurisdiction, not training: by default it stores and processes in the US, and even its Enterprise EU option keeps storage in the EU while processing still happens in the US. We covered that split in is Fireflies.ai GDPR-compliant.

    EU-hosted, does not train, but US-owned processors: tl;dv. tl;dv is the strongest of the four on residency. It is a German company, it stores data in EU data centres, and it commits in writing not to train on your content. The catch is ownership: its AI providers, Anthropic and Google (via Vertex AI), are US-owned, most of its other subprocessors are US companies, and it offers a US AI-hosting option. EU storage with US-owned processors is a real improvement, but it is not the same as removing US jurisdiction. We unpacked that in is tl;dv GDPR-compliant.

    Why storage residency is the wrong headline

    The most common mistake in these comparisons is to score on storage location alone and stop there. Storage residency answers where the bytes rest. It does not answer who can compel access.

    Under laws such as the US CLOUD Act, a US-owned provider can be ordered to produce data it controls regardless of which country the server sits in. So a meeting stored in a Frankfurt data centre, but processed by a US-owned AI provider, is not beyond US legal reach. This is why the matrix separates storage residency, processing residency, and subprocessor jurisdiction into three rows. A tool can pass the first and still fail the third, which is exactly the tl;dv case, and it is the row most feature comparisons never show.

    The three questions that decide sovereignty

    Where is the data stored? Where is it processed? And who owns the processors, because ownership determines whose law applies. A tool is only as sovereign as its weakest of those three answers, not its best.

    The consent row applies to all four

    One column of the matrix is identical across every tool. All four join calls as a bot that records every participant once a single person enables it, and Fireflies adds a bot-less desktop recorder that removes even the visible signal that recording is happening. In Germany and much of the EU, recording the non-public spoken word without the consent of all participants can be a criminal matter under Section 201 of the Criminal Code, and deploying a notetaker that records employees can trigger works-council co-determination. We set out what that requires in AI notetaker consent in Germany. Whichever tool you pick, the consent obligation is yours, and no US-hosted notetaker removes it for you.

    How to score your own shortlist

    If you are running your own evaluation, do not start from the feature grid. Start from these five checks, in this order, because a failure high on the list usually cannot be bought back lower down:

    1. Storage residency. Is meeting data stored in the EU by default, not as an enterprise add-on?
    2. Processing residency. Is it processed in the EU too, or does the recording travel to the US to be summarised?
    3. Subprocessor ownership. Are the AI and infrastructure providers EU-owned, or US-owned and reachable under US law?
    4. Training. Does the vendor train any model, its own included, on your content, even de-identified?
    5. Consent tooling. Does the tool support all-party consent and works-council requirements, or push the whole burden onto you?

    Our GDPR-compliant AI meeting assistant comparison scores the leading tools against these exact criteria, and the 2026 buyer's guide to GDPR-compliant recording covers the statutory background in more depth.

    The honest bottom line

    On this scorecard, tl;dv is the strongest of the four, and Fireflies is the best of the US-hosted options because it does not train on your calls. But none of the four clears the full sovereignty bar, because every one of them relies on US-owned processors somewhere in the chain. That is the gap Numi was built to close. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction on infrastructure you can point to, with no US AI provider in the loop and no training on your data. The meeting bot joins Microsoft Teams and Google Meet through an EU-only pipeline, and the integrations fit how your team already meets.

    If your evaluation ends at features, any of these four will do. If it starts with where your meeting data goes and whose law can reach it, the ranking looks very different, and the tool that keeps the meeting pipeline under EU control end to end is in a category the other four are not.

    Frequently asked questions

    Which AI notetaker is best for EU data sovereignty?

    Among Otter, Fireflies, Fathom, and tl;dv, tl;dv is strongest on residency because it stores meeting data in EU data centres and does not train on customer content, though its AI providers are US-owned and it offers a US processing option. Otter, Fireflies, and Fathom store and process data in the US by default. None of the four is US-owned-processor-free end to end, which is the bar a fully sovereign tool has to clear.

    Do these notetakers store meeting data in the EU?

    By default, only tl;dv stores meeting data in the EU. Otter and Fathom store all data in the US with no EU residency option. Fireflies stores and processes in the US by default and offers EU storage only on its Enterprise plan, where processing still happens in the US.

    Which of these tools train AI on your meetings?

    Otter and Fathom both state they train their own in-house AI on de-identified meeting content, with Fathom offering an opt-out. Fireflies and tl;dv both state they do not train AI on customer content. All four contractually restrict their third-party AI vendors from training on the data.

    What makes a notetaker fully data-sovereign?

    A fully data-sovereign meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction, with no US AI provider in the loop and no training on your data. Numi runs its meeting bot on Microsoft Teams and Google Meet through an EU-only pipeline.

    Numi keeps meeting recording, transcription, storage, and analysis under EU jurisdiction, on infrastructure you can point to. No US processing. No training on your data.

    Get Early Access