Most AI notetaker comparisons rank features: transcript accuracy, summary quality, CRM sync, price. This one ignores all of that and asks a single question a European buyer has to answer first. Where does your meeting data go, and whose law can reach it once it gets there. Judged on sovereignty rather than features, Otter, Fireflies, Fathom, and tl;dv separate cleanly, and the tool that wins on features is rarely the one that wins here.
Below is the matrix, then what each row means, then the honest bottom line, including where all four fall short of full sovereignty.
The sovereignty matrix
Every cell below is drawn from each vendor's own privacy policy, security page, or Data Processing Agreement. Where a vendor offers a genuinely responsible posture, the table says so.
| Criterion | Otter.ai | Fireflies.ai | Fathom | tl;dv |
|---|---|---|---|---|
| Company domicile | US | US | US | Germany (Aachen) |
| Storage residency | US (AWS) | US default; EU on Enterprise only | US | EU (Germany, Finland) |
| Processing residency | US | US (even with EU storage) | US | EU default; US optional setting |
| AI subprocessor jurisdiction | US (OpenAI, Anthropic, Google) | US | US (Anthropic, OpenAI, Google) | US-owned (Anthropic, Google Vertex AI) |
| Trains own AI on your data | Yes (de-identified) | No | Yes (de-identified, opt-out) | No |
| EU transfer mechanism | DPF + SCCs | DPF + SCCs | DPF + SCCs | SCCs |
| Public DPA | Yes | Yes | Yes | On request |
| Consent model | Bot records all participants | Bot plus bot-less recorder | Bot records all participants | Bot records all participants |
Sources: each vendor's privacy policy, security page, and DPA, current as of July 2026. "DPF" is the EU-US Data Privacy Framework; "SCCs" are Standard Contractual Clauses. Subprocessor jurisdiction reflects the corporate ownership of the named AI providers, which determines legal reach even when data is stored in the EU.
Reading the matrix: three tiers, not four tools
The four tools do not spread evenly. They fall into three tiers.
US-hosted, trains on your data: Otter and Fathom. Both store and process everything in the US, both send meeting content to US AI vendors, and both state they train their own in-house AI on de-identified meeting content. Fathom at least offers an opt-out; Otter's training runs by default. For a European buyer, these are the furthest from sovereign. We traced each in detail in where does Otter.ai send your meeting data and Fathom is free, but where does your meeting data go.
US-hosted, does not train: Fireflies. Fireflies deserves credit. Its privacy policy is clear that it does not train on your calls and contractually stops its vendors from doing so, and it publishes a DPA, SOC 2 Type II, and zero-retention terms. The sovereignty problem is jurisdiction, not training: by default it stores and processes in the US, and even its Enterprise EU option keeps storage in the EU while processing still happens in the US. We covered that split in is Fireflies.ai GDPR-compliant.
EU-hosted, does not train, but US-owned processors: tl;dv. tl;dv is the strongest of the four on residency. It is a German company, it stores data in EU data centres, and it commits in writing not to train on your content. The catch is ownership: its AI providers, Anthropic and Google (via Vertex AI), are US-owned, most of its other subprocessors are US companies, and it offers a US AI-hosting option. EU storage with US-owned processors is a real improvement, but it is not the same as removing US jurisdiction. We unpacked that in is tl;dv GDPR-compliant.
Why storage residency is the wrong headline
The most common mistake in these comparisons is to score on storage location alone and stop there. Storage residency answers where the bytes rest. It does not answer who can compel access.
Under laws such as the US CLOUD Act, a US-owned provider can be ordered to produce data it controls regardless of which country the server sits in. So a meeting stored in a Frankfurt data centre, but processed by a US-owned AI provider, is not beyond US legal reach. This is why the matrix separates storage residency, processing residency, and subprocessor jurisdiction into three rows. A tool can pass the first and still fail the third, which is exactly the tl;dv case, and it is the row most feature comparisons never show.
Where is the data stored? Where is it processed? And who owns the processors, because ownership determines whose law applies. A tool is only as sovereign as its weakest of those three answers, not its best.
The consent row applies to all four
One column of the matrix is identical across every tool. All four join calls as a bot that records every participant once a single person enables it, and Fireflies adds a bot-less desktop recorder that removes even the visible signal that recording is happening. In Germany and much of the EU, recording the non-public spoken word without the consent of all participants can be a criminal matter under Section 201 of the Criminal Code, and deploying a notetaker that records employees can trigger works-council co-determination. We set out what that requires in AI notetaker consent in Germany. Whichever tool you pick, the consent obligation is yours, and no US-hosted notetaker removes it for you.
How to score your own shortlist
If you are running your own evaluation, do not start from the feature grid. Start from these five checks, in this order, because a failure high on the list usually cannot be bought back lower down:
- Storage residency. Is meeting data stored in the EU by default, not as an enterprise add-on?
- Processing residency. Is it processed in the EU too, or does the recording travel to the US to be summarised?
- Subprocessor ownership. Are the AI and infrastructure providers EU-owned, or US-owned and reachable under US law?
- Training. Does the vendor train any model, its own included, on your content, even de-identified?
- Consent tooling. Does the tool support all-party consent and works-council requirements, or push the whole burden onto you?
Our GDPR-compliant AI meeting assistant comparison scores the leading tools against these exact criteria, and the 2026 buyer's guide to GDPR-compliant recording covers the statutory background in more depth.
The honest bottom line
On this scorecard, tl;dv is the strongest of the four, and Fireflies is the best of the US-hosted options because it does not train on your calls. But none of the four clears the full sovereignty bar, because every one of them relies on US-owned processors somewhere in the chain. That is the gap Numi was built to close. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction on infrastructure you can point to, with no US AI provider in the loop and no training on your data. The meeting bot joins Microsoft Teams and Google Meet through an EU-only pipeline, and the integrations fit how your team already meets.
If your evaluation ends at features, any of these four will do. If it starts with where your meeting data goes and whose law can reach it, the ranking looks very different, and the tool that keeps the meeting pipeline under EU control end to end is in a category the other four are not.