Otter.ai stores and processes meeting data in the United States, transfers European data to the US under the EU-US Data Privacy Framework and Standard Contractual Clauses, and trains its own proprietary AI on de-identified transcripts that its policy says may still contain personal information. For teams that need meeting data to stay under EU jurisdiction, that is the problem in one sentence.
Below is what Otter's own documents say about where your meeting data goes, why it matters under GDPR, and what an EU-sovereign alternative looks like.
Where Otter.ai stores your meeting data
Otter's published subprocessor list (effective March 2026) names Amazon Web Services as its cloud and customer-data storage provider, located in the United States. The privacy policy (updated June 2026) confirms it relies on cloud providers "based in the United States." Data at rest is encrypted with AES-256 on AWS.
What is not there matters as much as what is. Otter does not disclose any EU or EEA data-residency option on its security, privacy, or subprocessor pages. There is no European region you can select. For a European customer, the practical effect is simple: your meeting audio and transcripts are transferred to and held in the US.
The rest of the subprocessor chain points the same direction. Every subprocessor Otter lists is US-based, including two US frontier-model vendors, OpenAI and Anthropic, alongside Google Cloud and other US services. So it is not only storage that sits in the US. The vendors touching the data do too.
Does Otter train its AI on your conversations?
This is the point most write-ups get wrong, so it is worth being precise.
Otter's privacy policy states that it trains its own proprietary AI technology on de-identified audio recordings and on transcriptions, and it adds that those transcriptions "may contain Personal Information." That is Otter describing its own practice, in its own words.
Separately, Otter says it does not let its third-party AI providers train on the data: its security page states that no customer data is used to train the AI models of its service providers. Both things are true at once. Third-party vendors are contractually restricted, while Otter's own model improvement uses de-identified content that the policy concedes can still carry personal information.
De-identification is not the safe harbour it sounds like. Regulators and courts increasingly reject the idea that stripping obvious identifiers anonymises voice and conversation data, and Otter's own wording admits the training material may still contain personal information. If your meetings include client names, deal terms, or personal circumstances, "de-identified" is doing a lot of work.
How EU meeting data reaches the US
For European customers, Otter relies on the EU-US Data Privacy Framework, the UK Extension, and the Swiss-US Data Privacy Framework, and it uses Standard Contractual Clauses for transfers outside the EEA. Those are genuine, currently valid legal mechanisms.
The catch is what they are for. They exist to legitimise sending data to the US, not to keep it in Europe. After Schrems II struck down Privacy Shield, transfers to US processors depend on adequacy decisions that remain politically contested plus contractual clauses that shift risk onto paper. Your data still leaves EU jurisdiction and becomes reachable under US law. That is a structurally different position from a provider that never moves the data out of the EU in the first place.
The real-world risk is not hypothetical
Two well-documented events show why "where does the data go" is a practical question, not a compliance abstraction.
In September 2024, an engineer reported that after a video call ended, Otter emailed a full transcript, including hours of private post-meeting conversation, to every invitee. The recording had kept going after the participants thought the meeting was over. It was widely reported and, by his account, cost a deal.
Separately, a US class action was consolidated in October 2025 (In re Otter.AI Privacy Litigation) alleging that Otter recorded people who never consented and used the data to train AI. The plaintiffs were reportedly non-users, people who were simply in a meeting someone else had Otter running in. These allegations are unproven in court, and should be read as claims rather than findings, but the shape of the risk is clear: a US-hosted notetaker recording every participant creates exposure for everyone in the room, not just the account holder.
The free plan carries the same exposure
If you are using Otter's free tier because "it is just notes," the data posture does not improve. The same US storage, the same US subprocessors, the same Data Privacy Framework and SCC transfer model, and the same training language in the privacy policy apply across tiers. Stronger controls, such as disabling AI features, are enterprise-level and go through an account manager.
We wrote more about this pattern in the hidden cost of free AI notetakers: the price of a free notetaker is usually paid in data exposure rather than euros.
The EU alternative
If the requirement is that meeting data stays under EU jurisdiction, the answer is not a better US vendor, it is a sovereign one. Numi's meeting assistant keeps recording, transcription, storage, and analysis inside EU jurisdiction on infrastructure you can point to. No US processing. No training on your data. The meeting bot joins Microsoft Teams and Google Meet through an EU-only pipeline, and the integrations work the way your team already meets.
If you are comparing tools formally, our GDPR-compliant AI meeting assistant comparison scores the leading options against the five criteria that actually decide compliance: data residency, on-device transcription, Article 28 DPA terms, transfer impact assessments, and no-training obligations.
Otter is a capable product. For European teams that answer to GDPR and to their own customers, the question is not whether it transcribes well. It is where your meeting data lives, who can reach it, and what it is used for once it gets there.