Fireflies.ai logo

Fireflies.ai

fireflies.ai
High Risk
Updated July 30, 2026

Fireflies.ai is an AI meeting-assistant that records, transcribes, summarizes and analyzes meetings, positioning itself as enterprise SaaS with API/MCP developer surfaces. The consumer Terms of Service grant Fireflies an unusually broad, perpetual, irrevocable, sublicensable license to User Content — which for a meeting recorder means all participants' audio/video — while the Privacy Policy and Section 5(c) of the Terms contain an explicit commitment NOT to use User Content to train generative AI models. However, the consumer Privacy Policy explicitly conducts targeted advertising / 'sharing'/'selling' of personal data, collects a very broad range of PII plus voice/biometric data, and its own text appears truncated (cutting off mid-section), limiting confidence on retention and deletion. Certifications (SOC 2 Type II, GDPR, HIPAA via BAA) are asserted in marketing copy but the policy documents themselves name only limited attestation, and the DPA references a Data Privacy Framework self-certification. Professional users should review carefully and rely on the enterprise agreements (DPA + Business Terms) rather than the consumer Terms before submitting sensitive or proprietary meeting data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The consumer Terms confirm the user retains ownership of their User Content (inputs), but simultaneously require the user to grant Fireflies a broad perpetual, irrevocable, worldwide, sublicensable license to that content. For a meeting recorder, 'your User Content' as a host includes all participants' audio/video streams, which broadens the license's practical reach considerably.

Confidence
80%

Output Data Ownership

Low Risk

The Terms state that AI Outputs (transcriptions, summaries and other responses) are the user's User Content, meaning the user retains ownership subject to the same broad license granted for inputs. The Terms caution that Outputs may not be unique and users waive claims that another user's similar Output is not unique.

Confidence
72%

Training Data Usage

Low Risk

Both the consumer Terms and Privacy Policy contain explicit commitments that Fireflies will not use User Content / personal information to train generative AI models, and contractually prohibits its vendors from doing so. Fireflies does reserve the right to derive usage/statistical data and de-identified data for its own business purposes.

Confidence
85%

Data Retention & Deletion

Moderate Risk

The Terms commit to deleting copies of User Content within a 'reasonable timeframe' after deletion, subject to backup/archival/legal exceptions and copies remaining in other users' accounts. The Privacy Policy has a Data Retention section referenced in its contents, but the supplied text is truncated before that section, so no specific retention schedules or deletion SLAs are visible. No security-related retention obligations (HIPAA, SOC 2 audit log retention) are stated in the supplied consumer text.

Confidence
45%

Third-Party Data Sharing

High Risk

Beyond expected service-provider and integration sharing (which is disclosed and integral to a meeting assistant), the consumer Privacy Policy engages in targeted advertising and expressly acknowledges these activities may constitute 'sharing' or 'selling' under privacy law, including translating email/phone into hashed identifiers passed to advertising partners. This sharing extends beyond what the core meeting-transcription service requires and reaches advertising partners, which warrants a RED rating for the consumer tier.

Confidence
72%

Opt-Out Rights

Moderate Risk

The consumer Privacy Policy provides concrete opt-out mechanisms for ad targeting (cookie prompts, a Your Privacy Choices link, a mobile settings path, and a web form for hashed-identifier disclosures) and for marketing emails. However, there is no stated opt-out from core data collection, and opt-outs are browser/device-scoped and require renewal, so control is partial rather than comprehensive.

Confidence
68%

Compliance & Certifications

Moderate Risk

Within the policy documents themselves, compliance signals are limited: the consumer Terms reference DMCA and offer a BAA for HIPAA-regulated PHI, and the DPA references a Data Privacy Framework self-certification, GDPR/UK GDPR/CCPA and SCCs. The Business Terms claim independent third-party audits and certifications 'including SOC 2.' Most certification claims (SOC 2 Type II, GDPR, HIPAA) appear in marketing copy without third-party audit reports named in the policies, so frameworks are claimed rather than evidenced with attestations.

Confidence
60%

Model Explainability & Auditability

Moderate Risk

The consumer Terms disclose that AI Outputs may be biased, inaccurate or offensive and must be independently verified, providing transparency about model limitations, but offer no mechanism for enterprise auditing of model behavior in the consumer documents. The DPA (enterprise) provides audit rights, but the consumer documents do not describe model explainability or auditability tooling.

Confidence
50%

Security Practices & Breach History

Moderate Risk

The consumer Terms require strong/unique passwords and reference a security contact, and the Privacy Policy references a subprocessor trust page, but specific security controls (encryption at rest/in transit, pen testing, bug bounty, incident response) are not detailed in the supplied consumer text. Voice/biometric data is stated to be processed only by service providers and never on Fireflies' own servers. No breach history is disclosed. A trust center (trust.fireflies.ai) and security page are referenced.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The consumer Terms distinguish Business/Enterprise users who become subject to Business Terms and, for organizations, the DPA. The consumer documents indicate materially different handling for business customers (User Content processed on their behalf is governed by the DPA, not the Privacy Policy), signalling a meaningful delta, but the consumer documents alone do not fully quantify it. Private Cloud/Private Storage options are also referenced for certain subscriptions.

Confidence
60%

Human Review of User Inputs

Moderate Risk

The consumer Terms reserve broad rights to take action on User Content (delete, remove, refuse) and disclose that Fireflies may cooperate with law enforcement, but state Fireflies does not review all User Content and disclaims any duty to monitor. Service providers assist with 'analyzing meeting recordings.' There is no explicit blanket right for staff to routinely read prompts, but discretionary access for compliance/rights protection is reserved.

Confidence
55%

Regulatory & Litigation Exposure

Moderate Risk

The consumer documents address law-enforcement cooperation and government data requests, and the Terms impose binding individual arbitration with a class-action waiver, a 30-day opt-out, a mass-dispute regime, and a two-year claims limit. These vendor-favorable dispute mechanics plus disclosure to public authorities create moderate exposure considerations for users.

Confidence
68%

PII & SPI Data Inventory

High Risk

The consumer Privacy Policy discloses collection of a broad range of PII (name, company, email, phone, physical address, IP, device identifiers, log/usage data, calendar/contact data) plus meeting audio/video content and Voice Data that 'may be considered biometric identifiers or biometric information.' Biometric/voice data is SPI, and combined with targeted advertising and 'sharing/selling' of identifiers, the collection is extensive. Although disclosure exists, the breadth of SPI (voice/biometric, communications content) coupled with advertising-related sharing supports a RED rating for the consumer tier.

Confidence
70%

Policy–Product Currency

Low Risk

All supplied policy documents carry a 'Last Updated: March 6, 2026' date, well within 12 months of the 2026-07-30 analysis date. The documents substantively address the AI capabilities visible in the product surface (AI transcription/summaries, AI Services, APIs/MCP servers, integrations, third-party model connectors, model training stance), demonstrating coverage of the product actually shipped.

Confidence
80%

Cross-Document Consistency

Low Risk

Two consumer documents (Terms of Service and Privacy Policy) were supplied and are consistent with each other: both carry the same effective date, both affirm the no-training commitment, and both cross-reference each other and the DPA coherently. No material contradictions were found between the consumer Terms and Privacy Policy on training use, ownership, or sharing.

Confidence
70%

You've read all 15 risk ratings for Fireflies.ai. Create a free account to see the exact policy wording behind each rating.