Fireflies.ai
fireflies.aiFireflies.ai is an AI meeting-assistant that records, transcribes, summarizes and analyzes meetings, positioning itself as enterprise SaaS with API/MCP developer surfaces. The consumer Terms of Service grant Fireflies an unusually broad, perpetual, irrevocable, sublicensable license to User Content — which for a meeting recorder means all participants' audio/video — while the Privacy Policy and Section 5(c) of the Terms contain an explicit commitment NOT to use User Content to train generative AI models. However, the consumer Privacy Policy explicitly conducts targeted advertising / 'sharing'/'selling' of personal data, collects a very broad range of PII plus voice/biometric data, and its own text appears truncated (cutting off mid-section), limiting confidence on retention and deletion. Certifications (SOC 2 Type II, GDPR, HIPAA via BAA) are asserted in marketing copy but the policy documents themselves name only limited attestation, and the DPA references a Data Privacy Framework self-certification. Professional users should review carefully and rely on the enterprise agreements (DPA + Business Terms) rather than the consumer Terms before submitting sensitive or proprietary meeting data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The consumer Terms confirm the user retains ownership of their User Content (inputs), but simultaneously require the user to grant Fireflies a broad perpetual, irrevocable, worldwide, sublicensable license to that content. For a meeting recorder, 'your User Content' as a host includes all participants' audio/video streams, which broadens the license's practical reach considerably.
Output Data Ownership
The Terms state that AI Outputs (transcriptions, summaries and other responses) are the user's User Content, meaning the user retains ownership subject to the same broad license granted for inputs. The Terms caution that Outputs may not be unique and users waive claims that another user's similar Output is not unique.
Training Data Usage
Both the consumer Terms and Privacy Policy contain explicit commitments that Fireflies will not use User Content / personal information to train generative AI models, and contractually prohibits its vendors from doing so. Fireflies does reserve the right to derive usage/statistical data and de-identified data for its own business purposes.
Data Retention & Deletion
The Terms commit to deleting copies of User Content within a 'reasonable timeframe' after deletion, subject to backup/archival/legal exceptions and copies remaining in other users' accounts. The Privacy Policy has a Data Retention section referenced in its contents, but the supplied text is truncated before that section, so no specific retention schedules or deletion SLAs are visible. No security-related retention obligations (HIPAA, SOC 2 audit log retention) are stated in the supplied consumer text.
Third-Party Data Sharing
Beyond expected service-provider and integration sharing (which is disclosed and integral to a meeting assistant), the consumer Privacy Policy engages in targeted advertising and expressly acknowledges these activities may constitute 'sharing' or 'selling' under privacy law, including translating email/phone into hashed identifiers passed to advertising partners. This sharing extends beyond what the core meeting-transcription service requires and reaches advertising partners, which warrants a RED rating for the consumer tier.
Opt-Out Rights
The consumer Privacy Policy provides concrete opt-out mechanisms for ad targeting (cookie prompts, a Your Privacy Choices link, a mobile settings path, and a web form for hashed-identifier disclosures) and for marketing emails. However, there is no stated opt-out from core data collection, and opt-outs are browser/device-scoped and require renewal, so control is partial rather than comprehensive.
Compliance & Certifications
Within the policy documents themselves, compliance signals are limited: the consumer Terms reference DMCA and offer a BAA for HIPAA-regulated PHI, and the DPA references a Data Privacy Framework self-certification, GDPR/UK GDPR/CCPA and SCCs. The Business Terms claim independent third-party audits and certifications 'including SOC 2.' Most certification claims (SOC 2 Type II, GDPR, HIPAA) appear in marketing copy without third-party audit reports named in the policies, so frameworks are claimed rather than evidenced with attestations.
Model Explainability & Auditability
The consumer Terms disclose that AI Outputs may be biased, inaccurate or offensive and must be independently verified, providing transparency about model limitations, but offer no mechanism for enterprise auditing of model behavior in the consumer documents. The DPA (enterprise) provides audit rights, but the consumer documents do not describe model explainability or auditability tooling.
Security Practices & Breach History
The consumer Terms require strong/unique passwords and reference a security contact, and the Privacy Policy references a subprocessor trust page, but specific security controls (encryption at rest/in transit, pen testing, bug bounty, incident response) are not detailed in the supplied consumer text. Voice/biometric data is stated to be processed only by service providers and never on Fireflies' own servers. No breach history is disclosed. A trust center (trust.fireflies.ai) and security page are referenced.
Enterprise vs. Consumer Risk Delta
The consumer Terms distinguish Business/Enterprise users who become subject to Business Terms and, for organizations, the DPA. The consumer documents indicate materially different handling for business customers (User Content processed on their behalf is governed by the DPA, not the Privacy Policy), signalling a meaningful delta, but the consumer documents alone do not fully quantify it. Private Cloud/Private Storage options are also referenced for certain subscriptions.
Human Review of User Inputs
The consumer Terms reserve broad rights to take action on User Content (delete, remove, refuse) and disclose that Fireflies may cooperate with law enforcement, but state Fireflies does not review all User Content and disclaims any duty to monitor. Service providers assist with 'analyzing meeting recordings.' There is no explicit blanket right for staff to routinely read prompts, but discretionary access for compliance/rights protection is reserved.
Regulatory & Litigation Exposure
The consumer documents address law-enforcement cooperation and government data requests, and the Terms impose binding individual arbitration with a class-action waiver, a 30-day opt-out, a mass-dispute regime, and a two-year claims limit. These vendor-favorable dispute mechanics plus disclosure to public authorities create moderate exposure considerations for users.
PII & SPI Data Inventory
The consumer Privacy Policy discloses collection of a broad range of PII (name, company, email, phone, physical address, IP, device identifiers, log/usage data, calendar/contact data) plus meeting audio/video content and Voice Data that 'may be considered biometric identifiers or biometric information.' Biometric/voice data is SPI, and combined with targeted advertising and 'sharing/selling' of identifiers, the collection is extensive. Although disclosure exists, the breadth of SPI (voice/biometric, communications content) coupled with advertising-related sharing supports a RED rating for the consumer tier.
Policy–Product Currency
All supplied policy documents carry a 'Last Updated: March 6, 2026' date, well within 12 months of the 2026-07-30 analysis date. The documents substantively address the AI capabilities visible in the product surface (AI transcription/summaries, AI Services, APIs/MCP servers, integrations, third-party model connectors, model training stance), demonstrating coverage of the product actually shipped.
Cross-Document Consistency
Two consumer documents (Terms of Service and Privacy Policy) were supplied and are consistent with each other: both carry the same effective date, both affirm the no-training commitment, and both cross-reference each other and the DPA coherently. No material contradictions were found between the consumer Terms and Privacy Policy on training use, ownership, or sharing.
You've read all 15 risk ratings for Fireflies.ai. Create a free account to see the exact policy wording behind each rating.