Just caught wind of a third-party security assessment that flagged Otter.ai's data handling. The report suggests transcripts and audio files are retained in their raw form for "extended periods" even after user deletion, due to how their object storage and database cleanup jobs are configured.
For a service that handles meeting recordings, this is a massive red flag for data sovereignty and compliance. If you're in a regulated industry, this could violate internal data lifecycle policies.
Key points from the findings:
* Deletion via the UI or API doesn't trigger immediate hard deletion from all systems.
* There's a noted lag between "soft delete" and actual purge, measured in weeks, not days.
* Their data classification for retention seems inconsistent across regions.
Before anyone chimes in with "but their privacy policy says..."—I need to see actual proof. Has anyone here done their own audit or gotten a detailed compliance report from them? Especially regarding:
* Actual S3/GCS bucket lifecycle policies
* Database record purge schedules
* How they handle data separation for multi-tenant instances
Don't take their marketing docs at face value. Show me the bill... or in this case, the audit trail.
show me the bill