Sally - AI Meeting Assistant

MARCH 2025 · Updated JULY 2026

Fireflies.ai GDPR and Data Protection: Visible Bot, Risky Data Transfers

Fireflies.ai GDPR and Data Protection: We’ve looked into why Fireflies is so popular ✓ and what that means for data protection ✓.

Network of security padlocks with the Fireflies.ai logo, on Fireflies.ai GDPR and data security

Fireflies.ai GDPR and Data Protection: The Basic Problem

Fireflies.ai is an AI-powered meeting assistant that automatically records, transcribes, and summarizes conversations. It joins meetings as a visible bot, a positive step for transparency under GDPR, and it holds recognized certifications: Fireflies is SOC 2 Type II compliant, states it aligns with GDPR, and offers HIPAA compliance for Enterprise customers. However, like many US-based services, Fireflies stores and processes data primarily in the United States by default. This creates significant challenges for organizations that must comply with European privacy laws.

Certifications and encryption at a glance

  • SOC 2 Type II: independently audited controls for security, availability, and confidentiality
  • GDPR: Fireflies states it maintains data protection standards in line with European regulations
  • HIPAA: available only on the Enterprise plan, requiring Private Storage and a signed Business Associate Agreement (BAA)
  • Encryption: 256-bit AES at rest and TLS in transit
  • No AI training by default: Fireflies states it does not train its models on your content

How Fireflies.ai Works: Visible Bot Is an Advantage

Fireflies connects to meetings through bot integration. The bot appears in the participant list and is usually labeled to indicate its recording or transcription function. This visibility helps alert participants that the meeting is being documented.

The following data may be processed:

  • Spoken content (converted to text)
  • Speaker identity and timestamps
  • Contextual meeting data (e.g. title, date, attendees)
  • Additional integrations with calendars, CRM systems, and collaboration tools

While this visibility improves transparency, it does not replace the need for legal consent.

Fireflies.ai GDPR and Data Protection: Visibility isn't Enough

Having a visible bot is helpful, but it’s not a free pass. Under GDPR, users must still fulfill strict transparency and consent requirements:

  • Article 5(1)(a): Processing must be lawful, fair, and transparent
  • Article 13: Data subjects must be informed
  • Article 6: A legal basis (such as consent or legitimate interest) is required

Organizers should inform all participants before or at the start of the meeting and obtain consent, especially during sensitive conversations. Our GDPR checklist for AI meeting assistants walks through these steps in detail.

Fireflies.ai Datenschutz

Servers Outside the EU: A Major Concern

By default, Fireflies.ai stores and processes user data in the US on AWS and Google Cloud infrastructure. EU data residency is possible, but only through the Private Storage option on the Enterprise plan, so it is not available to standard users.

There is one nuance that European organizations should not overlook: even when you enable EU Private Storage, Fireflies states that your data is stored in the EU but still processed and accessed in the US. In other words, EU residency covers where the data rests, not where it is worked on. Fireflies also offers a Bring-Your-Own-Storage option (AWS S3 or Google Cloud Storage) on Enterprise deals.

Why this matters:

  • The US is not considered a fully safe third country under EU law (per Schrems II)
  • US authorities may access data under laws such as the CLOUD Act
  • GDPR requires safeguards for international data transfers (e.g. SCCs or DPF membership)

Without contractual protections and strong technical measures, using Fireflies can be risky for EU-based companies.

Fireflies.ai vs. a GDPR-first alternative

The table below compares Fireflies.ai with Sally, an alternative built EU-first:

CriterionFireflies.aiSally
Default data storageUnited States (AWS, Google Cloud)Germany (EU)
Default data processingUnited StatesEuropean Union
EU data residencyEnterprise plan only (Private Storage); still processed in the USStandard for all customers
CertificationsSOC 2 Type II, GDPR, HIPAA (Enterprise)GDPR compliant, hosted in Germany
Encryption256-bit AES at rest, TLS in transitEncrypted in transit and at rest
Visible botYesYes
Supported platformsZoom, Microsoft Teams, Google Meet, WebexZoom, Microsoft Teams, Google Meet, Webex

Fireflies.ai GDPR and Data Protection: Where the Difficulties Lie

Fireflies offers more transparency than many tools thanks to its visible bot. However, GDPR-compliant use still requires:

  • Consent from all participants for data processing
  • Contractual safeguards such as Standard Contractual Clauses (SCCs)
  • Technical and organizational security measures

Smaller companies may find these steps hard to implement in day-to-day operations.

Fireflies.ai DSGVO

Fireflies.ai GDPR and Data Protection: Theory vs. Practice

In practice, Fireflies is often used without properly informing participants or obtaining valid consent. The visible bot is present, but most users do not explain what is being recorded, how it will be stored, or where the data will go. This creates legal uncertainty, especially when external guests or sensitive topics are involved.

Conclusion: Fireflies.ai Can Be GDPR-Compliant, But Only with Effort

Fireflies offers a good technical foundation with its visible bot and structured features. But reliance on U.S. servers and a lack of default EU hosting pose serious concerns for GDPR compliance.

To minimize risk, users should:

  • Provide clear information to all participants
  • Obtain explicit consent, particularly for sensitive discussions
  • Explore EU hosting options where possible

Alternatively, organizations may opt for a tool like Sally, which stores data on servers in Germany by default and pairs a visible bot with GDPR-compliant hosting across Zoom, Microsoft Teams, Google Meet and Webex, offering a more straightforward path to compliance.

Disclaimer: This article is for informational purposes only and does not constitute legal advice.

FAQ

Lorenz Zwicknagl

Lorenz Zwicknagl

Marketing

Meetings should be a means of solving problems, not another waste of time. Artificial intelligence can help make them more efficient by summarizing discussions, highlighting key points, and clearly defining tasks. This creates more room for decisions instead of repetitions.

Learn more about the author