checklist
Meeting transcript retention policy template
A copyable retention policy for AI meeting transcripts, summaries, recordings, action items, and shared links in small teams.
Bottom line
Do not keep AI meeting transcripts forever by default. A meeting transcript can include customer problems, buying intent, candidate answers, employee issues, pricing, roadmap plans, security incidents, screen-share text, and private chat context. Keep it only while there is a real business reason, restrict who can read it, and delete or archive it on a schedule.
Use this default:
Raw transcripts: 30-90 days.
AI summaries: 90-180 days if they support customer, project, or hiring work.
Recordings: off by default unless a meeting category explicitly needs them.
Sensitive meetings: delete or restrict faster, unless legal or business owners require retention.
Before approving a transcript retention rule, run the AI Tool Risk Checker and record the final policy in the Small Team AI Security Checklist. If your team has not decided where transcripts live, start with where AI meeting transcripts should be stored.
Retention policy template
Copy this into your handbook, wiki, or security tracker.
AI meeting transcript retention policy
Purpose:
We use approved AI meeting assistants only for approved meeting categories. Meeting outputs are retained only while they support a documented business need.
Covered records:
- Audio and video recordings
- Raw transcripts
- AI summaries
- Action items
- Meeting chat used by the AI assistant
- Screen-share text used by the AI assistant
- Shared links and exported files
Default retention:
- Recordings: off by default, or delete within 30 days unless approved
- Raw transcripts: delete within 30-90 days
- AI summaries: retain for 90-180 days when needed for customer, project, or hiring work
- Action items: move to the task system and follow that system's retention rule
- Shared links: expire within 7-30 days
Restricted meetings:
Legal, HR, finance, board, fundraising, acquisition, security incident, regulated-data, health, payment, child, government, and highly sensitive customer meetings are not approved for normal AI transcription. If approved by the responsible owner, retention must be documented before the meeting.
Access:
Raw transcripts are private to the meeting owner and approved business owners by default. External sharing requires meeting owner approval.
Deletion:
The workspace admin or meeting owner deletes transcripts and summaries at the scheduled date, during offboarding, or after a restricted-data capture.
Review:
The retention policy is reviewed quarterly and after any vendor, integration, meeting category, or incident change.
Retention schedule
Use this as the starting schedule, then adjust for your contracts, laws, and business process.
| Record type | Default retention | Owner | Notes |
|---|---|---|---|
| Audio/video recording | Off by default or 30 days | Meeting owner | Keep longer only when training, compliance, or customer agreement requires it. |
| Raw transcript | 30-90 days | Workspace admin and meeting owner | Treat as the most sensitive meeting output because it preserves unreviewed detail. |
| AI summary | 90-180 days | Business owner | Keep summaries longer than raw transcripts only when they are reviewed and useful. |
| Action items | Follow task-system rule | Functional owner | Move actions to Jira, Linear, Asana, CRM, or the project system. |
| CRM call note | Follow CRM account rule | Sales or customer owner | Do not attach raw transcripts unless explicitly approved. |
| Hiring interview summary | 30-180 days | Recruiting or hiring owner | Align with candidate data rules and ATS policy. |
| Shared transcript link | 7-30 days | Meeting owner | Require password or authenticated access when available. |
| Restricted meeting output | Delete or legal hold | Qualified owner | Do not let employees decide case by case. |
The FTC’s data security guidance supports keeping sensitive data only while there is a business reason and using a written retention policy. For meeting transcripts, that means the team should define the business reason before the bot joins.
Meeting category rules
| Meeting category | Retention default | Sharing default | Approval note |
|---|---|---|---|
| Internal team meeting | Transcript 30-60 days, summary 90 days | Team only | Allow if employees know the bot is active. |
| Sales discovery call | Transcript 60-90 days, summary 180 days | Account team only | CRM sync needs separate approval. |
| Customer success call | Transcript 60-90 days, summary 180 days | Account and support owners | Block broad workspace sharing. |
| Product research interview | Transcript 30-90 days | Research team only | Remove identifiers when possible. |
| Hiring interview | Transcript 30-90 days, summary per ATS rule | Hiring team only | Candidate notice and ATS policy required. |
| Board, legal, HR, finance, fundraising, M&A | Block normal retention | Qualified owner only | Escalate before transcription. |
| Security incident or abuse report | Block normal retention | Incident owner only | Use the incident record system, not the meeting bot, as source of truth. |
If a meeting category does not appear here, treat it as unapproved until an owner adds it.
Deletion checklist
Run this checklist monthly or quarterly, depending on volume.
- Export a list of meeting-bot records by date, owner, meeting category, and sharing status.
- Delete raw transcripts older than the approved retention period.
- Delete recordings that were not explicitly approved for longer storage.
- Expire external links and password-protected shares.
- Move legitimate action items into the task system before deleting the transcript.
- Confirm CRM notes contain only reviewed summaries, not raw transcripts by default.
- Review hiring transcripts against candidate data rules.
- Review customer transcripts against account, contract, and support rules.
- Remove transcript access for departed employees.
- Record exceptions and the owner who approved each exception.
Deletion should not depend on each employee remembering their own transcripts. Where the tool supports admin retention, use it.
Exception register
Use an exception register when a transcript needs to be kept longer than default.
Transcript retention exception
Meeting title:
Meeting date:
Meeting owner:
Business owner:
Tool:
Record type: recording / raw transcript / AI summary / shared link / export
Meeting category:
Reason to keep longer:
Sensitive data present:
Approved retention date:
Access limited to:
Deletion owner:
Legal, contract, or customer requirement:
Approval date:
Review date:
Notes:
If the reason is vague, do not approve the exception. “May need later” is not a retention policy.
Vendor settings to verify
Before rollout, check whether your selected tool can enforce the policy.
| Setting | Why it matters |
|---|---|
| Auto-start recording or summary | Prevent surprise transcription in meetings that were never approved. |
| Auto-delete transcript or summary | Makes retention a system rule instead of a memory task. |
| External sharing restriction | Prevents transcript links from leaving the organization by default. |
| Email summary content | Avoid sending transcript or summary text into inboxes unnecessarily. |
| Admin visibility and deletion | Lets the workspace owner clean up records after offboarding or mistakes. |
| Link expiration and password protection | Reduces long-lived exposure from shared transcript links. |
| CRM, Slack, Drive, calendar, email, or ATS sync | Creates additional copies with separate retention rules. |
| Screen-share OCR and chat inclusion | Can pull more sensitive content into the summary than people expect. |
Zoom supports account, group, and user controls for meeting summaries, including automatic sharing choices, external sharing restrictions, authenticated links, auto-delete settings, chat and screen-share controls, and admin locks. Otter Enterprise documents custom data retention and centralized conversation management. Fireflies documents retention governance, Rules Engine, private storage options, and external link controls. Verify the exact plan before relying on any control.
Rollout plan
| Phase | Action | Exit criteria |
|---|---|---|
| Day 0 | Choose one approved meeting category. | Owner, retention, sharing, and deletion rules are written. |
| Day 1 | Configure vendor settings. | Auto-start, sharing, email, links, and deletion match the policy. |
| Week 1 | Pilot 3-5 low-risk meetings. | Records are private, findable, and deletable by the owner. |
| Week 2 | Delete or expire pilot records on schedule. | The team proves deletion works before expansion. |
| Month 1 | Add one more meeting category. | Each category has a separate retention rule and owner. |
| Quarterly | Review records, exceptions, integrations, and offboarding. | No orphaned transcripts, stale links, or unmanaged personal accounts. |
Evidence checked
- Zoom meeting summary admin controls
- Fireflies Data Security & Privacy for Meeting Notes
- How Fireflies keeps your information safe
- Otter Privacy & Security
- Otter Enterprise Admin Controls Overview
- FTC Protecting Personal Information: A Guide for Business
- NIST Privacy Framework
- Fireflies vs Otter vs Zoom AI Companion privacy checklist
FAQ
Should raw transcripts and AI summaries have the same retention period?
Usually no. Raw transcripts often contain more sensitive, unreviewed detail. Keep raw transcripts shorter and retain reviewed summaries only when they support customer, project, hiring, or operational work.
Is 30 days always enough?
No. It is a useful default for low-risk raw transcripts, but customer calls, sales notes, research interviews, and hiring workflows may need a different period. The point is to write the reason and owner before keeping the transcript longer.
Can we rely on the vendor’s retention controls?
Use vendor controls when they exist, but keep your policy outside the vendor. Also remember that CRM notes, email summaries, Slack shares, Drive exports, and ATS copies may have their own retention rules.
What should happen during employee offboarding?
Remove the employee from the meeting-bot workspace, transfer business-owned records if needed, delete personal or orphaned transcript copies, and expire shared links. Do the same for connected calendar, CRM, Drive, Slack, email, and ATS access.
Do we need legal review?
Use legal, compliance, HR, finance, security, or account-owner review when meetings include regulated data, employment decisions, contracts, legal advice, incidents, payment data, health data, or customer commitments. This template is an operations policy, not legal advice.
Recommended next step
Pick one AI meeting assistant and one meeting category. Fill in the retention policy template, configure the vendor settings, and test deletion on a low-risk meeting before allowing the bot into customer, hiring, or sensitive internal calls.