9 Best tl;dv Note Taker Alternatives (2026)

tl;dv exposed 181,000 meetings due to a missing security rule. Here are nine alternatives—from free options like Fathom to compliance-focused Fellow—plus what to ask any vendor before you migrate.

By
The Meetingnotes Team
|
18
mins
|
August 6, 2026
Tools

TLDR:

The Problem: tl;dv left 181,874 meeting records publicly queryable due to a missing Firestore security rule. A security researcher reported the vulnerability January 2026; as of August 2026, it remains unfixed and unacknowledged.

Key Takeaway: Compliance badges (SOC 2, GDPR) don't guarantee engineering discipline. Ask vendors about security incident response SLAs, tenant isolation, metadata access controls, and live call exposure before you migrate.

Quick Guide:

  • Free & unlimited: Fathom (bot-free since April 2026, no paywall on core features)
  • Compliance & governance: Fellow (zero-day retention, transcript redaction, information barriers, SOC 2 + HIPAA)
  • European data storage: Jamie (DORA certified, audio deleted after transcription)
  • AI polishes your notes: Granola (bot-free, works best if you're taking notes during calls)
  • Noisy environments: Krisp (bidirectional noise cancellation, bot-free)
  • Meeting analytics: Read AI (engagement scoring, daily briefings, video highlights)

Before you migrate, ask: Can one user see another's meetings? Is metadata queryable by any authenticated user? Can you join live calls uninvited via conference IDs? What happens after the AI processes the recording—are raw files deleted or kept forever?

Why You Might Be Looking

In August 2026, a security researcher discovered that tl;dv left 181,874 meeting records completely exposed due to a single missing Firestore security rule. Any authenticated user on the platform—including government, university, and corporate users—could query every meeting, including live conference IDs, participant email addresses, and recording status.

The researcher reported the vulnerability on January 28, 2026. The CTO promised a quick fix. By July—six months later—the vulnerability was still unfixed and the company had not responded. As of August 2026, tl;dv has not publicly acknowledged the vulnerability or released a fix.

This isn't a case where compliance badges or SOC 2 certifications protected users. tl;dv advertised SOC 2 compliance, GDPR compliance, and a 24-hour security response SLA. The vulnerability suggests that compliance frameworks check boxes; they don't guarantee the engineering discipline that prevents these gaps.

If you rely on tl;dv for sales teams, recording client calls, or any workflow where meeting metadata matters, it's worth evaluating alternatives. Here are nine options, each with a different strength.

What to Ask Any Vendor Before You Migrate

Before evaluating specific tools, here's a security checklist worth running through with any meeting recorder you're considering:

Tenant isolation: Can one customer's user account see another customer's meetings or metadata? If the answer is unclear or yes, that's a dealbreaker. Every vendor should isolate data by customer and by user within a workspace.

Metadata access controls: Is meeting metadata—who attended, when the call happened, duration, participants' email addresses—restricted to the account owner? Or is it queryable by any authenticated user? If it's queryable by anyone, you have tl;dv's problem.

Live call exposure: Can you query active meetings in real-time and access their conference IDs while the call is happening? If yes, an attacker could join uninvited. Metadata about live calls should never be accessible to the wrong users.

Default privacy settings: Are meetings private by default, or public? "Public by default" is a design flaw that quietly exposes transcripts and participant information. Check your vendor's settings before assuming you're covered.

Security incident response SLA: When you report a vulnerability, who's the contact and what's the guaranteed response time? A vendor that ghosted for six months has already told you how they'll handle the next incident.

Data retention after processing: What happens to raw recordings after the AI generates transcripts and summaries? Do they stick around indefinitely for compliance reasons, or are they deleted to reduce risk? If compliance deletion isn't an option, ask why.

9 tl;dv Alternatives, Organized by What You Actually Need

1. Fellow - If You Want a Secure tl;dv Alternative

Fellow is positioned explicitly for security-conscious industries. It's built to support compliance programs in finance, healthcare, and government rather than bolted-on as an afterthought. It includes granular recording controls, transcript redaction, pause/resume capture, information barrier policies, password-protected meeting recaps, and zero-day retention options where source recordings are deleted after processing, leaving only AI-generated summaries.

What you get: Botless capture across Zoom, Teams, Google Meet, and in-person via desktop app. Zero-day retention so raw recordings don't linger in your systems. Workspace-level recording policies that apply consistently across an organization. Pause/resume recording for sensitive topics, with independently logged pause events. Customizable consent disclosures for recording notices. Granular access permissioning by team, department, or individual user. Redaction of names, account numbers, and flagged terms from transcripts before sharing. SOC 2 Type II, GDPR compliance, HIPAA on Enterprise tier. Super Admin API for audit-ready deletion logs and exam-ready record retrieval. 50+ integrations including Salesforce, HubSpot, Glean, Slack, and direct MCP Server extensibility.

What's missing: The feature set is deep but complex; it requires more admin setup than simpler tools. Bot-free recording requires desktop app download, which adds adoption friction in some orgs.

Best for: Finance teams (private equity, investment banking), healthtech and fintech, legal, and enterprise teams. Compliance and risk officers who need firm-level policy control. Organizations handling regulated data where governance matters. Teams that specifically need zero-day retention, transcript redaction, or information barriers. Enterprises where a single missing security control could cause regulatory exposure.

Pricing: Contact sales for enterprise pricing.

2. Fathom - If You Want Free and Unlimited

Fathom is the best starting point if you need unlimited recording and transcription with no paywall. It became bot-free in April 2026, which was significant—until then, it relied on a visible bot joining calls, but Google's March 2026 security update made bot-based tools friction-dependent on host approval.

What you get: Unlimited recordings and real-time transcripts at no cost. Five AI summaries per month on the free tier. Syncs to Salesforce and HubSpot on the Business plan ($34/user/month). Speaker identification and searchable timestamps. Video playback so you can jump to specific moments and verify claims against the recording.

What's missing: The free tier caps AI summaries at five per month, which matters for teams running more than five meetings weekly. CRM integration is gated to the Business tier, which adds cost. Cross-meeting Q&A and analytics are available only on paid plans. For compliance use cases, Fathom lacks HIPAA (only SOC 2) and doesn't offer data residency by region—everything runs in US cloud.

Best for: Solo users, freelancers, and small teams who want to test the category before paying. Individual contributors who need basic meeting documentation. Teams that don't require CRM automation or compliance certifications.

Pricing: Free (unlimited recordings, 5 AI summaries/month), Premium $20/month, Business $34/user/month.

3. Granola - If You Want AI to Polish your Manual Notes

Instead of a bot joining the call or uploading audio to the cloud immediately, Granola listens through your computer, records locally, and processes the transcript on your machine. Your notes stay on your device until you explicitly share them.

What you get: Bot-free, on-device recording for Zoom, Google Meet, and Teams. AI polishes your notes after the call, combining what you wrote with the transcript for context. Unlimited free notes. No visible bot means professional decorum in sensitive calls. Works across Mac and Windows.

What's missing: No raw video or audio retention—Granola deletes the audio after transcription, so you can't replay the call. Granola works best when you're taking notes during the call. If you go silent, the output is weaker. No CRM sync. No cross-meeting search. No HIPAA or healthcare compliance. Mac experience is more polished than Windows.

Best for: Individual consultants and knowledge workers who want clean, portable notes. Professionals who actively participate in their meetings and want notes that feel thoughtful. Mac-first users who don't need to replay or clip recordings.

Pricing: Free (unlimited notes). No paid tier currently.

4. Krisp - If You're in a Noisy Environment

Krisp built its reputation on bidirectional noise cancellation—it works on incoming audio (what you hear) and outgoing audio (what others hear). The meeting AI is secondary to that core feature, but it's useful if you run calls from offices, coffee shops, or shared spaces where audio clarity is a problem.

What you get: Real-time noise cancellation that actually works. Bot-free recording that captures locally first. AI transcription and summaries. Supports Zoom, Google Meet, Teams, and Webex. Desktop apps for Mac and Windows plus mobile apps.

What's missing: The note-taking features are shallower than Granola or Fathom. Summary depth suffers on long, dense meetings. Storage is capped at 5 GB on the Pro plan, which fills faster than the marketing implies. The free tier is trial-only now, not a perpetual free plan. Pricing reflects that noise cancellation is the premium feature, so it costs more than comparable tools.

Best for: Distributed teams with audio quality problems. Sales teams running global calls where accents and microphone variability are real. Anyone already paying for Krisp for noise cancellation who wants meeting AI as a bonus.

Pricing: Free trial, Pro $8/user/month with storage caps, Team plans available.

5. Jamie - If You Need European Data Storage

Jamie records by processing audio directly from your meeting platform instead of joining as a visible participant. For sensitive contexts—client-facing calls, government meetings, healthcare discussions—that difference matters psychologically and operationally.

What you get: No bot joins the call. EU-hosted infrastructure with permanent audio deletion after transcription. ISO 27001 and DORA certified (the latter specific to EU financial services). Supports 100+ languages. Desktop and iOS apps for capturing in-person and hybrid meetings. Automatically identifies speakers and generates structured notes.

What's missing: No CRM sync. No cross-meeting search or Q&A. No video recording, only audio. Billing is in euros (€ 39/month for the Team plan), which adds currency conversion friction for US teams. Lacks HIPAA certification and healthcare-specific compliance options.

Best for: EU-based teams or organizations handling sensitive conversations. Compliance teams that prioritize data residency and privacy by default. Professional services (legal, consulting) where client optics matter. Teams that don't need CRM integration or cross-meeting analytics.

Pricing: Team plan €39/user/month. Free trial available.

6. Fireflies.ai - If You Need Specific CRM Automations

Fireflies positions itself as the CRM-first meeting assistant. It transcribes meetings in 100+ languages with 99% accuracy in English and 95% in other languages. It auto-joins your calendar events and syncs directly into Salesforce and HubSpot, updating call records, logging activities, and moving data without manual entry.

What you get: Universal platform coverage (Zoom, Google Meet, Teams, Webex). Real-time transcription with excellent accuracy on diverse accents and audio quality. Native integrations with Salesforce, HubSpot, Notion, Slack, and 50+ other tools. AI automatically extracts action items, topics, and sentiment. Customizable summaries so you can shape how meeting data looks in your CRM. SOC 2 Type II certified.

What's missing: Fireflies focuses on data export and CRM automation, not synthesis. It doesn't pull context from email or Slack into a single knowledge graph. Video playback isn't available. The free tier is limited (400 minutes transcription + storage). For solo users or small teams, the Business tier at $19/user/month adds up fast relative to Fathom's unlimited free tier.

Best for: Sales teams that live in CRM and need meeting data flowing in automatically. Customer success teams logging calls and updating account records. Any workflow where meeting transcripts need to sync to downstream systems without manual copy-paste. Organizations running global teams where multilingual transcription matters.

Pricing: Free (400 min transcription), Pro $10/user/month, Business $19/user/month. All plans include CRM sync.

7. Otter.ai - If You Need Real-Time Transcription

You can ask Otter "What did the client say about budget?" across any meeting from the past two years, and it returns timestamped results with context. For teams treating meeting notes as a searchable knowledge base instead of ephemeral documents, that matters.

What you get: Deep meeting archive with full-text search and natural language queries. OtterPilot auto-joins your calendar and generates summaries. Speaker identification and transcription in six languages (English US, English UK, Spanish, French, Japanese, German, plus Chinese Simplified in beta). Captures meeting slides and inserts them into notes. Pricing is transparent and relatively affordable at the entry level.

What's missing: Otter uses a visible bot, which matters less now that competing tools offer bot-free alternatives. Video recording isn't available—Otter is transcription-focused. CRM integration is limited compared to Fireflies. Multi-language support is narrower than competitors. The free tier caps at 300 minutes monthly, which forces paid plans faster than Fathom's unlimited free tier.

Best for: Individuals and small teams who treat past meetings as a searchable reference library. Teams that need rapid lookup ("What was decided in that July call?") without sifting through email threads. Organizations working primarily in English or the six supported languages. Users who want mature, battle-tested tooling.

Pricing: Free (300 min/month), Pro $16.99/month, Business $20/month. Free tier is limited; paid plans are where value concentrates.

8. Read AI - If You Want Meeting Analytics

Read AI takes a different angle. Instead of asking "Did we capture the meeting correctly?" it asks "How did the meeting go?" It scores engagement (talk time, sentiment, body language, question-asking patterns) and generates a daily briefing that connects meetings, emails, and calendar events into one intelligence layer.

What you get: Engagement scoring that measures how actively each participant contributed. Real-time meeting analytics. Video highlights so you can extract the moments that matter without watching the full recording. Cross-channel search across meetings, email, and calendar. Daily AI-powered briefings. Deep CRM integrations with Salesforce and HubSpot. Compliance options including HIPAA and SSO on Enterprise tiers.

What's missing: Video playback is gated to the Enterprise tier ($22.50/month annual, minimum 10 seats), not available on the Pro plan. The free tier allows only five meetings per month. The visible bot is still there—you don't get the bot-free benefit other tools have shifted to. Pricing climbs quickly once you need advanced analytics or compliance features.

Best for: Sales teams running high-volume calls who want coaching insights and win/loss analysis. Customer success teams analyzing customer interactions over time. Leadership and enablement functions trying to understand what's working in customer conversations. Teams that specifically want engagement scoring and call quality metrics, not just transcription.

Pricing: Free (5 meetings/month), Pro $19.75/month or $15/month annual, Enterprise $29.75/month or $22.50 annual, Enterprise+ $39.75/month or $30 annual (10-seat minimum).

9. Circleback - If You Need A Lightweight, Cost-Friendly Tool

Most meeting assistants are built around Zoom, Google Meet, and Teams. Circleback captures board meetings, client on-sites, and off-sites where people are physically present.

What you get: Bot-free desktop recording for virtual and in-person meetings. HIPAA and SOC 2 Type II certified for compliance-heavy use cases. Automatic speaker identification even when people aren't on a video call. Integration with Slack, Notion, Linear, and Jira. Mobile app for iOS. Customizable templates so meeting formats match your workflow.

What's missing: The search and analytics features are less sophisticated than Otter or Read AI. It's smaller and less widely adopted, so community resources and integrations are narrower than larger competitors. HIPAA compliance is available but requires Enterprise setup and review.

Best for: Organizations that run significant in-person or hybrid meetings. Consulting and services firms doing on-site client work. Legal teams handling confidential discussions. Healthcare and finance teams needing HIPAA-compliant capture across all meeting types. Teams that specifically need bot-free recording for professional contexts.

Pricing: Varies by plan. Check their website for current tiers.

Frequently Asked Questions

Why does bot-free vs. bot-based matter?

Until March 2026, bot-based tools (Otter, Fireflies, Read AI) joined calls invisibly or with minimal notice. Google's March 2026 update made third-party bots land in a "Potential Risk" queue where hosts must manually approve them every meeting. That friction forced vendors to offer bot-free alternatives. Bot-free tools (Jamie, Granola, Krisp, Fellow) capture audio via your device or the meeting platform itself, not by joining the call. This matters if professional decorum or client optics are a concern, or if your organization blocks third-party participants.

What's the difference between SOC 2 and HIPAA compliance?

SOC 2 is a security and operational audit that confirms a vendor has reasonable controls around data access, encryption, and incident response. It doesn't address healthcare-specific regulations. HIPAA is US healthcare law that requires specific protections around Protected Health Information (PHI) and is legally required for healthcare organizations. Compliance with SOC 2 doesn't equal HIPAA compliance. If you're in healthcare, finance, or law, verify which certifications your vendor actually holds and at what tier (often HIPAA is Enterprise-only).

Do these tools train on my data?

Major vendors (Fellow, Fathom, Jamie, Fireflies, Otter, Read AI) explicitly state they don't train their AI models on customer data. That said, "we don't train on your data" doesn't mean your data isn't retained or analyzed for product improvement. Ask for data retention and use policies in writing. tl;dv's silence for six months on a security incident suggests you should ask for these commitments from any vendor you're considering, not assume they have them.

How do I know if a vendor will respond to security issues?

Ask three questions: (1) What's the security contact and response SLA? (2) Do you have a vulnerability disclosure policy published? (3) Can you give me a reference from a customer who reported a security issue? If a vendor can't answer these clearly, that's a signal. The tl;dv incident happened because reporting a vulnerability led to radio silence. That's not unique, but it's worth screening for.

Is there a tool that does everything?

No. Every tool trades off depth in one area for breadth in another. Fellow wins on security and compliance. Fathom wins on free-tier generosity. Fireflies wins on CRM automation. Otter wins on archive search. Read AI wins on analytics. Pick the one that solves your actual constraint, not the one with the longest feature list.

Should I migrate from tl;dv right now, or wait?

If you're in a regulated industry (finance, healthcare, law) handling sensitive data, migrate now. The six-month non-response to a security researcher is material. If you're a small team running sales calls with no sensitive data, the impact is lower, but understanding tl;dv's response timeline (or lack thereof) is worth factoring in. The vulnerability is unfixed as of August 2026, so this isn't a solved problem you're waiting for resolution on.

The Wider Lesson

The tl;dv incident wasn't a breach in the traditional sense. Nobody cracked passwords or stole databases. It was simpler: a security rule was configured but never audited, then forgotten. For six months, a researcher tried to get the company to fix it. The company didn't respond.

This happens because compliance frameworks check boxes—"Are you SOC 2 certified?" "Yes."—but engineering discipline prevents vulnerabilities—"Are all your security rules actually configured?"—is a different question.

When you're evaluating a new tool, compliance badges are useful but incomplete. Ask about incident response. Ask for architecture documentation. Ask what happens when you report a bug versus when you report a security issue. Ask for references from customers who've lived through that process.

The tools listed above range from free to expensive, bot-based to bot-free, simple to complex. Pick the one that fits your workflow and your constraints. But before you sign up, ask your security team the questions listed at the start of this article. The six-month silence from tl;dv is a reminder that vendors don't always prioritize the problems you think they should.

Never take meeting notes again

Record, transcribe and summarize your meetings with Fellow.

Get started with Fellow todayStart a free trial

Got something to contribute?

Become a contributor, and add your unique take on these topics to our website.
Become a contributor