M Meetly
September 11, 20266 min read

Why Your IRB Will Reject Otter — And What Actually Passes Review

Otter.ai's own privacy policy says it trains AI on your interview audio and shares data with third-party vendors — details your IRB has to name. Here's what to write instead.

Otter.ai's privacy policy states it trains AI models on de-identified audio and transcripts and shares data with cloud, labeling, and AI vendors — details your IRB protocol must disclose. Meetly transcribes interview audio on the researcher's iPhone or Mac, so there's no third-party vendor or data-sharing clause to write into your consent form.

Meetly records and transcribes research interviews entirely on the researcher's iPhone, iPad or Mac. Nothing leaves the device to reach a transcription vendor's servers, so there's no third-party data-sharing clause for your IRB protocol to name. If you've ever tried to write the data management section of a protocol around Otter.ai, that's the paragraph this changes.

The consent-form question your IRB will ask anyway

Every IRB reviewing an interview study eventually asks the same question: what happens to the recording after you press stop. If a transcription vendor touches that audio, your protocol has to name the vendor, describe what it does with the data, and say so in the consent form participants sign before they talk to you.

What Otter's own privacy policy admits

Otter.ai's privacy policy answers that question directly, and not in your favor. It says the company uses recordings to improve and monitor its services, including training its proprietary AI technology on de-identified audio recordings and on transcriptions that may contain personal information.

Improve and monitor the Services, including training our proprietary AI technology on de-identified audio recordings and on transcriptions

— Otter.ai Privacy Policy, §2 How We Use Your Personal Information · source

The same policy names who else sees that data: cloud service providers, data-labeling service providers, artificial intelligence service providers and analytics providers, plus law enforcement when legally required. Storage runs through Amazon Web Services in the United States, with transfers to other countries covered by Standard Contractual Clauses — a chain of vendors your protocol now has to describe.

Why "de-identified" doesn't end the risk

De-identified is doing a lot of work in that sentence. Interview audio carries voice, accent, background noise and offhand detail a transcript strips out — exactly the kind of pattern an IRB worries about when it asks whether a tool could re-identify a participant from what's left.

Even when identifiers are removed, AI tools may infer personal information from patterns in the de-identified data.

— Lehigh University Office of Research, Guidance on Generative AI and Human Subjects Research · source

What your IRB actually wants to see

Lehigh's guidance is typical of what's showing up in protocol templates now: use of AI to analyze or process data must be disclosed to participants as part of the consent process, and the consent language has to name which AI tools are involved and whether they touch identifiable or de-identified data.

  • Name every tool that touches the recording, transcript or notes — not just the one you type into
  • Say in the consent form whether that tool trains its own models on your data
  • State where the audio is processed and stored, and for how long
  • Confirm whether the vendor can be compelled to hand data to a third party

Institutional coverage of this is uneven. An analysis of AI guidance at top U.S. universities found 94% issue guidelines for AI in teaching, while fewer than 20% address researcher use of AI tools directly — so most protocols are being written without an institutional template to follow.

On-device changes what you write in the protocol

Meetly's recording and transcription run on the phone or Mac itself, processing audio locally in 99 languages before anything is saved. There's no vendor server in the data flow, so the protocol section that used to list a third-party processor for interview audio can instead say the recording device is the researcher's own.

What your protocol has to nameOtter.ai (per its own privacy policy)On-device (Meetly)
Where the audio is processedCloud servers (Amazon Web Services, US-based)The researcher's iPhone, iPad or Mac
Used to train the vendor's AI modelsYes — de-identified audio and transcriptsNo — nothing leaves the device
Shared with third-party vendorsCloud, data-labeling, AI and analytics providersNone — there is no vendor in the data path
Cross-border transferYes, under Standard Contractual ClausesNot applicable
What a protocol has to name, tool by tool

A sample interview-insight digest — the artifact you still owe your IRB

On-device transcription answers the storage question, not the analysis one. Once the interview is transcribed, an agent working from the transcript can still build the local digest a qualitative study runs on — themes, verbatim quotes, session metadata. The table below is a realistic-but-fictional example of that output, not a real study.

ParticipantThemeSupporting quoteSession date
P-04Consent forms get skimmed under time pressure"I skimmed it because the recruiter was waiting"2026-08-14
P-07Distrust of cloud recording tools"I didn't want it recorded on someone else's server"2026-08-19
P-11Prefers a summary over the raw transcript"Just tell me what I said that mattered"2026-08-21
Realistic-but-fictional example digest — not drawn from an actual study

What still needs a person

None of this gets a protocol approved by itself. AI use in research tooling keeps climbing — use embedded in research platforms rose from 62% to 66% in a single year — but an IRB still reviews the whole study, not the app you recorded it with. On-device transcription removes a paragraph you used to have to write; it doesn't remove the reviewer.

The next protocol you write can describe your recorder in one sentence instead of a vendor's data-sharing policy. Record the next interview on the phone already sitting on the table, and write the data management section around what's actually true: the audio never left the room.

Meetly is free to start, on-device by default.

Get Meetly on the App Store

FAQ

Is Otter.ai IRB compliant?

There's no such thing as an 'IRB-compliant tool' — IRBs approve protocols, not software, so the honest answer is that Otter.ai's own privacy policy creates work your protocol has to do. It states Otter trains its proprietary AI on de-identified audio and transcripts and shares data with cloud, data-labeling, AI and analytics vendors, storing it on Amazon Web Services in the US with cross-border transfers under Standard Contractual Clauses. None of that makes Otter unusable for research — plenty of studies name it and disclose exactly this in their consent forms. It does mean you can't skip the disclosure and hope reviewers don't ask.

Does recording on-device remove all my IRB requirements?

No. On-device transcription removes the paragraph about a third-party vendor processing your audio, because there isn't one — Meetly transcribes on the researcher's own iPhone, iPad or Mac, and the audio stays on that device. Your protocol still needs a consent process, a data storage and retention plan, and a description of who on your research team can access the recordings and under what conditions. An IRB reviews the whole study, start to finish, and switching tools changes one section of the application — the data-flow paragraph — not the review itself or the rest of your confidentiality plan.

Can I still use a cloud transcription tool for interviews that aren't confidential?

Yes — the risk Otter's privacy policy describes is specifically about identifiable interview data, and plenty of qualitative work doesn't carry that risk: a public panel discussion, a conference talk, a focus group where participants already consented to published, attributed quotes. The test isn't the tool itself, it's whether a participant would reasonably expect their words to stay between you and them. If the answer is yes, and the content is identifiable, that's when a protocol needs to name exactly where the audio goes, who processes it, and whether it trains a vendor's models.

What do I change in my data management plan if I switch tools?

Replace the vendor data-flow paragraph with a device description: recording and transcription happen locally on the researcher's iPhone, iPad or Mac, in whichever of the app's 99 supported languages the interview was conducted in, and the audio file is stored on that device (or the researcher's own encrypted backup) rather than a vendor's servers. Keep the rest of the plan as it was — retention period, who on the team can access files, and how you'll de-identify quotations before publication. The consent form sentence about a third-party AI vendor can come out; the rest of your confidentiality plan stays exactly as rigorous.