· By Marcus Webb

Granola's Lawsuit Tests the Bot-Free Privacy Argument

A July class action treats Granola's silent capture as a wiretap. The case is early, the theory is the same one a federal judge just let proceed against Otter, and it lands hardest on tools that keep a copy of the meeting.

On 30 July 2026, Tarra Chamberlain filed a proposed class action against Granola, Inc. and Granola Labs Ltd. in the Northern District of California. The case is Chamberlain v. Granola, Inc., No. 3:26-cv-07926, assigned to Judge Edward M. Chen.

Chamberlain is a Florida resident. She had never signed up for Granola. She joined a Microsoft Teams or Zoom meeting, and another participant was running Granola. She got no notice, no privacy policy, and no chance to decline. The complaint says her speech was intercepted, transcribed in real time, and, on information and belief, used to train Granola’s models.

That is the same fact pattern as the Otter case, with one difference that the category has spent two years treating as a feature. Nothing joined the call. Nobody in the room could see a bot. Granola’s own marketing, quoted in the complaint from a page last visited 27 July 2026, put it this way: other people in the room “won’t know” the software is there, and that invisibility is “the distinction that matters most.”

What the complaint actually alleges

These are allegations. Granola has not been found to have broken any law. The parties stipulated in August to extend Granola’s deadline to respond. There is no ruling on the merits, and there may never be one. Treat every sentence below as what the plaintiffs say, not as a finding.

The complaint pleads seven claims: common-law intrusion upon seclusion; the federal Electronic Communications Privacy Act; California’s Invasion of Privacy Act sections 631 and 632; California’s Comprehensive Computer Data Access and Fraud Act; California’s Unfair Competition Law; and unjust enrichment.

Two facts do the work.

First, Granola is designed not to announce itself. Unlike a bot that appears in the participant list and can be kicked out, Granola captures from the user’s device. The other people on the call have no interface for noticing, let alone refusing.

Second, Granola uses meeting content for its own purposes by default. Its privacy policy, updated 8 September 2026, still says it uses de-identified data to train AI models unless the user opts out in account settings. Enterprise workspaces have that setting off by default and enforceable by an admin. A person who never had an account, which is the whole proposed class, has no settings page.

The complaint also quotes Granola’s privacy policy on a point that matters for remedies: data incorporated into models “will not be removed from those models and datasets, as removal may not be technically feasible without complete model retraining.” If that sentence is accurate, an opt-out going forward does not unwind what already went in.

Why this is not a bot case

Two weeks after this filing, Judge Eumi K. Lee let most of the claims against Otter.ai proceed. We wrote about that ruling at the time. The holding that generalises is not about bots. It is about whether the vendor independently collects, retains, and uses the communications for its own commercial purposes, rather than merely passing them through for the customer.

Granola is the test of that holding on the other architecture. Otter’s default capture is a visible bot. Granola’s is silent device capture. If the Otter court’s reasoning is right, the bot was never the problem. The copy the vendor keeps, and what it does with that copy, is the problem.

That is an uncomfortable sentence for a category that spent 2025 and 2026 selling “no bot” as the privacy answer. No bot is a real product advantage. It avoids the awkward participant, and it survives the platform crackdowns Microsoft and Google applied to unverified meeting bots. It is not a legal shield. The Granola complaint is what it looks like when plaintiffs treat invisibility as evidence of intent rather than as a courtesy to the room.

Bluedot still leads with “invisible” in its branding. After this filing, that word is doing the opposite of the work the marketing intends.

How we scored it

We dropped Granola’s recording-consent score from 4 to 3. The capture method did not change. The litigation posture did. A 4 was the score for silent, user-controlled capture with no active consent case. A 2 is Otter, whose case has already survived a motion to dismiss. Granola sits between those: the suit is real, it is early, and the marketing the complaint quotes is Granola’s own.

The training score was already a 2. The September privacy-policy refresh did not change the default. It restated it.

None of this makes Granola a bad notepad. The hybrid notes are still the most pleasant in the bot-free group. The $125 million Series C is still real. Enjoyable software can still be the wrong software for a client call in an all-party-consent state.

What actually reduces the exposure

Contractual no-training helps. Circleback, Jamie, and Fathom all state that they do not train on customer data. Jamie deletes the audio after transcription. Those are the right promises for a cloud tool. They are still promises about a copy the vendor holds.

The setup that does not create the copy is on-device processing. Hedy can run transcription, summaries, and its real-time layer locally on supported hardware, including, as of September 2026, capable Android phones. If the audio never reaches a vendor server, the vendor cannot independently collect, retain, or use it. That is the distinction the Otter court drew, applied to a product that does not need the copy in the first place.

On-device does not waive the duty to tell the other people in the room. In California, Illinois, Pennsylvania and the other all-party-consent states, recording without agreement is still recording without agreement, whether the file lives on your laptop or in a US data centre. Under GDPR, one participant’s consent has never covered the rest of the call. Say it out loud. Note the agreement. That obligation sits with you on every tool we rank, including Hedy.

What to do with this

If you already deployed Granola, do three things this week. Confirm the training opt-out is on for every user, not just the people who found the toggle. Write down the disclosure script your staff actually use at the start of a call. And ask counsel whether a bot-free tool that trains by default is a fact pattern you want to explain after the next complaint, rather than before it.

If you have not picked a tool yet, stop treating “no bot” as the privacy column. Ask where the audio goes, whether the vendor trains on it, and whether a non-user on the call has any way to know. The Granola complaint is what happens when the answers to those three questions are “the cloud,” “yes, unless someone opts out,” and “no.”


This is analysis, not legal advice. The Granola case is at the pleading stage. If your organisation records meetings across multiple jurisdictions, take advice specific to your deployment.