August 5, 2026 · 10 min read · Last reviewed August 5, 2026
Chamberlain v. Granola: When the “Invisible” AI Notetaker Became a Wiretap Lawsuit
Published August 05, 2026
- Chamberlain v. Granola (Case No. 3:26-cv-07926-EMC), filed July 30, 2026, is the first major class action targeting a 'bot-free' AI notetaker — reframing invisibility as a wiretap risk, not a feature.
- The 38-page complaint alleges Granola captures every meeting participant's speech without consent and uses transcripts to train its AI models by default.
- Combined with In re Otter.AI (visible-bot model) and Cruz v. Fireflies.AI (BIPA voiceprints), plaintiffs are now attacking every major cloud AI notetaker architecture in U.S. federal court.
- The lawful safe harbor is architectural: transcripts and training data that never leave the device cannot be intercepted, subpoenaed, or repurposed by a vendor.
- Basil AI's 100% on-device processing on Apple Speech Recognition avoids every theory in the Granola complaint — no cloud upload, no vendor-side transcript, no training-by-default.
Quick answer: On July 30, 2026, Tarra Chamberlain filed a proposed class action (Chamberlain v. Granola, Inc., Case No. 3:26-cv-07926-EMC, N.D. Cal.) alleging Granola's bot-free AI notetaker secretly intercepts virtual meetings on participants' devices and uses transcripts to train its models by default. The 38-page complaint asserts seven claims, including federal ECPA and California CIPA wiretapping violations.
On July 30, 2026, a Florida resident named Tarra Chamberlain filed a proposed class action against Granola, Inc. and Granola Labs Ltd. in the U.S. District Court for the Northern District of California. As first reported by PPC Land, the 38-page complaint (Case No. 3:26-cv-07926-EMC) accuses Granola of intercepting virtual meeting conversations without the knowledge of most participants and feeding those transcripts into its own AI model training by default. For an industry that spent 2025 arguing about the risks of visible AI bots joining calls, this is the moment the legal spotlight swung to the opposite architecture: the invisible, endpoint-level notetaker.
Granola built its brand on that invisibility. The company’s marketing pitch — that “other people in the room won’t know it’s there” and that “no bot joins your call” — made it the default notetaker across tech and venture circles, with customers like Asana, Cursor, and Mistral AI named in the filing. In March 2026, Granola raised a $125 million Series C led by Index Ventures at a $1.5 billion valuation. Four months later, that same “no bot” positioning is Exhibit A in a wiretap complaint.
What the Complaint Actually Alleges
According to the case coverage from Law360 and PPC Land, Chamberlain brought the suit on behalf of a proposed nationwide class and a California subclass. Her attorneys are Schubert Jonckheer & Kolbe LLP of San Francisco and Lowey Dannenberg, P.C. of White Plains, New York. The complaint asserts seven separate causes of action and demands a jury trial.
The legal theories are the ones the plaintiffs’ bar has spent two years developing against AI transcription vendors:
- Federal Electronic Communications Privacy Act (ECPA), 18 U.S.C. § 2511 — the federal wiretap statute prohibiting intentional interception of electronic communications.
- California Invasion of Privacy Act (CIPA) §§ 631 and 632 — California’s all-party-consent recording statute.
- California’s Comprehensive Computer Data Access and Fraud Act.
- Common-law invasion of privacy claims.
What makes the case unusual is the evidence. Two exhibits attached to the complaint are simply screenshots of Granola’s own marketing pages promising invisibility to the user and non-disclosure to everyone else on the call. Plaintiffs didn’t need leaked documents or a whistleblower — the “quintessential wiretap” theory, as the filing puts it, is built on the product’s public sales copy.
The Training-by-Default Half of the Case
The recording allegation is only half of the complaint. As Windows Forum summarized from the PPC Land reporting, Chamberlain also challenges Granola’s use of captured meeting data to improve its own AI models. The training toggle exists — but it belongs to the Granola account-holder, not to the non-users who were recorded. The people being transcribed do not know there is anything to switch off.
That opt-out-by-account-holder pattern is the same design that landed Otter.ai in litigation. Kilpatrick Townsend’s analysis of the Otter case noted that courts and regulators have grown skeptical of vendor claims that training on “de-identified” recordings solves the consent problem — a warning that applies equally to any vendor whose default is opt-out training on captured audio.
How This Case Fits the 2025–2026 Wave of AI Notetaker Litigation
Chamberlain v. Granola is not an outlier. It is the third distinct architectural theory tested by plaintiffs in eight months:
- Visible cloud bot — In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 (N.D. Cal.), consolidating Brewer, Walker, Theus, and Winston. The theory: even a visible bot doesn’t constitute informed consent under two-party-consent statutes. Judge Eumi K. Lee heard oral argument on Otter’s motion to dismiss on May 20, 2026.
- Biometric voiceprints — Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 (C.D. Ill.), filed December 18, 2025. Epstein Becker Green’s analysis details how the complaint targets Fireflies’ Speaker Recognition feature under the Illinois Biometric Information Privacy Act.
- Invisible endpoint capture — Chamberlain v. Granola, filed July 30, 2026. The bot-free architecture that was supposed to solve the notetaker consent problem is now itself the alleged violation.
Put together, the plaintiffs’ bar has now attacked every major cloud AI notetaker architecture used by the current market leaders. IAPP’s survey of these cases traces how decades-old wiretap statutes have found new significance thanks to a “creative plaintiff’s bar” that keeps finding new applications of old privacy laws to automated eavesdropping.
Why “Bot-Free” Doesn’t Automatically Mean “Consent-Safe”
The industry embraced bot-free notetakers as an improvement over Otter-style bots. And in one narrow sense, they are: no unfamiliar “OtterPilot” icon appears in the participant panel. But that improvement is a security downgrade wearing a UX costume. Endpoint-level capture moves disclosure, consent, and training-accountability from the SaaS platform into the hands of each employee — a control failure waiting to become a legal one, as one Windows Forum analysis put it.
There are three things “bot-free” does not fix:
1. It doesn’t solve two-party consent.
California’s CIPA, Florida’s wiretap statute, Illinois’ eavesdropping law, and roughly a dozen other state statutes require all parties to consent to being recorded. Invisibility makes obtaining that consent harder, not easier. If the visible-bot cases succeed, invisible capture is in a worse position, not a better one.
2. It doesn’t keep data on your device.
Most bot-free notetakers still send captured audio, transcripts, or both to vendor servers for processing, storage, and model training. The name is misleading: the tool isn’t local, only the capture point is local. Protecto’s comparison of Otter, OpenAI, Claude, and Perplexity data-handling practices shows how varied the retention and training defaults still are — and how often the opt-out is buried in account settings the recorded party never sees.
3. It doesn’t solve GDPR or the EU AI Act.
Under Article 5 of the GDPR, controllers must have a lawful basis and provide transparency about processing personal data. An invisible notetaker that captures EU participants’ speech without disclosure fails both. And starting August 2, 2026, the EU AI Act adds a further layer of obligation for AI systems used in worker monitoring and management contexts.
Cloud vs Bot-Free vs Truly On-Device: A Side-by-Side
The Granola complaint clarifies a distinction the industry has been blurring. “On-device capture” and “on-device processing” are not the same thing. Here’s what actually varies:
| Property | Cloud bot (Otter, Fireflies) |
Bot-free cloud (Granola-style) |
Truly on-device (Basil AI) |
|---|---|---|---|
| Where audio is captured | Cloud meeting bot | User’s device | User’s device |
| Where audio is transcribed | Vendor cloud | Vendor cloud | Apple Neural Engine (local) |
| Where transcript is stored | Vendor cloud | Vendor cloud | Local + optional Apple Notes / iCloud |
| Visible to other participants? | Yes (bot in participant list) | No (invisible by design) | N/A — user still discloses per state law |
| Training on transcripts by default? | Alleged in In re Otter.AI | Alleged in Chamberlain v. Granola | No — nothing leaves the device |
| Third-party subpoena surface | Yes (vendor server) | Yes (vendor server) | None — no vendor copy exists |
The two middle columns look different but litigate almost identically. Only the right column removes the class of harm the plaintiffs’ bar is targeting.
What This Means for Buyers of AI Notetakers
If you are an in-house counsel, IT admin, or department head evaluating notetakers this quarter, Chamberlain v. Granola changes the vendor-diligence checklist. Three questions now matter more than the transcript quality demo:
Where does the audio go the moment it’s captured?
If the answer includes any vendor server — even for a millisecond — the recording is potentially a “wire, oral, or electronic communication” being “intercepted” under ECPA. That’s the exact frame Holland & Knight’s GenAI litigation analysis identifies as the emerging viable wiretap theory for AI tools.
Who owns the opt-out for AI training?
If the account-holder controls training defaults for content spoken by non-users, you have inherited the Granola design flaw. The people on the other end of the call cannot meaningfully consent to something they don’t know is happening.
Are you buying a product or a compliance burden?
The HR Executive analysis notes that under the EU AI Act, AI systems used for worker monitoring and management may be classified as high-risk starting August 2026. Layer that on top of state wiretap statutes, GDPR, and BIPA voiceprint claims, and every cloud transcription vendor is now a compliance conversation, not a productivity purchase. Compliance itself is the customer’s determination — but the architecture the vendor forces you to buy determines whether that determination is possible at all.
Attorney-Client, MNPI, and PHI Meetings: A Special Warning
The stakes are not distributed evenly. If a Granola-style tool sits in a call between a lawyer and a client, the recording creates a serious risk to attorney-client privilege — because a third-party vendor has now received the communication. If it sits in an investor call with material nonpublic information, the transcript becomes a Reg FD problem. If it sits in a therapy or clinical intake session, the recorded speech is arguably PHI in the hands of a vendor with no BAA. Our deeper dive on why MNPI-sensitive teams need on-device notetakers walks through the asset-management version of this problem.
The Chamberlain complaint quotes Granola’s own pitch back at it: invisibility is the feature. In privileged and regulated contexts, invisibility is precisely the risk.
How Basil AI Solves This
Basil AI is designed around one architectural rule: audio, transcripts, and any derived data never leave your device. Transcription runs on Apple’s on-device Speech Recognition APIs, powered by the Apple Neural Engine, consistent with the guarantees documented in Apple’s privacy commitments. The result matters legally in three specific ways:
- No interception. There is no third-party server receiving the communication, so the ECPA / CIPA theory of “intercepting party” simply doesn’t attach to Basil the way it does to a cloud vendor.
- No training data. Basil does not have a corpus of user transcripts to train on because no user transcript ever leaves the device. There is no opt-out to bury — the default and the only setting is “not shared.”
- No voiceprint. Basil doesn’t generate a persistent biometric identifier of any speaker on a Basil-side server. That’s the specific harm alleged in the Fireflies BIPA case.
None of that removes the customer’s obligation to disclose recording to other participants where the law requires it. Basil does not make you compliant — compliance is your determination. But it does remove the entire class of vendor-side risk the Granola, Otter, and Fireflies complaints are built on. For a fuller technical walkthrough, see our on-device iOS 26 transcription guide and our note on AI transcript discoverability.
Before You Hit Record: A 5-Question Checklist
Whether you keep your current notetaker or replace it, these are the five questions to answer before the next call:
- Does the tool upload audio or transcripts to a vendor server? If yes, you are in the wiretap-theory zone.
- Is training on captured content opt-in, or opt-out? Opt-out is the design at issue in Chamberlain.
- Can non-users see or control the recording? If not, the two-party-consent problem does not go away because your bot is invisible.
- Does any participant reside in California, Florida, Illinois, Massachusetts, or Pennsylvania? Those are all-party-consent states; a single participant triggers the statute.
- Would you be comfortable if the entire transcript were produced in litigation next year? If not, don’t create it in a place a vendor can produce it.
What Happens Next in the Case
Chamberlain v. Granola is at the earliest possible stage — a complaint, not a ruling. Granola has not yet answered or moved to dismiss. The most likely near-term inflection points are (1) Granola’s motion to dismiss, which will echo the standing and consent arguments Otter raised in In re Otter.AI; (2) any preliminary injunction motion targeting the training-by-default feature; and (3) transfer or consolidation with related actions if additional plaintiffs file in other districts.
Whichever way the individual case resolves, the reputational damage to the “bot-free is safer” marketing category is already done. A vendor that raised $192.3 million on invisibility is now defending invisibility in federal court. The signal to every enterprise buyer is unmistakable: if the transcript ever leaves the device, the vendor’s architecture is your liability surface too.
The Bottom Line
Chamberlain v. Granola closes the loop on a two-year arc of AI-notetaker litigation. Visible bots are being sued. Voiceprint generators are being sued. And now, invisible endpoint capture — the model that was supposed to be the privacy-friendly answer — is being sued too. The only architecture that hasn’t been sued is the one where the transcript never becomes anyone else’s data. That’s the architecture Basil AI ships.
Get Weekly Privacy Insights
On-device AI tips, privacy news, and Basil AI updates. No spam.
Unsubscribe anytime. Privacy Policy
Try the AI Notetaker That Can’t Be Subpoenaed
Basil AI runs 100% on your iPhone or Mac. No cloud. No training. No vendor copy of your meeting.
Frequently Asked Questions
What is Chamberlain v. Granola about?
It is a proposed class action filed July 30, 2026 in the Northern District of California (Case No. 3:26-cv-07926-EMC) alleging Granola's AI notetaker records meeting participants without their knowledge and uses those transcripts to train its AI models by default. The suit brings seven claims, including federal wiretap (ECPA) and California Invasion of Privacy Act violations.
Is Granola actually 'bot-free' — and why does that matter legally?
Granola runs on the user's device and captures system audio instead of joining calls as a visible participant bot. The complaint argues that invisibility is the legal problem: other participants have no notice a recording is happening. That directly targets the two-party-consent statutes (California, Florida, Illinois, and others) where all parties must consent to being recorded.
How is this different from the Otter.ai and Fireflies lawsuits?
Otter (In re Otter.AI Privacy Litigation, 5:25-cv-06911) and Fireflies (Cruz v. Fireflies.AI Corp., 3:25-cv-03399) involve visible bots that join meetings. Chamberlain v. Granola targets the opposite model — an invisible, endpoint-level capture tool — arguing that even without a bot in the participant list, non-users still don't consent. Together, the three cases pincer both architectures used by cloud AI notetakers.
Does Granola train its AI on my meeting transcripts?
According to the complaint, Granola's default setting feeds captured transcripts into its own AI model training, and the opt-out belongs to the Granola account-holder — not to the non-users who were recorded. That means participants on the other side of a call typically have no way to know training is happening, let alone stop it.
Are on-device AI notetakers automatically safer?
Not on their own — the Granola case shows that 'on-device' still fails when audio, transcripts, or model-training data leave the device. What actually protects participants is architecture that keeps processing, storage, and model training entirely local, with no cloud upload. Basil AI uses Apple's on-device Speech Recognition and never uploads audio or transcripts to any server.
Which laws does the Granola complaint invoke?
The suit alleges violations of the federal Electronic Communications Privacy Act (18 U.S.C. § 2511), the California Invasion of Privacy Act (CIPA §§ 631 and 632), California's Comprehensive Computer Data Access and Fraud Act, and common-law invasion of privacy. Statutory damages under CIPA alone can reach $5,000 per violation, per participant.