A California federal court has allowed privacy claims against Otter.ai to proceed, in a case that could carry enormous financial consequences for the company.
The lawsuit combines four proposed class actions filed in 2025, targeting Otter.ai’s AI-powered notetaking tool used across virtual meeting platforms.
Plaintiffs allege that Otter’s notetaker bot joins Zoom, Microsoft Teams, and Google Meet calls, recording and transcribing participants’ speech in real time without proper consent.
They also claim the company retains that meeting data and uses it to train its AI models, without obtaining consent from non-subscribing participants on those calls.
The case brings claims under Illinois’s Biometric Information Privacy Act, the federal Electronic Communications Privacy Act, and California’s Invasion of Privacy Act.
On the California wiretapping question, Otter argued its bot was an authorised meeting participant and therefore a party to the conversation, but the court rejected that reasoning.
The court held that Otter is a third-party eavesdropper under Section 631, not an invited participant, because it independently collects, retains, and uses the recordings for its own commercial purposes rather than simply returning a transcript to the meeting host.
The court drew a distinction between Otter’s conduct and a prior case, Graham v. Noom, Inc., where a recording tool acted as an extension of the customer who deployed it.
On biometric privacy, the court found that Otter’s speaker-tagging features plausibly involve capturing voiceprints, allowing those BIPA claims to survive the initial pleading stage.
The court did impose some limits, dismissing common law privacy claims where plaintiffs simply called their conversations private without alleging specific facts showing a reasonable expectation of privacy.
However, it allowed those privacy claims to proceed where conversations involved sensitive topics, including medical discussions, which the court treated differently.
Claims under the Computer Fraud and Abuse Act, California’s CDAFA statute, and the Washington Privacy Act were dismissed, as were most common law privacy claims except for one plaintiff.
The surviving claims now open the door to discovery into how the notetaker joins meetings, what notice participants actually receive, and how recordings feed model training.
Statutory damages in play are significant: ECPA allows $10,000 per violation, CIPA $5,000, and BIPA up to $5,000 per voiceprint, with BIPA claims requiring no proof of actual harm.
Otter.ai previously reported a user base of more than 35 million as of December 2025, making the potential aggregate exposure across surviving claims exceptionally large.
The ruling addresses only the pleading stage and does not establish that Otter actually violated any of these laws, with class certification battles still ahead.

