Skip to content

A client asks whether their conversation is safe, and the honest answer is never a single checkbox — it's the sum of where the recording lives, who can reach it, and whether it was ever somewhere else along the way. This walks through what actually determines that, rather than what a feature list claims about it.

Intake call — new engagement

Decisions

  • Proceed on the terms discussed; formal agreement to follow

Actions

  • Confirm which prior notes can be referenced in the written summary

Open questions

  • Does the client want the recording itself retained past this engagement, or deleted once the summary is final
A confidential intake call, its record never generated or stored anywhere but the Mac in the room.

What "confidential" actually depends on

Three separate things determine whether a recording stays confidential, and a tool can get one right while getting another wrong: whether the audio ever left the device that made it, whether the device itself is secured against someone else opening its files, and whether whoever handles the resulting transcript afterward treats it with the same care as the conversation itself. A tool that never uploads anything has solved the first of the three — the other two are still up to the person using it.

Step 1 — start from a recorder that doesn't upload anything

This is the part a tool controls rather than a setting a user has to remember to enable. Coii AudioNotes records the microphone and the call's own audio as two local tracks, transcribes them on the Mac, and writes the summary there too — nothing about that pipeline sends the audio, the transcript or the minutes to a server at any point. That's not a privacy mode switched on for sensitive work specifically; it's how the app produces a transcript at all, for every recording, which means there's no setting to forget or misconfigure before a confidential call starts.

Step 2 — lock down the Mac itself

Not uploading a recording only protects it from a network; it does nothing about someone who has physical access to the Mac it's stored on. Turning on FileVault, Apple's built-in full-disk encryption, means the drive is unreadable without the login password, even removed and connected to another machine — a lost or stolen laptop with FileVault on stays locked rather than becoming an open file cabinet. This is a macOS setting, not anything specific to this app, and it's the single step that does the most for a confidential archive's actual security.

Step 3 — decide deliberately where the archive lives

By default, recordings, transcripts and minutes sit in the app's own local storage rather than anywhere synced automatically. That's worth confirming rather than assuming — if the Mac is set up to sync its whole user folder to a personal cloud account for unrelated reasons, it's worth knowing whether the app's data folder falls inside that sync scope, since a confidential recording that's fine sitting on one Mac may not be a recording you'd choose to also have living on a cloud drive.

Step 4 — think about what a speaker label reveals

Once a voice is named — replacing a generic "Speaker 2" with an actual name — that name becomes part of the transcript text itself, searchable the same as anything else in it. For most meetings that's exactly the point; for a conversation where even the fact of who was present is itself sensitive, it's worth considering whether a transcript needs real names attached at all, or whether initials or a role ("client," "counsel") serve the same purpose with less identifying detail sitting in a plain text file.

Step 5 — control who else uses the Mac

A recording's confidentiality is only as good as the login it sits behind. On a Mac shared with anyone else — a household member, a colleague, an assistant with occasional access — a separate macOS user account, each with its own password, keeps one person's archive from being casually browsable by another user of the same physical machine. This matters more than it might seem: the app itself has no separate login of its own, so whatever access the operating system grants is the access there is.

Step 6 — treat an exported copy as a new decision, not a formality

Exporting a transcript out of the archive — copying it into an email, a shared drive, a case file — is the moment the "nothing leaves the Mac" property stops applying to that specific copy. That's often necessary and often the whole point of having transcribed the call at all; it's worth being deliberate about it rather than treating a copy-paste as free of the same care given to the original recording.

What this doesn't claim, and shouldn't

No compliance certification is claimed here — not for therapy, not for legal work, not for any regulated field. What's actually true and checkable is the behaviour described above: nothing is uploaded, and the recording, transcript and summary exist only as files on the Mac that made them. That's the fact a compliance officer or a client can verify and reason about directly, rather than a badge asserting a standard has been met. Where a specific profession has its own formal requirements, checking those against this behaviour — rather than against a marketing claim — is the right next step, and this page isn't the source for what those requirements are.

How this compares to a cloud tool's confidentiality model

Several cloud notetakers offer a setting to opt out of having recordings used to improve the vendor's own models — which, by definition, means the default for everyone who hasn't found and enabled that setting is that their calls may be used that way. The wider list of meeting apps that don't train on recordings at all covers that distinction across several tools directly. A recording that's never uploaded in the first place removes the question of whether an opt-out setting is correctly configured, because there was never a point where the audio reached a system that setting would apply to.

Deciding whether to record a sensitive conversation at all

Before any of the technical steps above come into play, there's a prior decision worth taking seriously: not every confidential conversation should be recorded, even by a tool that never uploads anything. Some clients or patients will simply prefer no recording exists at all, regardless of how it's secured, and honoring that preference is a separate matter from how well the recording would have been protected. A tool that keeps everything local removes one category of risk; it doesn't remove the judgment call about whether recording is the right choice for a given conversation in the first place.

What "on the Mac" doesn't protect against

It's worth naming the limits plainly rather than overselling the guarantee. A recording that never leaves the Mac is still exposed to anything that compromises the Mac itself — malware, a coerced or shared login, a Mac left unlocked in a public place. Local storage closes off the specific risk of a vendor's servers being breached or a cloud account being compromised; it doesn't make the Mac itself invulnerable, which is exactly why the device-level precautions — FileVault, a strong login, not leaving the machine unattended and unlocked — matter as much as the fact that nothing was uploaded in the first place.

Retention: deciding how long a confidential recording should exist

Confidentiality isn't only about who can access a recording today — it's also about whether it should still exist a year from now. Some engagements have a natural point where the underlying recording is no longer needed, even if the written summary is kept. Because everything lives as ordinary files, deleting a specific recording once it's served its purpose is the same as deleting any other file — no account-level request to file, no vendor process to wait on, no confirmation email to a company that then has its own copy regardless of what gets deleted locally.

Recording an in-person conversation, not just a call

None of the above depends on the confidential conversation happening over a video platform. An intake meeting in an office, a client sitting across a desk, a source meeting in person — each records the same way, with the microphone doing the capturing rather than the call's own audio, and the same considerations about the Mac's own security and who else can access it apply identically either way.

Who ends up building a routine around this

Anyone whose work regularly involves conversations that can't be casually shared has more riding on getting this right than someone recording a weekly internal sync. Lawyers and therapists are the clearest examples, but the same logic applies to a journalist protecting a source, a consultant under an NDA, or an HR conversation that shouldn't be searchable by anyone outside the room. The wider field of meeting tools built with regulated or sensitive work in mind covers how several tools, not just this one, approach the same problem.

What a confidential recording still requires of you

None of the steps above replace judgment about what gets recorded in the first place, who's told about it, and what happens to a transcript once it exists — a tool that never uploads anything still can't decide on your behalf whether a specific conversation should be recorded at all, or who's entitled to a copy of it afterward. That's a professional and, often, a legal question specific to the conversation, not something this page or any product page is positioned to answer.

Building the habit before a conversation demands it

The moment this stops being an abstract precaution is usually a specific one — a client explicitly asking where the recording goes, or a compliance review asking the same question after the fact. Building the underlying habits — FileVault on, a dedicated user account if the Mac is shared, a deliberate decision about naming speakers — before that moment arrives means there's nothing to scramble to fix when someone actually asks.

A short setup worth doing once, before the first confidential call

Most of what's covered above is a one-time setup rather than a per-meeting task: turning on FileVault, confirming the archive folder isn't unintentionally synced somewhere, deciding on a naming convention for sensitive speakers, and setting up a separate user account if the Mac is shared. Done once, before the first confidential recording rather than after a client asks about it, none of it adds friction to any individual call afterward — the work happens up front, and every recording made after that inherits the same baseline without anyone having to think about it again mid-conversation.

Confidentiality across more than one Mac on a licence

A licence covers up to three of a person's own Macs, each keeping its own separate archive rather than a shared one — a confidential recording made on a laptop doesn't appear on a desktop covered by the same licence unless it's moved there deliberately. For someone who records client work on more than one machine, that means the same precautions — FileVault, a secure login, a deliberate decision about where files live — need applying to each Mac individually rather than assumed to carry over automatically from wherever they were first set up.

A short answer for when a client asks directly

Clients increasingly ask the question outright, and it's worth having a plain, honest answer ready rather than improvising one mid-conversation: the recording, the transcript and the summary are all produced and stored on the Mac in the room, nothing about any of them is sent to a server, and the drive itself is encrypted. That's a complete, accurate answer that doesn't lean on a certification that isn't there — and it's usually a more satisfying one to a careful client than a badge would be, because it describes exactly what happens rather than asking them to trust a label.

What it costs, what it runs on

None of this confidentiality routine is a paid tier or an add-on. Coii AudioNotes is $19 once, with a 30-day trial that needs no card and no account, running on macOS 13 Ventura or later, Apple Silicon or Intel. How local transcription actually works covers the underlying mechanism this page has been describing the consequences of.

Questions

Is Coii AudioNotes certified for handling confidential client work?
No compliance certification is claimed, for this or any use. What's true is the behaviour: the recording, transcript and summary stay on the Mac and nothing is uploaded — check that against your own field's specific requirements.
Does the app encrypt recordings automatically?
The app doesn't add its own encryption layer. Turning on FileVault, macOS's built-in full-disk encryption, protects everything on the Mac, recordings included, and is the standard way to cover this.
Can someone else who uses the same Mac see my client recordings?
If they're logged into the same macOS user account, potentially yes — the recordings are files like any other on that account. A separate user account, each with its own login, keeps one person's archive from a shared Mac's other users.
Is it legal to record a client conversation without telling them?
That depends on jurisdiction and the kind of consent it requires, which this page doesn't attempt to answer — a client's or patient's own compliance counsel is the right source for that, not a product page.