yapyapNotes
Explainer/

What \"delete\" means when the recording is not yours

Delete is the most reassuring button in software and the least specific. In a cloud notetaker it can mean at least four different things, only one of which is the thing you pictured, and in the case that matters most it is not available to you at all.

This is not an accusation aimed at any particular vendor. It is how the architecture works, and it works this way at all of them.

Four different deletes

The one you pictured. The bytes are unrecoverable. Nobody at the company could produce your audio if a court asked them to. This is the meaning the button implies and the least common thing it does on the day you press it.

The row is marked deleted. The recording disappears from your list. The object still exists in storage, flagged, until a scheduled job comes past. The interval is a business decision written into the retention policy, and it is usually measured in weeks — partly to let people undo an accident, partly because deleting things properly at scale is work.

The primary copy is gone, the backups are not. Backups exist so a bad deploy does not destroy the service, which means they are snapshots taken before you pressed anything. A vendor that honours deletion properly still carries you in restore points until those age out on their own schedule. Any vendor claiming instant erasure everywhere either does not take backups or is describing the primary store and calling it everything.

The audio is gone and the derivatives are not. This is the one people miss. Your recording produced a transcript, a summary, embeddings for search, and a row in whatever analytics pipeline counts meeting minutes. Some of those are your data. Some are aggregates. Deleting the source does not automatically walk the graph, and whether it does is a question about that specific vendor's engineering, not about the law.

None of this is hidden. It is in the data processing agreement, in a section most people scroll past on the way to clicking accept. If you want the real answer for your vendor, that document is where it is, and the number you are looking for is the retention window for deleted objects.

The case where the button is not yours

Here is the part that no amount of careful reading fixes.

Somebody adds a notetaker to a call. You speak. The recording, the transcript and the summary now live in their account, under their workspace, subject to their company's retention policy, which is set by an administrator you have never met.

You are in the recording. You do not have a login.

Ask them to delete it and you are asking a favour, not exercising a control. If they work somewhere with a legal hold, or a compliance policy that retains client calls for seven years, they may not be permitted to do it even if they want to. The transcript with your name on every other line is a record their employer owns.

In Europe you do have a real right to ask — Article 17, erasure — and it is worth knowing three things about it before you rely on it. It runs against the controller, which is their employer, not the notetaker vendor, who is usually a processor acting on instruction. It has exceptions, including records kept to establish or defend legal claims. And exercising it requires knowing the recording exists, which requires having noticed the bot on the guest list four months ago.

This is the asymmetry under the whole category. The person who pressed record gets a delete button. Everybody else gets a request form.

It is also, quietly, why so many organisations have started banning meeting bots outright. The consent problem gets discussed. The deletion problem is the one legal teams actually cannot solve.

Deleting from a local archive

The local version is genuinely simpler, and the honest description of it includes the parts that are not simple.

A recording in yapyap is a file on your disk. Delete it and the file goes, along with its transcript and every lens output derived from it. There is no vendor backup, because we never had a copy. There is no account to ask, no administrator, no processor, no support ticket.

There is, however, a retention window, and this post would be worthless if it skipped over ours.

Deleted recordings go to a .trash/ folder in your vault and are purged after thirty days. Same folder layout, same files, recoverable by moving one directory back. It exists for exactly the reason the cloud version exists: people delete things by accident.

Two differences carry the whole argument. It is thirty days on your own disk rather than an unspecified interval on somebody's storage cluster — you can see the folder, count the files and know precisely what is in it. And you can end it early yourself by emptying it, which is an action rather than a request.

Now the rest of the caveats, which are also real.

Your own backups still have it. Time Machine, File History, a cloned drive, the NAS in the cupboard. If your machine is backed up — and it should be — the recording is in those snapshots until they roll over. This is your infrastructure and your policy, which is the point, but it is not nothing.

A companion capture may exist on the phone. If a recording came from the phone and was handed to the desktop, check the phone as well as the laptop.

Anything you deliberately exported is wherever you sent it. A summary pasted into Slack is in Slack. A transcript mailed to a client is in two mailboxes. The local archive is only the copies you did not make.

And the other person in the conversation is still a person. Local recording removes the vendor from the picture. It does not remove the fact that you recorded somebody, which is a matter between you and them — and is why asking properly is worth more than any retention setting.

What changes is not that deletion becomes magic. It is that deletion becomes something you can perform yourself, completely, without asking anyone — and that the full list of remaining copies is a list you made and can therefore check.

The question to ask

For any tool you are considering, one question separates the architectures:

When I press delete, whose job is it?

If the answer is a scheduled process at a company, on their timetable, subject to their backups, with your derivatives handled at their discretion — that is a request, however good the company.

If the answer is the filesystem, immediately, on hardware in front of you — that is a delete.

And if you are the one being recorded, ask the earlier question instead: is there anything here I could delete at all? Most of the time, in a cloud notetaker somebody else is running, there is not. Which is much of why meetings are better kept on the machine they happened on, and what our own privacy page has to be specific about.

yapyap records, transcribes, and summarizes on the hardware you already own. No account, no subscription.

Download yapyap

also on:macOS · Windows · Linux · iPhone (Go) · Android (Go)

Free to try. No card, no account.
Then €69, once. Yours forever, every update included.
Your recordings never leave your computer.