Basic, Pro & Business: No BAA, HIPAA is Enterprise-only · Trains on de-identified recordings and transcriptions, with no plan-based exception published · Retention not stated
Enterprise: BAA on request · Whether a BAA changes the training posture is not stated · Customer-defined retention
| Basic, Pro & Business | Enterprise | |
|---|---|---|
| HIPAA BAA | No"HIPAA compliance is only available for the Enterprise plan"; Business at $30/user/month is not covered | Yeson request - contact your account manager to start the BAA process. Otter is not a covered entity by default; it becomes a Business Associate only once a BAA is signed |
| Trains on your data | YesOtter trains "on de-identified audio recordings and on transcriptions"; the privacy policy states no plan-based exception. Imported documents (e.g. from Google Workspace) are excluded from training | Not publicly clarified for this tierthe privacy policy states training on de-identified recordings and transcriptions with no plan-based carve-out, and no document states whether an executed BAA changes that posture |
| Survives deletion | Not publicly statedthe privacy policy gives no retention timeline, only that deletion renders data "irrecoverable or irreproducible"; customer-defined retention is an Enterprise control | Customer-defined retention policies; Otter deletes data on contract termination at customer request. No default retention period stated |
| Deployer / admin log access | Not publicly stated for these tiersadmin controls are documented for Enterprise | YesEnterprise admin controls are documented |
| Third-party attestation | SOC 2 Type 2 stated on Otter's Privacy & Security page. ISO 27001/2 is described as the framework their policies are "created based on," not a certification. Scope by plan not stated | SOC 2 Type 2 stated; ISO 27001/2 described as a framework basis, not a certification |
Otter Enterprise, the only plan with a BAA - paying $30/user/month for Business does not get HIPAA coverage; also Otter's ISO 27001/2 wording, which describes a framework basis rather than a certification
The Business plan, which has no BAA; also the assumption that signing a BAA turns training off, which Otter's published policy does not state
Vendor terms change without notice. This page reflects what Otter.ai published as of September 2, 2026. Re-verified quarterly.
If you need a scored Go / Conditional Go / No-Go verdict for a vendor decision — including a vendor not listed here — that's an AI Vendor Risk Assessment: three binary industry gates, nine scored criteria, four provenance fields on every finding. $997, delivered in 48 hours.
See how AVRA works →Want all 13 tools in one file?
Covers 22 tiers across 13 tools — same sourcing, side by side, printable for a vendor file.