Comulytic Note Pro Privacy and Security Claims Examined In Depth

Affiliate disclosure: Purchases made through links on this page may earn this site a commission at no extra cost to you. All affiliate links carry rel="nofollow sponsored".
Comulytic Note Pro Privacy and Security Analysis

Direct answer: Comu publishes several useful safeguards for Comulytic Note Pro, including AES-256 encryption for local audio and cloud data, TLS 1.2 or 1.3 in transit, AWS hosting in the United States, app access through phone biometrics or passcodes, account deletion, file deletion and a statement that user data is not used to train AI models. Those controls are encouraging, but they do not by themselves prove that every healthcare, legal, financial or enterprise use is compliant.

The product page labels Comulytic as GDPR, HIPAA and SOC 2 compliant. The Trust Centre uses narrower wording for some points. It says internal processes and controls are aligned with ISO 9001 and ISO/IEC 27001, and it highlights certifications held by AWS. It does not publicly display a Comu SOC 2 report, ISO certificate, HIPAA business associate agreement or independent audit scope on the pages reviewed. A regulated buyer should request those documents directly.

Important distinction: Security features describe how a system attempts to protect data. Compliance depends on scope, contracts, organisational use, jurisdiction and evidence. A badge is not a substitute for due diligence.

Review Comulytic Product Details

Privacy verdict at a glance

Area Published position Editorial assessment
Local audio encryption AES-256 Positive technical control
Cloud encryption at rest AES-256 Positive, but key management detail is limited
Data in transit TLS 1.2/1.3 Current standard
Cloud region AWS in the USA Important for residency assessment
Model training Company says user data is never used Useful contractual question
Cloud backup Optional for recordings Confirm defaults during setup
Notes storage Trust Centre says notes are stored in cloud Core privacy consideration
File deletion Individual files can be deleted Test end-to-end behaviour
Account deletion Company says associated server data is removed Backup timelines need clarification
App access Face ID, Touch ID or passcode Helpful endpoint protection
HIPAA Product page says compliant Request BAA and scope
SOC 2 Product page says compliant Request current report and auditor
ISO 27001 Trust Centre says controls are aligned Alignment is not certification

The controls are more detailed than those of many new hardware brands. The evidence package is still not sufficient for a high-risk organisation to approve the product automatically.

Comu recorder in use

What data does Comulytic handle?

An AI note taker can process more than an ordinary audio file. The data set may include:

  • raw voice recordings;
  • transcripts;
  • speaker labels;
  • summaries;
  • highlights;
  • action items;
  • client profiles;
  • contact information;
  • AI questions and answers;
  • custom vocabulary;
  • imported audio or video;
  • device and account identifiers;
  • usage and diagnostic data.

Voice recordings can reveal health, finances, employment, legal disputes, political views and personal relationships. Even when the voice itself is not treated as biometric identification, the content can contain highly sensitive personal data.

The privacy review must cover every derivative. Deleting an audio file is not enough if the transcript, summary, contact profile, export, backup and CRM copy remain.

Local storage and device encryption

Comu says recordings stored on the device receive AES-256 protection. The product includes 64GB of local storage and can record independently from a phone.

That is a strong starting point, but an enterprise reviewer should ask:

  1. Are files encrypted individually or through full-device encryption?
  2. Where are encryption keys generated and stored?
  3. Can Comu recover or access a key?
  4. What happens after repeated failed access attempts?
  5. Can audio be copied over USB without app authentication?
  6. Does a factory reset cryptographically erase the key?
  7. Are file names, timestamps and metadata encrypted?
  8. Is firmware signed and protected against rollback?

The Trust Centre says encryption keys are centrally managed in the cloud and protected by access controls. That wording means the design is not simply a user-held local key. It deserves closer review for threat models involving vendor access or account compromise.

Transfer and cloud processing

The device connects through Bluetooth and Wi-Fi. Comu says platform connections use SSL/TLS, insecure HTTP is redirected to HTTPS and modern TLS 1.3 is supported. Cloud data is encrypted at rest with AES-256.

The Trust Centre states that audio is transmitted to AI providers solely to provide requested transcription, summaries and insights. It also says user data is not used for model training, advertising or profiling.

The page does not name every AI provider or publish a complete subprocessor list in the reviewed section. A business should request:

  • provider names;
  • processing countries;
  • retention at each provider;
  • model-training contract terms;
  • incident-notification commitments;
  • deletion propagation;
  • cross-border transfer mechanisms;
  • if human review can occur.

The fact that AWS holds infrastructure certifications does not automatically certify the application running on AWS. Shared-responsibility boundaries matter.

Comu recorder in use

Cloud backup versus cloud notes

The Trust Centre makes an important distinction. It says processed recordings and notes are stored in the cloud only when Cloud Backup is enabled, but then clarifies that recordings otherwise remain in the app or device while notes are stored securely in the cloud.

The wording can be read in more than one way. Buyers should verify:

  • if raw audio ever remains in cloud processing storage;
  • if transcripts and summaries always remain in the cloud;
  • if Cloud Backup is enabled by default;
  • how long temporary processing files survive;
  • if disabling backup removes existing copies;
  • how mobile and web access affect storage;
  • if deleted files remain in disaster-recovery backups.

An editor should not simplify this into “everything stays local.” AI processing and notes involve cloud services.

Account and application access

Comu describes several application controls:

  • automatic account suspension after a defined number of failed logins;
  • Face ID, Touch ID or phone-passcode protection;
  • profile-level locks for contact content;
  • firewall protection;
  • threat monitoring;
  • abuse and bot detection;
  • routine assessments and audits.

These are useful controls, but the Trust Centre does not publicly state if consumer accounts support:

  • multi-factor authentication independent of the phone;
  • hardware security keys;
  • active-session review;
  • remote logout;
  • login alerts;
  • role-based access;
  • team audit logs;
  • single sign-on;
  • SCIM provisioning.

An individual user should enable the strongest phone lock, avoid shared device accounts and review active sessions. A business should not assume consumer biometric access equals enterprise identity management.

Deletion and retention

Comu says users can delete individual recordings or notes and that account deletion removes associated user data from servers. The FTC has repeatedly emphasised that companies must honour privacy, retention and deletion promises, especially for voice data.

A practical deletion test should:

  1. create a unique recording with a searchable phrase;
  2. confirm it appears in the app and web account;
  3. export a copy for the test record;
  4. delete the recording;
  5. check trash or recovery areas;
  6. search the transcript, summary and client profile;
  7. check all synced devices;
  8. request account export if available;
  9. ask support for backup-retention details;
  10. document the time until removal.

The return policy tells buyers to erase personal data before returning hardware. Comu performs a factory reset after receipt but disclaims liability for data left on the device. This makes user-controlled erasure an operational requirement.

Does Comulytic use recordings to train AI?

Comu states that user data is never used to train AI models and is not shared for advertising or profiling. This is a meaningful promise.

A business should still determine:

  • if the promise covers every subprocessor;
  • if de-identified or aggregated content is excluded;
  • if feedback submissions can be used;
  • if support access creates a separate permission;
  • if diagnostics contain transcript text;
  • if terms can change;
  • how the company enforces the restriction technically and contractually.

The safest editorial wording is “Comu says it does not use user data to train AI models.” It should not be shortened to an independently verified guarantee.

GDPR analysis

Comu says it complies with GDPR. For a European or UK organisation, using the product can still make the organisation a controller responsible for:

  • a lawful basis;
  • transparency to recorded people;
  • purpose limitation;
  • data minimisation;
  • retention;
  • security;
  • data-subject rights;
  • processor contracts;
  • international transfers;
  • high-risk impact assessments.

The UK Information Commissioner's Office advises organisations to tell people why a meeting is recorded, how the recording will be used and how long it will be kept. It also says organisations should identify and document a lawful basis.

Consent is not always the only possible lawful basis under data-protection law, but recording-law rules and organisational policies may separately require it. The safest practical habit is to give clear notice and obtain agreement before recording.

HIPAA analysis

The product page labels Comulytic HIPAA compliant. That does not automatically make every healthcare use compliant.

US Department of Health and Human Services guidance says a covered entity using a cloud provider to create, receive, maintain or transmit electronic protected health information generally needs a HIPAA-compliant business associate agreement with that provider when it acts as a business associate.

A healthcare buyer should ask Comu:

  1. Will it sign a BAA?
  2. Which legal entity signs it?
  3. Which services and apps are within scope?
  4. Which subprocessors receive protected health information?
  5. Are all relevant subprocessors covered by agreements?
  6. How are access logs and breach notices handled?
  7. Can cloud processing be restricted by region?
  8. What retention and deletion commitments apply?

Without a signed BAA and an approved organisational configuration, the presence of a HIPAA badge should not be treated as authorisation to record patient information.

SOC 2 and ISO claims

The product page says SOC 2 compliant. The Trust Centre says AWS offers SOC 1 through SOC 3 certifications and that Comu controls are aligned with ISO/IEC 27001.

These are different statements:

Statement What it means
AWS has a SOC report AWS controls were audited within a stated scope
Comu is hosted on AWS Comu uses that infrastructure
Comu has its own SOC 2 report Comu controls were examined in its own scope
Controls align with ISO 27001 Company says it follows aspects of the standard
Company is ISO 27001 certified Accredited certification exists for a defined scope

The public pages reviewed do not provide enough evidence to collapse those rows into one. Procurement should request the current report or certificate, scope, legal entity, auditor, period and any exceptions.

Recording law varies by country, state and context. Some US states generally require consent from all parties, while others follow one-party rules. Employment, education, court, healthcare and professional rules can add stricter obligations.

This article is not legal advice. A responsible workflow should:

  • announce recording before it begins;
  • explain the purpose;
  • state who can access the result;
  • provide an alternative when possible;
  • avoid hidden recording;
  • document consent where necessary;
  • stop if a participant objects;
  • follow local law and company policy.

Omi's official product page gives the same practical warning: always obtain permission and follow local recording law. Every AI recorder should be handled that way.

Threat model

Threat Example Useful control
Lost recorder Device left in taxi Device encryption, remote account controls
Compromised phone Attacker opens app Strong passcode, biometrics, MFA
Account takeover Reused password leaked Unique password, MFA, session review
Over-sharing Public link contains client call Expiring links and permission checks
Insider access Staff sees recordings unnecessarily Roles, logs and least privilege
Vendor breach Cloud system compromised Encryption, monitoring, incident contract
Prompt or summary error AI misstates a commitment Human verification and source playback
Excess retention Old sensitive calls remain Automatic deletion policy
Unlawful recording Participant not informed Notice and consent workflow

Security is strongest when technical controls and operating discipline support each other.

Enterprise due-diligence checklist

Before approval, request:

  • data processing agreement;
  • current subprocessor list;
  • security architecture summary;
  • penetration-test executive report;
  • vulnerability-management policy;
  • incident-response and notification terms;
  • SOC 2 report if claimed;
  • ISO certificate if claimed;
  • BAA if healthcare use is intended;
  • retention and backup schedule;
  • data-location options;
  • access-control matrix;
  • deletion procedure;
  • export and portability documentation;
  • AI training and human-review terms.

Run a limited pilot with synthetic or low-sensitivity data before recording confidential meetings.

Privacy scorecard

Question Public answer Buyer action
Is local audio encrypted? Comu says AES-256 Verify device behaviour
Is transport encrypted? TLS 1.2/1.3 Confirm all endpoints
Where is cloud infrastructure? AWS in USA Review transfer and residency
Is data used for AI training? Comu says no Put promise in contract
Can users delete files? Yes Test propagation and backups
Is cloud backup optional? Stated as optional for recordings Check default
Are notes cloud stored? Trust Centre says yes Apply retention controls
Is a BAA public? Not found on reviewed pages Request before PHI
Is a Comu SOC report public? Not found on reviewed pages Request evidence
Is Comu ISO certified? Page says aligned Request certificate if claimed

Final verdict

Comulytic publishes a credible baseline security story: local and cloud AES-256, TLS, AWS infrastructure, biometric app protection, deletion controls and no training on user data. Those are meaningful positives.

The main weakness is evidence clarity. Marketing badges are broader than the supporting Trust Centre language, particularly around SOC 2, ISO and HIPAA. Regulated buyers should treat those items as questions to resolve, not conclusions.

For ordinary business meetings, Comulytic can be used responsibly with notice, strong account security, limited retention and human review. For patient, legal, financial or highly confidential data, procurement should require contracts, audit evidence, subprocessor detail and a documented risk assessment before deployment.

Check Current Comulytic Features and Policies
Quick answers

Frequently asked questions

Clear answers to common questions readers check before choosing a Comu recorder.

Is Comulytic Note Pro secure?

Comu publishes AES-256, TLS, AWS hosting, device controls and deletion features. Suitability still depends on configuration, contracts, evidence and user behaviour.

Does Comulytic store recordings in the cloud?

The Trust Centre describes optional cloud backup for recordings, while notes are stored in the cloud. Temporary AI processing should be clarified with Comu.

Does Comulytic use data to train AI?

Comu says user data is never used to train AI models and is not used for advertising or profiling.

Is Comulytic HIPAA compliant?

The product page says so, but a healthcare organisation should request a signed BAA, scope and subprocessor details before processing protected health information.

Is Comulytic SOC 2 certified?

The product page uses a SOC 2 compliance label. The reviewed Trust Centre highlights AWS certifications but does not display a Comu SOC 2 report.

Is Comulytic ISO 27001 certified?

The Trust Centre says internal controls are aligned with ISO/IEC 27001. Alignment should not be described as certification without a valid certificate and scope.

Is local audio encrypted?

Comu says audio on the device is protected with AES-256. Buyers should ask how keys, USB access and factory reset are handled.

Can a user delete Comulytic data?

Comu says individual recordings and notes can be deleted and account deletion removes associated server data. Backup timelines should be confirmed.

Does a user need consent to record?

Requirements vary by jurisdiction and context. Clear notice and agreement are prudent, and local legal or organisational rules may require consent.

Can Comulytic be used for patient appointments?

Only after the healthcare organisation approves the workflow, obtains necessary agreements and follows consent, security and HIPAA requirements.

What should happen before returning the device?

The user should erase all personal data, remove account links and follow Comu's return instructions. The policy places responsibility for pre-return erasure on the user.

What is the biggest privacy risk?

The largest practical risk is recording sensitive conversations without a complete plan for notice, access, retention, deletion and downstream copies.