A proposed class action filed July 30, 2026, in the US District Court for the Northern District of California accuses Granola, the venture-backed AI meeting notetaker, of intercepting and recording virtual conversations without the knowledge of most participants, then feeding those recordings into its own AI model training by default.
The complaint, Chamberlain v. Granola, Inc. and Granola Labs Ltd., was brought by Tarra Chamberlain, a Florida resident, on behalf of a proposed nationwide class and a California subclass. It names two corporate defendants: Granola, Inc., a Delaware corporation, and Granola Labs Ltd., a United Kingdom software-development entity incorporated on March 3, 2023. Christopher Pedregal and Sam Stephenson, Granola's founders, have served as the UK entity's only directors since its formation, according to the filing.
Chamberlain's attorneys, from Schubert Jonckheer & Kolbe LLP in San Francisco and Lowey Dannenberg, P.C. in White Plains, New York, filed the case as Case No. 3:26-cv-07926-EMC. Although the complaint seeks a jury trial and asserts seven separate claims, its core allegation is simple: a notetaking tool marketed for its invisibility captured private conversations, then used them to improve its own commercial product, without most speakers ever knowing.
For an industry that increasingly relies on AI tools sitting inside sales calls, client meetings, and internal strategy sessions, the filing raises a question extending well past one notetaking app. What happens when the tool documenting a conversation does not tell the people in it that it is there, and then repurposes what it captured to make itself smarter?
What the complaint alleges
According to the filing, Granola's core product is AI notetaking software available on desktop, through macOS and Windows applications, and on mobile, through iPhone and Android apps. A user connects the tool to a calendar, and it automatically joins scheduled video calls on platforms including Google Meet, Zoom, and Microsoft Teams. An in-app button also lets a user start recording an unscheduled call, and the complaint states Granola can capture in-person conversations as well.
The mechanism, as described in the complaint, works by pulling audio from two sources on the user's computer: the microphone, which captures what the Granola user says, and the system audio output, which captures what everyone else on the call says. Because the software draws from whatever audio the computer plays, the complaint notes it can transcribe calls made through practically any internet calling or voice-over-internet application, not merely the major video platforms. That audio, according to the filing, is passed directly to a transcription vendor acting as Granola's agent, generating a live transcript while the meeting is still underway rather than processing a saved recording afterward.
A separate feature attempts to attribute each line of the transcript to a specific participant, labeling statements with a participant's display name from the meeting platform when configured to do so, and falling back to generic labels for the user's own audio versus everyone else's when it is not. The complaint states Granola can also infer who is speaking from context elsewhere in the transcript and let a user correct the attribution afterward.
None of this, the complaint states, is disclosed to other meeting participants by default. Two optional notice mechanisms exist instead: one posts a message in the meeting chat once transcription begins, and the other overlays a visible marker on the user's video feed. Because both require the user to switch them on separately, the complaint argues Granola can operate with neither notice active in the ordinary course of business. The filing also states that Granola does not configure Zoom or Teams settings on a customer's behalf, leaving any platform-level recording notice entirely up to the user.
The marketing language at the center of the case
The complaint places significant weight on how Granola describes this design choice in its own marketing. Quoting the company's website, the filing states Granola frames the absence of a visible bot as the distinguishing feature that separates it from other AI meeting assistants, telling prospective customers plainly: "Other people in the room won't know it's there."
Elsewhere on the site, according to the complaint, Granola argues that tools which announce themselves as visible bots change how people behave on a call, particularly in client conversations, interviews, and early-stage discussions, and that the strongest version of a meeting assistant is consequently one that stays unannounced. The complaint characterizes this framing as evidence that the lack of disclosure is not an accident of engineering but a deliberate business decision, one the company advertises to customers as a selling point rather than disclosing to participants as a risk.
The AI training allegation
Beyond the recording itself, the complaint's second major thread concerns what Granola does with the data afterward. The filing states model training is enabled by default for users on Granola's Free and Business plans, through a setting a user must locate and manually disable. On Business plans, the complaint adds, each individual user must opt out separately rather than an administrator doing so once for an entire workspace.
Even then, according to the complaint, the opt-out only applies going forward. The filing describes Granola's own materials as acknowledging the company cannot confirm that a user's data was excluded from training that occurred before the setting was changed, and as stating that once material has been used in training, isolating or removing specific data from the resulting model is not achievable using current techniques.
The complaint separately cites Granola's privacy policy, dated July 24, 2026, describing a similar limitation for data folded into the company's broader AI and analytics systems: removal, it states, would require rebuilding the underlying model or database from scratch rather than deleting a discrete record.
Because the individuals whose voices get captured on a call are frequently not Granola account holders themselves, the complaint argues they have no ability to exercise even the limited, forward-looking opt-out available to paying users. The people supplying the underlying training material, in other words, are not the people with any setting to adjust.
Sharing beyond the call
The complaint also describes how Granola's sharing settings can extend a captured conversation's reach well past the original participants. According to the filing, a Granola user can generate a link to a meeting note and set its access so that anyone holding the link can view it, a configuration the company itself labels as public. A person who receives that link does not need a paid Granola account to view the note, according to the complaint, and can use a chat feature to ask follow-up questions about what was discussed, drawing on the underlying transcript.
Granola also integrates with email, Slack, Notion, HubSpot, Affinity, Attio, and Zapier, the complaint states. When a note is shared to Slack specifically, the filing alleges a posted summary remains visible in the Slack message even after the underlying Granola note is later restricted to private access, and that a publicly accessible note can surface a meeting's title, attendees, date, and summary excerpt in a link preview generated automatically by Slack.
Legal theories at play
The complaint asserts seven claims for relief. The first is common law invasion of privacy under an intrusion-upon-seclusion theory, arguing Granola intentionally intruded on conversations where participants had a reasonable expectation of privacy, and that the intrusion, given its secrecy and its use for AI training, would be highly offensive to a reasonable person.
The second claim invokes the federal Electronic Communications Privacy Act, which restricts the interception, use, and disclosure of wire, oral, and electronic communications. The complaint argues Granola's US operations, including a San Francisco office it describes as the hub of its North American go-to-market efforts, bring its conduct within the statute's reach.
The third and fourth claims rely on California's Invasion of Privacy Act, commonly abbreviated CIPA, specifically sections 631 and 632 of the state's penal code. Section 631 addresses unauthorized interception and use of communications transmitted over a wire or line, while section 632 addresses recording a confidential communication using an electronic device without the consent of all parties. CIPA was originally written in 1967 to address telephone wiretapping, and courts have since extended its application to newer communications technologies. The complaint seeks statutory damages under these provisions of either $5,000 per violation or three times actual damages, whichever is greater, a formula set out in Penal Code section 637.2(a).
The fifth claim cites California's Comprehensive Computer Data Access and Fraud Act, arguing Granola accessed and used data from participants' devices without permission. The sixth invokes California's Unfair Competition Law, and the seventh alleges unjust enrichment, arguing Granola profited from data it obtained without compensating the people whose conversations supplied it.
The complaint states the proposed nationwide class likely consists of millions of individuals and that the amount in controversy exceeds $5,000,000, the jurisdictional threshold for federal class actions under the Class Action Fairness Act.
How the complaint frames industry norms
To support its argument that Granola departed from standard practice, the complaint points to competing notetaking tools, describing at least one rival as pledging never to use customer recordings or transcripts to train its own AI systems, and another as alerting participants by default whenever a meeting is being recorded while offering ways to avoid it. Granola, the complaint argues, chose the opposite path on both counts.
The filing further cites survey data on consumer privacy attitudes generally, without tying the figures to Granola directly. It references a Consumer Reports study finding 92 percent of Americans believe internet companies should be required to obtain consent before selling or sharing personal data, and a Pew Research Center study putting the share of Americans concerned about how companies use collected data at approximately 81 percent. The complaint also cites a 2021 industry analysis showing that after Apple's iOS 14.5 update required an affirmative opt-in for cross-app tracking, 85 percent of users worldwide and 94 percent of US users declined to share data when prompted.
Company background disclosed in the filing
The complaint traces Granola's corporate history using the company's own public statements and prior press coverage. It states Granola publicly launched its notetaking software in May 2024, following a six-month beta period involving roughly 150 users. The company raised a $20 million Series A round in 2024, followed by an additional $43 million round at a reported valuation of approximately $250 million. On March 25, 2026, according to the complaint, Granola announced a $125 million Series C financing round, pushing its valuation to approximately $1.5 billion.
The complaint lists customers including Vanta, Gusto, Thumbtack, Asana, Cursor, Lovable, Decagon, and Mistral AI, and separately names Brex and Vercel as San Francisco-based companies it says have become customers. The filing also describes Granola recruiting employees in California, hosting events in San Francisco, and placing billboards in the city as part of its marketing efforts.
Neither Granola, Inc. nor Granola Labs Ltd. had filed a public response to the complaint as of this writing. The company's own public materials, quoted throughout the filing, describe the product's lack of visible disclosure as an intentional design decision rather than an oversight.
Why this matters for marketing and advertising professionals
The allegations against Granola sit inside a rapidly accumulating body of CIPA and wiretapping litigation that has, over the past year, moved from advertising trackers toward AI products themselves. PPC Land has tracked this progression closely. In August 2025, a federal jury in San Francisco found that Meta violated CIPA by collecting sensitive health data from users of the Flo period-tracking app without consent, a verdict PPC Land reported centered on Meta's software development kit embedded inside a third-party app. That case established a template plaintiffs' firms have since applied to AI platforms directly.
By March 2026, a California court had entered a $50 million final judgment and permanent injunction against Meta over how Facebook user data was shared with third-party developers, a case PPC Land covered as part of a pattern of mounting privacy exposure across jurisdictions. The following month, a class action against Perplexity AI, Meta, and Google alleged the AI search engine embedded the Meta Pixel and Google Analytics to forward users' conversations, including health and finance queries, to advertising platforms without consent, as PPC Land detailed at the time; that case was later voluntarily dismissed without prejudice. A structurally similar complaint against OpenAI followed in May 2026, alleging ChatGPT's interface forwarded user queries to Meta and Google through embedded tracking code, a filing PPC Land examined in the context of CIPA's expanding reach.
The Granola complaint differs from these precedents in one significant respect. Where the Meta, Perplexity, and OpenAI cases centered on third-party advertising trackers embedded inside a platform for measurement purposes, the allegations against Granola concern a product whose entire function is to sit inside a conversation and generate a record of it, then use that record to improve its own underlying models. For marketing teams, sales organizations, and any professional service that has adopted AI notetaking tools during client calls, pitch meetings, or internal strategy sessions, the case tests whether the same legal framework that reached advertising pixels also reaches the AI assistants many teams now treat as a normal part of the meeting itself.
The case also lands amid a broader regulatory conversation about consent as a legal basis for AI training generally. In July 2026, the European Data Protection Board adopted guidelines on web scraping for generative AI, concluding, as PPC Land reported, that consent will most probably not serve as a workable legal basis for the kind of large-scale data collection that trains AI models, and that data made available on an open web page is not thereby consented to being scraped for that purpose. That guidance addresses European data protection law rather than the American statutes cited in the Granola complaint, yet both developments point toward the same underlying tension: AI companies building products on data whose original owners did not anticipate, and in many cases did not consent to, its use for model training.
For publishers, agencies, and platforms integrating AI notetaking or transcription tools into client-facing workflows, the Granola complaint offers a concrete illustration of the exposure such tools can carry when disclosure is optional rather than automatic. The seven claims for relief, and the statutory damages available under CIPA in particular, mean that even a modest per-violation calculation, multiplied across a nationwide class the complaint describes as likely reaching into the millions, could represent substantial financial exposure regardless of how any individual claim is ultimately resolved.
Timeline
- 2024 - Granola announces a $20 million Series A financing round following a six-month beta period, according to the complaint.
- May 2024 - Granola publicly launches its AI notetaking software, according to the complaint.
- August 4, 2025 - A federal jury in San Francisco finds Meta violated the California Invasion of Privacy Act by collecting health data from Flo app users without consent.
- March 3, 2026 - A California court enters a $50 million final judgment and permanent injunction against Meta over Facebook user data shared with third-party developers.
- March 25, 2026 - Granola announces a $125 million Series C financing round, reaching an approximately $1.5 billion valuation, according to the complaint.
- March 31, 2026 - A class action against Perplexity AI, Meta, and Google alleges secret sharing of AI conversation data with advertising platforms.
- May 13, 2026 - A class action against OpenAI alleges ChatGPT forwarded user queries to Meta and Googlewithout consent.
- July 7, 2026 - The European Data Protection Board adopts guidelines concluding consent is not a workable legal basis for large-scale AI training data scraping.
- July 24, 2026 - Granola's privacy policy, cited in the complaint, states that data incorporated into AI models cannot be removed without rebuilding the underlying model.
- July 30, 2026 - Tarra Chamberlain files the class action complaint against Granola, Inc. and Granola Labs Ltd. in the US District Court for the Northern District of California.
- August 1, 2026 - Attorney Rob Freund publicizes the filing on the social platform X, drawing wider attention to the complaint's allegations.
Related PPC Land coverage
- Jury finds Meta violated privacy law collecting health data - Reports the August 2025 federal jury verdict against Meta under CIPA, a precedent the Granola complaint's legal theories build upon.
- California court signs $50M Meta privacy injunction over Facebook data controls - Covers the March 2026 final judgment against Meta, part of the litigation pattern cited in recent CIPA filings.
- Lawsuit claims Perplexity shared AI chat data with Google and Meta secretly - Details the March 2026 class action alleging an AI platform forwarded conversation data to advertising trackers without consent.
- OpenAI's ChatGPT secretly sent your queries to Meta and Google, lawsuit claims - Examines the May 2026 complaint applying CIPA and ECPA theories to an AI chatbot's embedded tracking code.
- Consent collapses on three fronts as Zeta faces investor suit - Reports the European Data Protection Board's July 2026 guidance concluding consent cannot generally justify large-scale AI training data collection.
- LinkedIn hit with class action over hidden browser scan of 6,000 extensions - Covers a separate April 2026 complaint alleging undisclosed data collection practices, illustrating the broader wave of privacy litigation against technology platforms.
Summary
Who: Tarra Chamberlain, a Florida resident, filed the complaint on behalf of a proposed nationwide class and California subclass against Granola, Inc. and Granola Labs Ltd., the companies behind the AI meeting notetaking application Granola.
What: The complaint alleges Granola intercepts and records virtual and in-person meeting conversations without disclosing its presence to most participants by default, then uses those recordings, by default, to train its own AI models, a practice the filing says the company's own marketing describes as an intentional design choice rather than an unintended gap.
When: The complaint was filed July 30, 2026, in the US District Court for the Northern District of California. Attorney Rob Freund drew wider public attention to the filing on August 1, 2026.
Where: The case was filed in San Francisco, within the Northern District of California, where Granola maintains its stated North American headquarters.
Why: The filing matters to marketing and advertising professionals because it extends California's wiretapping and privacy statutes, already applied in prior cases against Meta, Perplexity, and OpenAI over embedded advertising trackers, to an AI product whose core function is recording conversations and repurposing them for model training, testing the legal exposure carried by any AI notetaking tool operating inside client or internal meetings without clear, upfront disclosure.
Discussion