Disclaimer: This article is for informational purposes only and does not constitute legal advice. Source protection obligations and law enforcement powers differ between jurisdictions and change over time. Consult your editor, in-house counsel, or a specialist media law firm for guidance on your specific reporting before handling material that could identify a confidential source.
It starts the way these conversations always start. Your source has information about wrongdoing inside an institution. They are frightened. They agree to talk on one condition: that you never reveal who they are. You hit record, and if you are like most journalists in 2026, the recording app on your phone or laptop is one of the popular AI transcription tools. By the time the conversation ends, that audio has been uploaded to a company's servers, converted to text, stored, indexed, and made searchable through an account tied to your name and your credit card.
Nothing about that arrangement is under your control the moment the upload starts. And as the record below shows, that copy is reachable in ways your notebook never was.
Why uploading interview audio endangers sources
When you record an interview and let a cloud transcription service process it, you are not keeping a private copy with an extra step. You are creating a permanent third-party record. Several things follow from that, and none of them are good for source protection.
First, the copy is tied to your identity. Cloud transcription services run on accounts: an email address, often a paid subscription, sometimes an employer's single sign-on. The vendor's logs link your identity to every recording you have made. You do not need the transcript content to be exposed for damage to occur: the pattern of which recordings happened when can be identifying once a leak investigation narrows to a handful of people. Metadata is testimony, and it usually receives far weaker legal protection than conversation content.
Second, the copy outlives your control. Reputable vendors retain transcripts and recordings for their own retention periods, and consumer defaults favour retention far beyond what sensitive reporting justifies. Support staff, automated abuse review, and in some cases machine learning pipelines may access or process that content unless you have found and changed settings you may not know exist. Every retention day widens the window in which something can go wrong.
Third, the breach surface is not yours. Your password discipline is irrelevant if the vendor's systems are compromised, misconfigured, or simply leaky. The recordings exist wherever the vendor and its infrastructure providers keep them, under whoever's keys. If they suffer a breach, your sources' words escape into the world through a door you never opened.
None of this requires malice by the vendor or a subpoena for the harm to materialise. It only requires a copy to exist outside your hands. Everything else in this article follows from that single architectural fact.
What legal process can reach, and when you find out
The core problem for journalists is procedural, not technical. Legal process served on your transcription vendor does not arrive at your desk.
In the United States, prosecutors and civil litigants can demand stored communications and records in several ways: a subpoena, a court order under the Stored Communications Act (18 U.S.C. § 2703(d)), or a search warrant. A provider who receives such process is legally obligated to comply. The same framework allows the government to obtain delayed notice orders (under 18 U.S.C. § 2705(b)), which gag the provider from telling you the request ever happened. Months can pass, sometimes years, before anyone learns that a third party turned over records.
Contrast that with what happens when investigators want your reporter's notebook. They must serve you or your employer, your newsroom's lawyers enter the fight, and a shield law gives you a forum to argue. A vendor-held copy bypasses that fight entirely. The demand lands in the provider's compliance inbox. Nobody calls your editor, your lawyers never file anything, and the strongest source protection law in your jurisdiction is never invoked, because nobody contested a request you never saw.
The constitutional picture is thinner than most reporters assume. In Branzburg v. Hayes (1972), the US Supreme Court held that the First Amendment does not give a journalist an absolute privilege in a grand jury investigation. Most states have shield laws of varying strength, but there is no comprehensive federal statute. And the third-party doctrine means records you voluntarily hand to a provider receive little protection.
The picture in the United Kingdom differs in detail and matches in conclusion. Section 10 of the Contempt of Court Act 1981 blocks compelled source disclosure unless disclosure is required in the interests of justice, national security, or the prevention of disorder, and Goodwin v. United Kingdom (1996) treats compelled disclosure as a serious interference with Article 10 of the European Convention on Human Rights. But these protections operate only through court challenges. During Operation Elveden, the Metropolitan Police obtained Sun journalists' phone records without notice, and in 2015 the Investigatory Powers Tribunal found two of those acquisitions unlawful. The protection existed in principle. It did nothing, because nobody was in the room to invoke it.
That is the pattern to internalise: protection you cannot trigger in time is not protection. The safest architecture is one where nothing exists for a demand to reach.
Real incidents: subpoenas, seizures, and vendor leaks
None of this is hypothetical. The last dozen years of press freedom cases and cloud vendor incidents sketch the exposure with uncomfortable clarity.
When investigators went through providers
James Rosen, Fox News, 2013. Court filings revealed that federal prosecutors investigating a State Department leak had read the personal email of correspondent James Rosen and tracked his movements through the State Department building using security badge logs. His email records were obtained through legal process served on his providers, not through a search of his person or his newsroom.
The Associated Press, 2013. The AP disclosed that the Justice Department had secretly collected telephone records covering two months of calls across more than 20 lines assigned to the AP and its journalists. The organisation learned about it from a court filing, after the fact.
CNN's Barbara Starr, revealed 2021. Under an FBI leak investigation, authorities obtained the calling and email records of CNN's Pentagon correspondent through legal process served on her providers, spanning several years. The same sweep reached Apple accounts belonging to congressional staff and email held by Microsoft, in each case with notice delayed far beyond the collection.
The mechanism in every one of these cases was identical: records were held by a provider, legal process went to the provider, and the journalist learned late or not at all.
When vendors themselves leaked
Government compulsion is not even the most common failure mode. Vendors leak on their own. We documented several of these in our meeting bot privacy manifesto, and they are worth restating for journalists specifically:
- Otter.ai leaked a private VC firm's meeting transcript to a researcher who had left the call hours earlier. The bot kept listening after participants left, and the transcript went where it should never have gone.
- Fireflies.ai exposed meeting recordings and transcripts through an unauthenticated API in April 2025. Security researchers found recordings belonging to thousands of organisations, including people using .gov email addresses. No account was required to read other people's meetings.
- An Otter bot in a Canadian hospital auto-joined patient rounds, recorded protected health information about seven patients, and emailed the transcript to 65 people, including 12 former employees.
- Class-action litigation, including In re Otter.AI Privacy Litigation (5:25-cv-06911, N.D. Cal.), now tests whether these tools violated biometric privacy and wiretapping laws at all.
Notice what all these incidents have in common. None happened because a journalist used a weak password, and none were prevented by a vendor's security page. The victims did ordinary work with ordinary trust, and the architecture did the rest. Recording a sensitive interview on a cloud transcription tool accepts exactly this class of risk, plus the subpoena risk described above.
What journalist ethics codes demand
The legal argument is only half the case. The ethics codes that govern journalists on both sides of the Atlantic are explicit that source protection is a duty, not a negotiating position.
The UK Editors' Code of Practice administered by IPSO states directly in Clause 14: "Journalists have a moral obligation to protect confidential sources of information." The National Union of Journalists' Code of Conduct says the same in its own words: "A journalist shall protect confidential sources of information." The BBC's editorial guidelines commit the corporation to protecting the identity of sources, with only narrow, justified exceptions. In the United States, the Society of Professional Journalists' code asks journalists to minimise harm and recognises that gathering information can cause harm if handled carelessly. Protecting the people who speak to us at personal risk is what makes future sources willing to speak at all.
Two implications follow that rarely get said out loud.
First, a pledge covers the systems, not just the reporter. When you promise anonymity, the source reasonably assumes the promise covers your notes, your recordings, and every copy derived from them. Choosing a cloud tool whose servers hold the recording in law-enforcement-reachable storage does not keep that promise; it outsources it. You have delegated the source's protection to a company whose priorities are uptime and growth, not your source's safety.
Second, the professional standard is to not create what you cannot protect. A reporter would not leave this afternoon's notebook face-up in a coffee shop. A cloud transcript is worse than an unattended notebook: it never expires, it is searchable by anyone with vendor-side access, and it links back to your identity through your account. Ethical practice with sensitive interviews is minimisation by design. Record locally, transcribe locally, keep only what you and your editor have agreed to keep, and make every copy deliberate.
The promise of confidentiality is only as strong as the worst place a copy of the interview lives. Do not let the worst place be somebody else's server.
A source-safe transcription workflow
Source-safe transcription does not require exotic tools. It requires a deliberate default. Here is a workflow that keeps every step on hardware you control.
1. Prepare the machine
Use a device with full-disk encryption enabled (FileVault on macOS, BitLocker on Windows). Create a separate user account for sensitive reporting work, so cloud sync services stay out of your interview workspace. Disable iCloud, OneDrive, Dropbox, and Google Drive sync for any folder where interview recordings or transcripts live. Automatic cloud sync is the single most common accidental upload path.
2. Capture without a bot
For in-person interviews, a desktop recorder is the right tool: no third party is present in the room, and no audio packet needs to leave the device. For phone or video interviews, avoid capture that routes through cloud meeting-recordings infrastructure. The moment audio lands in a platform's cloud recordings folder, you have a vendor-held copy again. Capture locally, then transcribe locally.
3. Transcribe locally
Use a tool whose speech recognition model runs on your machine. Modern local models (the Whisper family, run in-process) reach accuracy that, for clear interview audio, is close to cloud services. Verify the claim: set the device to airplane mode, run a test transcription with no network available, and confirm the transcript still appears. A tool that cannot transcribe in airplane mode is, for your purposes, a cloud tool whatever its marketing says.
4. Summaries with care
Summaries are where careful workflows spring leaks. Pasting an interview transcript into a cloud chatbot recreates the entire exposure you just avoided. Either summarise yourself, or use a tool with a built-in local summarisation model. Treat cloud AI services as off-limits for text that could identify a source unless your newsroom's lawyers have reviewed the arrangement.
5. Retention and housekeeping
Once a transcript is verified, decide deliberately what to keep. Many newsroom policies allow deleting raw audio after verification, and confidential-source work argues for keeping the smallest set: the transcript you need, not the audio you do not. Back up only to encrypted media you control. Revisit all of this whenever you change tools, because defaults are the enemy, and tools update their defaults.
How the major tools compare
The deciding criteria for source work are simple and non-negotiable. Does the transcription model run on your device? Does any audio, transcript, or summary leave your device in the default configuration? Is an account required to use it? Run every tool through those three questions and the market splits cleanly:
| Tool | How it captures | Where transcription runs | Audio or transcripts uploaded | User account | Suitable for source work |
|---|---|---|---|---|---|
| Otter.ai | Bot or app | Cloud | Yes | Required | No |
| Fireflies.ai | Meeting bot | Cloud | Yes | Required | No |
| Rev | Manual upload | Cloud (incl. human transcribers) | Yes | Required | No |
| tl;dv | Meeting bot | Cloud | Yes | Required | No |
| Granola | Desktop app, no bot | Cloud APIs | Yes | Required | No |
| Whisper.cpp (direct) | Local file or microphone | On your device | No | None | Yes, with setup |
| Clearminutes | Desktop app, no bot | On your device (Whisper) | No | None | Yes |
Two things are worth underlining. First, "no bot" is not the same as "private": Granola captures audio locally without a bot, but sends it to cloud transcription APIs, which is the same exposure as Otter for our purposes. Second, the only rows that pass all three tests are the rows where the model runs on your hardware. That is the only configuration that makes the subpoena question moot, because there is nothing at a vendor to subpoena.
Our full local transcription privacy guide covers the evaluation criteria in more depth if you need to defend the choice to a skeptical editor or IT team.
A recommendation for source work
For journalists handling material that could identify a confidential source, the recommendation is simple: use a tool that runs entirely on your machine, verify that it does, and cut every upload path out of the workflow by default.
Clearminutes is built around exactly that constraint. It is a desktop application for macOS and Windows that captures interview audio without a bot, transcribes it with a Whisper model running on your own CPU or GPU, and stores the transcript in a local database on your machine. Summarisation runs on a built-in local model, so the default workflow sends nothing over the network: no audio, no transcript, no summary. It works with the internet disconnected entirely, which is also how you verify it. Run an interview in airplane mode and watch a transcript appear.
Full disclosure, in keeping with the subject of this article: Clearminutes is closed-source software, so you are taking our architectural claims on trust plus your own verification rather than reading the code. We publish a transparency page describing what the product transmits, and the airplane-mode test above lets you confirm the data flow yourself in five minutes.
On pricing: Clearminutes costs £12 per month or £108 per year on desktop, with a £249 one-time lifetime option, so a newsroom can own the workflow outright rather than renting a cloud relationship. An iPhone app exists at $4.99 per month, though for sensitive interviews the desktop application is the better tool, with encryption, storage, and model execution under your direct control.
The honest trade-off: local transcription is slightly less accurate than the best cloud models on difficult audio, such as heavy accents or poor field recordings, and setup takes an afternoon instead of a signup form. Against that, a subpoena served on a vendor returns nothing, because there is no vendor holding your interviews. For low-sensitivity conversations, cloud tools remain a reasonable convenience. For a source whose freedom, job, or safety depends on your discretion, the calculus is not close.
Transcribe at your desk. Not in the cloud.
Clearminutes runs Whisper locally, stores transcripts on your machine, and needs no account and no bot. Free to try, works fully offline.
Download Clearminutes Read the privacy guide