On the App Store. Windows in open early access.

Meeting notes only you can read.

Start transcribing with an explicit start, follow live captions, and review a speaker-attributed transcript beside structured notes. Search, ask questions with citations, and export the record on iPhone, iPad, and Windows 11.

Autopen locks your notes and transcripts with a key created on your device. We cannot read what you save unless you choose to share a recovery copy of that key. Accounts from before protection was required are locked once their owner turns it on.

i Autopen sees your meeting while it is being transcribed and written up. That is how the record gets made. While notes are being generated our servers hold a working copy of the transcript that our systems can read. When processing finishes, is cancelled, or permanently fails, we schedule that copy for deletion; it stays readable until cleanup succeeds. An Autopen account, an internet connection, and cloud processing are required.
Your key, your notesOn a protected account, your saved notes and transcripts are encrypted under a key created on your device. Without a copy of your key, Autopen cannot decrypt them. A recovery copy, if you choose one, gives Autopen that copy.
No training on your meetingsExcluded by product policy, a provider opt-out, and provider API terms. We do not claim Zero Data Retention: the notes provider's default abuse-monitoring logs may hold content for up to 30 days.
Audio is kept only to transcribe itYour recording goes into private encrypted storage so it can be transcribed, and it is deleted after processing. A failed or stalled retry can hold it longer.
iPhone, iPad, WindowsOne account and one workspace across every available client.
Zero-access encryption

How protection works.

Every new account is protected before its first note, and older accounts are protected once the owner turns it on. Your account gets an encryption key, created on your device. Autopen and its providers still process readable audio and text, because that is how a transcript and notes get produced. Autopen then encrypts the finished transcript and notes to your account's key before storing them, and your device encrypts the title, folder name and speaker corrections before they are sent. Without a copy of your key, Autopen cannot decrypt the transcripts and notes saved on a protected account. A recovery copy, if you choose one, gives Autopen that copy.

01

What we see while it is made

Your audio goes to the transcription provider. Your transcript goes to the notes provider. Both see it in the clear, because that is how a transcript and notes get produced. When you use Ask, Autopen and the notes provider receive your question, relevant meeting passages, and recent turns of that conversation. On a protected account, your device supplies the passages. Autopen does not keep an Ask conversation as server-side history, and the notes provider may hold content in abuse-monitoring logs for up to 30 days.

02

What we hold while it runs

While your notes are being generated, our servers hold a working copy of the transcript that our systems can read. When processing finishes, is cancelled, or permanently fails, we schedule that copy for deletion. It stays readable until cleanup succeeds; retries, stalled processing, or a failed cleanup pass can keep it longer.

03

Twelve words are the way back

Write down your 12 recovery words. If you lose them and every device that holds your key, your protected notes cannot be recovered, by you or by Autopen, unless you asked Autopen to keep a recovery copy (recovery from that copy is not available yet).

04

A spare key, only if you want one

You can ask Autopen to keep a copy of your key so that, once recovery ships, we can let you back in if you lose your words. That recovery path is not available in the apps yet; until it is, losing your words and every device that holds your key still means losing access. If you keep a copy, Autopen is technically able to open your notes for that account. A personal recovery copy can be turned off in Settings; turning it off does not retract a copy that was already used. Where an organization manages your account, the organization may control it and it cannot be turned off from the app.

Protection changes what you can do today. Search runs on your device, over the meetings that device has downloaded. Live captions, transcript corrections, retitling, speaker renames and regenerating notes are not available on a protected account. Write your 12 recovery words down and keep them safe. Today a protected account can only be opened on a device that already holds its key: recovery on a second computer is not available yet, and one-tap pairing between devices is not built.
Get Autopen

Choose the native Autopen app for your device.

The iPhone and iPad app is on the App Store, and the Windows app downloads straight from this site. No invitation or sign-in is needed for the Windows download.

iPhone and iPad

Autopen for iOS and iPadOS

Record meetings, follow live captions, review transcripts and notes, search, ask cited questions, organize the workspace, and export permitted content.

Download on the App Store
Windows 11

Autopen for Windows

A Microsoft-signed installer for Windows 11. Free to download, no account needed to download, and the exact SHA-256 is on the page.

Download Autopen for Windows
A durable meeting record

The transcript stays under the notes, so you can check them.

Autopen keeps the source transcript, structured synthesis, and next steps together so people can verify the record before they act on it.

01

Live transcript, reviewed after

Follow live captions and review the final speaker-attributed transcript. On an account that is not protected you can also correct wording and rename speakers; those edits and live captions are not available on a protected account.

See how the workspace works
02

Notes shaped to the work

Use a professional built-in style or create an editable, reusable structure for leadership reviews, discovery calls, interviews, and more.

Explore note styles
03

Search, ask, export, and sync

Find meeting text, ask questions with transcript citations, create Word or PDF exports, and work with the same organized workspace on your authorized devices. On a protected account, search runs on the device, over the meetings it has already downloaded.

Review platform support
Notes that remain accountable

Useful enough to act on. Grounded enough to review.

Generated notes stay connected to the transcript rather than replacing it. Teams can verify names, numbers, decisions, owners, and commitments before the record leaves the room.

  • Read the notes beside the transcript they came from.
  • Regenerate the same meeting in another approved note style. Regeneration is not yet available on a protected account.
  • Capture decisions, risks, questions, and follow-ups in a consistent format.
  • Export a clean record without turning the workspace into a black box.
Clear processing boundaries

Know where the meeting goes.

Autopen is a cloud service. The processing path is documented so security and privacy teams can evaluate the actual systems, providers, data categories, and retention boundaries.

01 · Capture

Native client

Audio is captured on an authorized mobile or desktop device and sent over encrypted transport.

02 · Transcribe

Speech provider

The approved speech provider receives audio and returns speaker-attributed transcript results.

03 · Structure

Notes provider

The notes provider receives the transcript text and your note-style instructions, and returns notes in a fixed structure.

04 · Work

Text workspace

Transcripts, notes, styles, and metadata synchronize to authorized account devices.

05 · Store

Your workspace

On a protected account, your device encrypts the meeting title, folder name and speaker corrections before they are sent, and Autopen encrypts the finished transcript and notes to your account's key before storing them. Either way, your device holds the key that opens them.

i
Important boundary: the Autopen service and speech provider must process audio; the Autopen service and notes provider must process transcript text. The service is not end-to-end encrypted. Provider credentials never ship in the native clients. Zero-access encryption protects what is saved, not what is being processed.
Identity

SSO and lifecycle

WorkOS-backed SAML/OIDC, verified domains, directory events, session revocation, and managed-account enforcement.

Policy

Retention and access

Separate transcript, notes, Trash, export, app-lock, offline, sharing, and participant-notice policy.

Endpoint

Containment with limits

Session revocation, device inventory, and acknowledged cache-wipe commands that never call an offline device “erased.”

Evidence

Content-free audit

Security events, aggregate usage, signed SIEM delivery, and destructive controls without a member-content reader.

Enterprise design-partner controls

Govern the service without browsing private meetings.

Autopen’s enterprise control model separates identity, policy, device control, and audit from the content employees create. Owners and security administrators can evaluate the implemented control surfaces; ordinary administration does not include an endpoint for opening a member's private transcript or notes. No administrator screen or support tool in Autopen opens a customer's transcript or notes. On a protected account there is no server-side index over your meeting text either, because building one would mean reading it. On an account that is not protected, an account-scoped search index over your own meeting text is what makes server search work.

Individual and small-team use is open to anyone today. Enterprise controls are in design-partner review.

Assurance status

Each security claim is tied to its evidence status.

Autopen distinguishes implemented application controls, configured provider safeguards, deployed infrastructure, operating evidence, and independent assurance. The current service is not represented as SOC 2 or ISO 27001 certified, HIPAA compliant, or approved for regulated workloads. Record and upload content only where you have authority to do so and its sensitivity fits the safeguards described here.

  • Application control design and tests Available for review
  • Provider no-training controls Configured; retention approval pending
  • Production operating evidence In progress
  • SOC 2 Type II report Not yet claimed
Output quality plan

Our quality plan targets the meetings that break transcription.

The regression plan uses synthetic fixtures and internal dogfood to evaluate names, numbers, speaker attribution, difficult audio, faithfulness, coverage, action items, style adherence, and material hallucinations. Autopen does not ask customers to share their calls for routine model review.

A

Real meeting conditions

Evaluation is designed around accents, crosstalk, poor microphones, interruptions, jargon, long meetings, and speaker revisions. Representative testing of the current configuration is still in progress.

B

Blind note review

The plan compares notes without brand cues and treats a material fabricated decision or commitment as a release blocker.

C

Reproducible evidence

Provider and model provenance remain attached to processing so quality decisions can be reviewed, repeated, and changed deliberately.

Enterprise design partners

Review requirements before starting a pilot.

We are working with organizations that want high-quality meeting records and can help define the identity, retention, endpoint, procurement, and assurance requirements for a controlled first pilot.