You didn't pay a subscription fee for that Zoom call, that Teams standup, or that Google Meet catch-up. But "free" video conferencing has never meant "no cost" — it means the cost is paid in data instead of dollars. Every meeting you join generates a second, invisible meeting: one between your device and the platform's servers, where account details, device fingerprints, usage patterns, and sometimes the content of the call itself are collected, logged, and in some cases used to train AI models or shared with third parties.
We dug into the public privacy policies, data processing addendums, and independently documented practices of the three biggest names in video conferencing to quantify exactly what's being collected, who controls it, and what happens to it afterward. The picture that emerges is less about any single alarming data point and more about how much adds up over a year of daily meetings.
The Data Collection Landscape at a Glance
| Zoom | Microsoft Teams | Google Meet | |
|---|---|---|---|
| Account & profile data | Name, email, phone, address, profile photo | Name, email, org directory data | Full Google Account profile |
| Device & network metadata | IP address, device IDs, timestamps | Device ID, OS, network data | Device and connection data |
| Meeting content access | Chat, uploaded files, recordings | Chat, files, recordings | Recordings (if enabled) |
| Behavioral telemetry | Support and usage data | Hundreds of tracked in-app events | Performance and crash analytics |
| Used for AI training by default | Yes, unless admin opts out | Limited, org-controlled | Not used for advertising |
| Notable track record | $85M class-action settlement | Admin-managed diagnostics only | Ongoing scrutiny of broader ad ecosystem |
Zoom: Ten Categories of Data and an Opt-Out You Have to Find
Zoom's own privacy documentation lists account data, meeting participant details, device information, support data, and address book or calendar data among the categories of personal data it processes for business use. Independent audits have gone further, identifying ten distinct data categories and six third-party sharing arrangements tied to Zoom's practices, contributing to a privacy score of just 30 out of 100 in one 2026 assessment.
Perhaps the most consequential recent change: as of Zoom's January 2026 policy update, meeting audio, video, and chat content can be used to train AI models unless an account administrator actively opts out. That's an opt-out model, not opt-in — meaning the default setting works against the privacy-conscious user rather than for them. Unless someone with admin rights on your account has gone looking for that toggle, your meeting content may already be feeding a model.
Zoom has also weathered real consequences for its data practices, including an $85 million class-action settlement tied to prior privacy and security failures, and it continues to patch security vulnerabilities on a rolling basis — including a critical Windows privilege-escalation flaw patched as recently as August 2025.
Microsoft Teams: Hundreds of Tracked Events, Buried in Enterprise Settings
Microsoft frames Teams' data collection as necessary "diagnostic data," split into required and optional tiers, and states plainly that it doesn't use this data for marketing. But the sheer scale of what's tracked is worth pausing on. Microsoft's own developer documentation catalogs telemetry events for actions as granular as admitting someone from a meeting lobby, adding a contact, tapping a notification setting, or selecting a GIF in chat — hundreds of individually named events across the mobile app alone.
Control over this data doesn't sit with the end user. It sits with IT administrators, who decide via Group Policy or mobile device management whether required or optional diagnostics reach Microsoft, and which "connected experiences" are enabled for their organization. If you're an employee on a managed device, you likely have no visibility into — let alone control over — what's being logged every time you join a call, mute yourself, or share a file.
Google Meet: Riding on the Back of Your Google Account
Google is the most explicit of the three on one specific point: it states it does not use information in apps where you primarily store personal content — including Meet — for advertising purposes, and reiterates that it does not sell Meet data to third parties. That's a real, verifiable commitment, and it's stronger than what many competitors put in writing.
But Meet doesn't exist in isolation, it's a feature of the same Google Account that also runs Search, YouTube, Android, and Gmail. Consumer advocacy researchers who reviewed Google's broader terms found that the company's language clearly discloses that it uses collected data for advertising purposes at the account level, and that Google's terms treat the data it collects as an asset that can be sold, with notice given only if a sale occurs, leaving real ambiguity about how cleanly "Meet data" is walled off from the rest of the advertising engine tied to your identity. Independent privacy scorecards have rated Google Meet around 35 out of 100, citing integration with the broader Workspace and advertising ecosystem as the core concern.
Why the Aggregation Problem Matters More Than Any Single Data Point
No single piece of data collected in a meeting — your IP address, your device model, a timestamp — is alarming on its own. The risk is cumulative. Account data, device fingerprints, meeting metadata, behavioral telemetry, and content access, stitched together over hundreds of meetings a year, build a remarkably complete picture of who you talk to, when, how often, and in some cases what you said. That profile sits on a company's servers indefinitely, subject to their retention policies, their third-party partnerships, their breach history, and increasingly their AI training pipelines.
This is the structural issue with the client-server model that Zoom, Teams, and Meet all rely on: your conversation has to pass through their infrastructure to reach the other person. The server is always in the loop, which means there's always a copy, a log, or a metadata trail generated somewhere you don't control — regardless of how carefully any single company writes its privacy policy.
The Alternative: Take the Server Out of the Loop
At MeetingPoint, we built around a different assumption: the most private data is the data that never gets collected in the first place. MeetingPoint uses peer-to-peer WebRTC connections — your browser and the other person's browser negotiate a direct, end-to-end encrypted connection, and your video, audio, and files travel straight between devices. There's no account to create, no email required, and no central server sitting in the middle logging the call. We couldn't hand over a recording of your conversation even if we wanted to, because we're never in possession of it.
"Free" communication doesn't have to mean paying with your data. It just requires architecture that was built with that trade-off in mind from day one.
Sources include the Zoom Privacy Statement and independent third-party privacy audits, Microsoft's public Teams data collection and diagnostic telemetry documentation, and Google Meet's privacy and security disclosures for users and admins, alongside research from Consumer Reports' Innovation Lab. This article reflects publicly available policy language as of mid-2026; platform privacy practices change, so readers handling sensitive conversations should always check current policy documents directly.