Isn't the account holder's agreement enough, since they're the one using the app?
No — and this is a structural feature of how personal data protection works, not a technicality. These frameworks distinguish between the party who controls a tool and the individual whose personal data is actually being processed.
When a salesperson records a call, the client's voice, statements and any personal details they share are that client's personal data. The client is not a party to the agreement between the salesperson (or their employer) and the software provider. An independent basis for collecting that data still has to exist. Regulators and legal commentators are consistent on the point: where consent is required, it has to come from the data subject, and it cannot be inferred from a business relationship with a third-party vendor.
Doesn't the fact that they said it to a real person, out loud, mean it was already given?
Not in the way that matters here. There is a well-recognised difference between disclosing something in a specific conversational context and having that disclosure extracted, structured and persisted somewhere it can be retrieved indefinitely and cross-referenced with other facts about you.
Research on AI and privacy treats this recontextualisation — data given for one purpose being captured, structured and reused in ways the person never anticipated — as one of the core sources of legitimate privacy concern with AI systems, not a fringe worry. Someone answering a rep's question honestly on a phone call has not thereby agreed to become a permanent, linked node in that rep's client-memory system.
So what actually addresses this?
The defensible pattern is that consent is sought at the point of the conversation, not assumed from the account holder's sign-up:
- > A short, clear disclosure at the start of a recorded call or meeting — what is being recorded, and roughly what it is used for — gives the other person a real, in-the-moment chance to decline or ask questions.
- > It should happen every time, not once. Each relationship, and often each specific conversation, is a new instance of someone else's personal data entering the system.
- > If they decline, the answer is not to record and delete afterwards. It is not to record.
What does Closer actually do about this — and what does it not do?
The honest version, checked against what is built rather than what a mitigation section would ideally say:
- > Closer does not ask the client for consent. There is no in-app consent prompt and no automatic "this call may be recorded" announcement. That disclosure is yours to make, in the room, every time.
- > Closer does not decide whether recording is appropriate. It has no view of which jurisdiction you are in or what your client agreed to. Nothing in the product should be read as a signal that recording a given conversation is lawful.
- > What Closer does give you is an answerable record. A client's stored memories can be exported as a markdown file you can actually show them, and deleting the client erases that client's whole memory scope along with every note, action and knowledge-graph row Closer holds for them.
- > The audio itself is not kept. Closer stores a hash of the recording as a cache key, plus the transcript and summary derived from it. There is no audio file sitting on a server waiting to be subpoenaed — but the transcript is a full record of what was said, and it is stored.
- > Email is never addressed from a transcript. Recipients for any drafted follow-up come from the client record, so something a third party said on a call cannot redirect where a message goes.
None of that substitutes for telling the person. It makes the promise you make them one you can keep.
Key takeaways
- > Your agreement with a software vendor is not the client's agreement to be recorded and remembered.
- > Saying something out loud in one context is not consent to have it extracted, structured and stored indefinitely.
- > Consent belongs at the point of recording, in that conversation, every time — not once at sign-up.
- > Closer has no consent prompt: making the disclosure is the user's job, not the product's.
- > Closer keeps no audio, and a client's memory scope can be exported and erased in full.