Consent-first recording: how Ona approaches it

Ona exists to remember your conversations. That only works if the people in those conversations can trust what is happening. A recorder in the room changes the room, and we think the tool, not just the person holding it, carries responsibility for that.
So before we wrote recording code, we wrote recording rules. This post explains them: what Ona does, what it refuses to do, and why the boring details of defaults matter more than any policy page.
Recording is a social act
The legal baseline is real but low. Consent law differs by region: some places require one party's consent, some require everyone's. Ona asks you to know your local rules, and when in doubt, to get everyone's yes. But the law is the floor, not the goal.
The goal is a meeting where nobody feels ambushed. In our experience the sentence "I'd like to record this so I can be present instead of typing, is that okay?" gets a yes almost every time. People do not object to memory. They object to surveillance. The difference is knowing about it.
Defaults do the ethics
Policies live in documents; defaults live in the product. Ona's defaults are where our position actually ships:
- You start every recording yourself. Ona never begins on its own, not even for a meeting on your calendar.
- Recording is visible. The app shows a clear recording state the whole time, never a hidden background capture.
- Nothing joins your calls. Ona records from your side; it does not send a bot into the meeting to lurk in the participant list.
- Deletion is real. Audio is deleted once it is transcribed; remove a meeting and the transcript and everything derived from it go too.
None of these are technically impressive. All of them are deliberate. Each one trades a little convenience for a lot of trust, and we think that trade is the product.
In the room, not just on calls
The RecordPen raises the stakes, because it goes where screens do not: site visits, walking meetings, a table in a loud cafe. A capture device that small has to be held to the same standard, so it follows the same rules. It records only when you press it, it shows its state, and it syncs to the same memory with the same controls.
We also encourage a habit that has nothing to do with hardware: say it out loud. "I'm recording this on my pen so we don't lose anything." Eight words, once, at the start. It turns the device from a secret into a service everyone at the table benefits from, because anyone can ask you later what was said.
What we choose not to build
Consent-first also means saying no to features that would sell. We do not build always-on ambient capture. We do not build stealth modes or hidden recording. We do not train our models on your conversations, and we do not sell what you said to anyone. If a feature only works when someone in the room does not know about it, it does not ship.
The test we use is simple: would every person in the conversation be comfortable seeing exactly how this works? When the answer is yes, recording stops being a risk to manage and becomes what it should have been all along, a shared memory of a conversation everyone knew was worth keeping.