5 min read

Meetily: Private AI Meeting Notes With No Bot (GitHub, Scanned)

Records, transcribes and summarizes meetings on your own computer, with no bot joining the call.

Meetily logo
✅
Scan: safe. Nothing malicious. Two things to know: a Microsoft build-tools installer is committed to the repository though nothing uses it, and the CI actions are all unpinned; the app's own analytics are off unless you opt in. Scanned Sep 10, 2026; the full report is below.

Meetily is a desktop meeting recorder that keeps everything local. It captures your microphone and the computer's audio together, so it works with Zoom, Meet, Teams or anything else without a bot joining the call, and transcribes live with Whisper or NVIDIA's Parakeet running on your machine. When the meeting ends it writes a summary with the model you choose: a local Ollama model by default, or Claude, Groq, OpenRouter, OpenAI or any OpenAI-compatible endpoint. You can also import an existing recording and re-transcribe it with a different model or language.

It is a single Tauri app with a Rust backend and a Next.js interface, using Metal and CoreML on Macs and Vulkan on Windows. Builds are offered for Apple Silicon Macs and 64-bit Windows; Linux users build from source.

Meetily is made by Zackriya Solutions, MIT-licensed, with about 31,400 stars and version 0.4.1. The free Community Edition sits beside a paid Meetily PRO built on a separate codebase, with more accurate transcription, custom templates, PDF and DOCX export and automatic meeting detection. The speaker diarization mentioned in the repository's description is listed in the README as a PRO feature, not part of the free app.

Who it is for

Consultants, lawyers, clinicians and other professionals who cannot send meeting audio to a cloud note-taker, and anyone who dislikes AI bots joining their calls.

Getting started

1. macOS on Apple Silicon, with Homebrew

brew install --cask meetily

2. Windows: run the x64 installer from the releases page. Linux: build from source

git clone https://github.com/Zackriya-Solutions/meetily && cd meetily/frontend && pnpm install --frozen-lockfile && ./build-gpu.sh

Summaries need a language model: install Ollama for fully local summaries, or add an API key for Claude, Groq, OpenRouter or OpenAI, in which case the transcript is sent to that provider. The Windows build needs a CPU with AVX2, and CUDA acceleration only comes with a source build. Recording other people may require their consent where you live.

Safety scan

We cloned Zackriya-Solutions/meetily at commit a2cb62e on Sep 10, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.

  • No secrets, no suspicious code patterns and no bare-IP URLs across 536 files and about 113,000 lines of Rust and TypeScript.
  • One committed binary: frontend/vs_buildtools.exe, 4.5 MB, a Windows executable carrying Microsoft's code-signing certificate chain, which matches the Visual Studio Build Tools bootstrapper. It arrived in an October 2025 release commit and nothing in the code refers to it. It plays no part in the app you install, but if you need the build tools, download them from Microsoft.
  • We read the analytics code. Meetily uses PostHog, and AnalyticsProvider.tsx sets analyticsOptedIn to false for new installs and resets it to false once for older installs, so nothing is sent until you switch it on. Transcripts go off the machine only if you choose a cloud model for summaries.
  • 114 known advisories (3 critical, 42 high). frontend/pnpm-lock.yaml holds 77, including two Next.js 14 criticals that concern a running Next server; Meetily builds Next as a static export inside Tauri, so no Next server runs. Nine sit in backend/requirements.txt, the older Python server with Docker scripts, which the self-contained desktop app does not use, and 28 in Cargo.lock, none critical.
  • Eight workflows, none using pull_request_target, and none of the 28 third-party actions pinned to a commit. The six installer scripts all belong to that Python backend and none uses sudo or pipes a download to a shell. Licence and contributing guide present; no security policy, Dependabot or CodeQL.

What the scanner counted

CheckResult
SecretsNone found.
Suspicious codeNone found.
Install-time code1 Cargo build script. 6 installer scripts
Committed binaries1 executable or compiled object committed; listed under the raw findings.
CI workflows8 workflows. None use pull_request_target. 28 of 28 third-party actions pinned to a tag rather than a commit.
Network hosts21 distinct hosts referenced from source; most often huggingface.co, github.com, api.github.com, stackoverflow.com. No URLs to bare IP addresses.
Known vulnerabilities114 advisories across 1,527 pinned packages: 3 critical, 42 high, 43 moderate, 12 low, 14 unrated. Cargo.lock: 855 packages, 28 advisories; backend/requirements.txt: 10 packages, 9 advisories; frontend/pnpm-lock.yaml: 662 packages, 77 advisories.
Project hygieneHas licence file, contributing guide. Missing security policy, automated dependency updates, CodeQL.
OpenSSF ScorecardNot scored: the project is not in Scorecard's weekly index.

The raw findings

Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.

Installer scripts (6)
Committed binaries (1)
  • frontend/vs_buildtools.exe: PE (Windows executable), 4 MB
Worst known vulnerabilities (24 of 114)
AdvisorySeverityPackageSummary
GHSA-2xp9-vwfh-vxw4criticalnext@14.2.35Next.js: Unauthenticated Remote Code Execution in Image Optimization API when AVIF files are used
GHSA-p293-qw3h-jr36criticalnext@14.2.35Next.js: Unauthenticated Remote Code Execution on windows-hosted servers
GHSA-w7jw-789q-3m8pcriticalshell-quote@1.8.3shell-quote quote() does not escape newlines in object .op values
RUSTSEC-2026-0194highquick-xml@0.37.5Quadratic run time when checking a start tag for duplicate attribute names
RUSTSEC-2026-0195highquick-xml@0.37.5Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
RUSTSEC-2026-0194highquick-xml@0.39.4Quadratic run time when checking a start tag for duplicate attribute names
RUSTSEC-2026-0195highquick-xml@0.39.4Unbounded namespace-declaration allocation in `NsReader` enables memory-exhaustion denial of service
GHSA-82j2-j2ch-gfr8highrustls-webpki@0.101.7rustls-webpki: Denial of service via panic on malformed CRL BIT STRING
GHSA-2jrp-274c-jhv3highpydantic-ai@0.2.15Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling
GHSA-5rvq-cxj2-64vfhighpython-multipart@0.0.20python-multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
GHSA-pp6c-gr5w-3c5ghighpython-multipart@0.0.20python-multipart has Denial of Service via unbounded multipart part headers
GHSA-wp53-j4wj-2cfghighpython-multipart@0.0.20Python-Multipart has Arbitrary File Write via Non-Default Configuration
GHSA-3pq3-5fj3-cg6vhighaxios@1.16.1Axios: HTTP/2 adapter bypasses configured DNS lookup and proxy controls
GHSA-542g-h47m-68v8highaxios@1.16.1Axios: Denial of Service via Unhandled 'error' Event in HTTP/2 ClientHttp2Session Initialization
GHSA-c29m-xwm3-cm6rhighaxios@1.16.1Axios: ReDoS in fromDataURI data: URL parser freezes the Node event loop (DoS)
GHSA-gcfj-64vw-6mp9highaxios@1.16.1Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
GHSA-m8m8-qj5v-23w3highaxios@1.16.1Axios: Node HTTP adapter prototype-pollution gadget allows request socket hijack via inherited createConnection
GHSA-mghh-pgcx-3jjjhighaxios@1.16.1Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
GHSA-x97p-jq2g-jp4fhighaxios@1.16.1Axios: Prototype Pollution Gadget in axios toFormData Options
GHSA-3jxr-9vmj-r5cphighbrace-expansion@2.1.0brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
GHSA-6j4f-fj2g-mc7phighbrace-expansion@2.1.0brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing stack exhaustion
GHSA-mh99-v99m-4gvghighbrace-expansion@2.1.0brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
GHSA-qhr7-859c-m2p7highbrace-expansion@2.1.0brace-expansion: DoS via uncontrolled recursion on nested brace groups causing stack exhaustion
GHSA-rgw5-rvv9-x895highbrace-expansion@2.1.0brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation

By the numbers

Stars31.4K
Forks3,430
Contributors20
Commits661
Open issues202
Open pull requests154
Releases12
Latest releasev0.4.1
LicenceMIT
Main languageRust
Project age1 year
Last pushSep 15, 2026
Tracked files536
Lines of code113.4K
Checkout size47 MB

Lines by language: Rust 48.6K, TypeScript 32.1K, C/C++ header 9,263, Shell 4,676, PowerShell 4,019, Markdown 3,475.

Questions

Is Meetily free?

The Community Edition is MIT-licensed and free, with local transcription and AI summaries. Meetily PRO is a separate paid product with more accurate models, custom summary templates, PDF and DOCX export, automatic meeting detection and team deployment. Cloud summary providers bill you for their API use; Ollama costs nothing.

Does Meetily join my meetings as a bot?

No. It records system audio and your microphone directly on your computer, so other participants see no extra attendee. That also makes it your job to tell people they are being recorded.

Does Meetily send my audio to the cloud?

No. Recordings, transcripts and transcription models stay on your machine. The only thing that leaves is the transcript text sent for summarizing, and only if you pick a cloud provider instead of a local Ollama model.


This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.