What a video call shows about you
Your face and background are the least of it
Most people think about video call privacy in terms of what’s visible on screen. Close the blinds, tidy the bookshelf, angle the camera away from the laundry pile. That’s real, but it’s the smallest part of what a call actually transmits. A video call is a live data pipe running through your device, your network, a third-party platform’s servers, and every other participant’s device. Each of those points sees or logs something different, and most of it has nothing to do with what’s in frame.
What your IP address gives away
Every call needs to route packets between participants, and that routing starts with IP addresses. The platform’s servers see the IP address of every device that connects, and so, depending on the connection method, might other participants. An IP address alone doesn’t hand over your street address, but it typically resolves to a city or region through commercial geolocation databases, and it reveals which ISP you’re on. If you’re calling from a work network, it can also reveal that you’re at that employer’s office rather than home.
This is server-side metadata that exists independent of anything you say or show. The platform has it in logs even if the call itself was never recorded.
WebRTC can leak your real IP even through a VPN
Most browser-based video calling (Google Meet, Zoom’s web client, and plenty of others) uses WebRTC, a protocol built for real-time peer-to-peer media. To connect two devices that are both behind routers and NAT, WebRTC uses a process called ICE, which asks STUN servers “what does the outside world see as my IP address.” That answer gets embedded in connection metadata that can be visible to the browser tab, and in some peer-to-peer configurations, to the other party’s client directly.
Here’s the part that catches people off guard: turning on a VPN doesn’t automatically change what WebRTC reports. If the browser resolves your IP before the VPN’s tunnel is the only route out, or if the app has its own network stack that bypasses the OS-level VPN, the STUN response can reflect your real ISP-assigned IP rather than the VPN’s exit IP. This isn’t a flaw unique to one vendor, it’s a structural consequence of how NAT traversal works. Some VPN clients and some browsers have settings to disable WebRTC’s IP-revealing behavior specifically, and it’s worth checking whether yours does, but assuming a VPN is fully covering you here without testing it is exactly the kind of gap that video call privacy actually has.
Blur and virtual backgrounds are pattern matching, not privacy
Background blur and virtual backgrounds work by running a segmentation model on each video frame, one trained to distinguish “person-shaped foreground” from “everything else.” That model isn’t perfect. It struggles with hair edges, glasses, complex lighting, and fast movement, and objects you’re holding or leaning near often get misclassified as part of you and stay unblurred for a frame or two. It’s a genuinely useful tool for softening a messy room, but it’s a cosmetic layer applied after the camera already captured the full unedited frame. That raw frame still passes through your device’s video pipeline before the blur is applied, and depending on the app, it may still be the version handed to a recording or notetaking bot if one is active on the call.
The platform sees more than you think
Even when a call isn’t recorded, the platform operating it typically retains metadata: who joined, when, for how long, from what device type, and often the rough location derived from IP. This is standard operational logging, the same kind any service keeps to run its infrastructure and investigate abuse. It’s not sinister on its own, but it means “the call wasn’t recorded” and “the call left no trace” are different claims. The account-level record persists regardless of whether audio and video were saved.
If your organization has integrated the platform with single sign-on or a corporate directory, your calendar, meeting attendance, and sometimes engagement signals (camera on/off time, whether you were the active speaker) can also feed into workplace analytics tools. That’s a policy decision made by whoever administers the account, not something visible from the call window itself.
Other participants can record without you knowing
Screen recording software runs entirely outside the video call platform’s control. Anyone on the call with basic screen capture tools, built into every major OS, can record the session without triggering any notification to other participants, unless the platform itself displays a separate in-app recording indicator for its own recording feature specifically. That indicator says nothing about a participant’s local screen recorder.
The other common exposure here is AI notetaking bots. Tools that join as a silent participant to transcribe and summarize a meeting are common in workplaces now, and they capture full audio, sometimes video, and store it on that vendor’s servers, subject to that vendor’s retention and training policies rather than the meeting platform’s. If a bot joins with a name like “Notetaker” or an unfamiliar company’s branding, that’s a separate data controller now holding a transcript of the conversation, and what happens to that transcript afterward depends entirely on that third party’s terms, not on anything the meeting platform promises.
Whether recording someone requires their consent, and what form that consent needs to take, varies by jurisdiction and by context. That’s worth checking against your local rules rather than assuming either “recording is fine” or “recording is always restricted.”
Calendar links carry their own metadata
Meeting invites often embed a persistent link or a fixed meeting ID rather than a one-time code. If that invite gets forwarded, pasted into a public channel, or indexed by a calendar app that syncs broadly, anyone with the link can potentially join, view the participant list, and in some platform configurations, see attendee names before the host admits them. This is less about the call itself and more about invite hygiene: a static, reused meeting link is a standing door, not a one-time key.
What you can actually control
None of this adds up to a single fix, and no one setting closes every gap described above. But a few concrete habits address specific exposures:
Mute the microphone by default and unmute deliberately. It’s the simplest control you have, and it directly limits ambient audio capture, background conversations, and anything picked up when you’re not actively speaking.
Turn the camera off when you don’t need it on. Every frame that’s captured is a frame that could be processed by a segmentation model, stored by a recording feature, or handed to a third-party notetaker.
Check whether your VPN client or browser specifically addresses WebRTC IP leaks, and test it rather than assuming coverage. There are browser-based leak test pages that show what IP a WebRTC connection actually reports.
Use meeting-specific links or waiting rooms instead of a static, reused ID, especially for recurring or sensitive calls.
Ask before a notetaking bot joins, and treat its presence as a separate vendor now holding a copy of the conversation, not an extension of the platform you already trust.
Review what your calendar app syncs and to whom before it auto-populates invite details across other connected accounts.
None of these turn a video call into something untraceable, and that’s not really the goal. The goal is knowing which parts of the call are visible to which party, so the choices you make (mic on or off, camera framing, whether to accept a bot into the room) are informed rather than assumed.
If you want more explainers like this one, breaking down what everyday tools actually expose and what’s worth doing about it, you can find the rest of them on The Privacy Wire.