Does Gemini share your data? What Google keeps and reviews
· Updated · Written and maintained by Joaquín Trapero, Nonimo
Does Gemini share your data? Google’s answer is that it does not sell it. That is accurate, and Google says so in writing, but it is not really what most people are asking.
What they want to know is who ends up seeing a client’s file, and on that Google is unusually direct: a subset of Gemini conversations is read by people, and the ones that were read are not deleted when you delete your activity. Both of those sentences are Google’s own.
This page reads the Gemini documentation for what it says, separates the consumer app from the Workspace version because they are governed differently, and then applies the Australian test, which no vendor page mentions. Our guides to ChatGPT, Claude and Microsoft Copilot do the same for those assistants.
There are two Geminis, and the difference is contractual
Before any of the detail is useful, work out which one your staff are using. The name on the screen is the same. The governing document is not.
| Which one | Who you are to Google | Which notice governs it |
|---|---|---|
| Gemini app, personal Google Account | A consumer | Gemini Apps Privacy Hub |
| Gemini in Google Workspace | A customer | Cloud Data Processing Addendum |
| Gemini through Vertex AI | A cloud customer | Google Cloud terms |
Read from Google’s own documentation on 19 September 2026.
The unhelpful reality is that a person can be signed into both on the same laptop, and the browser does not make it obvious which account a tab belongs to. That is a fact about your practice, not about Google, and checking it is free.
Is the tab signed in with a personal Google Account?
YesThe consumer Gemini app, governed by the Gemini Apps Privacy Hub. A subset of chats is read by reviewers.
NoGo to the next question.
Is it a work account on Google Workspace?
YesGemini in Workspace, governed by the Cloud Data Processing Addendum, with retention set by your administrator.
NoIf it runs through Vertex AI, Google Cloud terms govern it.
The name on the screen is the same in all three. The account decides which document you are relying on.
Why the answer cannot be given once
Anything written about this has a shelf life, and Google’s own pages carry their dates for that reason. The consumer notice was last updated on 10 August 2026, the Workspace one on 14 August 2026, and the data regions documentation on 18 September 2026, the day before this page was written.
Each of the three documents carries its own date. A firm that settled this a year ago settled it on a different set of commitments, which is a good reason to diarise a review date rather than record a final answer.
When two accounts are signed in at once
A partner opens a personal Gmail on Sunday and leaves it signed in. On Monday the firm’s Gemini is one tab away and the personal one is another, and both look identical. Nothing warns the user which terms apply to the document they just dragged in.
Google itself acknowledges the two tracks exist, in one line of the consumer notice: “If you have a work or school Google Account, your use of Gemini Apps may be subject to different data handling terms.” The word may is doing real work there, and resolving it is a job for whoever runs your systems rather than for the person holding the file.
What the Gemini app collects, and the line about reviewers
The Gemini Apps Privacy Hub, last updated 10 August 2026, lists what is collected: what you say to Gemini, the files, images and page content you share, the responses generated, your feedback, and information about your device, language and location.
Then it says who reads some of it.
A subset of chats are reviewed by human reviewers (including Google’s trained service providers) to help improve Google services.
And it gives the corresponding instruction, which is the single most quotable sentence any of these providers publishes.
Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services.
That is a vendor telling a professional audience, in plain words, not to put a client’s file into the box. It is worth reproducing verbatim in the AI policy you hand to staff, because it carries more weight coming from Google than from a partner.
It is not only the words
The list Google publishes goes beyond the text. It names the files, videos, screens you ask about, photos, imported chats and page content you share from your browser, alongside your feedback, your language, your device type and your location information.
For a professional practice the location and device entries matter more than they look. They are the records that tie a particular person, in a particular office, to a particular question at a particular time, which is exactly the kind of evidence a dispute ends up turning on. None of that is unusual for a consumer service. What is unusual is handling a client file inside one.
Reviewed chats are not deleted when you delete
The consequence sits a few lines further down, and it is the one people miss.
Chats reviewed by human reviewers (and related data like your language, device type, location info, or feedback) are not deleted when you delete your activity.
Deleting your activity clears your activity record. It does not touch the copy that was pulled for review. Google says elsewhere that reviewed conversations can be kept for up to three years. For a litigator, a copy that outlives deletion is the kind of thing the NSW Supreme Court’s rules on subpoenaed material make you check before anything goes in.
Connected apps widen what a single prompt can pull in
Gemini can be connected to other Google services and to tools from other companies, and Google states that it “saves and uses info from Connected Apps according to this notice, including to provide and improve Gemini Apps”.
It is the same widening as in ChatGPT, and it deserves an explicit decision rather than a default. A connection to a mailbox or a document store means a short prompt can pull in material nobody intended to send, and the person who typed it will not necessarily see what came with it.
How long Google keeps it
Three numbers govern the consumer app, and which one applies depends on a setting most people have never opened. ChatGPT, Claude and Copilot each publish their own numbers, and no two of them match.
The figure of 72 hours is the interesting one, because it is what Google keeps even when a user has switched everything off, in order to run the service and handle feedback. It is not zero, so anyone who tells you that turning activity off means nothing is kept has it wrong.
What the setting does and does not cover
Turning the activity setting off also stops future chats being used to train Google’s models. The user can change the retention period instead of switching it off, choosing a shorter or longer window from the same screen.
What the setting does not cover is the review copy, which Google names as the exception in the sentence quoted above. Of the four assistants, this is the clearest case of a control that does exactly what it says and still leaves a documented gap, and it is a good reason to read the exception rather than the headline.
Training and transit are two different questions
A promise about training is a promise about one downstream use of your words. It says they will not be folded into a future model. It does not say the text stayed in your office, that it was not stored, that no person read it, or that it was not produced under legal process.
When the Privacy Act says the disclosure happens
The Office of the Australian Information Commissioner describes what happens at the moment of sending, in its Guidance on privacy and the use of commercially available AI products, published 21 October 2024 and updated 17 January 2025. Its worked example is an insurance company putting a customer’s claim details, including health information, into a public chatbot.
By entering the personal information into the AI chatbot, the insurance company is disclosing the information to the owners of the chatbot.
The disclosure is complete when the text arrives. Training is a second event with a second answer, and a switch that governs the second has no bearing on the first. Nor does a data centre in Sydney, which is covered further down.
The test that decides which side you are on
The regulator marks out the other side of the line by asking who controls the system, not which brand is on the screen.
If your organisation is using a proprietary AI system rather than a publicly available chatbot, for example, and has protections in place to ensure that information entered into the system will not be disclosed outside the organisation (such as to the system developer), this will constitute a use rather than a disclosure of personal information.
This is precisely why the consumer and Workspace versions of Gemini are not the same conversation, even though they answer in the same voice and sit behind the same logo. The consequences of getting it wrong are set out in the breach guide.
Gemini in Google Workspace: what the contract changes
For Workspace, Google’s generative AI privacy hub, last updated 14 August 2026, makes the commitments that the consumer notice does not.
Your content is not used for any other customers. Your content is not human reviewed or otherwise used for Generative AI model training outside your domain without permission.
It adds that interactions stay within your organisation, that Gemini does not share your content outside it without permission, and that data stored through Workspace services is customer data as defined by the Cloud Data Processing Addendum.
| Gemini app, personal account | Gemini in Google Workspace | |
|---|---|---|
| Human review | Reviewers read a subset of chats | Not outside your domain without permission |
| Model training | Used unless the activity setting is off | Not outside your domain without permission |
| Retention | 18 months by default, 72 hours with activity off, up to 3 years if reviewed | 90 days to indefinite, up to 36 months for the Gemini app |
| Who sets it | The user | Your administrator, through Vault |
Gemini Apps Privacy Hub, last updated 10 August 2026; Generative AI in Google Workspace Privacy Hub, last updated 14 August 2026.
Retention moves to your administrator
Under Workspace, retention stops being a user setting and becomes an administrative one. Google publishes ranges from 90 days to indefinite for Gemini in Workspace, and up to 36 months for the Gemini app used under a Workspace account. Gemini Notebook content is not retained after the session ends.
That is a materially different position from the consumer app, and it is available on licences many practices already hold. It is also the answer an insurer is looking for when it asks which AI tools you use and under what terms, which is covered in our guide to the AI questions on a cyber questionnaire.
The commitment is a domain boundary, not a country boundary
Read the Workspace sentence carefully and it promises something about who, not about where. Content is not used for other customers and not used to train models outside your domain. Nothing in it says the processing happens in Australia.
Those are separable questions, and Google answers the second one in a different document, which is the next section. Conflating them is the most common error in this whole subject, and it is the reason our approach for organisations treats residency and control as two lines rather than one.
What a Workspace administrator actually controls
If your practice is on Workspace, several of the answers above stop being user settings and become yours. That is the real argument for moving people onto it, and it is worth knowing what is in the box before you buy anything else.
Retention, Vault and the Gemini app
Google publishes the retention ranges as administrative choices: 90 days to indefinite for Gemini in Workspace, up to 36 months for the Gemini app used under a Workspace account, and no retention after the session for Gemini Notebook. Workspace data retention is managed through Vault in the usual way.
An administrator who configures none of that has still chosen something, because the defaults apply. Writing the choice down, with its date, is the cheapest half of the work, and it is the half an insurer asks about in the AI section of a cyber questionnaire.
Which editions include the data regions control
The data regions control is not reserved for the largest customers. Google lists it with Enterprise Plus, Frontline Plus, Business Standard and Business Plus, Education Standard, and Enterprise Essentials and Essentials Plus, with a separate extra licence available and a fundamental version for Frontline Standard.
A small Australian practice on Business Standard therefore has the control. What it does not have is an Australian region to point it at, which is the subject of the next section.
Where the data lives, and why Australia is the wrong question to ask Workspace
Google publishes a data regions control for Workspace. It covers Gemini prompts and responses, both at rest and during processing, which is a stronger commitment than several of the alternatives on this site make. It offers two choices.
| Commitment | Choices published | Australia available |
|---|---|---|
| Workspace data regions | United States or Europe | No |
| Vertex AI, processing within a region | Many, per model | For two Gemini models |
Google Workspace data regions documentation, last updated 18 September 2026; Google Cloud data residency table, last updated 16 September 2026.
For an Australian practice on Workspace, that is the end of the residency conversation: there is no Australian region to select. The documentation also notes that data regions cannot be applied to data types outside its list, such as logs or cached content.
The two models that run in Sydney
The cloud platform is where an Australian commitment does exist, and it is narrower than the marketing around data sovereignty suggests. Google’s residency table lists australia-southeast1 as a supported location for machine learning processing within the region.
As at 16 September 2026, exactly two Gemini models carry that commitment: Gemini 3.5 Flash and Gemini 2.5 Flash at 128k context. The Pro models do not, and neither do the newest Flash releases. That is simply what Google publishes, and it limits what any system built on it can honestly promise.
What APP 8 actually turns on
Australian Privacy Principle 8 does not ask where the disk is. It asks whether the recipient is a person who is not in Australia, and section 16C then makes an act by that overseas recipient which would have breached the principles your breach.
Choosing a region changes where bytes rest. It does not change who received them. The full rules on cross-border disclosure, and the assessment clock that starts when someone in your practice first suspects a problem, are in our guide on notifiable data breaches and AI.
Does Gemini share your data, and with whom?
Two sentences answer the selling question, and both are from Google.
We take your privacy seriously, and we do not sell your personal information to anyone.
Your Gemini Apps chats are not being used to show you ads.
Both are statements about a policy that carries a date, 10 August 2026 for the Gemini notice. The second is written in the present tense, which matters only because these pages change, and the date is the only guarantee you get. The same caution applies to every quotation in our guides.
Sharing is covered separately, in Google’s privacy policy effective 2 April 2026, and the legal process clause is the ordinary one.
We will share personal information outside of Google if we have a good-faith belief that disclosure of the information is reasonably necessary to: Respond to any applicable law, regulation, legal process or enforceable governmental request.
The same policy is equally plain about geography: “We maintain servers around the world and your information may be processed on servers located outside the country where you live.”
Sharing is not one thing
It helps to keep three ideas apart, because they get merged into a single yes or no. Selling is a commercial transaction, and Google says it does not do it. Sharing with service providers is an operational necessity that every provider discloses. Disclosure under legal process is a legal obligation that no provider can refuse on your behalf.
So does Gemini share your data? One word cannot answer that. The more useful answer is that Google rules out the first, describes the second and keeps the right to the third, and the same is true of the other three products covered here.
Three things people believe that Google’s documents do not say
These come up in practice and are answered above. Each has a close relative among the beliefs about ChatGPT, Claude and Copilot.
Not selling is one commitment. Human review, retention and legal process are three separate ones.
Google names reviewed chats as the exception, and says they are kept for up to three years.
Workspace means it is not used outside your domain. The published data region choices are the United States or Europe.
None of this is aimed at Google, whose consumer notice is the most direct provider document we have quoted. In each case a summary written by somebody else has quietly widened a commitment.
What to do this week, at no cost
None of this requires a purchase, and the order matters more than the effort.
- Find out which account each person is signed into. Consumer or Workspace changes every answer on this page.
- Open the Gemini Apps Activity setting on the personal accounts and decide, deliberately, what it should be.
- Review the connected apps, and turn off the ones nobody chose on purpose.
- Quote Google’s own sentence about reviewers in your written rules, rather than paraphrasing it.
- Record the decision, with its date, because it is what you will be asked to produce later.
If any of this ends up mattering to a claim, what an Australian cyber policy covers is the next question, and it is not one to research on the day.
What the Privacy Act asks, and what no setting answers
The OAIC has not prohibited any of this. Its position is a recommendation, and quoting it accurately matters.
As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available AI chatbots and other publicly available generative AI tools, due to the significant and complex privacy risks involved.
The binding obligation is APP 6, which asks whether the individual would reasonably expect the use or disclosure. A client who came to you about a will did not contemplate a language model, and an engagement letter that is silent on AI leaves you without that argument. A council sits outside the Privacy Act, so APP 6 is not its test either, and the state law that replaces it is not the same everywhere.
For a law or tax practice, the expectation argument starts with a client data paragraph written for Australian engagement letters.
The regulator has already written your scenario
In December 2025 the regulator wrote again on generative AI at work, naming ChatGPT, Grammarly, Claude, Copilot and Gemini.
Its case study is an employee uploading a customer’s hardship application, with health and family details, against the employer’s own policy. That is the scenario we build for, described by a regulator rather than a vendor, and it makes a better staff briefing than anything a software company could write.
What none of this fixes
Every control above governs what Google does after the text arrives. None of them governs whether it arrives, and that is where the exposure lies.
That gap is where our own software sits, and it is worth being exact about what it does. Nonimo runs on the computer, replaces identifiers before the text is sent, and shows what it changed so a person can overrule it. That order matters, because for an Australian practice the Privacy Act is engaged the moment the text is pasted, not later.
It pseudonymises rather than anonymises: the mapping can be reversed and is stored encrypted on the user’s own machine. What it keeps is set out on Nonimo’s security page, and the licence terms on the licence page.
If you buy nothing, three things still move the needle: decide which accounts people sign in with, write one page naming what may never be pasted, and name the person to ring when it happens anyway. Comparing tools comes afterwards, which is the right order.
Sources
Every page below was open in front of us on 19 September 2026.
- Gemini Apps Privacy Hub, last updated 10 August 2026. What is collected, the human reviewer sentence, the instruction about confidential information, the default of 18 months, the 72 hours with activity off, the three years for reviewed chats, the statement that reviewed chats are not deleted, connected apps, the sentence on not selling, the advertising sentence, and the line about work or school accounts.
- Google, Generative AI in Google Workspace Privacy Hub, last updated 14 August 2026. Content not used for other customers, not human reviewed or used for training outside the domain without permission, the Cloud Data Processing Addendum, and the retention ranges including Gemini Notebook.
- Google Workspace, data covered by data regions, last updated 18 September 2026. The United States or Europe choice, Gemini prompts and responses covered at rest and during processing, and the exclusion of logs and cached content.
- Google Cloud, Vertex AI data residency, last updated 16 September 2026. The australia-southeast1 column and the two Gemini models that carry a commitment to processing within the region.
- Google privacy policy, effective 2 April 2026. The legal process disclosure sentence and the statement about servers around the world.
- OAIC, Guidance on privacy and the use of commercially available AI products, published 21 October 2024, updated 17 January 2025. The insurance company disclosure example, the proprietary system counterexample and the best practice recommendation.
- OAIC, GenAI tools in the workplace, 4 December 2025. The named products and the hardship application case study.
- OAIC, APP Guidelines chapter 8, version 1.3, updated 3 October 2025. Cross-border disclosure turning on the recipient.
- Privacy Act 1988 (Cth). Australian Privacy Principles 6 and 8, and section 16C.
Common questions
Does Gemini share your data or sell it?
Google's Gemini Apps privacy notice says it does not sell your personal information to anyone, and that your Gemini Apps chats are not being used to show you ads. It does share information outside Google in stated circumstances, including legal process.
Do humans read Gemini chats?
Google says a subset of chats are reviewed by human reviewers, including its trained service providers, to help improve Google services. The same notice asks you not to enter confidential information you would not want a reviewer to see.
How long does Google keep Gemini chats?
The default for Gemini Apps Activity is 18 months, adjustable by the user. With the activity setting off, chats are kept for 72 hours. Chats picked for human review can be kept for up to three years on a separate track.
Does deleting my activity delete everything?
No. Google states that chats reviewed by human reviewers, and related data such as language, device type, location information or feedback, are not deleted when you delete your activity. Deletion clears your activity record, not that copy.
Is Gemini in Google Workspace treated differently?
Yes. Google says Workspace content is not used for other customers, and is not human reviewed or used to train generative AI models outside your domain without permission. The data is handled as customer data under the Cloud Data Processing Addendum.
Can Gemini data be stored in Australia?
Not through Google Workspace data regions, where the choices published on 18 September 2026 are the United States or Europe. On Vertex AI, processing within the region in australia-southeast1 is committed for two Gemini models rather than the whole range.
What happens to files I upload to Gemini?
Google lists files, videos, screens you ask about, photos, imported chats and shared page content among what it collects. On a personal account those sit under the Gemini Apps notice, including the possibility of human review.
Does using Gemini breach the Privacy Act?
Sending a client's details to a public chatbot is treated as a disclosure, and Australian Privacy Principle 6 governs it. Whether it is also a notifiable breach is a separate assessment with its own statutory clock, and it is not automatic.
What does the OAIC say about tools like Gemini?
It recommends as best practice that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools. It named Gemini among others in a December 2025 post on workplace AI.