[nonimo]
EN
Download

Does Gemini use your data, and who reads your chats?

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Does Gemini use your data? Yes, and Google says so more plainly than any of its competitors. On consumer Gemini Apps with the Keep activity setting on, Google states that it uses your activity to provide, develop and improve its services, including training generative AI models, and that human reviewers help with that work.

It then does something the others do not. It tells you, in the same document, not to put confidential material in. That single sentence is the most useful thing on the page for a British firm, and it is also the one that most people never reach. This guide works through what it means, along with the retention clocks, the reviewer question and the Workspace version, from Google’s own pages as they stood on 19 September 2026.

The sentence Google prints, and what it means for a firm

Here is the line, from the Gemini Apps Privacy Hub, last updated 10 August 2026.

Please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services, including machine-learning technologies.

Read it as a lawyer reads an exclusion clause. This is no warning about hackers: it tells you that, used exactly as intended, the product may let someone other than you see what you typed, and let Google use it to improve its models.

For a practice with a duty of confidence, that sentence does most of the analysis on its own. That does not make Gemini unsafe, but it does mean the free consumer product was not built for client files, and the vendor has written that down. The AI policy template is where you turn that into a rule your staff have actually read.

What Gemini Apps collect

Four categories, and only the first is a professional problem.

What Google collectsExample
Your conversationsThe prompts you submit or speak, and the tasks you ask Gemini to do
LocationThe general area from your device, your IP address, or Home or Work in your Google Account
FeedbackWhat you send when you rate a response
Usage informationApps, browsers and devices, identifiers, browser and device type, operating system

Uploads count as conversation content in full, as does data pulled in from connected apps. A single page of British correspondence routinely carries a name, a date of birth, an NHS number, a National Insurance number, a postcode that identifies a household, and a second person who never agreed to anything. Whether sending it is also a reportable breach is a separate question, worked through in the guide on client data and a data breach.

Who reads your Gemini chats

This is where Google is unusually specific, and the specificity is a gift to anyone trying to make a decision.

What reviewers do, and who they are

Google states that a subset of chats is reviewed by human reviewers, including Google’s trained service providers. Their job is to assess whether responses were low quality, inaccurate or harmful, and to suggest better ones. Chats are also reviewed to keep Gemini safe and to address violations of the Terms of Service. For a clinic letter that reviewer sits outside the care team, which is the person the Caldicott need to know principle is written to keep out.

There is a genuine protection attached, and it should be stated as clearly as the risk. Google says chats are disconnected from your account before being sent to service providers. That reduces the link back to a person. It does not remove the content of the document, which is the part that names your client.

The distinction is worth getting right, because it decides who is protected. Disconnecting the chat from the account protects the person who typed it: the reviewer does not know it was your paralegal. It does nothing for the person the document is about, whose name, address and NHS number are in the text being read. Whether that reading is also a reportable breach is worked through in the breach guide.

The three years that outlive your deletion

Now the clause that surprises people, in Google’s own words: chats reviewed by human reviewers, and related data such as your language, device type, location information or feedback, “are not deleted when you delete your activity”. Instead they are retained for up to three years.

3 years
how long a reviewed Gemini chat is kept, and deleting your activity does not reach it. Gemini Apps Privacy Hub, 10 August 2026

That turns most people’s assumption on its head. Deleting a conversation feels like the end of the matter. For the subset that went to a reviewer, it is not, and you are not told which subset yours was in.

How long Google keeps it

Three clocks, running at once, and a firm that only knows the first will describe its own position wrongly.

18 monthsdefault auto-delete for activity
72 hourswith Keep activity off
3 yearsfor a reviewed chat
Gemini Apps Privacy Hub, sections on retention and on human review, 10 August 2026

The default auto-delete period for Gemini Apps activity is 18 months. You can change it to 3 months or 36 months, or switch auto-delete off entirely, and you can delete chats by hand at any time.

Turning Keep activity off does not mean nothing is kept

Temporary chats, and chats you have when Keep activity is off, are retained with your account for 72 hours. Google gives two reasons: to answer you, using the last 24 hours of your chat as context, and to protect Google, its users and the public, with the example that a copy exists in case of a system failure.

Then comes the sentence that matters. “Even if your Keep activity setting is off or you use temporary chats, Google still uses your chats to respond to you and help protect Google, our users and the public, including with help from human reviewers.”

So the setting stops training and clears the history. The chat is still sent to Google, still kept for 72 hours and, on Google’s own wording, a reviewer may still be involved.

Two more lines from the same section belong in the same picture. Google keeps some data until you delete your Google Account, such as how often you use Gemini Apps. And where Gemini worked with another Google service, that service keeps its own copy under its own policy.

What you deleteWhat it reaches
A single chatThat chat, from your activity
All Gemini Apps activityYour activity, and not a chat a reviewer saw
Your Gemini Apps activityNot data saved by other Google services you used through Gemini
Your Google AccountData Google says it keeps until the account goes

The third row is the one that catches firms out. Ask Gemini to do something that involves another Google service and that service saves its own activity under its own policy, so clearing your Gemini history leaves it untouched.

The feedback button that takes 24 hours with it

One more aside, and it is the same trap that exists in every product in this category. If Keep activity is off and you choose to send feedback, Google collects your feedback, context to understand it including the last 24 hours of your chats, and any content included in those chats, such as uploads and data from connected apps.

A thumbs down on a bad summary therefore hands over the document you were summarising, and the three before it. That belongs in a staff briefing, not in a policy nobody reads, and it is worth a line when you answer an insurer’s questions about AI use.

Does Gemini use your data for training?

On consumer Gemini Apps with Keep activity on, yes. Google’s description of how activity is used names training generative AI models directly, alongside providing, developing and improving its services and protecting Google and the public.

Turn Keep activity off and future chats are not used to train the models, unless you send feedback. Temporary chats are not used to train them either. Audio, and Gemini Live videos and screenshares, are not used to improve Google services by default, and that is a separate consent.

SettingTrains the modelsHuman reviewRetention
Keep activity onYesYes, a subset18 months by default
Keep activity offNo, unless you send feedbackGoogle says reviewers may still help protect the service72 hours
Temporary chatNoNot for improving Google AI with reviewers72 hours
A reviewed chat, any of the aboveUsed to improve servicesIt has already happenedUp to 3 years

The fourth row is the one to remember. It applies on top of whichever setting you chose, and it is the row to quote when you answer an insurer’s questions about AI use.

Training is not the same as passing through Google’s servers

Most of what is written on whether Gemini uses your data comes down to the training question, and that is the least important of the five.

When someone in your office sends a document, five things happen and only one of them is training. The text is transmitted to a company outside your firm. It is retained for some period. An automated system reads it, and sometimes a person does. It becomes reachable by legal process directed at whoever holds it. And, depending on a setting, it may be used to adjust model weights.

Google’s own drafting makes this easier to see than most, because the privacy hub keeps training, review and retention in three different places with three different answers. A firm that reads only the training paragraph will tell a client something true and incomplete, and will be surprised by the three years later. The same five questions asked of ChatGPT, Claude and Copilot give three more sets of answers.

Who your data controller is, if your firm is in the UK

Read the same clause across four providers on the same afternoon and a split appears. Two route a British user to an Irish entity, and two route them to the United States. Google is the clearest of the four, because it names Britain explicitly rather than leaving it to fall through a gap.

From the Google Privacy Policy, effective 2 April 2026: Google Ireland Limited is the controller for users based in the European Economic Area or Switzerland, and “Google LLC for users of Google services based in the United Kingdom”, at 1600 Amphitheatre Parkway, Mountain View, California.

ProviderController named for a UK userWhere
GeminiGoogle LLCMountain View
ChatGPTOpenAI OpCo, LLCSan Francisco
ClaudeAnthropic Ireland, LimitedDublin
Microsoft CopilotMicrosoft Ireland Operations LimitedDublin

The AI carve-out that stops at the Channel

The same section has a sentence written for this exact subject, and it is worth quoting because of where it draws the line. Google Ireland Limited, it says, is the controller responsible for processing information to train Google’s AI models for the purpose of deploying them in services provided by Google Ireland Limited in the European Economic Area or Switzerland.

So for model training specifically, Google has named an Irish controller, and named it for the EEA and Switzerland. The UK is in neither. A British user’s data, including for AI training, sits with the Californian entity on the face of the document.

None of this is a scandal, or on its own a reason to pick a different vendor, but it is a fact about your supply chain that belongs in your record of processing, and it changes which company you would be writing to. It also belongs alongside the other three rows, which the ChatGPT guide sets out from OpenAI’s side.

Gemini in Google Workspace is a different product

If your firm pays Google for email, this section is the one that applies to you, and it reverses most of the answers above.

What the Workspace hub says

Google’s Generative AI in Google Workspace Privacy Hub, last updated 14 August 2026, states that your content is not used for any other customers, and that it is “not human reviewed or otherwise used for Generative AI model training outside your domain without permission”. It states that interactions stay within your organisation, and that Gemini does not share your content outside it without permission.

The contractual footing changes too. User prompts are customer data under the Cloud Data Processing Addendum, and Workspace does not use customer data for training models without the customer’s prior permission or instruction.

Consumer Gemini AppsGemini in Workspace
Trains models outside your domainYes, with Keep activity onNot without permission
Human reviewA subset, by Google and its service providersNot without permission
ContractConsumer termsCloud Data Processing Addendum
Who the admin isNobody, it is a personal accountYour own organisation

The gap the hub names itself

One line stops this being a clean win, and it is worth knowing before you promise a client anything. Workspace organisational file sharing and data region settings apply to Workspace apps, but the hub notes that they do not apply to Gemini Notebook data specifically. A promise about where data sits belongs in the AI wording of your client terms only once you have checked it against lines like this one.

That is a narrow carve-out and it may not touch your firm at all. It is in here because it is the pattern that runs through this entire subject: the guarantee is real, but the exceptions are what you need to check. A guarantee about data regions that does not cover one feature is exactly the sort of thing a client’s solicitor finds after the event.

There is a practical consequence in an office of fifteen people. The Workspace promises attach to the work account. Your staff also have personal Google accounts, on their own phones, where none of them apply. Which account someone signed into is the whole difference, and it is invisible from the outside.

So what you need to check is which account people are signed into. Sit with one person, open Gemini on the device they actually use, and read the account at the top right. Then do it on the phone. That check takes five minutes and decides the answer for all four assistants, most sharply for Copilot, and writing the result down is what the AI policy template is for.

Does Google share your Gemini data?

Not by sale, and Google says so directly in the review section: it does not sell your personal information to anyone. What Google does instead is disclose it to others, and that list is longer.

Route outWhat it means in practice
Service providersTrained reviewers who see chats disconnected from your account
Other Google servicesAnything Gemini did through Wallet, YouTube or similar, under that service’s policy
Connected appsGoogle apps and outside services you switch on yourself
Legal processWhere Google must meet a law, regulation or enforceable governmental request
Google grounding servicesSome responses are grounded on Search results

Two of those five are chosen by the person at the keyboard rather than by your firm. Connected apps are enabled per user, and the grounding behaviour is part of how the product works rather than a setting. Your external IT provider can tell you which connectors are live on a Workspace tenant; on a personal Google account, nobody can.

The legal process line is the one that no configuration touches. It is ordinary, every provider has an equivalent, and it is the reason the only reliable control is what goes in rather than what happens afterwards. In litigation the same gap shows up in what lawyers sign: the court declarations look at what came out of a tool, and what went into it is mostly left to the firm.

Does Gemini show you adverts from your chats?

Google’s answer is a flat no, and it is short enough to quote whole: “Your Gemini Apps chats are not being used to show you ads. If this changes, we will communicate it clearly to you.”

That is a real difference from one of Gemini’s main rivals, and it should be recorded without being inflated. It is a description of a business model at a point in time, complete with a sentence anticipating that the model might change. It is not a promise about the future, and Google has not framed it as one. The product that now does the opposite is described in the ChatGPT guide.

How to turn it off and delete what is there

Five steps, in the order that recovers the most control per minute.

  1. Decide which account people sign in with. Consumer Gemini and Gemini in Workspace are different products with different promises, and only the account tells them apart.
  2. Turn Keep activity off, or shorten it. Off gives you 72 hours. Leaving it on with auto-delete set to 3 months is the middle setting most firms actually want.
  3. Use temporary chats for anything sensitive. They are not used to train Google’s AI models and are kept for 72 hours.
  4. Tell people what the feedback buttons do. With Keep activity off, sending feedback hands over the last 24 hours of chats and any content in them.
  5. Accept that a reviewed chat cannot be deleted. Deleting activity does not reach it, so the control that matters is not sending the document in the first place.

Worth knowing as well: changing your Gemini Apps settings does not change other Google settings, so Web and App Activity or Location History may keep saving data as you use other Google services. If an external provider administers your Workspace tenant, steps one and two are theirs to confirm rather than yours to assume.

Is Gemini safe under UK law?

No regulator has ruled on a named product, and any page telling you the ICO has approved or banned Gemini is wrong. What applies is the ordinary law: the UK GDPR with the Data Protection Act 2018, supervised by the ICO, plus whatever your professional regulator and your indemnity insurer require. In a council the Freedom of Information Act joins it and turns a prompt into something a resident can request: what that changes.

LayerWho supervises itWhat it asks of your firm
UK GDPR and the Data Protection Act 2018The ICOYour own lawful basis, identifiable information removed where possible, a data sharing agreement
Data (Use and Access) Act 2025The ICOAcknowledge a complaint within 30 days, respond without undue delay
Your professional rulesYour professional bodyYour duty of confidence to the client
Your indemnity coverYour insurer, at renewalAnswers to its questions about AI use

Google sets out its own legal bases for Gemini Apps under EU and UK law: performance of a contract, legitimate interests with appropriate safeguards, legal obligations, and consent for certain features. Those are Google’s bases for its own processing. They are not yours, and a firm cannot borrow them.

In practice the regulator is rarely the thing that frightens a partner, and pretending otherwise makes for a bad risk assessment. The fine feels distant. What does not feel distant is having to write to a client and explain where their file went, and then explain the same thing to your professional body and to your indemnity insurer at renewal. Those three conversations arrive long before the ICO does, and they are the reason most firms act.

A contract does not decide who the controller is

When the ICO published its response to the generative AI consultation series, it made a point that cuts against comfortable readings in both directions. Controllership turns on the practical reality rather than the label, and “a contract does not necessarily determine whether an organisation is a controller”. It also flagged the risk that deployers of closed models do not have meaningful control over all the processing at deployment.

Your firm chose to send the document, so your firm needs the lawful basis and owes the duties in Article 5(1)(f) and Article 32. The ICO’s practical advice on sharing personal data to improve an AI model is a sequence: identify a lawful basis first, then minimise, because “if an organisation is able to anonymise the information, or remove identifiable information from the documents shared, then they should do so”, then put a data sharing agreement in place.

One duty is newer than most guidance acknowledges. The ICO states that all data protection provisions of the Data (Use and Access) Act 2025 came into force on 19 June 2026, and you must now acknowledge a complaint about your handling of personal information within 30 days and respond without undue delay. What is arriving from the other direction, through your customers rather than your regulator, is in our note on the EU AI Act timetable.

What none of this fixes

Everything above describes a product. The problem in a small practice is a person, on a Friday afternoon, with a bundle that will not read itself. In a solicitors’ practice that bundle opens with the client’s name, date of birth and NHS number, so what a fee earner’s extract still gives away once it is sent matters more than which assistant you choose.

No setting changes what is in the document. Delete every name from a page of correspondence and a specific street address, a minor in the household and a file reference at a named previous adviser will still identify the matter to anyone who has seen the file, and often to anyone in the same town. Identifiability is a property of the whole document, not of the words you removed.

What a masking tool does here, and what it does not

The facts first, so you can check them. Nonimo is a Mac and Windows app that finds identifiers in text before it is sent and hides them, working on the machine rather than in a cloud, with a policy set by IT rather than by each user.

For the United Kingdom it covers NHS numbers, UTRs and driving licence numbers written after their label, National Insurance numbers with or without one, and postcodes, plus a vehicle registration, masked as a number plate when a word such as “Registration:” comes before it, and a mobile number that follows a label such as “Mobile:”.

Each of them is masked in front of you, where you can undo it, so the person who knows the matter has the last word on every change.

What it puts in their place is a reversible label, and the key linking each label to the real detail is kept encrypted on your own computer. That is pseudonymisation in the sense Article 4 gives the word, so the data remains personal data for whoever holds the key, and the key is yours. It lowers risk, and it does not take a document outside data protection law. The longer treatment of that distinction is in the breach guide.

What it keeps on your computer is set out on Nonimo’s security page.

The account

Decide which Google account each person signs into.

The list

Five lines at most: the documents that may never go in.

The person

Name who to call when someone does it anyway.

Three things that help even if you buy nothing at all

If you buy nothing at all, three things still help. Decide which Google account each person signs into. Write a short list, five lines at most, of the documents that may never go in. Name the person to call when someone does it anyway.

Whether your insurance would pay out if it went wrong is a separate question, set out in the UK cyber insurance comparison, and our other guides cover what to look for when it is time to judge a tool.

Put the same tests to ChatGPT, Claude and Copilot and the answers differ, but none of them is that the document stayed in your office.

Sources

Checked 19 September 2026.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does Gemini use your data to train Google's models?

Yes, on consumer Gemini Apps with Keep activity on. Google states it uses your activity to provide, develop and improve its services, including training generative AI models, with human reviewers involved.

Do humans read Gemini conversations?

Google says a subset of chats is reviewed by human reviewers, including trained reviewers from its service providers, and asks you not to enter confidential information you would not want a reviewer to see.

If I delete my Gemini activity, is everything gone?

No. Google states that chats reviewed by human reviewers, and related data such as your language, device type and location, are not deleted when you delete your activity and are kept for up to three years.

What happens if I turn Keep activity off?

Chats are still retained with your account for 72 hours so Google can answer you and protect its service, and Google says human reviewers may still be involved in that protection work. They are not used to train the models.

Does Gemini use my chats to show me adverts?

Google's answer on its privacy hub is no: your Gemini Apps chats are not being used to show you ads, and it says it will communicate clearly if that changes. That is a different position from some competitors.

Who is my data controller for Gemini if I am in the UK?

Google LLC in Mountain View, California. Google's privacy policy names Google Ireland Limited for the European Economic Area and Switzerland, and names Google LLC specifically for users based in the United Kingdom.

Is Gemini in Google Workspace different from the free Gemini app?

Yes, materially. Google states that Workspace content is not reviewed by humans or used to train generative AI models outside your domain without permission, and that prompts are customer data under the Cloud Data Processing Addendum.

Is it safe to put client data into Gemini under UK law?

No regulator has ruled on a named product. Your firm stays the controller and needs a lawful basis, and the ICO advises removing identifiable information from shared documents where that is possible.