Knowledge · Is this AI tool safe · 8 minutes

Is Gemini safe? Privacy in the Gemini app and Google Workspace

What Google does with Gemini chats: human review, model training, retention and data regions. Personal accounts vs Google Workspace, with settings step by step.

Last updated: October 5, 2026

Is Gemini safe? What it depends on

Gemini is the name of several Google products. For privacy, one distinction matters most: the Gemini app on a personal account (Gemini Apps, gemini.google.com and the mobile app) versus Gemini in Google Workspace, used on a work or school account managed by an administrator.

The two run under different rules. A personal account falls under the Google Privacy Policy and the Gemini Apps Privacy Notice. A Workspace account falls under the company's agreement with Google and the Cloud Data Processing Addendum. So the question "is Gemini safe" has two answers, depending on which account you sign in with.

arLET'S does not label other companies' products as safe or unsafe. Below are facts from Google's documents and from regulators, with dates, plus a list of what those documents do not tell you.

What Google does with data you type into Gemini on a personal account

According to the Gemini Apps Privacy Hub (updated 24 September 2026), Google uses your Gemini activity to provide, develop and improve its services, including training generative AI models. Saved activity also includes, among other things, audio, Gemini Live videos and screenshares, feedback, info from websites you visit with Gemini, and location info.

Human reviewers read some chats. Chats are disconnected from your account before review. Reviewed chats, together with related data such as language, device type or location, are not deleted when you delete your activity. Google keeps them for up to three years.

The setting that controls this is called Keep Activity and sits on the Gemini Apps Activity page. For users aged 18 and over it is on by default. By default, activity older than 18 months is auto-deleted, and you can change this to 3 or 36 months or turn auto-delete off.

When you turn the setting off, new chats do not appear in your history and are not used to train models unless you send Google feedback. Google still keeps them for 72 hours to respond and to protect the service and its users. Temporary chats are kept for the same 72 hours and are not used for training either.

Google itself says in the privacy hub not to enter confidential information you would not want a reviewer to see. That is a good rule for any AI tool on a personal account. We cover it in more detail in can you paste data into ChatGPT.

Gemini in Google Workspace: what changes on a business account

According to the Generative AI in Google Workspace Privacy Hub (updated 14 August 2026), customer content is not human reviewed or used to train models outside the customer's domain without permission. Google processes it on the customer's instructions under the Cloud Data Processing Addendum and the Workspace service terms.

In most editions the Gemini app on a Workspace account is a core service covered by the same agreement as Gmail or Drive. Retention is set by the administrator: up to 36 months for the Gemini app, and from 90 days to indefinite for Gemini in Gmail, Docs and other apps.

For Gemini in Workspace, Google lists ISO/IEC 27001, 27701, 27017, 27018 and 42001 certifications and SOC 1/2/3 reports. The hub notes that Gemini in Chrome is not covered by the ISO, SOC or FedRAMP certifications. In schools (Workspace for Education), some features are restricted by default for users designated as under 18.

A common trap: an employee signed in to a personal Gmail account in the browser uses Gemini under consumer terms, even when pasting a work email. That is a textbook case of shadow AI.

Where Gemini data is processed and on what legal basis

For personal accounts in the European Economic Area and Switzerland, Gemini Apps are provided by Google Ireland Limited, and by Google LLC elsewhere. The Google Privacy Policy says data may be processed on servers outside your country. For transfers from the EEA to the US, Google relies on the EU-U.S. Data Privacy Framework and, where no adequacy decision applies, on standard contractual clauses (legal frameworks page, effective 23 August 2025).

In Workspace, a company can choose a data region. Since 29 June 2026 the Gemini app follows Workspace data region settings: the administrator can set storage and processing in the EU or the US, down to individual organizational units (according to Google's announcement of that date). In-region processing and storage come with Enterprise Plus and Frontline Plus. Education Standard and Education Plus get in-region storage only.

The data region is a setting the administrator configures. Check it in the admin console before assuming your data stays in Europe.

How to turn off Gemini activity and training, step by step

On a personal account: 1) Open myactivity.google.com/product/gemini (Gemini Apps Activity), or get there from your Google Account settings. 2) Turn off Keep Activity. 3) If you keep it on, set auto-delete to 3 months. 4) Delete older chats you do not want kept. 5) Use a temporary chat for one-off questions.

Keep two limits in mind. Turning it off applies to future chats. Chats already selected for review stay for up to three years and cannot be deleted from your account.

On a Workspace account the controls sit with the administrator: 1) In the admin console, check whether the Gemini app is on and for whom. 2) Set chat retention. 3) If you need data in the EU, configure a data region for the right units. 4) Block or limit personal Google account sign-in on work browsers so chats do not drift to consumer accounts. Write the team rules down in an AI use policy.

Known incidents and regulator actions

On 12 September 2024 Ireland's Data Protection Commission (DPC), Google's lead EU supervisory authority, opened an inquiry into Google Ireland. It examines whether Google carried out a required data protection impact assessment (GDPR Article 35) before training its PaLM 2 model on EU users' data. As of 5 October 2026 we found no published decision.

In August 2025 researchers Ben Nassi, Stav Cohen and Or Yair described 14 attack scenarios against Gemini-based assistants in the paper "Invitation Is All You Need". A poisoned calendar invite or email carried a hidden instruction that Gemini executed when the user asked, for example, about their schedule. The authors reported it to Google, which deployed mitigations. This is an example of prompt injection.

On 30 September 2025 Tenable described three vulnerabilities in Gemini (Cloud Assist, the search personalization model and the browsing tool) that allowed exfiltration of a user's saved information and location data. According to Tenable, Google has fixed them.

As of October 2026 we found no public decision by the Polish data protection authority (UODO) or the Italian Garante concerning Gemini.

When Gemini makes sense for a business, and when it does not

It makes sense when the company already works in Google Workspace, Gemini runs on company accounts, the administrator has set retention and, if needed, an EU data region, and the team has written rules. Your data then stays under the same agreement as your email and documents.

It does not make sense when employees use personal accounts, because chats may then be used for training and seen by reviewers. Also take care with features that read email and calendar or act on your behalf, because someone else's content in an email can influence what the assistant does.

Whatever the account, do not paste keys, passwords or .env files. If you want to see what such a snippet contains, use the /wklej tool, which recognizes it in your browser without sending anything. For comparison with other tools, see our articles on ChatGPT, Copilot and DeepSeek.

What we do not know

Google does not say what share of chats goes to reviewers or where reviewers are physically based. It is also unknown how long data from chats effectively remains in models that have already been trained. The Workspace privacy hub lists no separate processing locations beyond the data region settings. The outcome of the DPC inquiry into PaLM 2 is not known. Google's policies change often, so check the update date of the source documents before you decide.

In short

  • Personal accounts and Workspace are two different data regimes. A business should use Gemini only on Workspace accounts.
  • On a personal account, chats may be used for training, and those read by reviewers are kept for up to three years.
  • Turning off Keep Activity stops training on new chats, but Google still keeps them for 72 hours.
  • The EU data region in Workspace is set by the administrator, and full in-region processing comes only with selected editions.
  • Features that read email and calendar have been the target of documented prompt injection attacks, which Google patched after disclosure.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is the Gemini app safe?

It depends on what you type and which account you use. On a personal account Google may use chats for training and show them to reviewers, which is why Google itself advises against entering confidential information.

Does Gemini read my conversations?

On a personal account, reviewers read some chats after they are disconnected from your account and keep them for up to three years. In Google Workspace, content is not human reviewed without the customer's permission.

Does Gemini train on my data?

On a personal account, yes, if Keep Activity is on. Once it is off, new chats are not used for training unless you send feedback. In Workspace, data is not used for training outside your domain without permission.

How long does Gemini keep conversations?

18 months by default, adjustable to 3 or 36 months. With activity off and in temporary chats, 72 hours, and chats read by reviewers for up to three years.

Does Gemini keep data in the EU?

On a personal account data may be processed outside the EU. In Workspace the administrator can set an EU region, with in-region processing available in Enterprise Plus and Frontline Plus.

Sources

  1. Google: Gemini Apps Privacy Hub (updated 24 Sep 2026)
  2. Google: Manage and delete your activity in Gemini Apps
  3. Google Workspace: Generative AI in Google Workspace Privacy Hub (updated 14 Aug 2026)
  4. Google Workspace Updates: Gemini app data regions support (29 Jun 2026)
  5. Google: Legal frameworks for data transfers (effective 23 Aug 2025)
  6. Data Protection Commission (Ireland): inquiry into Google AI model PaLM 2 (12 Sep 2024)
  7. Nassi, Cohen, Yair: Invitation Is All You Need (arXiv, 16 Aug 2025)
  8. Tenable: The Trifecta, three Gemini vulnerabilities (30 Sep 2025)

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also