[nonimo]
EN
Download

What Gemini does with your data, and what deleting does not

· Updated · Written and maintained by Joaquín Trapero, Nonimo

Google keeps chats that a human reviewer read for up to three years, and deleting your Gemini activity does not remove them. Google says so itself, on its own Gemini Apps Privacy Hub, in the retention section, in those words.

It is also the most useful thing to know about Gemini privacy, because everything else people worry about has a setting and that one does not. Training has a switch. History deletes itself on a schedule. Reviewed chats have neither, and nothing in the product tells you whether yours were among them.

What follows reads the primary documents and reports what each says, with its date. If what you really need to know is whether something you already pasted has become a problem, that question has its own guide.

What you doWhat it reaches
Delete a conversationThat conversation, from your activity
Turn Keep Activity offFuture chats, not past ones
Set automatic deletion to 3 monthsSaved activity, on that schedule
Nothing availableChats already read by a reviewer

Google, Gemini Apps Privacy Hub, last updated August 10, 2026.

Google’s own warning, in Google’s words

Before any of the detail, there is a line in the Gemini Apps Privacy Notice that does most of the work, and it is one sentence long. After describing that human reviewers, including trained reviewers from its service providers, look at some of the data it collects, Google writes: please don’t enter confidential information that you wouldn’t want a reviewer to see or Google to use to improve our services.

That is the vendor telling a professional firm not to put client material into the product. No regulator said it, no competitor said it, and it is not buried in a terms of service PDF. It is in the notice the product links to, dated June 29, 2026, and a firm’s written AI policy can quote it directly.

It also sets the frame for the rest of this page. Google is not being evasive about Gemini chats; of the four major providers it publishes the most operational detail, including numbers nobody made it disclose.

The difficulty with Gemini privacy is elsewhere. That detail is spread across a notice, a hub of FAQs and a separate Workspace document, each carrying its own date, and no two of them answer the same question in quite the same words.

What Gemini collects, which is more than the prompt

The notice lists what arrives, and it is the longest such list among the four major providers’ notices. Prompts and uploads are the first two items. After that it broadens quickly.

CategoryExamples Google gives
What you shareFiles, videos, screens you ask about, photos, imported chats
Gemini LiveTranscripts and recordings of audio, video and screenshares
Connected AppsSearch or YouTube history, page context and URL from Chrome
Device and systemCall and message logs, contacts, installed apps, screen content

Google, Gemini Apps Privacy Notice, last updated June 29, 2026.

The mobile permissions list

The fourth row is the one that catches people off guard. On the mobile apps, Google lists system permissions and device data including call and message logs, contacts, installed apps, language preferences and screen content, each with a stated reason.

None of that is collected without the permission being granted, and each has an obvious product purpose. For a firm whose phone contacts are a client list, granting the contacts permission is a disclosure of the client list, independent of anything anyone ever typed into a chat.

Connected Apps, and the line Google draws around them

Gemini works with Connected Apps, including Google’s own and services from other companies reached through Model Context Protocol server tools. What Gemini takes from them becomes part of your inputs, and what it sends to them is processed under their policies rather than Google’s.

Google states the boundary plainly: it does not monitor or secure data from custom Connected Apps run by other companies, and choosing to connect them may expose your data, passwords, devices and accounts to unauthorized access. Whatever the vendor questionnaire your client sends says about subprocessors, a connector you enabled yourself is outside it.

Does Gemini train on your chats?

On a personal account, that is decided by one setting called Keep Activity, and the answer flips with it. There is no separate training toggle in Gemini the way there is in ChatGPT.

Understand that single switch before you touch it, because it bundles things most people would rather keep separate. History, personalization and model training all hang off the same control, so a user who wants to keep their chat history and stay out of training has no setting for that combination. The nearest equivalent to the ChatGPT arrangement, where those are two switches, does not exist here.

Setting stateHistoryUsed to improve models
Keep Activity onSaved, deleted automatically on scheduleYes
Keep Activity offNot saved past 72 hoursNo, absent feedback
Temporary chatNot savedNo

Google, Gemini Apps Privacy Hub, last updated August 10, 2026.

Keep Activity on, and what it turns on

With Keep Activity on, Google states that your chats and what you share are saved in your activity, and that it uses your activity to provide, develop and improve its services, including training generative AI models, as well as to protect Google, its users and the public with the help of human reviewers.

Saved activity is wider than the chat. Google lists audio, Gemini Live videos and screenshares, feedback, information from websites you visit with Gemini, product usage and location information, including your device’s general area, IP address, or the home and work addresses in your Google account.

One exception runs the other way. Google states that audio and Gemini Live videos and screenshares are not used to improve its services by default, which is the one category you opt in to rather than out of.

Keep Activity off, and the 72 hours

Turn it off, or use a temporary chat, and retention drops from months to hours. Google states those chats are retained with your account for 72 hours, used to respond to you with the last 24 hours as context, and to protect Google, its users and the public, for example so a chat survives a system failure.

18 monthsdefault automatic deletion for saved activity
72 hoursretention with Keep Activity off
24 hoursof chat used as context, and pulled in by feedback
Google, Gemini Apps Privacy Hub, last updated August 10, 2026

Temporary chats are not used to train Google’s models, and Google states that with Keep Activity off and no feedback submitted, future chats are not used to improve its AI models either. Both are written commitments rather than inferences, and both are reversed by the feedback button described further down.

What deleting actually deletes, and what it misses

Deleting your Gemini Apps activity removes the record from your activity, on the schedule you chose or immediately if you delete by hand. It does not reach everything.

This matters more in the United States than the equivalent question does elsewhere, and for a structural reason. There is no federal data protection authority here to ask a provider what it still holds, so the retention paragraph in a vendor’s own notice is the whole answer, not the start of a complaint.

Nowhere else is that answer written down. That is also why the breach analysis and the state notification clocks are the practical next step here, rather than a number from a regulator who does not exist.

The three years behind a human review

Google’s words, in the retention section of the notice: chats reviewed by human reviewers, and related data such as your language, device type, location information or feedback, are not deleted when you delete your activity. Instead, they are retained for up to three years.

3 years
the maximum Google states a Gemini chat reviewed by a human is retained for, and it is not removed when you delete your activity. Gemini Apps Privacy Hub, August 10, 2026

The FAQ on human review repeats the three years and adds what the review is for: reviewers assess whether responses were low quality, inaccurate or harmful, suggest better ones, and check for violations of the terms. Google also states that chats are disconnected from your account before being sent to service providers.

Look closely at the word disconnected. It means the reviewer does not see whose account it came from. It does not mean the reviewer cannot read the names, the matter reference and the address that were inside the text, because those were in the text rather than in the account.

The auto delete default nobody changes

The other half of the retention answer is a setting most people never open. Saved activity is deleted automatically after 18 months by default, and you can change that to 3 months, to 36 months, or to no automatic deletion at all.

Eighteen months is a long time for a professional firm and three is usually plenty. Changing it takes under a minute in Gemini Apps Activity, and it is the single most valuable thing on this page that a partner can do without asking anyone. Google adds, separately, that deleting Gemini activity does not delete data saved by other Google services you used it with.

Training is one use of your text, not the only one

Everything above comes back to one mix-up. We do not train on your data is a promise about one use of your words. It does not say nobody read them, that nothing was kept, or that they never left your office.

Google is unusually direct about this, which is to its credit. Its settings page states that your Gemini settings do not control processing of your chats to create anonymized data to improve Google services, and that even with Keep Activity off, Google still uses your chats to respond to you and to help protect Google, its users and the public, including with help from human reviewers.

What still happens with Keep Activity off

What still happensWhere Google says so
Chats kept with your account 72 hoursPrivacy Hub, retention FAQ
Human reviewers may see themConfiguring your settings
Anonymized data made from themConfiguring your settings
Other Google services keep their own recordPrivacy Hub, retention

Google, Gemini Apps Privacy Hub, last updated August 10, 2026.

Read that table next to the equivalent one for ChatGPT and the shape is the same at all four providers. The switch you were told to check is genuine, it is narrow, and it was never the thing that decides whether client text left the building.

In the United States that distinction has a practical edge rather than a philosophical one. A training commitment is a promise about a model that will exist in a year. A retention period describes a file that exists now, on a date when opposing counsel or a client’s auditor can ask about it. Some courts now expect counsel to keep that record themselves, and one standing order in California asks for the prompts by name.

Only one of those two ever turns up in a discovery request, and it is not the one the settings screen is about. For a law firm that is the argument for taking client identifiers out at the keyboard rather than trusting the policy on the intranet.

The feedback button, and the 24 hours it carries

Every major assistant has a version of this, and Google’s is the widest. It is also the only one that specifies a time window, which makes it easy to picture.

If Keep Activity is off and you choose to submit feedback, Google states it collects your feedback, context that helps it understand the feedback including the last 24 hours of your chats, and any content included in those chats, such as uploads and data from Connected Apps.

So a person who turned everything off, worked on three client matters in the morning, and pressed thumbs down on an unhelpful answer in the afternoon has handed over the morning. The feedback is then reviewed by specially trained teams, which Google notes is in some cases required by law.

Nothing about that is hidden and nothing about it is unreasonable for a product that has to catch harmful output. It is just not what anyone expects from a thumbs up, and no setting on this page protects you from it. Make sure the people who use the product know.

The same button on Workspace and at the other providers

On a Workspace account the same button behaves differently and better, which is covered further down: the prompt and output travel only if the sharing checkboxes stay selected, and the result is not used to train the Workspace models. The consumer version has no equivalent checkbox.

AssistantWhat a thumbs up or down carriesKept for
Gemini, personal accountLast 24 hours of chats and their contentNot stated
Gemini in WorkspacePrompt and output, if checkboxes stay selectedUp to 18 months
ChatGPTThe entire associated conversationPer retention policy
ClaudeThe entire related conversation5 years

Google Gemini and Workspace privacy hubs, OpenAI help center, and Anthropic privacy center, read September 19, 2026.

Four products, four wordings, one behavior: the rating is the smallest part of what the button sends. If a single habit is worth training into a firm, more than any policy document, it is this one.

Does Gemini share or sell your data, and does it show you ads?

Three questions that get answered as one, and Google’s answers differ from those of the other big consumer assistants, in Google’s favor.

On selling, the human review FAQ states that Google does not sell your personal information to anyone. On advertising, the hub is explicit in a way its competitors are not: your Gemini Apps chats are not being used to show you ads, and if this changes, Google will clearly communicate it.

QuestionChatGPTGemini
Sells personal dataNoNo
Chats used for advertisingNot describedStated as no
Shares for cross-context advertisingYes, you can opt outNot stated for chats

OpenAI US privacy policy of September 10, 2026, and Google Gemini Apps Privacy Hub of August 10, 2026.

Read the Gemini column as a statement about the present tense, because that is how it is written. A commitment with if this changes attached is a commitment to tell you, not a commitment never to change. The rest of the ChatGPT comparison shows what a change of that kind looks like when it arrives.

A work account changes the answer: Gemini in Workspace

If your firm is on Google Workspace, most of this page stops applying and a different set of commitments takes over. This is the single largest lever available to a small firm and it usually costs nothing extra.

What Google commits to, and the words that bound it

Google’s Workspace privacy hub answers the training question with one word, No, and then explains it. Prompts are customer data under the Cloud Data Processing Addendum, and Google commits not to use customer data to train or fine-tune its Workspace generative AI models without the customer’s prior permission or instruction.

The hub adds three summary commitments: interactions stay within your organization, existing Workspace protections apply automatically, and your content is not reviewed by humans or used for model training outside your domain without permission. Note the qualifiers in that last one, outside your domain and without permission, which are the difference between a promise and a slogan. Those qualifiers are why a firm should quote the contract, not the hub, in what its engagement letter tells a client about AI.

Retention on a work account, set by your admin

The retention answer also changes, and it moves from your hands to your administrator’s. Google publishes it as a table, and the three products behave differently.

ProductRetentionSet by
Gemini in Workspace90 days to indefiniteAdmins
Gemini app, work accountUp to 36 monthsAdmins
Gemini NotebookNot retained after the sessionNobody

Google, Generative AI in Google Workspace Privacy Hub, last updated August 14, 2026.

Feedback is limited too, and differently from the consumer side. Google states that in Workspace the prompt, contextual sources and output travel only if the sharing checkboxes remain selected, that feedback is not used to train the Workspace generative AI models, and that feedback data may be retained for up to 18 months.

HIPAA, FedRAMP and where Gemini sits

For a US firm this is the row that decides procurement. Google states that Gemini can support HIPAA workloads, and that the HIPAA Included Functionality and the Workspace HIPAA implementation guide have both been updated to include it. It also states that Gemini has FedRAMP High authorization. Supporting a workload and being covered are different claims, and how each vendor words that distinction is where procurement decisions actually get made.

Read those as what they are. They mean the product can be used inside a compliance program that you run; they do not mean the product is compliant, because compliance attaches to the covered entity and not to a tool. Every one of the four major assistant vendors words this the same way, and every summary of them gets it wrong.

The practical test for a small firm is narrower than the certification list and easier to apply. Ask your administrator three things: whether Gemini is on for your domain, what retention they have set for the side panel and for the Gemini app, and whether anyone has ever looked at the second of those. In most firms of this size the answers are yes, the default, and no.

Where the data is processed, and why that answers little here

Google is an American company processing American customer data on American infrastructure, with regional commitments that exist mainly for European customers. For a firm in the United States the transfer question that dominates European coverage of this subject has no domestic equivalent, because there is no federal data protection authority to satisfy.

The version that does bite here is contractual rather than geographic: what your Workspace agreement says, what your clients’ security questionnaires demand, and what your cyber policy assumes you have in place. Those are answerable. Server location, for most US firms, is not the question.

How to change your Gemini privacy settings, and delete what is there

Four steps, all free, all in the same place. Do them in this order, and write down the date.

  1. Open Gemini Apps Activity and set the automatic deletion period. Three months is a sensible default for a professional firm; the shipped default is eighteen.
  2. Decide about Keep Activity. Off means 72 hours instead of months, and no future chats used to improve Google’s models.
  3. Review Connected Apps. Anything connected is sending and receiving under its own policy, and Google states it does not secure custom connectors run by other companies.
  4. Delete what is already there. Bear in mind the one category deletion does not reach, which is the whole point of this page.
SettingWhat it does
Keep Activity onChats saved and used to improve Google’s models, including training
Keep Activity offChats kept 72 hours; future chats not used to improve models unless you send feedback
Auto delete after 3 monthsSaved activity erased after 3 months, a sensible period for a firm
Auto delete after 18 monthsSaved activity erased after 18 months, the default most people keep
Auto delete after 36 monthsSaved activity erased after 36 months
No automatic deletionSaved activity stays until you delete it by hand
Any of the aboveChats a human reviewer read stay up to 3 years, whatever you delete

Google, Gemini Apps Privacy Hub, last updated August 10, 2026.

Then tell people what the feedback buttons send. It is the only control on this list that lives in a person’s habits rather than in a settings screen, which is why the rollout usually needs whoever runs your Google Workspace, not just an email.

What a tool can do here, and what no tool can do, including ours

Software of this kind can mask identifiers before text is sent, because identifiers sit in predictable places and some carry check digits a machine can verify arithmetically. It can show what it changed so a person can overrule it, and it can leave a record that the control was on.

It cannot decide that a document is too sensitive to send. It cannot see that a paragraph identifies a client through facts rather than names. And it cannot make you compliant, because compliance is not a property that software has.

What our engine does and does not do in the United States

An SSN, an EIN or a Medicare beneficiary identifier gets masked before sending when a label the engine knows is next to it, and what takes its place is a general REFERENCE tag, with the digits gone. An email address is replaced without asking, because its format leaves no doubt, and so is a card number with a valid check digit. You watch it happen and can undo it.

Nonimo runs on the computer itself, on Mac and Windows, and IT sets the policy step for the whole firm rather than for each user. What it replaces, it replaces reversibly, keeping the mapping encrypted on the user’s own computer. That is pseudonymization rather than anonymization, and it is how our pages for organizations describe it too.

The app’s encrypted store on your disk is described on Nonimo’s security page.

If you buy nothing at all, do these five things

  1. Change the automatic deletion period from eighteen months to three. One minute, no budget, and it is the largest single reduction available to you.
  2. Quote Google’s own sentence in your policy. The vendor asking you not to enter confidential information is more persuasive than anything you will write.
  3. Get onto a work account if you are on Workspace already. The training answer reverses and your admin gets retention controls.
  4. Tell people what the thumbs up and thumbs down buttons send. No setting covers it and it carries a whole day of chats.
  5. Audit Connected Apps once a quarter. Google says it does not secure the custom ones, so nobody else is checking.

A firm that does all five is in better shape than one that bought software and did none of them. If a technical control later looks worth it, our license terms say what ours is and is not.

Two things you will read elsewhere that are wrong today

We checked both claims below against the current documents on September 19, 2026.

The first is that turning off Gemini activity deletes your data. It changes what is saved going forward and it lets you clear what is stored, and it does not touch the category Google itself carves out in the retention section. Pages that present the setting as a delete button are describing three of the four things it does.

The second is that Gemini is used to target ads at you. Google’s hub states the opposite for Gemini Apps chats, in the present tense, with a promise to communicate a change. The confusion comes from Google’s advertising business as a whole, which is real, large, and governed by different settings on a different page.

Both claims can be checked in a minute, which is the useful part. These documents are public, dated, and shorter than most of the articles written about them. This page carries a date for the same reason, and so does each of the guides on the other assistants.

Sources

Checked September 19, 2026. Every link below returned a live page on that date.

The same questions for the other three assistants: does ChatGPT share or sell your data, does Claude train on your data, and does Microsoft Copilot train on your data.

Nonimo is the software that does this on your own computer: it masks client names and IDs before your text reaches ChatGPT . No account, and your client's details never leave your machine.

Common questions

Does deleting my Gemini activity delete everything?

No, and it is the one part of Gemini privacy that no setting reaches. Google states that chats reviewed by human reviewers, and related data such as your language, device type, location and feedback, are not deleted when you delete your activity, and are retained for up to three years.

Does Gemini train on my chats?

On a personal account with Keep Activity on, yes. Google states it uses your activity to provide, develop and improve its services, including training generative AI models. Turning Keep Activity off stops future chats being used that way.

How long does Google keep my Gemini chats?

By default they are deleted automatically after 18 months, and you can change that to 3 months, 36 months or never. With Keep Activity off, chats are kept with your account for 72 hours instead.

Does Gemini use my chats to show me ads?

Google states that Gemini Apps chats are not being used to show you ads, and adds that if this changes it will clearly communicate it. That is a statement about the present, with a notice promise attached.

Can a person at Google read my Gemini chats?

A subset, yes. Google states that human reviewers, including trained reviewers from its service providers, review some of the data it collects, and asks you not to enter confidential information you would not want a reviewer to see.

Does a Google Workspace account change the answer?

Substantially. Google states that prompts are customer data under the Cloud Data Processing Addendum, and that it does not use customer data to train its Workspace generative AI models without the customer's prior permission or instruction.

Is Gemini HIPAA compliant?

Google states that Gemini can support HIPAA workloads and that it has been added to the HIPAA Included Functionality and the Workspace HIPAA implementation guide. Compliance remains the covered entity's obligation, not a property of the product.

What happens if I press thumbs up in Gemini?

More than a rating travels. If Keep Activity is off and you submit feedback, Google collects the feedback, the last 24 hours of your chats as context, and any content in those chats, including uploads and Connected Apps data.

How do I stop Gemini from collecting my data?

Open Gemini Apps Activity, turn Keep Activity off, and delete existing activity. Google notes that even then it retains chats for 72 hours to respond to you and to protect its services, with help from human reviewers.