Is Gemini Private? What It Means for Confidential and Legal Work

It depends on which Gemini you mean. Consumer Gemini on a personal Google account is the wrong place for client-confidential work. Google states it uses that activity to improve its services, including training generative AI models, and a subset of chats are seen by human reviewers. Gemini for Google Workspace and Vertex AI are a different posture: Google states enterprise content is not used to train its models without permission, and it falls under a data processing agreement. The burden is on your firm to confirm which product, and which terms, you are actually on. This is general information, not legal advice. Policy facts here were checked against Google's own notices, last updated June 29, 2026; confirm the current terms before you rely on them.

Short answer: Is Gemini private? It depends on the version. Consumer Gemini on a personal account is used to improve Google services, trains generative AI models, and a subset of chats get human review. Gemini for Workspace and Vertex AI default to no training under a data processing agreement. Retention runs long: even with activity off, chats sit about 72 hours.

TL;DR

  • Consumer Gemini is wrong for client data. On a personal account, activity is used to improve Google services and to train generative AI models, and a subset of chats get human review (Google, updated June 29, 2026).
  • Turning activity off does not erase everything. Conversations are still kept about 72 hours, and chats already pulled for human review are retained up to 3 years, disconnected from your account.
  • Default retention is long. Keep Activity (formerly Gemini Apps Activity) holds chats for 18 months by default, adjustable to 3 or 36 months, or indefinite.
  • Temporary Chat is not a no-train contract. Google states Temporary Chats are not used to train its models, but they still sit on your account about 72 hours and give you no signed commitment.
  • The developer API splits by tier. Google states the free Google AI Studio tier uses your content to improve its products including machine learning; the paid Gemini API does not train on your prompts or responses.
  • Workspace and Vertex are a different product. Google states enterprise content is not used to train models outside your domain without permission, stays in your organization, and sits under the Cloud Data Processing Addendum.
  • A toggle is not a contract. A consumer setting can change. A signed DPA with data-region controls is what client-confidential work needs.
  • ABA 512 makes verification your job. You must understand the tool's data handling and, in general, get informed client consent before entering confidences.
Quick check

On consumer Gemini, once a chat has been pulled for human review, how long can Google retain a copy?

Gemini Apps Activity setting

Which Gemini are you on, and why the difference is the whole answer

People say "Gemini" as if it is one thing. For confidentiality it splits at least four ways, and they carry different promises.

  • Consumer Gemini. The app you reach with a personal Google account. Governed by the Gemini Apps privacy notice.
  • Gemini for Google Workspace. Gemini inside a paid Workspace tenant your admin controls. Governed by Workspace terms.
  • Vertex AI. Google Cloud's enterprise platform for building on Gemini models, governed by Google Cloud terms.
  • Gemini developer API. For teams building their own tools on Gemini models. Splits into a free Google AI Studio tier and a paid API tier, which carry different training postures.

A lawyer who opens gemini.google.com with a Gmail login is on the first one. That matters, because the privacy posture flips between them.

Consumer Gemini vs Workspace and Vertex

This table is the short version. Always confirm the current terms yourself, since vendor policies move.

QuestionConsumer Gemini (personal account)Workspace / Vertex AI (enterprise)
Used to train Google models by defaultYes, activity is used to improve services including training generative AI modelsNo, not used to train models outside your domain without permission
Human review of your chatsYes, a subset is reviewed by peopleNo, not human reviewed for training without permission
Retention18 months by default (3 or 36 optional); 72 hours even with activity offStored in your tenant under your controls and retention policy
Admin controls and DPANo, consumer terms onlyYes, Cloud Data Processing Addendum, data-region policies, DLP
Fit for privileged workNoCloser, with the agreement and controls in place

Two traps to name. First, a personal Google account is the path of least resistance, and it is the consumer tier. Second, turning off activity is a setting, not a signed no-train commitment, which is a weaker thing to point to if anyone asks how the data was handled.

Here is the same logic as a decision path.

Loading diagram...

What Google actually says about consumer Gemini

This is the part that should stop a lawyer cold. Google's own Gemini Apps notice tells users plainly: "Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services." That is Google describing its own product as unfit for secrets.

Three facts drive it, all from Google's Gemini Apps notice (updated June 29, 2026):

  • Activity is used to improve services, including training generative AI models. When Keep Activity is on, your chats feed that process.
  • A subset of chats are reviewed by human reviewers, including trained service providers, to help improve Google services.
  • Copies persist even after you delete. Chats already selected for human review are kept up to 3 years, disconnected from your account, and are not removed when you delete your activity.

Default retention runs 18 months, adjustable to 3 or 36 months, or indefinite. Even with Keep Activity turned off, conversations are kept about 72 hours. So the "off" switch narrows exposure. It does not give you a clean confidentiality guarantee.

What Google says about Workspace and Vertex

The enterprise side reads differently because it is a different contract. In its October 2024 privacy whitepaper, Google Cloud states the core commitment directly: "Your data does not train our models." It adds that it does not use data you provide to train its own models without your permission, and that output generated from your data is treated as Customer Data under the Cloud Data Processing Addendum. Its Gemini for Google Cloud data governance page repeats the point in plain terms: "Gemini doesn't use your prompts or its responses as data to train its models."

Gemini for Workspace data governance

For Gemini for Google Workspace, Google states that your prompts and generated content stay within your organization and are not shared with or used by other customers. It also states this content is not used to train models outside your domain without permission, and that your existing Workspace controls, including data-region policies and Data Loss Prevention, apply.

Gemini in Google Docs

There is one more path, for teams that build their own tools: the Gemini developer API. Google states the paid Gemini API does not use your prompts or responses to train its models, while the free Google AI Studio tier does use submitted content to improve its products, including for machine learning. Eligible enterprise customers can also ask about a contractual zero-data-retention option under Google Cloud terms. If your team ships on the API, the tier you are billed on, and the retention option you negotiate, set the privacy posture.

The shape is what you want for client data: a no-train default, a written data agreement, controls your admin owns, and stated control over where data is stored. The catch is conditional. These protections attach to the paid enterprise products under their terms, not to a Gmail login. Read your own contract and confirm the data-region and retention settings your admin has chosen.

Safe and unsafe lawyer uses, tied to confidentiality

The duty of confidentiality under Model Rule 1.6 does not pause for a new tool. ABA Formal Opinion 512 applies it to generative AI directly. You must understand how the tool handles your input, and you should generally get the client's informed consent before entering confidences into a tool that could expose them. Boilerplate consent in an engagement letter is not enough. There is a second exposure beyond the ethics rule: privilege protects communications a client keeps confidential, so routing privileged material through a tool that samples chats for outside review is the kind of disclosure that can put that protection at risk.

Map that to consumer Gemini, where a reviewer may read your chat and copies can persist:

Reasonable on consumer Gemini (no client confidences):

  • Drafting a plain-English explainer of a public legal concept.
  • Rewriting or shortening text that contains no client or matter detail.
  • Brainstorming a deposition outline using hypothetical, anonymized facts.
  • Summarizing a published statute or a public court opinion.

Not safe on consumer Gemini:

  • Pasting a client contract, term sheet, or settlement figure.
  • Entering names, parties, or any detail that identifies a matter.
  • Uploading privileged communications or work product.
  • Running anything you would not want a Google reviewer to read.

The dividing line is simple. If a reviewer reading it would breach a confidence, it does not belong in consumer Gemini. On Workspace or Vertex with a DPA in place, the calculus changes, but you still verify the terms and match the tool to the sensitivity of the matter.

The verdict

Consumer Gemini on a personal account is not private enough for client-confidential work, and Google's own warning says as much. Activity trains its models. Human reviewers see a sample, and copies can outlive your delete button by years. Temporary Chat helps for casual questions, but it is a mode, not a contract. Gemini for Workspace and Vertex AI are built on different terms. They default to no training on your content, they sit under a written data processing agreement, and your own admins hold the controls. That is a real difference, but it is conditional. The protection lives in the contract and the admin settings, not in the word "Gemini." Confirm which product you are on and read the current terms. Where client confidences are involved, handle consent under ABA 512.

The same plan-versus-terms split shows up with other tools. See our guides on whether ChatGPT is confidential for legal work and Claude for legal work. For task selection, ChatGPT for lawyers and our best legal AI tools for in-house counsel cover where general chatbots fit. The full duty set is in our ABA Formal Opinion 512 guide.

Vaquill AI is a legal AI suite for in-house counsel built on the assumption that your matter data is privileged, with a no-train stance and source-linked answers over real US statutes and opinions. A legal tool is not magic. What changes is that the confidentiality terms are written for client data instead of a general consumer audience, which is the gap consumer Gemini leaves open.

Sources: Google Gemini Apps privacy notice, Gemini for Google Workspace privacy hub, How Gemini for Google Cloud uses your data, Generative AI, Privacy, and Google Cloud (Google Cloud whitepaper, October 2024), Vertex AI data governance. Google Gemini API Additional Terms of Service (Google, checked June 2026). ABA Formal Opinion 512 (American Bar Association, July 2024).

FAQ

Is Google Gemini private for legal work? Not on a personal account. Consumer Gemini activity is used to improve Google services including training generative AI models, and a subset of chats are seen by human reviewers. Gemini for Workspace and Vertex AI are a different posture with a no-train default and a data agreement.

Does consumer Gemini train on what I type? Yes, when Keep Activity is on. Google states it uses that activity to provide, develop, and improve its services, including training generative AI models. Confirm the current notice, since these terms change.

Do humans read my Gemini chats? On consumer Gemini, a subset of chats are reviewed by human reviewers, including trained service providers, to help improve Google services. Google advises you not to enter confidential information you would not want a reviewer to see.

Does using Gemini waive attorney-client privilege? Pasting privileged material into consumer Gemini, where a human reviewer may see it, can undercut the confidentiality that privilege depends on. Privilege protects communications the client keeps confidential, and routing them through a tool that samples chats for outside review is the kind of disclosure that can put it at risk. Enterprise Gemini under a DPA sits differently, but the safe rule is to keep privileged content out of any tool whose terms you have not confirmed. This is general information, not legal advice.

If I turn off Keep Activity, is my data deleted? Not fully. Conversations are still kept about 72 hours, and chats already selected for human review are retained up to 3 years, disconnected from your account, and are not removed when you delete activity.

Is Temporary Chat private? Google states Temporary Chats are not used to train its models, which helps for casual questions. It is still not a confidentiality guarantee: the chat sits on your account about 72 hours, and Temporary Chat gives you no signed no-train commitment for client data.

How long does Gemini keep my conversations? By default Keep Activity holds chats for 18 months, and you can set it to 3 or 36 months, or indefinite. Even with activity off, Google states conversations are kept for about 72 hours.

Does the free Gemini API or Google AI Studio train on my data? Google states the free Google AI Studio tier uses submitted content to improve its products, including for machine learning, while the paid Gemini API does not use your prompts or responses to train its models. If your team builds on the API, the billing tier decides the training posture. Confirm the current API terms before you rely on this.

Is Gemini for Google Workspace safe for client data? It is built on different terms. Google states Workspace content stays within your organization, is not used to train models outside your domain without permission, and falls under the Cloud Data Processing Addendum. You still need to confirm your admin's data-region and retention settings.

Can I use Gemini and stay compliant with ABA 512? With care. You must understand how the tool handles your data, match it to the sensitivity of the matter, and generally get the client's informed consent before entering confidences. Boilerplate consent in an engagement letter is not enough.

Last updated: July 2026.

Legal AI that reads your documents and knows the law.
Ask a legal question, review a contract, or search thousands of your files. Every answer shows where it came from. 7-day free trial, no card.
Updated July 3, 202615 min read

New legal AI guides, weekly.

Arshita Anand

Arshita Anand

Co-Founder & CEO · Attorney

Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.