Is Gemini private? It depends on your account type. For in-house counsel, that answer decides where confidential work can live. At GC AI, the enterprise legal AI platform a three-time general counsel (Anki, Bloomtech, and Replit) built for in-house teams, we get this question from legal teams weighing Google's AI against their confidentiality obligations.
On CZ and Friends, GC AI's podcast hosted by CEO Cecilia Ziniti, Molly Abraham, VP of Legal at Coinbase, told the story of a vendor notice that rearranged her week: terms that read as if customer data, confidential included, could also train the vendor's LLM. Customers erupted and the vendor walked the language back.
Abraham's team went past the outrage. They pulled every agreement that touched Coinbase data and checked each one for AI training language.
Her reasoning applies to any vendor, Google included:
"If something else ingests your confidential information and can spit it out, even in a transformed state, that's still your confidential information."
Abraham runs Google's AI at work ("We use Gemini, I have my own ChatGPT subscription," she told Ziniti), which makes her audit standard the right test for any in-house lawyer weighing what Gemini does with confidential information. Your account type sets the answer.
Consumer accounts, including the $199.99-a-month kind, run under terms that would fail her audit. Google Workspace and Vertex AI accounts run under contractual terms written to pass it.
Every claim below comes from Google's own documentation, worth reading the way Abraham read her vendor agreements.
The Short Answer: Is Gemini Private?
On a consumer account, no. Google saves your Gemini chats by default, samples a subset for human review, and uses your activity to train its generative AI models. Chats a human reviewer has read stay on Google's systems for up to three years, and deleting your activity leaves those copies in place.
On a Google Workspace or Vertex AI account, the terms change: your prompts stay inside your company's domain, and Google does not use them to train models outside your domain without permission.
Google says as much itself, in the Gemini Apps Privacy Hub:
"Please don't enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services."
That sentence settles the consumer-account question for anyone whose job includes the word "confidential." It leaves open what the rest of the company will ask you next: which plans carry which terms, what happens to a deleted chat, and where privileged work can live.
What Gemini Collects, Stores, and Shares
Gemini's consumer data handling runs through a setting Google now calls Keep Activity (formerly Gemini Apps Activity), and the defaults favor Google's model development over your confidentiality. Here is what the Gemini Apps Privacy Hub discloses, as of October 2026:
Chats save by default: Gemini stores your conversations and whatever you share with them, files, photos, screens, and Gemini Live recordings included. Auto-delete defaults to 18 months, adjustable to 3 months, 36 months, or never.
Humans read a sample: Google states that a subset of chats is "reviewed by human reviewers (including Google's trained service providers)."
Reviewed chats survive deletion: Conversations pulled for human review are retained for up to three years, disconnected from your account. Deleting your activity removes your copy and leaves theirs.
Turning activity off still leaves a 72-hour window: With Keep Activity off, or inside a Temporary Chat, conversations sit on Google's servers for up to 72 hours.
Your uploads are in scope: Google's August 2025 privacy update extended sampling to uploaded files for accounts with the setting on, effective September 2, 2025.
Past chats feed new answers: Personalization (Google's Personal Context setting) is on by default, and Gemini can reference your prior conversations to shape new responses.
Training is explicit: Google's terms say it uses your activity to provide, develop, and improve its services, including training generative AI models.
Google discloses each point plainly, which is a credit to Google. It also means "we didn't know" stops working as a defense the day someone on your team reads the terms.
Privacy by Plan: Free, AI Plus, AI Pro, AI Ultra, Workspace, and Vertex AI
Every consumer Gemini plan shares one privacy posture, and the business accounts share another.
Price changes the model quality and usage limits. Account type changes the data terms.
Plan | Price (as of August 2026) | Data terms | Trains on your prompts? | Built for |
Gemini (free) | $0 | Consumer (Gemini Apps Privacy Hub) | Yes, with activity on | Personal use |
Google AI Plus | $4.99/month | Consumer | Yes, with activity on | Personal use, more capacity |
Google AI Pro | $19.99/month | Consumer | Yes, with activity on | Personal use, top models |
Google AI Ultra | $99.99 to $199.99/month | Consumer | Yes, with activity on | Power users and creators |
Gemini in Google Workspace | Bundled with Workspace business plans | No training outside your domain without permission | Company-wide productivity | |
Vertex AI / Gemini API | Usage-based | No | Developers building AI applications | |
GC AI | $500/month, 14-day trial | SOC 2 Type II, SOC 3, GDPR, ZDR across the AI stack, AES-256 | No | In-house legal work: Exact Quote citations, contract Playbooks, and 14 hours back per lawyer per week (December 2025 ROI study) |
Source: Google AI subscription plans and the Gemini Apps Privacy Hub, August 2026.
The $199.99 Ultra tier and the free account hold the same confidentiality terms. On Gemini, privacy is set by the account type, and no price changes it.
The GC AI row prices differently because it sells a different layer: legal work product, cited and confidential, on top of the models.
Cameron Clark, Head of Legal at Arc'teryx, answered the price question in four words:
"Pays for itself in weeks."
The Workspace terms are genuinely stronger. Google treats Workspace prompts as customer data under the Cloud Data Processing Addendum and states that your data "is not reviewed by humans or used for generative AI model training outside your domain without permission," per its Workspace AI privacy documentation. Admins control retention through Google Vault, Workspace's retention and eDiscovery layer, and data loss prevention (DLP) rules can wall Gemini off from sensitive labels. That configuration is what makes Gemini usable for lawyers at all.
Is Gemini Safe for Confidential Information at Work?
The security risks of using consumer AI for confidential legal work come down to disclosure (human reviewers can read sampled chats), retention (copies outlive your delete button), and account confusion (the same product runs under different terms depending on who is signed in).
Gemini is safe for confidential information only on a Workspace or Vertex AI account your company controls, and even there the safety comes from configuration, contract terms, and discipline about which account holds the session. Three failure modes matter most for legal work.
The Account-Switch Trap
Lawyers use Gemini for real work. On another CZ and Friends episode, Verkada General Counsel Bill Berry described drafting a secondary-transaction policy, a document with no public template anywhere, from a handful of prompts in Gemini. He called what came back amazing.
A document like that is internal by nature: it describes how a private company moves its own equity.
Run that session on the company Workspace account and the draft stays inside the domain boundary. Run it in a personal Chrome profile, the kind that auto-opens on a home laptop, and the session runs on consumer terms: saved by default, sampled for review, eligible for training.
The most expensive privacy setting in Gemini is the account picker.
Human Review Is Disclosure
Model Rule 1.6 requires reasonable efforts to prevent unauthorized disclosure of information relating to a client. A consumer workflow that ships a sample of chats to human reviewers, including third-party service providers, hands client information to people outside any engagement the moment a reviewer opens the transcript.
Abraham's line applies verbatim: transformed, summarized, or embedded in a model, it is still your confidential information.
Retention Outlives Your Control
The 72-hour floor and the three-year tail both sit on Google's infrastructure, and legal process aimed at Google can reach them there.
Some company is going to face this in discovery: a litigation hold it cannot execute, on documents it cannot enumerate, held by a party it does not control. The time to care is before your chats are part of the record.
What You Should Never Paste Into Gemini
On a consumer Gemini account, keep out anything you would be unhappy to see in a reviewer's queue or a training corpus:
Privileged material: Litigation strategy, memos to or from counsel, board briefings prepared at legal's direction.
Unannounced deal information: Counterparty names, purchase prices, term sheets, anything that moves a stock or breaks an exclusivity clause.
Employee data: Compensation, performance issues, health accommodations, immigration status.
Regulated customer data: Anything touched by HIPAA, GLBA, CCPA, or GDPR, and anything your data protection clauses promise to handle under contract.
Material your own confidentiality clauses cover: If your company signed an NDA over it, pasting it into a consumer chatbot is your side of the breach.
The same account handles public work without drama: summarizing a published regulation, brainstorming against a public template, drafting from facts already in a press release. Teach your team one question before the paste: would I email this to a stranger who might keep it for three years?
How to Make Gemini More Private
If your company keeps Gemini in the stack, five settings shrink the exposure, in the order a legal team should check them:
Check the account before the chat: confirm the session runs under your company's Workspace domain, and treat a personal profile as a different product with different terms.
Turn off Keep Activity: retention drops from the 18-month default to 72 hours, and new chats stay out of the human-review sample.
Use Temporary Chats for one-off questions: they skip the activity log, personalization, and model training.
Turn off past-chat personalization: Gemini stops referencing your prior conversations to shape new answers.
Have your admin set the controls that matter most: on Workspace, retention runs through Google Vault, and DLP rules can keep labeled documents away from Gemini entirely.
The settings help: real limits on a consumer account, configuration control on a business one.
None of it changes what Gemini is: a general-purpose AI wired into a productivity suite. A legal team's confidential-work standard asks more than a settings page can give.
Privilege, ABA Opinion 512, and the Heppner Problem
Privilege is where consumer AI use stops being a policy question and becomes a courtroom one. In United States v. Heppner (S.D.N.Y., February 17, 2026), Judge Jed Rakoff ordered a criminal defendant to produce his AI chat transcripts.
Heppner had used a public AI platform to draft reports on his own defense strategy after indictment, and the court held the exchanges carried no attorney-client privilege and no work product protection: an AI platform is no one's attorney, the platform's terms allowed training and disclosure (so confidentiality was never reasonably expected), and no lawyer had directed the work.
Coverage from the Harvard Law Review blog to state bar associations treated it as a first-of-its-kind ruling on AI privilege.
The case named a different AI platform, and the reasoning transfers to any consumer account whose terms allow training and human review. Consumer Gemini's terms, quoted above, meet that description on their face.
Ziniti knows this doctrine firsthand. She told Abraham on the episode that she has personally litigated privilege over Slack messages, at a company she says helped make law in the area, and her takeaway is operational: privilege follows the terms and the direction of counsel, wherever the conversation happens.
Heppner left the same analysis open. Work directed by counsel, on a platform with contractual confidentiality, may keep protection, the way privilege extends to accountants and translators a lawyer engages.
Platform choice keeps that argument available.
ABA Formal Opinion 512 (July 29, 2024) frames the rest: competence, confidentiality, and communication duties apply in full when lawyers use generative AI.
Those duties belong to the lawyer, and no platform can discharge them for you. The platform's job is to keep its own terms from working against you while you meet them.
Abraham put the employee-behavior half of the risk in one line:
"A non-lawyer asking an LLM for legal advice is not necessarily their lawyer."
Her framework for the job is worth stealing whole.
She describes three hats for legal leaders on AI: the enabler who unblocks sanctioned AI use before employees route around legal, the protector who audits where company data flows, and the super user who runs the work through AI personally. All three hats point to the same move: give the company a governed place to do AI work, because the ungoverned place is one browser tab away.
What In-House Counsel Need From a Private Legal AI Platform
Legal AI platforms built for in-house teams answer the data privacy question with terms you can verify: security certifications an auditor can check, zero data retention agreements with the model providers, and no training on customer data. That is the bar to hold any vendor to on security and data retention, and it is the one GC AI, the enterprise legal AI platform built for in-house counsel, publishes in full.
GC AI is SOC 2 Type II and SOC 3 certified, GDPR compliant, with zero data retention agreements with OpenAI, Anthropic, and Google, and AES-256 encryption, documented on its live subprocessor list.
Google itself is on that list. When GC AI routes work through Google's models, Gemini's maker keeps nothing after processing.
For diligence past the marketing layer, GC AI's Trust Center carries the downloadable SOC 2 Type II and SOC 3 reports, the DPA, and the subprocessor list, and gc.ai/security documents the controls a security team asks about next: organization-level choice of which model providers are enabled, with audit logging of who changed a model setting and when.
A private platform still has to be good at the work. In the In-House Legal Bench (May 2026), GC AI's R&D team scored four AI platforms against 100 real in-house legal tasks, graded against more than 1,200 attorney-developed criteria:
GC AI: 86.8%
ChatGPT (GPT-5.5): 79.8%
Claude (Opus 4.7): 68.4%
Gemini (3.1 Pro): 57.5%
GC AI led all ten task categories, with the widest margins in regulatory tracking and legal research. Those numbers explain a habit Abraham confessed on the podcast: she runs the same research through multiple AI platforms at once, "because it is a helpful cold dose of reality sometimes to see the differences that come back, because the answers are so polished and thorough that it lends itself to credibility. And then you realize, wait a second, I did not get the same answer."
That cross-checking is time general-purpose AI makes you spend. Exact Quote gives you character-level citations from your source documents, so checking an answer means clicking it.
Files holds up to 1,500 pages of contracts and policies in permanent collections inside the certified boundary.
And the audit Abraham ran, pulling every agreement that touches company data to check for AI training language, is now a question you can type. Contract Intelligence, GC AI's portfolio-scale contract analysis product, connects your agreements from Google Drive, SharePoint, or direct upload into a Vault, extracts the terms you describe in plain language into a View with every value cited back to its source clause, and answers portfolio-wide questions like "which of our vendor agreements permit AI training on our data" in minutes.
Joys Choi, Senior Director of Legal at Tipalti, summed up the standard:
"Out of all the AI tools I've used, GC AI delivers the most impact for attorneys: confidential, reliable, and efficient."
As of October 2026, 2,200+ legal teams use GC AI, including the legal departments at Hitachi, TIME, Liquid Death, Snyk, and Columbia Sportswear, plus 300+ public companies.
Gemini vs GC AI: Privacy at a Glance
Privacy question | Gemini (consumer) | Gemini (Workspace) | GC AI |
Primary customer | Consumers | Companies on Google Workspace | In-house legal teams |
Trains on your prompts? | Yes, with activity on | No training outside your domain without permission | No |
Human review of chats | A sampled subset | No review outside your domain | No |
What survives deletion | Human-reviewed chats, up to 3 years | Retention set by your admin | Nothing at the model layer: zero data retention agreements with its AI providers, backed by SOC 2 Type II and SOC 3 certification |
Source: Gemini Apps Privacy Hub, Google Workspace AI privacy documentation, and gc.ai/subprocessors, August 2026.
The same account-level audit applies to ChatGPT and Claude, and the same data security standards govern every vendor on your list, Google included.
Start With One Privacy-Sensitive Workflow
Pick the one document you would never paste into a consumer chatbot, a vendor DPA review works well, and run it through GC AI during a trial. In GC AI's December 2025 ROI study of more than 100 active customers, 97.5% of teams saw value before month one, which means the trial window is longer than the proof window.
If your team wants the grounding first, our free CLE-eligible legal AI classes teach the prompting and governance habits this article assumes.
You read your vendor agreements the way Molly Abraham reads hers. Read your AI platform's terms the same way, and put the confidential work where the terms deserve it.
Frequently Asked Questions
Is Google Gemini Confidential?
No on consumer accounts, from the free tier through AI Ultra. Google saves Gemini chats by default, samples a subset for human review, and uses activity to train its generative AI models, and its own privacy hub warns users against entering confidential information. Google Workspace and Vertex AI accounts carry contractual confidentiality: prompts stay inside your company's domain and train nothing outside it without permission.
Can Human Reviewers Read My Gemini Chats?
Yes, on consumer accounts. Google states that a subset of chats is reviewed by human reviewers, including Google's trained service providers. Workspace accounts carry a different commitment: no human review outside your domain without permission.
Does Deleting a Gemini Chat Remove It From Google's Servers?
Deleting a chat removes it from your saved activity, and copies can outlive the deletion. Chats sampled for human review stay on Google's systems for up to three years. Treat deletion as cleanup of your view, and treat the paste itself as the decision point.
Is Gemini Temporary Chat Private Enough for Legal Work?
Temporary Chat is private enough for low-stakes questions only. It skips your activity log, personalization, and model training, and it expires after 72 hours, but during that window the conversation still sits on Google's servers under consumer terms. Privileged or confidential legal work belongs on a platform with contractual confidentiality, like a company Workspace account or a dedicated legal AI platform.
Does Gemini for Google Workspace Train on Your Company's Data?
No. Google treats Workspace prompts as customer data under the Cloud Data Processing Addendum and states they are not reviewed by humans or used to train generative AI models outside your domain without permission. Confirm your admin has set Google Vault retention and DLP rules to match your legal team's obligations.
Does Gemini Access the Content of Your Gmail and Google Docs?
Yes. Inside Google Workspace, Gemini can work with Gmail and Docs content under the same permission boundaries that control who can view those files, and the Cloud Data Processing Addendum treats that content as customer data that stays in your domain. Domain-level data protection is a separate question from attorney-client privilege, which depends on how and at whose direction the work happens.
Is Gemini More Private Than ChatGPT for Legal Work?
Consumer Gemini and consumer ChatGPT sit in the same category for legal work: both save chats by default and use consumer activity to improve their models, so the safer comparison is consumer versus business terms on either platform. GC AI's Is ChatGPT Private guide runs the same audit on OpenAI.
Are There Legal AI Tools for In-House Teams That Prioritize Data Privacy?
Yes. Look for a legal AI platform with contractual confidentiality: SOC 2 Type II and SOC 3 certification, GDPR compliance, and zero data retention agreements with its model providers. GC AI, purpose-built for in-house counsel, meets that bar with OpenAI, Anthropic, and Google among its zero-retention providers. In the In-House Legal Bench (May 2026), GC AI passed 86.8% of 100 in-house legal tasks against Gemini's 57.5%, and a 14-day trial requires no credit card.







