Gemini for Workspace — privacy & data policy

Provider: Google. PromptPrivacy score: 98/100. Last verified August 26, 2026.

What happens to your data?

Your prompts, Workspace content, and AI responses remain strictly within your organization's secure boundary and are governed by Google's Cloud Data Processing Addendum. Google does not share your data with other customers, human reviewers, or third parties, nor does it train foundational AI models on your inputs. Administrators maintain complete control over data retention, feature access, and data export.

Does it train on your data?

Google Workspace does not use customer prompts, Workspace content, webpage context, uploaded files, or generated responses to train or fine-tune generative AI models without prior customer permission or instruction. Content is not reviewed by humans for model training outside your domain.

Can you opt out?

Yes. Model training on customer data is disabled by default under enterprise terms. Administrators can fully disable the Gemini app or individual side-panel features in Gmail, Docs, Drive, Meet, and Chat, while end users can turn off connected Workspace apps and browser context sharing.

Data retention

Retention is determined by administrators and varies by product: Gemini in Workspace prompt history ranges from 90 days to indefinite (with user deletion enabled by default); the Gemini app retains conversations for up to 36 months (defaulting to 18 months, or 72 hours if history is disabled); and Gemini Notebook prompts and responses are not retained after the session ends. Uploaded files and generated Workspace content follow the Cloud Data Processing Addendum (CDPA) Section 6 deletion terms. In-product feedback data may be kept for up to 18 months.

Encryption & security

Gemini incorporates Google Workspace enterprise-grade security controls, including support for Client-side encryption (CSE) to block AI access to sensitive files. Grounding requests through Google Search are encrypted and processed ephemerally without being logged. The service is certified under SOC 1/2/3, ISO 9001, ISO/IEC 27001, 27701, 27017, 27018, and ISO/IEC 42001, and holds FedRAMP High authorization.

Is it safe for work?

Yes. Gemini for Workspace provides robust enterprise-grade safeguards, is covered under the Cloud Data Processing Addendum (CDPA), adheres to strict data isolation boundaries, and maintains certifications such as ISO 27001, ISO 42001, SOC 1/2/3, FedRAMP High, and HIPAA support.

Source policy: https://support.google.com/a/answer/15706919