Gemini logo

Gemini

gemini
High Risk
Updated August 18, 2026

The analyzed documents are Google's general-purpose consumer Privacy Policy and a landing page linking to Terms of Service and AI principles — not Gemini-specific terms. The policy is recent (effective May 26, 2026) and explicitly acknowledges AI/ML processing (training models, Gemini Apps, Cloud AI). It is user-favorable on deletion controls, export tools, and states Google does not sell personal information. However, it describes extensive data collection (identifiers, location, activity, communications, and optionally health/biometric data), broad use for advertising and product/AI development, and government data disclosure. Crucially, the actual Gemini Terms of Service and any Gemini-specific privacy notice were not retrieved, so key questions on input/output ownership, training use of prompts, and human review of Gemini conversations cannot be answered from the supplied text. Users should review Gemini-specific terms before using with sensitive or proprietary data.

AI Transparency Facts

Independent analysis by TermsWatchdog · © 2026 TermsWatchdog

Input Data Ownership

Moderate Risk

The general Privacy Policy states Google collects content users create, upload, or receive, but does not address ownership or licensing of user inputs — that would be governed by the Terms of Service, which was not retrievable. Silence on ownership within the supplied documents is a gap.

Confidence
30%

Output Data Ownership

Moderate Risk

The supplied documents (a privacy policy and a links page) contain no statement about ownership of AI-generated outputs. Output ownership is a Terms-of-Service matter, and the Gemini/Google Terms of Service was not among the retrievable text.

Confidence
20%

Training Data Usage

Moderate Risk

The policy states Google uses publicly available information to train its AI models, including for Gemini Apps and Cloud AI. It does not, in the supplied text, clearly state whether a user's own Gemini prompts and uploads are used for model training — that carve-out would live in the Gemini Apps privacy notice, which was not retrieved. The training language present focuses on publicly available and research-and-development data.

Confidence
45%

Data Retention & Deletion

Low Risk

The policy provides clear user deletion and export controls, including per-item, per-product, and full-account deletion, plus auto-delete options for activity. Retention is described as variable by data type with some data kept for legitimate business or legal purposes; no specific numeric retention schedule or deletion SLA is given in this text, but self-service deletion tools are clearly documented.

Confidence
70%

Third-Party Data Sharing

Moderate Risk

The policy states Google does not sell personal information and does not 'share' it as defined by the CCPA, and shares personal information outside Google only with consent, with domain administrators, service providers, or for legal reasons. However, it also shares non-personally identifiable information with advertising and measurement partners and allows specific partners to collect information from the browser/device for advertising. The advertising-oriented sharing broadens the footprint beyond what a standalone AI assistant strictly requires.

Confidence
65%

Opt-Out Rights

Low Risk

The policy provides multiple concrete opt-out and control mechanisms: Activity Controls, ad personalization settings via My Ad Center, signed-out search customization opt-out, and cookie/device-level settings. U.S. state privacy law rights including opt-out of profiling and targeted advertising are described.

Confidence
70%

Compliance & Certifications

Moderate Risk

The policy references compliance with U.S. state privacy laws (CCPA and others), the Washington My Health My Data Act, Nevada SB 370, and 'certain legal frameworks' for data transfers, but names no third-party audit or certification (no SOC 2, ISO 27001/42001, or EU AI Act attestation in the supplied text). Compliance is asserted rather than evidenced by named certifications. GDPR is implied through EU affiliate references but not explicitly claimed in this excerpt.

Confidence
55%

Model Explainability & Auditability

High Risk

The supplied documents contain no commitments regarding model explainability, transparency into AI behavior, or enterprise auditing of the AI. Links to AI principles and a Responsible AI report are referenced but no auditability terms appear in the retrievable text.

Confidence
30%

Security Practices & Breach History

Moderate Risk

The policy discloses encryption in transit, access restrictions with confidentiality obligations, security review of collection/storage/processing practices, and account-level features like 2-Step Verification. It does not mention encryption at rest, penetration testing, bug bounty, formal incident response, or any breach history in the supplied text, and no dedicated trust center/security report is cited beyond general safety pages.

Confidence
55%

Enterprise vs. Consumer Risk Delta

Moderate Risk

The consumer policy references that Workspace/Cloud Platform users are governed by a separate Google Cloud Privacy Notice and that domain administrators control organizational accounts, implying a different regime for enterprise. However, no enterprise agreement was supplied, so the actual data-handling delta cannot be assessed from the retrievable text.

Confidence
40%

Human Review of User Inputs

Moderate Risk

The general policy discloses that service providers review YouTube content and listen to samples of saved user audio to improve recognition technologies, and that access is restricted to staff who need it. It does not specifically address human review of Gemini prompts and responses — that would be in the Gemini Apps privacy notice, which was not retrieved.

Confidence
45%

Regulatory & Litigation Exposure

Moderate Risk

The policy openly discloses that Google receives and responds to government and law enforcement requests for user data, states it reviews and pushes back on overly broad requests, and publishes a Transparency Report. This transparency is favorable, but the routine disclosure of user data to governments is an inherent exposure users should note.

Confidence
65%

PII & SPI Data Inventory

High Risk

The policy documents collection of a very broad range of PII (name, phone, address, IP, device identifiers, precise geolocation, activity, communications) and explicitly enumerates SPI categories including biometric information, health information, and demographic data such as race/ethnicity. While disclosure is detailed and much SPI is optional/consent-based, the breadth of sensitive data collected across the Google ecosystem is extensive.

Confidence
70%

Policy–Product Currency

Moderate Risk

The Privacy Policy is dated effective May 26, 2026 — well within 12 months of the analysis date — and it explicitly addresses AI/ML processing, model training, and Gemini Apps. However, no PRODUCT SURFACE was supplied to confirm coverage of Gemini's current capabilities, so under the INSUFFICIENT EVIDENCE RULE the rating is capped at YELLOW despite the strong recency.

Confidence
50%

Cross-Document Consistency

Moderate Risk

Two documents were supplied, but Document 1 is essentially a landing page of links (not substantive policy text) and Document 2 is the full Privacy Policy; the actual Terms of Service, Gemini Apps privacy notice, and any DPA were not retrievable. With only one substantive policy document to compare, a meaningful cross-document check is not possible and no contradictions were identified in the available text.

Confidence
25%

You've read all 15 risk ratings for Gemini. Create a free account to see the exact policy wording behind each rating.