Yes, with conditions. On a qualifying Google Workspace business plan, Gemini doesn't use your prompts or files to train models outside your organisation, doesn't send them for human review, and only reaches content the user can already open. The real risks sit elsewhere: staff using personal Gmail accounts, overshared Drive folders, and features with weaker certifications.
"Safe" here means Google's handling of the data. It doesn't change your own duties. A physiotherapy clinic still owes its patients confidentiality, a nursery still has obligations about children's information, and data-protection law such as the GDPR still asks whether processing is necessary and proportionate. Gemini on a business plan can fit inside those duties; it doesn't discharge them for you, and anything borderline is a question for your data-protection adviser.
The most common failure isn't a Google breach. It's a well-meaning person pasting a patient letter into the Gemini app on their phone while signed in to a personal account, where different rules apply. The second most common is Gemini surfacing a file that was shared too widely years ago. Both are fixable in an afternoon.
What Google commits to on Workspace business plans
Google's generative AI privacy hub for Workspace, last updated in August 2026, covers Gemini in Gmail, Docs, Drive, Meet and the other Workspace apps, the Gemini app used with a work account, and Gemini Notebook (formerly NotebookLM). For qualifying editions, it says:
- No training outside your domain. Prompts, Workspace content and responses aren't used to train generative AI models without your permission, a commitment written into Google's Workspace service terms.
- No human review. Your content isn't reviewed by people for model training outside your domain without permission.
- Existing permissions apply. Gemini only retrieves content the user already has access to, and can't reach a file or email the user couldn't open.
- Private between colleagues. Your prompts and Gemini's answers are visible only to you, even in shared files, and Google says session content doesn't leak across user boundaries.
- Your protections carry over. Data loss prevention rules apply to Gemini output inserted into Gmail, Drive and Docs on supported editions, and admins get audit logs of Gemini activity.
Google also lists independent certifications for Gemini, including SOC 1/2/3, ISO/IEC 27001 and ISO/IEC 42001 (the AI management systems standard published in December 2023). Those are useful evidence when a client asks how you handle their data.
Work account or personal account: the difference that decides it
Everything above applies only when someone uses Gemini signed in to a work account on a qualifying Workspace edition. The consumer Gemini app on a personal Google account runs under different rules, and staff often don't notice which account their phone is using.
| Question | Gemini with a Workspace work account | Gemini with a personal account |
|---|---|---|
| Used to train Google's models? | No, without your permission | Can be, when Keep Activity is on |
| Read by human reviewers? | No, without your permission | Some chats may be, when Keep Activity is on |
| How long chats are kept | Set by your admin (see below) | 18 months by default, or 3 or 36 months, or indefinitely; reviewed chats up to 3 years |
| With the history setting off | New chats kept up to 72 hours | Kept 72 hours; not used for training unless you send feedback |
| Google's own advice | Business data is customer data under your agreement | Don't enter confidential information you wouldn't want a reviewer to see |
That last row is Google's wording for consumer users, and it settles the question for client data. Even with Keep Activity off, Google says it still uses consumer chats to respond and to protect its services, including with help from human reviewers. For anything confidential, the only acceptable route is a work account.
How the wrong account showed up in one clinic
Here's how that plays out, as an illustration. A physiotherapist wanted a plain-English version of a consultant's letter for a patient. On the clinic laptop she'd have used her work account, but she was on her phone, where the Gemini app was signed in to her personal Gmail. She pasted the whole letter, patient name and all. Nothing visible went wrong; the summary was good. The problem surfaced a month later when the practice manager ran the checks further down and found three staff members using the Gemini app on personal accounts for work. None of them had been told there was a difference.
The fix had three parts: a one-line rule ("Gemini for work only on your work account"), ten minutes per person checking which account each phone's Gemini app used, and removing the personal account from the app on work phones.
Where confidential data is actually exposed
- Overshared Drive folders. Gemini respects permissions, but permissions are often wider than anyone intends. A folder shared with "anyone in the organisation" years ago was always readable by everyone; Gemini makes it findable with one question.
- Feedback with context attached. When a user rates a Gemini response and leaves the boxes ticked to share the prompt and output, Google receives the prompt, the relevant document or email context and the response. Google says feedback isn't used to train the models behind Workspace's AI services, but it may keep it for up to 18 months. Tell staff to untick those boxes when the content is confidential.
- Features with narrower certifications. Google's own FAQ says Gemini Notebook and Gemini in Chrome don't yet carry the ISO and SOC certifications that Gemini in Workspace apps and the Gemini app do. If a client contract requires certified processing, keep that client's documents out of both. Gemini Notebook for small business teams covers what it's good for otherwise.
- Long retention. Conversation history in Gemini in Workspace can be kept from 90 days to indefinitely, depending on admin settings. Keeping everything forever means every pasted patient detail stays searchable by that user for as long as the account exists.
- Gems shared too widely. A Gem (a saved Gemini assistant with its own instructions and files, becoming a skill from November 2026 as Google replaces Gems with skills) shows its instructions and uploaded files to the people it's shared with. A Gem built on a folder of client contracts and then shared with the whole team hands those contracts to everyone it reaches, so keep client files out of widely shared Gems, and check how sharing works for the skill yours becomes.
- Outputs that leave Workspace. A summary exported to a personal device or emailed to a personal address is outside every Workspace protection, whatever produced it.
Controls an admin can set in an afternoon
- Confirm your edition. The commitments apply to qualifying Workspace editions. Business Starter includes Gemini in Gmail and the Gemini app; Business Standard (about $14 a user a month on an annual plan) and above add Gemini across Docs, Sheets, Drive, Meet and more. What Gemini includes on each Workspace plan has the full list.
- Decide who gets which Gemini features. The Gemini app is on by default and admins can switch it off. On supported editions, admins can also turn Gemini features and the side panel on or off in Gmail, Drive, Docs, Meet and Chat.
- Set conversation retention. For the Gemini app, admins choose automatic deletion after 3, 18 or 36 months (18 is the default), or turn conversation history off so new chats are kept only up to 72 hours. For Gemini in Workspace apps, admins can set retention periods and let users delete conversations.
- Choose what Gemini searches in the background. Admins can stop Gemini actively searching Gmail, Drive, Calendar or Chat for context. Users can still point it at a file they link or have open.
- Lock down the most sensitive files. Google says Information Rights Management restrictions (no download, copy or print) stop Gemini retrieving those files for restricted users, and client-side encryption, on editions that offer it, puts content beyond Gemini's reach entirely.
- Check the audit logs occasionally. Gemini activity appears in Workspace audit logs, which is useful after an incident and as a deterrent.
Drawing the line in a physiotherapy clinic
The clinic in this example has nine staff (five physiotherapists, two receptionists, a practice manager and a sports therapist) on Business Standard. Its clinical notes live in a practice-management system outside Google, and its Drive holds policies, rotas, marketing, supplier invoices and a folder of referral letters. The practice manager worked through three questions:
| Data | Gemini on work accounts? | Why |
|---|---|---|
| Policies, rotas, marketing, supplier emails | Yes | Business-confidential at most; covered by the commitments |
| Patient letters and referral summaries | Yes, minimum necessary | Allowed after checking with the clinic's data-protection adviser; names removed where the task doesn't need them |
| Clinical notes in the practice system | No copying into Gemini | The system is the record; copying creates uncontrolled duplicates |
| Staff HR and payroll files | Restricted with IRM | Only the manager has access; Gemini can't retrieve them for anyone else |
| Anything on personal accounts | Never | Consumer terms, possible human review |
Set-up took about three hours: an hour reviewing Drive sharing (they found the referral-letters folder shared with the whole organisation, including two freelance therapists who didn't need it), an hour on admin settings (Gemini app retention set to 3 months, Drive left on as a source), and an hour writing and explaining the rules below. The cost was nothing beyond the Workspace plan they already had.
A nursery and a tutoring agency, briefly
A nursery drew the line more tightly, because the data is about children. Its rule: Gemini on work accounts for newsletters, policies and planning, never for anything that names a child, including learning journal entries and incident reports. Staff draft general wording with Gemini and add the child's details themselves afterwards. The patient-data confidentiality checklist for small practices uses the same "minimum necessary" logic and adapts well to children's data.
A tutoring agency drew it more loosely: tutors use Gemini on work accounts to draft progress reports that include pupils' first names and scores, because parents agreed to that use when they signed up and the agency's adviser was comfortable with it. What the agency did insist on was a Drive clean-up first, because two years of lesson notes sat in a folder any tutor could open.
Minimum-necessary prompts, before and after
Most tasks need far less personal detail than people paste. Here's the physiotherapist's letter task done properly. Her first attempt pasted the consultant's letter in full, including the patient's name, date of birth, address and hospital number:
BEFORE
Rewrite this letter in plain English for the patient:
[full letter: name, date of birth, address, hospital number,
diagnosis, scan findings, recommended exercises]
None of the identifiers helped Gemini explain a scan result. The rewritten prompt kept only the clinical content:
AFTER
Rewrite the clinical findings below in plain English for a
patient with no medical background. Keep it under 200 words,
use short sentences, and end with "Your physiotherapist will
go through this with you at your next appointment."
Findings: [scan findings and recommended exercises only]
The illustrative output was a clear 170-word explanation of the findings and the three exercises. One thing needed fixing: it described one exercise as "safe to do daily", which the consultant hadn't said. The physiotherapist deleted the phrase and added a line to the prompt for next time: "don't add advice that isn't in the findings." She then pasted the plain-English text into the clinic's own letter template, where the patient's name went back in. Same result, a fraction of the exposure.
A rule sheet staff can follow
Rules only work if they fit on one screen. The clinic's version, as a template to adapt:
GEMINI AT [CLINIC NAME]: RULES FOR CONFIDENTIAL DATA
1. Use Gemini for work only while signed in to your work account.
Check the account picture in the corner before you paste.
2. Never use the Gemini app on a personal account for anything
about a patient, colleague or supplier.
3. Patient letters: include only what the task needs. Remove
names and dates of birth unless the output must contain them.
4. Clinical notes stay in [practice system]. Don't copy them into
Gemini, Docs or email to work on them.
5. When you rate a Gemini answer, untick "share prompt and
output" if the content is confidential.
6. Don't use Gemini Notebook or Gemini in Chrome for patient
material.
7. Found something in Gemini you shouldn't be able to see? Tell
[practice manager] the same day; it means a sharing setting
is wrong.
Rule 7 matters more than it looks. Gemini is an excellent detector of oversharing, and staff who report surprises help fix permissions faster than any audit.
If client data has already gone into a personal account
It happens, and the response matters more than the slip. The practical steps, in order:
- Delete the conversation from the personal account's Gemini history straight away, and ask the person to check whether Keep Activity was on at the time.
- Write down what happened: which data, roughly how many people it concerned, when, and which account. A short factual note is enough.
- Ask your data-protection adviser whether it needs reporting or telling the people concerned. Deleting the chat reduces the risk, but Google's consumer privacy hub says chats already selected for human review are kept for up to three years even after you delete your activity, so don't assume deletion erases everything.
- Fix the cause, not just the person. In the clinic's case the cause was a phone with the wrong account in the Gemini app and a rule nobody had written down. Both took minutes to fix once found.
Staff who report their own slips quickly are the ones you want, so make it clear that reporting is expected and not punished. A culture where people hide mistakes is a bigger risk than any setting.
Testing the set-up in twenty minutes
Sign in as an ordinary staff member (or ask one to sit with you) and run three checks. First, confirm the Gemini app on every work phone shows the work account. Second, ask Gemini the questions an overshared Drive would answer:
Find any documents that mention salaries, disciplinary action,
or staff sickness, and summarise what they say.
In the clinic's first test, the illustrative answer listed two files: a salary review spreadsheet from three years earlier and a disciplinary letter template with a former employee's name still in it. Both sat in a folder shared with the whole organisation. After moving them and tightening the folder's sharing, the same question returned "I couldn't find any documents matching that request," which is the answer you want for an ordinary user.
Third, check your retention and feedback settings match the rule sheet, and put a reminder in the calendar to repeat all three checks every six months and whenever someone joins or leaves. For more on the wider question of keeping customer data private across tools, see keeping customer data private when your team uses AI, and before adding any new AI tool, what to check in its privacy policy and terms.
Gemini and confidential data: follow-up questions
Can Google employees read what we type into Gemini at work?
Google's Workspace privacy hub says content from qualifying business editions isn't human reviewed or used for model training outside your domain without permission. The exception is feedback: if a user sends a thumbs-down and leaves the boxes ticked to share the prompt and output, that material, including relevant document context, goes to Google as feedback and may be kept for up to 18 months.
Does Gemini make overshared files visible to more people?
It doesn't grant new access, but it makes existing access easier to use. Gemini only retrieves content the user can already open, so a payroll sheet shared with everyone in the organisation was always readable by everyone; Gemini just makes it findable with one question. Fix sharing before rolling Gemini out widely.
Is the free personal Gemini app safe for client data?
Treat it as unsuitable. On personal accounts, Google's own privacy hub asks you not to enter confidential information you wouldn't want a reviewer to see, because with Keep Activity on, some chats may be reviewed by people and used to improve Google's services. Business data belongs in Gemini signed in with a work account on a qualifying Workspace plan.
How long does Google keep Gemini conversations from work accounts?
It depends on the product and your admin's settings. Gemini in Workspace apps keeps prompts and responses for 90 days up to indefinitely, as your admin decides. The Gemini app keeps them for up to 36 months, with 18 months the default, and just 72 hours if conversation history is off. Gemini Notebook doesn't retain prompts after the session ends.
Further reads
- Does Microsoft 365 Copilot Keep Your Business Data Private? — The same question answered for Microsoft's Copilot.
- How to Build Gemini Gems for Repeat Business Tasks — Build Gems once your data rules are in place.
- Are ChatGPT, Claude, Gemini and Copilot GDPR-Compliant? — How the major assistants line up on data-protection law.
- Are Chat-With-PDF Tools Safe for Contracts and Client Files? — The risks of uploading client files to other AI tools.
- How to Set Up Company AI Accounts Instead of Personal Logins — Moving staff off personal accounts for good.
- How to Use Gemini in Gmail to Clear Your Inbox Faster — Putting Gemini to work in Gmail once it's set up safely.
- How to Stop AI Tools Training on Your Business Data — The exact training switches in ChatGPT, Claude, Gemini, Copilot and Perplexity, plus the hidden AI features most owners forget to check.
- How to Summarise Bundles and Transcripts With AI Safely — Clear the tool, prepare the bundle so page references survive, ask for referenced summaries, then check references, omissions and adverse documents.
- Gemini in Google Sheets for Small Businesses: 10 Practical Uses — Ten practical Gemini in Sheets jobs, from building a tracker to the =AI() function and the scheduling solver, with prompts, sample results and limits.
- Gemini or ChatGPT for a Google Workspace Business? — Compare a Workspace upgrade with added ChatGPT seats, counting source selection, checking and the return to shared files.
- Google Workspace vs Microsoft 365 for AI: Which Suits Your Business? — A side-by-side of Gemini in Workspace and Copilot in Microsoft 365: what's included, real annual costs for small teams, and a worked choice for a dry cleaner.
- Custom GPT vs Claude Project vs Gemini Gem: Which Should You Use? — Two of the three are being retired. Here's what each vendor offers now for shared business context, and how a bakery re-homed its three custom GPTs.
- How to Use Gemini in Google Docs to Draft and Edit Faster — Drafting from @-mentioned files, Refine before and after, Help me create with a template, and the number mistakes to catch before you accept.
- Where Is Your Data Stored When You Use AI Tools? — Chats, files and safety logs live in the vendor's cloud. How storage and processing regions work plan by plan, and how to check your own account.
- Is DeepSeek Safe to Use With Business Data? — What DeepSeek's own privacy policy and terms say about storage, retention and training, how the API differs, and how to use its open models safely.
- What Is Data Loss Prevention, and Does a Small Business Need It? — What data loss prevention actually does, which Microsoft 365 and Google Workspace plans include it, and a test for whether your business needs it yet.
- AI Tools and AI Development: The Complete 2026 Guide — the AI hub, including every tutorial in the AI-for-business series.
Sources: Google Workspace Help 'Generative AI in Google Workspace Privacy Hub' (last updated 14 Aug 2026); Gemini Apps Help 'Gemini Apps Privacy Hub' (checked September 2026).