Provision record
Google Gemini · Gemini Apps Privacy Notice · View original document ↗

Three-Year Reviewer Retention After Deletion

High severity High confidence Explicitdocumentlanguage Common · 294 of 352 platforms
Get alerted the next time Google Gemini changes these terms. Follow Google Gemini →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Google Gemini recorded 4 documented changes in the last 30 days.
Follow Google Gemini →
Monitor governance changes for Google Gemini Monitor emails you the same day this changes. The archive stays free.
Follow Google Gemini →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The notice states that even after a user deletes their Gemini Apps Activity, reviewer copies of conversations may be retained by Google for up to three years under applicable retention policies.

This analysis describes what Google Gemini's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that the user-initiated deletion of Gemini Apps Activity does not result in immediate or complete deletion of conversation data, as reviewer copies are retained on a separate retention schedule of up to three years. This creates a discrepancy between the deletion action available to users and the actual data lifecycle that compliance teams must account for when evaluating deletion request workflows.

Recent Activity

This document changed recently

Medium Jul 1, 2026

The updated privacy notice establishes that Google collects data from third-party services you connect to Gemini, including Model Context Protocol server tools, and that such connections are not monitored or secured by Google. The notice explicitly states that choosing to connect third-party apps may expose your data, passwords, devices, and accounts to unauthorized access. The revised terms also clarify that you can use temporary chats, which are not retained for AI improvement purposes with human reviewer assistance. You can manage connected app permissions through Gemini Spark settings.

View change record →
Medium May 21, 2026

The updated notice adds new disclosure sections explaining how data flows when using Gemini Spark (remote browser and computer access), how avatar creation collects and processes information, and clarifies that Google collects information about AI reasoning steps during task execution. The notice also refines language around subscription information to specify 'Google AI plan' rather than just generic 'paid subscription.' These changes do not establish new obligations but rather expand the transparency disclosures provided to users about existing and new features.

View change record →
Medium Apr 30, 2026

The updated notice now explicitly identifies Memory as a feature that operates on the basis of user consent, alongside Voice Match. The revised language removes prior geographic restrictions on personalization, meaning Gemini can now reference chat history to generate personalized insights for all users globally, not just those outside the EEA, Switzerland, and the UK. The removal of the statement 'Keep Activity must be on to use this feature' simplifies the operational requirement but does not establish a new obligation. You can learn how to turn the Memory feature on or off through the updated privacy notice.

View change record →

Clause Stability Mostly Stable

1
Change
4
Months Monitored
May 21, 2026
First Seen
May 22, 2026
Last Seen
This clause type exists across 5261 other provisions on other platforms.
This clause has changed once in 4 months of monitoring.

Change history

added May 21, 2026

This reveals that user deletion requests do not actually remove data from reviewer systems, creating a significant privacy gap between user expectations and actual data retention practices.

View full change record →

Consumer impact (what this means for users)

Under this clause, deleting Gemini Apps Activity through Google's activity controls does not delete reviewer copies of conversations, which may be retained for up to three years. The agreement states that Google's retention policies govern the lifecycle of reviewer copies independently of user-initiated deletion.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Submit a data deletion request through Google's privacy tools at myaccount.google.com/delete-services-or-account. Note that reviewer copies may still be retained for up to three years as stated in the privacy notice.

How other platforms handle this

Tinder Medium

If you choose to reveal any personal information about yourself to other users, you do so at your own risk. We strongly encourage you to use caution in disclosing any personal information online.

Skillshare Medium

When you are asked to provide information, you may decline to do so; but if you choose not to provide information that is necessary to provide some of our Services, you may not be able to use those Services.

See all platforms with this clause type →

Monitoring

Google Gemini has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Follow Google Gemini → Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
When you delete your Gemini Apps Activity, Google's retention policies still apply and some data may be retained for a period of time. For example, when you delete your activity, reviewer copies of your conversations may be retained for up to 3 years.

Excerpt from Google Gemini's Gemini Apps Privacy Notice

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1) REGULATORY LANDSCAPE: This provision directly engages GDPR Article 17 (right to erasure) and equivalent UK GDPR provisions, which require data controllers to erase personal data upon valid request subject to specific exceptions. The notice does not specify which exceptions apply to the three-year reviewer retention; compliance teams should assess whether the stated retention basis satisfies the legitimate grounds required under applicable law. CCPA deletion right provisions and equivalent US state laws are also relevant. The Irish DPC and UK ICO are primary enforcement authorities. 2) GOVERNANCE EXPOSURE: High. The assertion that reviewer copies persist for up to three years after user-initiated deletion may conflict with regulatory expectations under GDPR Article 17 unless a documented lawful basis for the extended retention is established and communicated. The notice does not specify the legal basis for this retention period, which creates disclosure and compliance gaps for EEA and UK-based users. 3) JURISDICTION FLAGS: EEA and UK users face the highest regulatory exposure given GDPR and UK GDPR erasure requirements. California residents may assess this under CCPA deletion rights. Organizations processing Gemini data on behalf of EU/UK data subjects under data processing agreements should evaluate whether this retention term is compatible with those agreements. 4) CONTRACT AND VENDOR IMPLICATIONS: Enterprise and Workspace customers should confirm whether their data processing agreements with Google modify the three-year reviewer retention term. Standard consumer terms may not be suitable for enterprise deployments in regulated sectors where deletion obligations are contractual or regulatory. 5) COMPLIANCE CONSIDERATIONS: Legal teams should map this provision against deletion request handling procedures and assess whether responses to erasure requests adequately disclose the reviewer retention period. Policy documentation should clearly distinguish between activity deletion and full data deletion. Regulatory notifications may be required if this retention practice is found to be inconsistent with applicable law in relevant jurisdictions.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Applicable agencies

  • FTC
    The FTC has jurisdiction over data practices that may be inconsistent with representations made to consumers about the effect of deletion controls.
    File a complaint →
  • State AG
    State attorneys general in California and other states with comprehensive privacy laws have enforcement authority over data deletion rights and the adequacy of deletion mechanisms offered to residents.
    File a complaint →

Applicable regulations

EU AI Act
European Union
CCPA/CPRA
California, USA
Colorado AI Act
US-CO
Connecticut Data Privacy Act Amendments
US-CT
CAN-SPAM
United States Federal
EU AI Act - High Risk Provisions
EU
FTC Act Section 5
United States Federal
GDPR
European Union
Indiana Consumer Data Protection Act
US-IN
Kentucky Consumer Data Protection Act
US-KY
UK GDPR
United Kingdom
Universal Opt-Out Mechanism Expansion 2026
US

Provision details

Document information
Document
Gemini Apps Privacy Notice
Entity
Google Gemini
Document last updated
May 5, 2026
Tracking information
First tracked
May 21, 2026
Last verified
May 21, 2026
Record ID
CA-P-012681
Document ID
CA-D-00326
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
3c0f4ea7cc72fb94bf7ff539921da6db42ea20e8191a5612a962df0fdf98885f
Analysis generated
May 21, 2026 00:18 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Google Gemini
Document: Gemini Apps Privacy Notice
Record ID: CA-P-012681
Captured: 2026-05-21 00:18:05 UTC
SHA-256: 3c0f4ea7cc72fb94…
URL: https://conductatlas.com/platform/google-gemini/gemini-apps-privacy-notice/provision/CA-P-012681/three-year-reviewer-retention-after-deletion/
Accessed: July 25, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Related Analysis

Governance intelligence across arbitration, AI governance, data rights, indemnification, and retention

Provision-level monitoring, governance timelines, and regulatory mapping built from archived source documents and historical version tracking.

Frequently Asked Questions

What does Google Gemini's Three-Year Reviewer Retention After Deletion clause do?

This provision establishes that the user-initiated deletion of Gemini Apps Activity does not result in immediate or complete deletion of conversation data, as reviewer copies are retained on a separate retention schedule of up to three years. This creates a discrepancy between the deletion action available to users and the actual data lifecycle that compliance teams must account for when …

How does this clause affect you?

Under this clause, deleting Gemini Apps Activity through Google's activity controls does not delete reviewer copies of conversations, which may be retained for up to three years. The agreement states that Google's retention policies govern the lifecycle of reviewer copies independently of user-initiated deletion.

How many platforms have this type of clause?

ConductAtlas has identified this type of provision across 294 platforms. See the full comparison.

Is ConductAtlas affiliated with Google Gemini?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Google Gemini.