What Google commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.
Governance and contractual terms
- Training use (default)
- Consumer Gemini Apps, default ('Keep Activity' on): yes — Google states it uses activity 'to provide, develop, and improve its services (including training generative AI models).' Paid Gemini API / Vertex AI: no — Google states it does not use prompts or responses from paid use to improve its products. Free/unpaid Gemini API and AI Studio: yes — treated the same as consumer activity, used to improve Google's products.
- Retention
- Consumer Gemini Apps, Keep Activity on: auto-deletes after 18 months by default (adjustable to 3 or 36 months, or kept until manually deleted). Keep Activity off / temporary chats: 72 hours. Conversations selected for human review: kept up to 3 years regardless of the user's deletion. Paid Gemini API: prompts/responses logged for a limited, unstated period solely to detect abuse; Search-grounding and Maps-grounding data held on separate shorter schedules (30–90 days, or up to 6 months for chat history).
- Opt-out
- Yes, for consumer Gemini Apps — the 'Keep Activity' setting in Gemini Apps Activity. Turning it off stops future conversations being used for training, unless the user separately sends explicit feedback. Not applicable to the paid API/Cloud tier, where training is off by default.
- Data residency
- Vertex AI offers an EU multi-region endpoint that, per Google's documentation, keeps ML processing inside EU member states specifically (not the same as EEA — UK and Switzerland are excluded) when a jurisdictional endpoint is explicitly selected; the global endpoint gives no residency guarantee at all. No equivalent residency option was found for consumer Gemini Apps. Exact current wording not independently re-fetched in this pass — see verification note.
- Sub-processor list
- Published at cloud.google.com/terms/subprocessors for Google Cloud; the page did not render for automated fetch in this pass. The Cloud DPA references a contractual right to object to new sub-processors (§11.4).
- DPA available
- Yes, for Google Cloud and the paid Gemini API, self-serve via clickthrough acceptance (reportedly through Cloud Console account settings). Not offered for the free consumer Gemini Apps product, which is governed by the Gemini Apps Privacy Notice instead.
- Contracting entity
- Consumer Gemini Apps: Google Ireland Limited (EEA/Switzerland) or Google LLC (elsewhere). Google Cloud: entity determined by customer billing address per Google's own entity-lookup page.
- EU contracting entity
- Google Ireland Limited for consumer Gemini Apps. Google Cloud EMEA Limited has been named in Google's own communications about EU regulatory designations — not independently re-confirmed as the general EU contracting entity for Cloud/Vertex AI in this pass.
- Governing law
- Not independently confirmed by direct fetch in this pass — reported consistently in third-party summaries as California law / Santa Clara County courts for Google Cloud terms. Verify against cloud.google.com/terms directly before publishing.
- Certifications
- ISO/IEC 42001:2023 (Google Cloud AI management system), ISO/IEC 27001 (reported, not independently re-verified this pass), SOC 2 (reported, not independently re-verified this pass)
- AI Act Code of Practice
- yes
- Vulnerability disclosure
- Yes — Google Bug Hunters program (bughunters.google.com), including a dedicated AI Vulnerability Reward Program. Exact reward figures reported in trade press (e.g. a $30,000 top reward, prompt injection explicitly out of scope) were not independently confirmed by direct fetch of Google's own rules page in this pass — see verification note.
- Documented incidents
- No incident found that Google has directly confirmed as its own disclosure. Third-party security researchers have published several: a Chrome 'Gemini Live' panel-hijack flaw (CVE-2026-0628, disclosed to Google 23 Oct 2025, patched January 2026); a Gemini CLI code-execution flaw reported shortly after that tool's launch; and various indirect prompt-injection reports affecting Gemini's integration with Gmail and other apps through 2025. All are documented by named researchers but none carries a Google-published incident report — present as third-party-disclosed, not Google-confirmed.
Model inventory
Listed by the AI Act deadline each model falls under, which depends on when it was placed on the EU market rather than on its capability. No benchmark scores — why not.
| Model | API identifier | EU availability | AI Act deadline | Covered by DPA |
|---|---|---|---|---|
| Gemini 3 Pro | gemini-3-pro | 18 November 2025 (date not independently re-confirmed on a Google-primary page this pass) | 2 Aug 2026 | Consumer app under the Gemini Apps Privacy Notice; API/Vertex AI under the Gemini API Additional Terms / Cloud DPA |
| Gemini 3.1 Pro | gemini-3.1-pro | 19 February 2026 | 2 Aug 2026 | Same split as above |
| Gemini 3.6 Flash | gemini-3.6-flash | 21 July 2026 | 2 Aug 2026 | Same split as above |
Who you are contracting with
Google runs two materially different products under one brand, and the dossier fields above are split accordingly. Consumer Gemini Apps are provided by Google Ireland Limited in the EEA and Switzerland, and by Google LLC everywhere else — stated directly in Google’s own support documentation. Google Cloud (which includes Vertex AI and the paid Gemini API) determines the contracting entity by customer billing address, per a cross-reference in the Cloud Terms of Service; the entity-lookup page itself didn’t render for direct fetch in this pass, so the exact current entity should be confirmed before publishing.
Training use and retention
The split here is three-way, not two-way, and it’s the fact most likely to get flattened if this dossier is summarized carelessly: consumer Gemini Apps train on conversations by default (opt-out via “Keep Activity”); the paid Gemini API and Vertex AI do not use prompts or responses to improve Google’s products under any circumstance Google states; but the free Gemini API tier and AI Studio behave like the consumer product and do use submitted content to improve Google’s services. Anyone building on the free API tier assuming API-grade privacy would be wrong.
Retention mirrors the split: 18 months by default for Keep Activity on (adjustable to 3 or 36 months, or indefinite), 72 hours for temporary chats or Keep Activity off, and up to 3 years for conversations selected for human review regardless of the user’s own deletion choice.
Residency and sub-processors
Vertex AI’s EU multi-region endpoint is reported to keep ML processing inside EU member states specifically when explicitly selected — narrower than “EEA,” since it appears to exclude the UK and Switzerland — while the global endpoint gives no residency guarantee at all. That distinction (an opt-in regional endpoint vs. a global default with no guarantee) matters enough that it should be re-confirmed against Google’s current documentation before publishing a firm claim about it.
The Cloud sub-processor list is published, and the DPA references a contractual right to object to new sub-processors, but the list’s contents weren’t captured by automated fetch in this pass.
Certifications
The one certification independently confirmed by direct fetch is ISO/IEC 42001:2023, announced in a December 2024 Google Cloud blog post — the post doesn’t specify which exact products (Cloud, Workspace, the Gemini app) fall inside that certification’s scope, which is worth pinning down before publishing. Broader claims (ISO 27001, SOC 2, PCI DSS, FedRAMP) are consistently reported across Google’s compliance pages but weren’t independently re-fetched this pass.
AI Act posture
Google announced in July 2025 that it would sign the EU’s GPAI Code of Practice, but paired that commitment with public reservations — its own blog post warned that AI Act implementation “could… slow Europe’s development and deployment of AI,” and set conditions around working with the EU AI Office on proportionality. That combination of “yes, but publicly qualified” is worth preserving in any published summary rather than reducing to a flat yes. See the framework for why the distinction matters from 2 August 2026.
Model inventory notes
No EU-specific release date, separate from the global date, was found for any current Gemini model — the dates above are global availability dates, carried over pending a more thorough check of Google’s model cards. Two of the three model dates above came from search-summary sourcing rather than a direct fetch of the model card and should be treated as provisional.
This record describes contractual and governance terms as read on the date shown, for the tier shown. Providers revise terms without notice — verify against the provider's own documentation before relying on any of it. Nothing here is legal advice.