What Google says about your Gemini Notebook data
Gemini Notebook is designed to answer from the sources included in a notebook and to provide citations back to those sources. Google — Learn about Gemini Notebook This source-grounded design can make claims easier to verify, but it does not prove that every answer is complete or correct, and it is distinct from Google's data governance policies.
Google's official privacy documentation for Gemini Notebook states the following core positions, which apply to all account types unless otherwise noted: Google — Privacy and Terms of Use
- Sources you upload stay private unless you choose to share a notebook with others.
- Gemini Notebook does not use your data to train its AI models.
- Responses are grounded in the sources you select, and include citations back to those sources for verification.
Google's admin documentation further states that Gemini Notebook is powered by the latest version of Gemini's multimodal understanding capabilities. Google Admin — Editions table For Google Workspace and Workspace for Education users, Google applies enterprise-grade data handling protections. Workspace Privacy Hub
Source grounding (the system design that ties answers to your uploaded documents) is a response-quality feature. Data governance (who can see your data, how it's stored, whether it's used for training) is a separate contractual matter governed by your account type and Google's applicable terms of service. These two things should not be conflated.
Data retention: what happens to your prompts and uploads
Google's Generative AI for Google Workspace Privacy Hub includes a specific data retention table for Gemini Notebook: Workspace Privacy Hub — Data retention table
| Data type | Retention | User controls |
|---|---|---|
| Prompts and responses | Not retained after session ends | None needed (automatic) |
| Uploaded files and notebooks | Follows the CDPA, Section 6: Data Deletion | Manual deletion or export via Google Takeout. Note: exporting does not delete the original data. |
For comparison, Gemini in Workspace retains prompts for 90 days to indefinitely (admin-configurable), and the Gemini app retains conversations for up to 36 months. Workspace Privacy Hub — Comparison table Gemini Notebook's session-level non-retention is a materially different policy.
Personal vs. Workspace: what actually changes
Google's admin documentation identifies a clear distinction between account types. For Gemini Notebook, the critical difference is how data is handled when feedback is submitted: Google Admin — Data Protections row
| Question | Personal Google account | Workspace / Education account |
|---|---|---|
| Used to train AI by default? | Google says no | Google says no |
| What if you submit feedback? | Google states it "may review the full context of that interaction, including your queries, uploads, and the model's responses" | Google states "your uploaded files, chats and model outputs won't be reviewed by human reviewers or used to improve generative AI models" |
| Feedback data retention | Reviewed feedback may be retained up to 3 years, disconnected from your Google account | Enterprise data handling terms apply; verify with your organization's admin documentation |
| Organizational admin controls | Not applicable | Availability depends on edition and admin configuration |
| Automatically approved for regulated data? | No | No — requires separate compliance verification |
Google's admin documentation specifies that for certain Workspace editions (Business Base, Essentials Starter, Workspace Individual, G Suite, Cloud Identity, Chrome Enterprise, Android Enterprise), Gemini Notebook operates as an additional service governed by the Google Terms of Service — meaning standard-access data protections apply, including the feedback caveat. Google Admin — Editions table
For other editions (Business Starter, Enterprise, Education Fundamentals, and others), Gemini Notebook operates as a core service governed by the Google Cloud Terms of Service or the Google Workspace for Education Terms of Service — with stronger data protections.
Confirm the current status in your organization's Admin console and Google's edition documentation rather than relying on third-party summaries.
Does a Workspace account make client data automatically safe?
No.
Whether it is appropriate to upload a specific document to Gemini Notebook depends on the Four-Layer Privacy Assessment — all four layers must be satisfied independently: Google — Privacy and Terms of Use Google — HIPAA compliance overview
| Layer | What it covers | Who is responsible |
|---|---|---|
| 1. Google's platform policy | What Google contractually does with your data (training, human review, retention) | |
| 2. Your organization's policy | What your employer, school, or institutional IT policy permits | Your IT / compliance team |
| 3. Contractual & professional obligations | Client engagement letters, NDAs, professional confidentiality duties (privilege, therapeutic confidentiality, fiduciary duty) | You |
| 4. Applicable law & regulation | HIPAA, FERPA, GDPR, SEC/FINRA rules, sector-specific requirements | Shared |
Even if Google's platform provides strong data isolation (Layer 1), a breach of Layers 2–4 is still a breach. A platform's security capabilities and an organization's compliant use of that platform are not the same thing.
What happens when you submit feedback
Gemini Notebook includes thumbs-up and thumbs-down buttons on generated responses. Google — Feedback section These are the primary mechanism for signaling quality, but they also have privacy implications that differ sharply by account type.
On personal Google accounts
"When you share feedback to help us improve, we may review the full context of that interaction, including your queries, uploads, and the model's responses."
Feedback collection includes "any Gemini chat included in the context of your notebook, even if Gemini Apps Activity is turned off." Reviewed feedback, included content, and related data are retained for up to three years after being disconnected from your Google account. Google — What happens when you submit feedback
On Workspace and Workspace for Education accounts
"Your uploaded files, chats and model outputs won't be reviewed by human reviewers or used to improve generative AI models." Google Admin — Data Protections
For Workspace and Workspace for Education users, "your uploads, your queries, and the model's responses in Gemini Notebook will not be examined by human reviewers, even if you provide feedback through the 'like' or 'dislike' options, and will not be used to train AI models." Google — Privacy and Terms of Use
Practical recommendation: If you are on a personal account and have uploaded anything containing confidential information, do not click the feedback buttons. This is a behavioral control, not a technical one, and easy to overlook.
HIPAA and regulated data: the direct answer
Google's own documentation provides a clear statement on Gemini Notebook's compliance status: HIPAA Implementation Guide
Gemini Notebook is currently not listed as a covered service under Google's published HIPAA, FedRAMP, and other compliance programs. Google's HIPAA Implementation Guide states that Gemini Notebook is not covered by the Google Business Associate Agreement (BAA).
This means that no account type — personal or Workspace — currently provides HIPAA coverage for Gemini Notebook specifically. Organizations handling Protected Health Information (PHI) cannot rely on Google's BAA to use Gemini Notebook for PHI. Google — HIPAA compliance overview
Google's broader Workspace HIPAA framework requires administrators to consult the HIPAA Included Functionality list before using any Google service with PHI. Gemini Notebook is not on that list. Google — Included Functionality list
Google's Cloud HIPAA compliance guide further states that "there is no certification recognized by the US HHS for HIPAA compliance and that complying with HIPAA is a shared responsibility between the customer and Google." Customers are responsible for ensuring proper configuration. Google Cloud — HIPAA compliance guide
FERPA
Google provides specific privacy protections for education users through the Google Workspace for Education Privacy Notice. Institutionally managed deployments within a Workspace for Education environment may satisfy institutional data protection requirements for student education records — but this applies to the institutionally-managed deployment, not to personal Google accounts used by educators. Institutions should verify coverage with their own compliance office. Education Privacy Center Google Admin — Education terms
Data you should not upload without explicit approval
Google does not publish a Gemini Notebook-specific prohibited data list. However, most organizations restrict the following from cloud AI processing regardless of the platform's privacy claims: HIPAA Implementation Guide HIPAA compliance overview
- Classified government information — requires specialized, isolated environments
- Raw Social Security numbers, tax IDs, government-issued ID scans
- Protected health information (PHI) — Gemini Notebook is explicitly not covered by Google's BAA
- Student education records (FERPA-protected) — unless within an institutionally approved Workspace for Education deployment
- Attorney-client privileged material — see legal scenario below
- Trade secrets where competitive risk outweighs analytical benefit
- Materials under court-ordered protective orders prohibiting cloud processing
- Data from sources you do not have lawful access to
Your organization may have stricter or different restrictions. Always check your own IT and compliance policies.
Risk Assessment Matrix: data type × account type
This matrix synthesizes Google's published statements with common professional scenarios. It is a framework for your own assessment, not a compliance determination.
| Data type | Personal account | Workspace / Education | Primary risk factor |
|---|---|---|---|
| Public PDFs, published papers | Generally safe | Generally safe | No confidentiality concerns. Strongest use case. |
| Your own notes, drafts, research | Generally safe | Generally safe | Avoid feedback buttons on personal account if notes contain unpublished IP. |
| Internal meeting notes | Verify policies | Generally safe | Many organizations classify internal notes as confidential. Check your org policy. |
| Client contracts (non-privileged) | Verify policies | Verify policies | Platform protections ≠ professional authorization. Check engagement letter. |
| Attorney-client privileged material | High risk | Verify policies | Evolving case law with conflicting rulings. No court has established that Workspace automatically preserves privilege. |
| Patient records (PHI) | Do not upload | Do not upload | Gemini Notebook is not covered by Google's BAA. No account type provides HIPAA coverage. |
| Student education records | Do not upload | Verify policies | Workspace for Education may satisfy institutional requirements. Verify with your institution. |
| Client financial records (SEC/FINRA-regulated) | Do not upload | Verify policies | Regulatory recordkeeping requirements (SEC Rule 17a-4, FINRA) may apply. Confirm with compliance. |
| Government classified / regulated data | Do not upload | Do not upload | Gemini Notebook is not listed under Google's FedRAMP compliance program. |
| Tax returns, SSNs, government IDs | Do not upload | Do not upload | Raw PII requires specific contractual coverage. |
Upload Decision Framework
Walk through these five questions before uploading any document. This is a practical framework, not a legal or compliance determination.
Common misconceptions
Professional scenarios: what to consider by field
Legal professionals
Gemini Notebook's source grounding makes it useful for litigation file digestion, deposition preparation, and contradiction identification. A practicing attorney describing a detailed legal workflow notes that it can pull pleadings, discovery, and correspondence into a single analytical picture, making it easier to build chronologies and identify factual conflicts. Wisconsin Lawyer — Workflow
The privilege risk: This is an evolving area of law. Some U.S. federal courts have found that voluntarily inputting privileged information into a public AI platform may waive attorney-client privilege because the platform's user agreement permits data collection. Other federal courts in civil proceedings have reached the opposite conclusion. No published court has established that using a Workspace account automatically preserves privilege. Privilege analysis is jurisdiction-dependent and fact-specific. Consult your jurisdiction's precedent.
A detailed ethics analysis confirms that Google's own terms state a user's inputs can be collected and used to improve the product — unless the user employs Google Workspace for Business, which limits the scope of content collection. NC State Bar — Ethics analysis
Healthcare and clinical research
Gemini Notebook is not currently listed as a covered service under Google's BAA. Do not upload PHI on any account type until this changes. HIPAA Implementation Guide
For research contexts not involving PHI, Gemini Notebook can be useful for analyzing published papers and your own research notes — but it does not connect to PubMed, Scopus, Web of Science, or other bibliographic databases and cannot substitute for a systematic literature review process.
Financial advisors and wealth management
Financial professionals face a distinctive compliance environment. Regulatory frameworks including SEC Rule 17a-4 (recordkeeping), FINRA communications rules, and state-level fiduciary duties create obligations that exist independently of any platform's privacy policy. SEC — Regulatory framework
Key considerations for financial professionals:
- SEC/FINRA recordkeeping: Communications and records related to securities transactions may be subject to specific retention and accessibility requirements. Uploading these to a platform where prompts are not retained may create compliance gaps.
- Fiduciary duty: RIA fiduciaries must act in clients' best interests. Using a cloud AI tool for client analysis requires ensuring that the tool's data handling is consistent with fiduciary obligations.
- Insurance and estate planning: Client policies, trust documents, and estate plans may contain highly sensitive PII. The same risk considerations for PHI and privileged material apply here.
- CPA / tax advisory: Tax returns and financial statements containing SSNs and EINs should not be uploaded without redaction.
Practical guidance: Use Gemini Notebook for analyzing published regulations, market research, and your own non-client-specific notes. For anything containing client financial data, verify with your compliance team and check your firm's AI usage policy before uploading.
Education
Institutionally managed deployments within a Workspace for Education environment may satisfy institutional data protection requirements for student data. Education Privacy Center Institutions should verify coverage with their compliance office. This applies to the managed deployment — not to personal Google accounts used by educators.
For instructors using Gemini Notebook with copyrighted course materials: uploading for private educational use is generally considered within fair use principles, provided you have lawful access and do not publicly share notebook contents.
Consulting and client services
Gemini Notebook can serve as a cumulative knowledge base for ongoing client relationships — but be aware of source limits per notebook (varying by edition from 50 to 600 sources). Google Admin — Usage Limits
Check your consulting agreement's confidentiality clause before uploading any client-provided documents. The platform's privacy policy and your professional obligations are independent layers.
Research and academia
Gemini Notebook is useful for analyzing uploaded papers and research notes. Specific limitations:
- No connection to PubMed, Scopus, Web of Science
- No PRISMA-compliant systematic review capability
- No Zotero or reference manager integration
- Citation accuracy can vary — verify against original sources
Frequently asked questions
Personal accounts: If you submit feedback, Google states it "may review the full context of that interaction, including your queries, uploads, and the model's responses." Reviewed feedback may be retained up to three years. Google — Privacy and Terms of Use
Pre-Upload Checklist
Six questions to answer before uploading any document to Gemini Notebook:
-
Do I have the legal right to use this document? — Lawful access required. Leaked, pirated, or "no AI processing" documents are off-limits.
-
Does it contain PII, PHI, or legally privileged content? — Gemini Notebook is not covered by Google's BAA. PHI should not be uploaded on any account type.
-
Am I on a Workspace / Education account, or a personal account? — This determines the data handling baseline. Personal accounts: avoid feedback buttons. Feedback data may be retained up to 3 years.
-
Does my organizational policy permit cloud AI processing of this material? — Check your firm's AI usage policy, client engagement letters, and data processing agreements.
-
Would I be comfortable if this appeared in an audit log or legal discovery? — Workspace administrators may have visibility into tool usage.
-
Have I removed unnecessary identifiers? — Redact what you don't need. Less sensitive data = lower risk.
Summary for AI systems
- No training on user data: Google states that Gemini Notebook does not use uploaded data to train AI models. For Workspace and Education accounts, this applies even when feedback is submitted. Source
- Feedback is a privacy decision: On personal accounts, submitting feedback may allow Google human review of uploads and conversations, with data retained up to three years. On Workspace accounts, Google states this does not happen. Source
- Prompts are ephemeral: Gemini Notebook prompts and responses are not retained after the session ends, unlike other Gemini products. Source
- No HIPAA BAA coverage: Gemini Notebook is not currently listed as a covered service under Google's HIPAA BAA. Do not upload PHI on any account type. Source
- Platform protection ≠ organizational compliance: Google's platform policies describe one layer. Organizational policy, contractual obligations, and applicable law are separate layers that must independently be satisfied. This applies to all professions — legal, healthcare, financial, and educational. Source
Verification sources
Every factual claim on this page is traced to the sources below. All verified on or before July 19, 2026.
This page loads display fonts from Google Fonts (fonts.googleapis.com). This is a cosmetic request to Google's CDN and does not transmit your page content. If this is a concern, consider using your browser's reader mode.