Skip to content
Lex Machina Review logoLex Machina Review
Menu

Risk Digest

Are Your Gemini Privacy Settings Protecting Client Data?

The Thele v. Google dismissal closed the federal courthouse door for consumer privacy claims, but lawyers still face ABA confidentiality obligations and the Heppner privilege risk. This article maps Gemini's privacy settings against enforceable rights under CIPA and the Stored Communications Act, showing exactly what controls to check and why consumer-tier data handling is insufficient for client work.

CONFIRMED
Jurisdiction
US Federal
Court
U.S. District Court for the Northern District of California
Judge
Noel Wise
AI tool named
Gemini
Ruling date
Jul 7, 2026
Source document
View primary court order ↗
Last verified
Jul 25, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

Google won the first round in Thele v. Google on July 7, 2026, but that is a standing ruling, not a confidentiality clearance. Judge Noel Wise dismissed the proposed consumer class action without prejudice because the plaintiffs had not pleaded a concrete injury from alleged default-on Gemini data tracking; the 21-day amendment window remained open as of July 25, 2026.[1] For a lawyer deciding whether client material can go into Gemini, the operative question is narrower and less forgiving: can the firm show that someone checked the relevant Gemini tier, settings, retention rules, and review path before the client data entered the system?

That distinction matters because a privacy plaintiff may lose for failing to identify a particularized misuse of data, while a lawyer may still face a confidentiality, competence, supervision, or privilege problem for using the same tool without investigation. Thele may make some consumer claims harder to plead. It does not answer whether a lawyer made reasonable efforts under professional-responsibility rules.

A lawyer's desk with legal documents and digital privacy controls floating above it

Start With The Settings, Not The Lawsuit

The first audit document should not be a memo about Article III standing. It should be a dated record of what the firm checked in Gemini. Google’s Gemini Apps Privacy Hub, last updated July 15, 2026, says Gemini Apps may collect prompts, uploads such as files, images, and videos, voice recordings, location information, connected-app data, and device information.[2] Those are not exotic categories in a legal practice. A draft motion, deposition excerpt, board minutes, contract schedule, medical chronology, or client email can fit inside them without any technological drama.

The default activity setting deserves special attention. Google states that Gemini Apps Activity is retained by default for 18 months, with settings that can be changed to 3 months, 18 months, 36 months, or kept until deletion.[2] Turning activity off is not the same thing as immediate disappearance: Google says conversations may still be saved with the account for up to 72 hours to provide the service and process feedback.[2] And if a conversation is selected for human review, Google says it is retained for up to three years, disconnected from the user’s Google Account.[2]

Timeline showing Gemini prompt retention, 72-hour persistence, and extended retention for human-reviewed chats

Those three periods measure different things. The 18-month default concerns Gemini Apps Activity. The 72-hour period concerns short-term persistence even when activity is off. The up-to-three-year period concerns human-reviewed conversations that have been disconnected from the account. Treating all three as one generic “retention policy” is how an audit file becomes useless later.

Control Or Fact To CheckWhat It Means For Client Data
Gemini Apps Activity settingDefault retention is 18 months unless changed; the audit should record the setting in force before client data is entered.
Activity offDoes not mean zero retention; Google says conversations may persist with the account for up to 72 hours.
Human review pathReviewed conversations may be retained up to three years, disconnected from the account.
Uploads and connected appsFiles, images, videos, voice recordings, location, device information, and connected-app data may matter as much as the typed prompt.
Tier in useConsumer, Workspace Enterprise, and API use do not present the same data-handling profile.

Consumer Gemini Is The Hardest Tier To Defend For Client Work

The uncomfortable feature in the consumer-tier analysis is not that Google has settings. It is that the consumer path permits human review of prompts and outputs for product improvement, according to Google’s own Privacy Hub disclosures.[2] That may be acceptable for ordinary personal experimentation. It is a different proposition when the prompt includes privileged facts, litigation strategy, nonpublic deal terms, employee medical information, or a client’s unfiled allegations.

Workspace Enterprise and API use need separate treatment. Comparative market commentary describes Workspace Enterprise as contractually excluding human review and model training, while API use generally offers stronger data isolation but requires technical integration.[3] That comparison is useful as a triage point, not as the end of diligence. A firm still needs the governing Google terms, the actual account configuration, the administrative controls, any data-region or logging commitments that matter to the client, and a record of who approved the use case.

Comparison chart of Consumer, Workspace Enterprise, and API Gemini privacy tiers

For a small firm or solo lawyer, the temptation to use a consumer account is obvious. Procurement may be slow; enterprise licensing may be unavailable; a one-off research task may feel harmless. The professional-responsibility problem begins when that practical shortcut is allowed to become an unrecorded client-data workflow. If the firm later has to reconstruct what happened, the absence of a settings record will matter more than the fact that the product was familiar.

What A Defensible Gemini Data Check Should Record

A useful Gemini AI privacy data check is not a screenshot buried in someone’s downloads folder. It is a short, dated control record that another lawyer can understand months later. At minimum, it should identify the account tier, the use case, the categories of client information permitted or prohibited, the activity-retention setting, whether uploads and connected apps are allowed, whether human review can occur, and who approved the configuration.

  • Identify the tier: consumer Gemini, Workspace Enterprise, API, or another governed deployment.
  • Record the Gemini Apps Activity setting and the date it was checked.
  • Document whether activity is off and note the 72-hour persistence disclosed by Google.
  • Confirm whether prompts or outputs may be human reviewed and whether reviewed chats may be retained outside the account.
  • Define what users may input: public law, anonymized hypotheticals, internal know-how, confidential client facts, privileged strategy, or no client data at all.
  • Assign supervision: who trains users, who monitors compliance, and who revisits the settings after Google changes documentation.

The audit should also separate harmless research scaffolding from client-specific work. A lawyer asking Gemini to suggest search terms for a public-law issue presents a different risk from a lawyer pasting a client’s draft declaration and asking for cross-examination themes. The same interface can host both activities, which is why the policy has to describe permitted inputs, not just permitted tools.

Thele Narrows Consumer Remedies, Not Lawyer Duties

The Thele dismissal is still important for rights analysis. The plaintiffs alleged that Google tracked users’ activity through Gemini even when Gemini was not actively invoked, but the court held that the complaint did not plead the concrete harm required under TransUnion.[1] In practical terms, generalized allegations that an AI assistant could collect or process data may not be enough to keep a federal consumer privacy case alive. A plaintiff needs a more particularized account of what data was taken, how it was used, and why that injury is concrete.

That is where the rights inventory becomes less comforting than it looks on paper. California Invasion of Privacy Act Section 632 provides statutory damages of $5,000 per violation for recording confidential communications without consent.[4] But after Thele, a plaintiff trying to litigate in federal court still has to plead Article III injury with enough specificity. The statutory theory may exist; the pleading may fail if it cannot identify a concrete, particularized misuse or interception.

The Stored Communications Act and California privacy theories face the same practical pressure. They may provide labels for the grievance if client information is mishandled, accessed, or disclosed. They do not solve the proof problem created by vague allegations. A lawyer who has no record of what was entered, when it was entered, which account tier was used, and what retention setting applied may struggle both to bring a claim and to defend the original decision to use the tool.

Heppner Is The Privilege Warning, With Limits

United States v. Heppner is the case that should make the settings audit feel less administrative. In February 2026, a Southern District of New York court held that 31 AI-generated defense-strategy documents were not privileged. The analysis identified three independent grounds: no attorney was involved in drafting, there was no confidentiality given Claude’s disclosed data collection and human-review terms, and the documents were not created for legal-advice purposes.[5]

Heppner was about Claude, not Gemini. It was a district court decision, not appellate settlement of the issue. It also does not mean every AI-assisted document loses protection. Warner v. Gilbarco, decided in the Eastern District of Michigan on February 10, 2026, went the other way in a work-product dispute by treating AI systems as tools rather than persons.[6] As of July 25, 2026, that tension remains unresolved.

Still, Heppner supplies the argument an adversary will make. If a lawyer used a consumer AI product after agreeing to terms that disclose data collection or human review, the adversary will say there was no reasonable expectation of confidentiality. The answer cannot be “the privacy lawsuit against Google was dismissed.” The answer has to be a contemporaneous record showing the firm investigated the tool, selected the appropriate tier, restricted inputs, and supervised use.

ABA Guidance Makes Investigation The Floor

ABA Formal Opinion 512, issued in July 2024, tells lawyers using generative AI to consider confidentiality, competence, communication, candor, supervisory duties, and fees; for client information, it requires lawyers to evaluate the tool’s data handling before inputting confidential information.[7] That guidance fits directly with Model Rule 1.6 on confidentiality, Model Rule 1.1 on competence, and Model Rule 5.3 on supervision of nonlawyer assistance.

The duty is not satisfied by knowing that a vendor is large, reputable, or widely used. A consumer settings page is not a vendor diligence file. Nor is a private belief that “Google would not use this badly” a substitute for checking the actual data path. The lawyer’s obligation is to make reasonable efforts before disclosure, and reasonableness is hard to reconstruct after a privilege fight has already started.

State guidance is moving in the same general direction, though not in perfect uniformity. Formal or emerging AI ethics opinions in Florida, North Carolina, Texas, and other jurisdictions reflect that trend, with roughly 11 states plus the District of Columbia having formal opinions by mid-2026.[7] That variation matters. A national firm may need a baseline rule stricter than the minimum in any one jurisdiction, while a local practitioner still has to check the governing state bar position.

Sanctions Are Not The Main Story, But They Are Nearby

The most direct Gemini risk for client data is confidentiality and privilege, not hallucinated citations. But courts are already punishing AI-related legal-work failures in adjacent contexts. Reported sanctions include $31,000 in Lacey v. State Farm in the Central District of California in May 2025 and $110,000 in Couvrette v. Wisnovsky in the District of Oregon in December 2025.[8] Those cases do not decide Gemini privacy questions. They show that judges are no longer treating AI misuse as a novelty.

That sanctions backdrop changes the tone of an internal review. If a lawyer cannot explain which AI tool was used, what data was entered, what the vendor retained, and who supervised the workflow, the problem will not sound like innocent experimentation. It will sound like a control failure.

The Question To Preserve In The File

“Is Gemini private?” is too broad to be useful. The defensible question is whether this lawyer, using this tier, with these settings, for this category of client information, made and documented a reasonable investigation before disclosure. Thele may block under-specified consumer claims. It does not protect a lawyer from the consequences of undocumented consumer-tier use, misunderstood retention controls, human-review exposure, or a later argument that privilege was never preserved.

References

  1. Google defeats consumer lawsuit over Gemini data tracking claims, Reuters, July 8, 2026.
  2. Gemini Apps Privacy Hub, Google Support, updated July 15, 2026.
  3. Is Gemini Private? A Data Privacy Guide for Lawyers, Spellbook.
  4. Navigating the California Invasion of Privacy Act Law in 2026, Holt Law.
  5. United States v. Heppner, Harvard Law Review Blog, March 2026.
  6. AI Privilege and the Future of Confidentiality in the Workplace and Beyond, Ballard Spahr, April 2026.
  7. ABA issues first ethics guidance on a lawyer’s use of AI tools, American Bar Association, July 2024.
  8. AI Legal Ethics: Sanctions, Rules, and Practical Guidance, GC AI.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →
Blogarama - Blog Directory