Gemini is easy to reach because most people already have a Google account. That convenience is the risk. A team member opens Gemini with a personal login, pastes in a client brief or a customer list, and company data is now covered by consumer terms nobody on your side reviewed. Keeping data safe in Gemini comes down to three things: using the account type that carries business protections, setting the controls that account gives you, and agreeing on what never goes in.
Know which Gemini you are using
Google documents two quite different situations. Gemini inside Google Workspace is covered by Workspace's generative AI privacy commitments: Google states that Workspace does not use customer data to train models without the customer's prior permission or instruction, and that your interactions stay within your organization. Gemini on a personal account is covered by the Gemini Apps privacy hub instead, which describes human review of some conversations and separate retention rules. Confirm which one each person is signed into before anything else, and read the current terms for your plan, because they change.
Mind the activity and retention settings
On personal accounts, Google's Gemini Apps help pages describe a Keep Activity setting with an 18-month auto-delete default, adjustable to 3 or 36 months or indefinite. They also say that chats reviewed by human reviewers are disconnected from the account and kept for up to three years, and are not removed when you delete your own activity. For Workspace, Google's documentation says admins decide how long prompts and responses are kept. If your records policy says client material should not sit in a vendor system indefinitely, set the shorter window at the organization level instead of trusting each user to do it.
Decide which Workspace services Gemini can search
Workspace admins can control which services, such as Gmail, Drive, Calendar and Chat, Gemini is allowed to draw on. Treat that as a permissions decision. Gemini can only surface what the person asking already has access to, so overshared folders and open-to-anyone links become findable in seconds. Tidying sharing settings before you roll Gemini out is often the most valuable step.
Use classification and DLP to fence off sensitive files
Google describes admins using built-in AI classification and data loss prevention rules to identify sensitive content, and information rights management to restrict it. Under those rules, if a user is not allowed to download, print or copy a file, Gemini will not retrieve it for them. If you handle contracts, financials or regulated records, label them and let the policy do the work.
Turn on logging and look at it
Google says Workspace provides logging and export for Gemini activity, so admins can review usage and data access across the organization. A log nobody reads is only a record after the fact. Give it an owner and a cadence: a monthly skim for unexpected usage or changed settings catches most drift.
Write down what never goes in
Controls reduce exposure; they do not replace judgment. Keep credentials, API keys and passwords out of prompts entirely. Keep regulated or contractually restricted material out unless your agreement and your client's terms explicitly allow it. Strip names and identifiers from anything you paste when the question does not need them. And treat what comes back as a draft: a person should check any claim before it reaches a client or a published page.
A short checklist
Confirm everyone works in the company Workspace account, not a personal one. Set the retention window. Decide which services Gemini may search and fix oversharing first. Apply classification and DLP to sensitive files. Assign an owner to the activity logs. Publish the never-paste list and review it twice a year. If a vendor claim matters to a contract or a client commitment, read the current terms yourself.