Skip to content
,
Gemini · Part 6

Privacy and Workspace admin basics for normal users

8 min read
Privacy and Workspace admin basics for normal users, with the official product logo. Editorial illustration for Analytics Made Simple.

Privacy in the Gemini app comes from two places: the controls you set yourself and the rules your company’s Workspace administrator sets. Know which kind of account you are signed into, what your IT team can keep on file, and which kinds of data should never go into the Gemini app at all.

Privacy settings are the part of AI products that everyone means to “look at later.” Later arrives when a teammate pastes a customer export into a personal Gemini tab, or when someone asks why a chat from three months ago still shows up in their activity history. You do not need to become a security engineer. You do need a small set of controls and a clear line between your personal account and your work seat.

Personal controls worth knowing

ControlWhat to learnWhat it does not do
Gemini Apps ActivityReview and delete chats; training toggles when they existMake secrets safe to paste
Account typePersonal Gmail is not a work seatOverride Workspace policy
Workspace adminFeatures can be off by app, region, or DLPProve every button is allowed
Your habitsTreat outputs as drafts; export via Takeout if neededReplace an acceptable-use policy

Google explains Gemini app privacy in the Gemini Apps Privacy Hub and in related Help Center articles, and the details change over time. As a user, you should learn how to do these things:

  • Find Gemini Apps Activity, or whatever the current name is for the chat history controls.
  • Review and delete past chats that you no longer want stored in your activity.
  • Check whether your activity may be used to improve Google’s machine learning, and turn that off when the control is available.
  • Export your data through Google Takeout when you need a copy.
  • Manage linked apps and extensions, and any public links to chats that you shared.

Turning a control off is not a license to paste secrets. It lowers some of the training and history risk, but it does not make risky data safe.

Personal account versus work Workspace seat

TopicPersonal Google accountWork Workspace
Who sets policyYou + Google consumer termsYour org + Google Workspace terms
Admin togglesMostly youIT can enable/disable Gemini features
Best forLife admin, learning, non-work projectsCompany data and company workflows
Failure modeShadow IT with customer dataAssuming every button is allowed everywhere

If your company gives you a Workspace account, keep your work content in that account and use its approved Gemini features. Using a personal Gemini account for work files because “it is smarter today” is how incidents start.

Admin basics for people who are not admins

You do not need the admin console, but you do need to know what to ask. Here are six good questions for your IT team:

  1. Is Gemini in Gmail, Docs, and Sheets turned on for our organizational unit (the group of accounts that shares settings)?
  2. Is the Gemini app for work turned on, and under what data rules?
  3. Are there data loss prevention rules, often shortened to DLP, that block sensitive labels?
  4. What is the approved list of data classes for AI tools?
  5. Who do we contact when a feature appears in a blog post but not in our company account?
  6. Are Gems (custom assistants) allowed to be shared, and with whom?

Write the answers in a team document. Knowledge that lives only in chat messages disappears when someone leaves.

Data classes in plain language

ClassExamplesDefault AI rule
PublicMarketing pages, public PDFsUsually OK on approved tools
InternalProcess docs without secretsPrefer work seats; follow policy
ConfidentialCustomer lists, unreleased financeOnly approved enterprise tools, or none
Regulated / specialHealth, payment raw data, government IDsUsually never in consumer AI

When a class is unclear, ask someone before you paste. Guessing wrong is not a productivity hack.

Retention and hygiene habits

  • Delete chats that contain accidental sensitive pastes as soon as you notice them.
  • Avoid using chat as the only record of an important decision.
  • Prefer links to Drive files you control over pasting whole documents into prompts.
  • Sign out of your Google accounts on shared computers.
  • Do not screenshot AI answers that include secrets and drop them into open chat channels.

What Google says about limitations, and why you care

Google’s Gemini overview materials note accuracy problems and bias risks, and they say that models can state incorrect information with confidence. Privacy and product limits are different topics, but they meet in practice. A private wrong answer can still hurt you, and a shared wrong answer can hurt your customers. The official limitation language is a reminder to keep humans in the loop, and it is not a legal waiver for shipping nonsense.

Training a teammate without scaring them

If you are the person who has to bring a coworker up to speed, a seven-step order works well. It builds on the earlier posts in the series, which cover the product map, the plan choices, a first session, the Workspace loop, and the upload ladder.

  1. Show the map of Gemini products in five minutes.
  2. Show the plan reality, so they do not buy random upgrades.
  3. Run the 30-minute first session on a safe task.
  4. Demo the Workspace loop on a dummy draft.
  5. Walk through the upload ladder with real examples from your team’s world.
  6. Bookmark the Privacy Hub and your internal AI use policy.
  7. End with the sentence “When unsure, ask before you paste.”.

Common privacy mistakes

  • Assuming that deleted from the chat screen means deleted from every log forever.
  • Using a personal account for work because the free limits are higher that week.
  • Sharing a chat link publicly without reading the whole chat first.
  • Believing that “the admin would have stopped me” counts as a control strategy.
  • Ignoring differences in region and in education accounts.

Four things to do after reading this

  1. Open the Gemini Apps Privacy Hub and find the activity controls for your account type.
  2. Review whether any old chats should be deleted.
  3. Write your data-class rule in four lines and store it next to your team’s onboarding checklist.
  4. If you use Workspace, send IT your three admin questions when you do not know the answers.

A realistic incident and the boring fix

Say a marketing intern pastes a spreadsheet of event registrants into a personal Gemini account to “clean the columns.” The sheet includes emails and phone numbers. The intern means well, but the company now has personal data sitting in a consumer AI history. The boring fix has several layers. You delete the chat if the controls allow it, tell the privacy or security contact as your policy requires, retrain the person with the upload ladder, and move the cleaning task into an approved Workspace or desktop process. Shaming the intern without fixing the workflow just guarantees a quieter repeat.

Shared devices, family plans, and browsers

Shared laptops need signed-out sessions. Family Google One plans can share storage while AI chats stay tied to each person’s identity. Browser profiles matter too. Keep your work and personal profiles separate so that cookies and account-chooser prompts do not trick you late at night. If you use a password manager, make sure it is not filling in the wrong Google account on gemini.google.com when you are in a rush.

Children, schools, and supervised accounts

Education and supervised accounts may have different Gemini availability and different default protections. If you are a parent or a teacher, do not assume that the consumer Privacy Hub text applies unchanged. Use the education-specific guidance your school provides, and keep student personal data out of consumer tools.

What “improving models with your data” means in practice

Consumer products sometimes use your activity to improve their systems unless you opt out, where a control exists. Enterprise products often limit training on your content by contract. Those are different worlds. Reading a marketing slogan is not a substitute for reading the Privacy Hub and the summary of your Workspace agreement from IT. When a salesperson says “we never train on your data,” ask which product edition and which contract clause they mean.

A minimal personal policy you can adopt today

  1. Work data stays in work accounts and approved tools.
  2. No regulated ID numbers or secrets go into any chat.
  3. Take a two-minute look at your activity each month for accidental pastes.
  4. Never make a public share link for a chat that ever held internal information.
  5. When you join a new team, ask for the one-page AI use policy on day one.

International travel and account-chooser traps

Traveling with two Google accounts on one phone is a classic way to go wrong. You open Gemini to translate a menu and later discover you were in the work account, or the other way around. Before a trip, label your browser profiles clearly and practice switching once. If your company uses advanced protection or device management, follow those rules even when the hotel Wi-Fi is annoying.

Public Wi-Fi is a separate issue from Gemini privacy, but the two stack. Do not open sensitive Drive files and then ask a side panel to summarize them on an untrusted network without guidance from IT on using a VPN (a private, encrypted connection).

Auditing your own last 30 days

  1. List the AI tools you actually opened, including Gemini and any others.
  2. For each one, note the account type: personal or work.
  3. Note the most sensitive paste you can remember.
  4. If any paste fails your data-class table, clean it up and write down what you will do next time.
  5. Share what you learned, without names, if the risk was structural and not just personal.

This audit takes fifteen minutes. It can spare you the “we had no idea people used that” meeting after an incident.

What good admin communication looks like

If you are an admin, publish a short page with screenshots of the enabled features, a data-class table, and a contact channel. Users ignore PDFs that read like contracts. They do read a one-page guide with examples, such as “customer email in Workspace Gemini: OK if the data loss rules allow it; customer CSV in personal Gemini: never.” Update the page when Google renames products, so that people stop searching random blogs.

Quick recap

  • Learn the activity controls, and still do not paste secrets.
  • Personal and work accounts are different worlds, both legally and in daily practice.
  • Non-admins still own good questions and good habits.
  • Next up is the post on when Gemini is the wrong tool.

Series notes

This is Part 6 of Learn Gemini from scratch (Gemini series). It is written for normal users and team leads, and not only for admins.

Sources

Written by

Jose S

Founder & Lead Analyst · Analytics Made Simple

Hands-on data strategist, analytics engineering lead, and educator. Writing practical, no-fluff guides to help everyday teams, analysts, and engineers master SQL, AI systems, and modern data architectures.

Keep going

Same lessons in your feed

Short diagrams, hooks, and weekly tutorials on Substack, Instagram, X, and Facebook.

Google Search Prefer our practical guides in Google Search & Top Stories: