Your Gemini Prompts Can Carry Gmail Into Training
Google's denied it three times in nine months. Since January, every denial says "directly."
Introduction
On November 21, 2025, Google's @gmail account answered a viral claim with one flat sentence: "We do not use your Gmail content to train our Gemini AI model." Four months later it published the denial again, this time carrying the qualifier every version has used since January: Gemini and AI Mode "don't train directly on your Gmail inbox or Google Photos library."
In June, WIRED's Reece Rogers put the narrower question to Google about a new data setting that had just gone live across Search: is it on by default? Spokesperson Davis Thompson replied that the settings "help users get more relevant results and revisit their searches" and "can be turned on or off at any time," never saying whether it's on by default.
If you switched on Personal Intelligence, the Gemini feature Google made free to every US personal account in March, and you've asked Gemini about a flight sitting in your inbox, the prompt that pulled it out of Gmail is training material by Google's own description of how the feature works.
What Google's June Email Actually Changed
The setting driving this round is called Search Services History, announced by email and unrelated to today's Terms of Service. Rogers, whose test account received the message on June 23, 2026, published the first account of it the next day, twelve days ahead of TechCrunch, which opened its own version by calling itself "a belated PSA."
Search Services History splits Search-adjacent activity out of the old Web & App Activity control, covering nine products from Search and Lens to Translate and Search Live. Inside it sits a "Save Media" checkbox that hands Google photos you run through Lens, audio from voice searches, and Translate practice recordings for AI training, and the help documentation names the purpose plainly as "(such as training generative AI models)." Neither WIRED's nor TechCrunch's coverage mentions Gmail or the Google Photos library, because the setting doesn't reach either one.
Unchecking the box later doesn't pull anything back. The pop-up Google shows when you turn the setting off, quoted by WIRED, says training copies of saved media are kept "for up to 4 years, even if you delete the original activity," a line that never appeared in the email.
Today's Terms of Service is a separate document with a much duller story. Diffed against the May 22, 2024 version, it makes six substantive changes, and none of them grants new AI-training rights over Gmail or Photos content. The license clause people are reacting to, the one defining "your content" to include "emails you send and receive through Gmail," has been in force since 2024, as has the anti-jailbreaking and anti-scraping language plenty of coverage this month called new, mine included. One genuinely new section puts background data use for updates, security, and advertising on your own data plan.
"Directly" Is Doing All the Work
Personal Intelligence launched in January 2026 for paying AI Pro and Ultra subscribers, then went free to all US personal accounts on March 17. It's opt-in, running on per-app connections rather than one master switch: you "choose if and when you want to connect apps like Gmail and Google Photos," per Google's own post, with YouTube and Search in the same set. It's the first Google product putting your inbox and photo library on the other end of a Gemini prompt.
The same post carries the denial, one paragraph over: "Gemini and AI Mode don't train directly on your Gmail inbox or Google Photos library. We train on limited info, like specific prompts in Gemini or AI Mode and the model's responses, to improve functionality over time."
Read together, those two sentences describe a route. The Register reported Josh Woodward, VP of Google Labs, Gemini and AI Studio, spelling it out at the January launch: Google would not use a road trip's photos, the license plate in them, or Gmail messages for model training, "but the prompts and responses, filtered to remove personal information, would get fed back to the model as training data." I'd read "directly" as lawyer-hedging, but it's more literal than that: ask Gemini when your flight leaves and it reads Gmail to answer, and the prompt and the answer become the training material while no model ever reads the inbox itself.
Google's Photos help page runs the pledge at two widths on one page: "We don't train any generative AI models outside of Google Photos with your personal data in Google Photos" up top, and, in the section on connecting Photos to other services, "does not train generative AI models outside of Google Photos directly on your imagery and audio." The narrower version is the one that governs once you've connected something.
Google Has Now Denied This Three Times
Round one was November 2025. A viral post claimed Gmail users had been auto-opted into AI training, Malwarebytes amplified it, then corrected itself for adding to "a perfect storm of misunderstanding." Google's @gmail account posted its denial on November 21, and spokesperson Jenny Thomson gave The Verge a near-identical line that week.
Round two arrived with Personal Intelligence going free in March. Google followed on April 7 with a Keyword post titled "Here's how we built Gmail to keep your data secure and private in the Gemini era," which closes: "Bottom line: Your inbox is your business." Round three is happening now, nine months after the first one, with the same denial, and since January, the same qualifier.
One line inside that denial hasn't held up. "We have not changed anyone's settings" is contested: plaintiffs in Thele v. Google allege the company switched Gemini Smart Features to default-on across Gmail, Chat, and Meet "on or about October 10, 2025" without consent, and a Verge staffer reported finding previously-disabled Smart Features turned back on. Judge Noël Wise dismissed the amended complaint on July 7, for lack of standing, writing that plaintiffs "have so far only alleged that Gemini could be used to track their data," a ruling on standing, not on whether Google changed the default. Plaintiffs have until August 18 to file again, with a case management conference set for October 13.
Who Benefits
Alphabet, and the mechanism is the input cost of the buildout. On the July 22 Q2 2026 earnings call, CFO Anat Ashkenazi raised full-year capex guidance to $195–205 billion, up from $180–190 billion in May, after a quarter that alone cost $44.9 billion and produced roughly negative $5.9 billion in free cash flow, Alphabet's first negative quarter in about two decades. Sundar Pichai put Gemini's monthly users at 950 million on the same call.
Spending at that scale only pays back if the models keep getting better, and models get better on data. The supply is tightening: the Wall Street Journal reported (via ppc.land) that major publishers are weighing blocking Google's crawlers because AI Overviews are cutting referral traffic as much as 44% at the Washington Post. Every door that closes on scraped third-party text raises the value of first-party data generated inside Google's own products, by people who already clicked agree.
There's a cover incentive underneath the money one. In September 2025, a federal jury found Google liable for $425.7 million to roughly 98 million users in Rodriguez v. Google, for continuing to collect third-party app data after those users switched off Web & App Activity, the exact control Search Services History has now been split out of. Google hasn't paid; the court-authorized case site says Google has asked the court to vacate the judgment and "There is no money available now." Its response to an adverse verdict about ignoring an opt-out was breaking the setting into finer pieces and emailing every user about their new control.
Why the Right Question Never Gets Answered
Rogers found the setting already enabled on his own account with "Save Media" checked, while users who had previously turned off Web & App Activity and Search Personalization got it switched off automatically. That's the narrower question Thompson wouldn't answer.
No regulator is making it answer. Nothing from the EU, a federal agency, or a state has targeted the June setting or today's terms, and the FTC spent 2026 walking the other way: Reuters reported that the agency set aside earlier AI-related consent orders in favor of policing deceptive claims about AI products, not data practices. The EU's roughly $1 billion fine on Google, July 23, was for self-preferencing in Search and anti-steering on Google Play, a different subject entirely. The only institution that has forced Google to account for this class of conduct was a jury, and Google is still contesting that verdict.
The Bottom Line
The Gmail denial is accurate today and it will be accurate in November, because it describes passive scanning of an inbox, and Google built something that goes around the inbox: the question you type about a message you got, sent to a model that learns from questions. Switching off Personal Intelligence's Gmail connection is a real fix almost nobody knows to make, after nine months arguing about a claim that was never true.
The question WIRED asked in June is still open: is Search Services History on by default? Thele's plaintiffs get another attempt on August 18, and the court reconvenes on October 13, though neither proceeding is built to resolve a settings question. Google could clear it up in one sentence. It's been five weeks.