On September 29, 2026, Google filed a motion to dismiss the second amended complaint in Thele v. Google. The proposed class action alleges that Google switched on its Gemini AI assistant by default across Gmail, Google Chat, and Google Meet in October 2025, giving the AI access to users' private communications without asking first. A federal judge dismissed an earlier version of the complaint in July 2026, but on standing grounds, not because the privacy theory failed. The plaintiffs refiled in August, and the case is still alive.
This is a different case from the wrongful-death lawsuit filed in March 2026 over Gemini's chatbot behavior. That case concerns product safety. This piece is about data privacy and consent.
If your organization runs on Google Workspace, this is not only a consumer story. The central theory is that an AI assistant processing communications without every participant's consent can violate wiretapping law. The same statute, California's CIPA, already drives session-replay lawsuits. It could also apply to an AI meeting assistant your company turned on without telling the people on the call.
Is Gemini a privacy risk for businesses?
Yes, in a specific and fairly common way: Gemini can touch more of your data than a typical chatbot. Beyond prompts and file uploads, Google's documentation describes connected data from Gmail, Google Drive, Google Calendar, YouTube, Google Maps, and Chrome. For a deeper look at how AI systems handle personal data, see our guide on how AI systems process personal data.
Google also says that data is encrypted, but encryption does not remove Google's own access. Google can process prompts, uploads, and outputs for safety, abuse prevention, legal compliance, and human review.
For a business, the practical risk is not abstract. Two examples:
- An employee pastes a client contract into consumer Gemini to get a quick summary.
- A company never checks whether Gemini's "smart features" were switched on across its own Workspace tenant before someone discusses something confidential in Meet.
The wider pattern is covered in our article on privacy risks of LLMs and enterprise AI governance.
What is the Gemini Gmail privacy lawsuit about?
Thele v. Google LLC (Case No. 5:25-cv-09704) is pending in the U.S. District Court for the Northern District of California, San Jose, before Judge Noël Wise. It was filed in November 2025. Thomas Thele and Melo Porter were the original plaintiffs, and the second amended complaint also names Edward Goldstein.
The core allegation is that around October 10, 2025, Google changed Gemini's smart features in Gmail, Chat, and Meet from opt-in to on by default. The plaintiffs say this let the AI process private communications without consent. They compare it to unlawful wiretapping.
The complaint relies on several legal theories:
- California's Invasion of Privacy Act (CIPA)
- The federal Stored Communications Act
- California's Computer Data Access and Fraud Act
- Intrusion upon seclusion
On July 7, 2026, Judge Wise dismissed the earlier complaint with leave to amend. The court found the plaintiffs had not alleged a concrete harm sufficient for federal standing. Reporting on the ruling says they also had not described which specific data Google accessed. The judge did not rule that the privacy theory was wrong.
The plaintiffs filed a second amended complaint on August 18, 2026. Google moved to dismiss it on September 29, 2026. As of this writing, that motion is pending. No class has been certified, and there is no settlement.
The legal theory matters more than the single case. It treats an AI assistant quietly processing a conversation as a possible wiretap if the people involved never consented. CIPA is the same statute behind session-replay and tracking-script suits against websites. For background on that statute, read our CIPA compliance guide. Whether a court accepts the theory for AI assistants is still untested.
How long does Gemini retain data?
| User type | Default retention | Notes |
|---|---|---|
| Consumer Gemini | 18 months | Auto-delete can be set to 3 or 36 months. Google's page also lists an option with no auto-delete. |
| Consumer Gemini with Keep Activity off, or Temporary Chats | 72 hours | Kept for service delivery and safety only |
| Human-reviewed conversations | Up to 3 years | Not deleted when you delete your activity |
| Google Workspace | Set by admins | Google says customer data is not used for model training without the customer's prior permission |
| Gemini API (paid) | Limited logging | Google says prompts and responses are not used to improve its products |
The gap between consumer and enterprise defaults is where business risk concentrates. An employee using a personal Gemini account on a work laptop gets consumer-grade retention and possible human review. They do not get the protections your Workspace agreement may provide.
Deleting Gemini activity also does not delete data stored in connected services such as Gmail or Drive. Those keep their own retention rules.
What businesses should do about Gemini privacy risk
- Confirm what is enabled in your Workspace tenant. Do not assume Gemini's smart features are off. Check the admin console settings for Gmail, Chat, and Meet directly. The Thele plaintiffs allege that Google changed defaults without clear notice.
- Separate consumer and enterprise use in policy. If employees can reach consumer Gemini from a work device, your data may fall under consumer retention and human review.
- Treat AI meeting assistants as a consent problem. If Gemini or any AI assistant processes a call, every participant arguably needs notice. In all-party-consent states, they may need to give affirmative consent. Apply the same standard you already use for session replay and call recording.
- Use admin controls on purpose. Google says Workspace admins can turn Gemini on or off, manage access by app, and limit which Workspace data sources Gemini searches. Review these settings instead of relying on defaults.
- Build an AI governance process. Our AI governance guide explains how to set consent and access controls around AI tools you did not build but still deploy.
- Watch the litigation, not just the headlines. If Thele survives this motion, expect the same theory to be tested against other AI-assistant deployments.
Beyond the Gmail privacy class action: growing regulatory attention
Courts are not the only place Gemini's data practices are being questioned. In February 2026, Senator Elizabeth Warren sent a letter to Google CEO Sundar Pichai about Gemini's planned built-in checkout. The checkout runs on Google's Universal Commerce Protocol, developed with retailers. Warren asked what user data would be shared with retailers, how it could affect pricing, and how consent would be obtained. She set a February 17 response deadline.
Product terms are also shifting fast. Starting October 9, 2026, Google is limiting model access by plan for personal accounts. Users without a Google AI plan keep Flash-Lite only, Google AI Plus subscribers keep Flash-Lite and Flash, and Pro and Ultra subscribers keep all three models. Policies that mention specific Gemini tiers should be revisited regularly.
FAQ
Is Gemini safe to use for business?
It depends on which Gemini your employees use. Google says Workspace customer data is not used to train its models without the customer's prior permission, and paid Gemini API prompts are not used to improve its products. Consumer Gemini, including when accessed from a work device, does not carry those commitments by default.
How long does Google keep Gemini data?
Eighteen months by default for consumer accounts, with auto-delete adjustable to 3 or 36 months. Conversations selected for human review can be retained for up to three years, even if you delete your activity.
What is the Gemini Gmail privacy lawsuit about?
Thele v. Google alleges that Google enabled Gemini by default across Gmail, Chat, and Meet in October 2025 without user consent, raising wiretapping-style claims under California law. A July 2026 dismissal rested on standing, not the merits. Google's motion to dismiss the second amended complaint, filed September 29, 2026, is pending.
Can employees opt out of Gemini data collection?
Consumer users can turn off Gemini Apps Activity, adjust auto-delete, use Temporary Chats, or delete their activity. For Workspace, Gemini access and retention are managed by admins, not by each employee. For how opt-outs work in another major AI product, see our piece on GPT-5 training data opt-out.
The consent theory behind the Gemini Gmail privacy class action is the same one driving CIPA litigation over session replay and tracking scripts. See our breakdown in CIPA vs. CCPA. Book a demo to talk through your Workspace and AI-tool exposure.



