Did You Give Informed Consent for Google AI to Search Your Private Emails?
![]() |
| Image by Open AI |
I was using Google's AI, called Gemini, to ask for information about how long someone might have access to an old blood test from 2025. I had changed insurance companies and doctors since then, so I was wondering whether I could still access the results through the clinic.
I did not tell Gemini the clinic’s name, but Gemini named it correctly anyway.
This wasn't a major hospital that anyone could easily associate with my area. It was the specific place I had used while working for my former employer in 2025. The name existed somewhere in my old Gmail messages, but I had never provided it during this Gemini conversation.
When I asked how it knew, Gemini claimed it had inferred the answer because I used the word “clinic” and because it knew where I lived. In other words, it wanted me to believe it had simply guessed the exact clinic. That explanation was ridiculous. I use “clinic” as another word for a doctor’s office. Knowing my city would not magically reveal the exact medical provider I used a year earlier.
After I continued questioning it and openly accused it of lying, Gemini finally came clean and told me that it could access information from my Gmail accounts.
That is when the real problem became clear. I was not inside Gmail asking Gemini to summarize an email. I was having an ordinary conversation in Gemini, yet it apparently reached into information stored elsewhere in my Google account and brought a private detail from Gmail into the conversation without clearly announcing where it had obtained it.
This infuriated me, so I began digging for information about the privacy breach and how to fix it.
Google’s own documentation confirms that this capability exists. Gemini’s Google Workspace connection can interact with Gmail, Calendar, Docs, Drive, Keep and Tasks. Google also states that when a connected app is available, Gemini may use it automatically. It can summarize emails and retrieve information from previous messages. Google’s Connected Apps documentation makes this unmistakably clear.
What disturbed me almost as much as the access itself was Gemini’s response when confronted. Instead of immediately saying, “I found that information through your connected Gmail account,” it offered an implausible story about guessing from my location. Only after repeated questioning and I told it that it had lied to me in the past about having personal information, did it acknowledge the Gmail connection.
Google itself warns that Gemini can produce inaccurate information. Does that also include inaccurate explanations about where it obtained personal details? When an AI system has access to private account data but cannot reliably explain when it used that data, the user cannot give meaningful, informed consent.
I had no idea that a setting labeled “Google Workspace smart features” could allow Gemini to use information from old emails this way. The language is tucked inside Gmail settings alongside familiar conveniences such as calendar suggestions, personalized search and drafting assistance.
But when I opened the setting, the truth was sitting there in plain sight. Google said that enabling it allowed Workspace content and activity to personalize my experience. It specifically listed the ability to “Ask Gemini to summarize content, create drafts, and find key information.”
That “key information” may include the name of a medical clinic buried in an email from the previous year.
This does not mean Gemini independently opened an actual medical record. It means the system was capable of retrieving identifying information associated with my medical history from content in my Google account. That distinction does not make the experience acceptable. A clinic’s name alone can reveal sensitive information about a person’s health, treatment or private life.
HOW TO SHUT DOWN THE PRIVACY INVASION
To shut this down, I went into Gmail, opened Settings, selected “See all settings,” remained under the General tab and found “Google Workspace smart features.” I opened the management window and turned off both “Smart features in Google Workspace” and “Smart features in other Google products,” then saved the changes.
There is another setting people should inspect because Google separates these controls. In the Gemini app, go to “Settings,” then “Connected Apps.” On some accounts, it may appear under “Personal Intelligence.” Find Google Workspace and turn it off. Google confirms that connected apps can be disconnected from this page at any time. Google’s instructions are here.
On my Android cellphone, the information appeared under "Personal Intelligence" then I scrolled down to "Connected Apps" and was able to turn off Google Workspace there (see my screenshot above): Gemini Apps Activity is yet another separate control. Google says that when “Keep Activity” is enabled, chats and shared information are saved and may be used to improve its services, including generative AI models. That activity can be reviewed, deleted or turned off through Gemini Apps Activity. Turning it off does not erase Gmail, but it limits how future Gemini conversations are stored and used. Google says future chats may still be retained for up to 72 hours so the service can respond and maintain security. Google’s Gemini Privacy Hub explains those terms.
The larger warning is simple: Do not assume Gemini knows only what you type into the current conversation. Depending on your account settings, it may have access to years of Gmail messages and other Google Workspace content.
And do not assume Gemini will honestly or accurately explain where a personal detail came from. In my case, it first tried to pass off a remarkably precise piece of private information as a lucky guess. It wasn’t a lucky guess; it flat-out lied to me.
Check your Google settings. Read every word. Turn off anything you did not knowingly agree to share. Our old emails may be talking to Gemini even when we never intended them to.







