Your data is processed on Google's servers. Google may retain your data for up to 55 days, and content flagged by Google's automated abuse detection systems may be reviewed by authorized Google employees.
| Question | Answer |
|---|---|
| Can Google access your prompts or documents? | Yes — retained up to 55 days for abuse monitoring (details) |
| Can Google train AI on your prompts or documents? | No — prohibited by contract (details) |
| Can Google employees or contractors review your data? | Potentially — if flagged by automated systems (details) |
| How long does Google retain your data? | Up to 55 days for abuse monitoring |
| Can Amazon employees or contractors review your data? | Limited (details) |
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Google, which processes your prompts, and Amazon Web Services, which hosts the Bells Up AI application, each hold SOC 2 and ISO 27001 certifications.
When you use Google Gemini models (Gemini 2.5, Gemini 3, etc.) through Bells Up AI, three parties are involved in processing your request:
Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.
What Google Does: Google develops the Gemini family of AI models and operates the API infrastructure that processes your requests. When you submit a prompt through Bells Up AI, it is sent directly to Google's servers for processing.
Bells Up AI uses the paid tier of the Gemini API. Google's Gemini API Additional Terms of Service explicitly prohibit using your data to train AI models:
"When you use Paid Services, including, for example, the paid quota of the Gemini API, Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products."
Why this applies to you: Bells Up AI accesses the Gemini API through a paid Google Cloud billing account, so this no-training commitment applies to your usage through our platform.
Important distinction: The unpaid tier (free quota) has different terms — Google states that they do use unpaid tier data for training. Bells Up AI uses Google's paid tier.
The Gemini API Additional Terms of Service address ownership of generated content:
"Some of our Services allow you to generate original content. Google won't claim ownership over that content. You acknowledge that Google may generate the same or similar content for others and that we reserve all rights to do so."
Your rights:
Google retains API data temporarily for abuse monitoring purposes:
"Google retains the following data for fifty-five (55) days for the purposes of detecting and preventing violations of the Prohibited Use Policy to maintain the safety and security of the Services, and any required legal or regulatory disclosures: Prompts: The text prompts you submit to the API. Contextual Information: Any additional context you provide with your prompts. Output: The responses generated by the Gemini API."
What this means:
Google runs automated content classification systems on all API data:
"Automated Detection: Automated systems scan API usage for violations of our Prohibited Use Policy, such as hate speech, harassment, sexually explicit content, and dangerous content."
What Google's automated classifiers look for:
Based on Google's Prohibited Use Policy, automated classifiers detect content in these categories:
What this means for legal work: These classifiers generate flags based on content patterns, not context. A contract describing fraud allegations, a litigation memo discussing violent crimes, or a healthcare privacy agreement referencing medical conditions could trigger classifier flags—even though the content is legitimate legal work.
Google's terms limit human access to your data to specific circumstances:
"When prompts or model outputs are flagged by safety filters and abuse detection systems described above, authorized Google employees may assess the flagged content, and either confirm or correct the classification or determination based on predefined guidelines and policies. Data can be accessed for human review only by authorized Google employees via an internal governance assessment and review management platform."
"If a project consistently exhibits suspicious activity, it may be flagged for manual review by authorized Google personnel."
Note: The Gemini API Additional Terms of Service also mention human reviewers, but that language applies only to quality review of the unpaid tier (free quota). Bells Up AI uses paid-tier API access, which is not subject to that provision.
| Who | Permitted Access | Under What Circumstances |
|---|---|---|
| Authorized employees | Flagged content review | When safety filters or abuse detection systems flag content |
| Authorized employees | Manual review | When a project consistently exhibits suspicious activity |
| Authorized employees | Legal compliance | When required by law or regulatory disclosure |
Google specifies that human review is conducted through "an internal governance assessment and review management platform," and that Paid Services data logged for abuse monitoring is used "solely for the purpose of detecting violations of the Prohibited Use Policy and any required legal or regulatory disclosures" (Gemini API Usage Policies — Abuse Monitoring, last updated June 9, 2026).
Contractual restrictions: Google's Paid Services terms prohibit using your prompts or responses to improve Google's products (Gemini API Additional Terms, "Paid Services" Section, effective March 23, 2026; last updated April 28, 2026). Data logged for abuse monitoring may not be used for any purpose other than policy enforcement and legal compliance.
As noted above, automated content classifiers may flag legitimate legal work. Flagged content is subject to review by authorized Google employees under these access provisions.
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all API communications |
| Encryption at rest | AES-256 during the retention period |
| Access controls | Limited to authorized personnel via internal governance platform |
| Compliance | SOC 2 Type 2, ISO 27001/27017/27018/27701, HIPAA-eligible |
Bells Up AI's use of the Gemini API is governed by:
Under the Data Processing Addendum, Google commits to:
Google Gemini maintains the following certifications:
What Amazon Does: Amazon provides the cloud infrastructure where the Bells Up AI application runs. This includes:
When you use Gemini models through Bells Up AI, your prompts travel directly from our application to Google's servers. Amazon does not process your AI requests.
Amazon provides the computing resources and storage that our application uses. Under the AWS Shared Responsibility Model:
Amazon operates the physical servers and storage infrastructure we use. Amazon's access to data stored on its infrastructure is governed by contract and verified by independent audits:
"[Amazon] will not access or use Customer Data except as necessary to maintain or provide the Services, or as necessary to comply with the law or a binding order of a governmental body."
This prohibits Amazon from using your data to develop Amazon's own AI or other products, or from providing your data to others for such purposes.
Amazon's SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon's identity system; no hardcoded passwords |
Bells Up AI's use of Amazon services is governed by:
Under the Data Processing Addendum, Amazon acts as a "data processor" — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| Gemini API Additional Terms of Service (effective March 23, 2026; last updated April 28, 2026) | No-training commitment (paid tier), content ownership, data handling | View |
| Gemini API Usage Policies — Abuse Monitoring (last updated June 9, 2026) | Data retention (55 days), abuse monitoring, human review | View |
| Google APIs Terms of Service | General API terms, monitoring, confidentiality | View |
| Google Data Processing Addendum | Data processing obligations for paid services | View |
| Certifications and Security for Gemini | Compliance certifications (SOC, ISO, HIPAA) | View |
| AWS Data Processing Addendum | Amazon's data handling, confidentiality commitments | View |
If you have questions about how your data is protected when using Gemini models through Bells Up AI, contact us at info@bellsup.ai.
This document describes data handling for Google Gemini models accessed via the Gemini API. Other models available through Bells Up AI have different data flows — see the privacy information page for each model family.
This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.