Last Reviewed: September 7, 2026

At a Glance

Your data is processed on Google's servers. Google may retain your data for up to 55 days, and content flagged by Google's automated abuse detection systems may be reviewed by authorized Google employees.

At a glance: Google (Gemini) privacy practices
QuestionAnswer
Can Google access your prompts or documents?Yes — retained up to 55 days for abuse monitoring (details)
Can Google train AI on your prompts or documents?No — prohibited by contract (details)
Can Google employees or contractors review your data?Potentially — if flagged by automated systems (details)
How long does Google retain your data?Up to 55 days for abuse monitoring
Can Amazon employees or contractors review your data?Limited (details)

Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Google, which processes your prompts, and Amazon Web Services, which hosts the Bells Up AI application, each hold SOC 2 and ISO 27001 certifications.


The Three Parties Involved

When you use Google Gemini models (Gemini 2.5, Gemini 3, etc.) through Bells Up AI, three parties are involved in processing your request:

  1. Google is the Model Developer and Service Operator — the company that created and trained the Gemini family of AI models and operates the API infrastructure that processes your requests.
  2. Amazon is Bells Up AI’s Infrastructure Provider. Amazon Web Services (AWS) provides the servers, storage, and networking that host the Bells Up AI application. Chats, workflows, and document analysis go directly from our application to Google’s servers; they do not use Amazon’s AI services. The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are not sent to that service.
  3. Bells Up AI ("we" or "us") — We built and operate the application you are using.

Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.


Google: The Model Developer and Service Operator

What Google Does: Google develops the Gemini family of AI models and operates the API infrastructure that processes your requests. When you submit a prompt through Bells Up AI, it is sent directly to Google's servers for processing.

No Training on Your Data

Bells Up AI uses the paid tier of the Gemini API. Google's Gemini API Additional Terms of Service explicitly prohibit using your data to train AI models:

"When you use Paid Services, including, for example, the paid quota of the Gemini API, Google doesn't use your prompts (including associated system instructions, cached content, and files such as images, videos, or documents) or responses to improve our products."

— Gemini API Additional Terms of Service, "Paid Services" Section (effective March 23, 2026; last updated April 28, 2026)

Why this applies to you: Bells Up AI accesses the Gemini API through a paid Google Cloud billing account, so this no-training commitment applies to your usage through our platform.

Important distinction: The unpaid tier (free quota) has different terms — Google states that they do use unpaid tier data for training. Bells Up AI uses Google's paid tier.

Content Ownership

The Gemini API Additional Terms of Service address ownership of generated content:

"Some of our Services allow you to generate original content. Google won't claim ownership over that content. You acknowledge that Google may generate the same or similar content for others and that we reserve all rights to do so."

— Gemini API Additional Terms of Service, "Use of Generated Content" Section (effective March 23, 2026; last updated April 28, 2026)

Your rights:

Data Retention: The 55-Day Window

Google retains API data temporarily for abuse monitoring purposes:

"Google retains the following data for fifty-five (55) days for the purposes of detecting and preventing violations of the Prohibited Use Policy to maintain the safety and security of the Services, and any required legal or regulatory disclosures: Prompts: The text prompts you submit to the API. Contextual Information: Any additional context you provide with your prompts. Output: The responses generated by the Gemini API."

— Gemini API Usage Policies — Abuse Monitoring (last updated June 9, 2026)

What this means:

Automated Processing of Your Data

Google runs automated content classification systems on all API data:

"Automated Detection: Automated systems scan API usage for violations of our Prohibited Use Policy, such as hate speech, harassment, sexually explicit content, and dangerous content."

— Gemini API Usage Policies — Abuse Monitoring (last updated June 9, 2026)

What Google's automated classifiers look for:

Based on Google's Prohibited Use Policy, automated classifiers detect content in these categories:

What this means for legal work: These classifiers generate flags based on content patterns, not context. A contract describing fraud allegations, a litigation memo discussing violent crimes, or a healthcare privacy agreement referencing medical conditions could trigger classifier flags—even though the content is legitimate legal work.

Who Can Access Your Data at Google

Google's terms limit human access to your data to specific circumstances:

"When prompts or model outputs are flagged by safety filters and abuse detection systems described above, authorized Google employees may assess the flagged content, and either confirm or correct the classification or determination based on predefined guidelines and policies. Data can be accessed for human review only by authorized Google employees via an internal governance assessment and review management platform."

— Gemini API Usage Policies — Abuse Monitoring (last updated June 9, 2026)

"If a project consistently exhibits suspicious activity, it may be flagged for manual review by authorized Google personnel."

— Gemini API Usage Policies — Abuse Monitoring (last updated June 9, 2026)

Note: The Gemini API Additional Terms of Service also mention human reviewers, but that language applies only to quality review of the unpaid tier (free quota). Bells Up AI uses paid-tier API access, which is not subject to that provision.

Personnel permitted to access data and under what circumstances
WhoPermitted AccessUnder What Circumstances
Authorized employeesFlagged content reviewWhen safety filters or abuse detection systems flag content
Authorized employeesManual reviewWhen a project consistently exhibits suspicious activity
Authorized employeesLegal complianceWhen required by law or regulatory disclosure

Google specifies that human review is conducted through "an internal governance assessment and review management platform," and that Paid Services data logged for abuse monitoring is used "solely for the purpose of detecting violations of the Prohibited Use Policy and any required legal or regulatory disclosures" (Gemini API Usage Policies — Abuse Monitoring, last updated June 9, 2026).

Contractual restrictions: Google's Paid Services terms prohibit using your prompts or responses to improve Google's products (Gemini API Additional Terms, "Paid Services" Section, effective March 23, 2026; last updated April 28, 2026). Data logged for abuse monitoring may not be used for any purpose other than policy enforcement and legal compliance.

As noted above, automated content classifiers may flag legitimate legal work. Flagged content is subject to review by authorized Google employees under these access provisions.

Technical Protections

Technical protections: encryption and access controls
Protection Implementation
Encryption in transitTLS 1.2+ for all API communications
Encryption at restAES-256 during the retention period
Access controlsLimited to authorized personnel via internal governance platform
ComplianceSOC 2 Type 2, ISO 27001/27017/27018/27701, HIPAA-eligible

Governing Agreements

Bells Up AI's use of the Gemini API is governed by:

Under the Data Processing Addendum, Google commits to:

Compliance Certifications

Google Gemini maintains the following certifications:

See: Certifications and Security for Gemini


Amazon: Our Infrastructure Provider

What Amazon Does: Amazon provides the cloud infrastructure where the Bells Up AI application runs. This includes:

What Amazon Does NOT Do

When you use Gemini models through Bells Up AI, your prompts travel directly from our application to Google's servers. Amazon does not process your AI requests.

Amazon's Role is Limited to Infrastructure

Amazon provides the computing resources and storage that our application uses. Under the AWS Shared Responsibility Model:

Can Amazon Access Bells Up AI's Infrastructure?

Amazon operates the physical servers and storage infrastructure we use. Amazon's access to data stored on its infrastructure is governed by contract and verified by independent audits:

"[Amazon] will not access or use Customer Data except as necessary to maintain or provide the Services, or as necessary to comply with the law or a binding order of a governmental body."

— Amazon Web Services Data Processing Addendum

This prohibits Amazon from using your data to develop Amazon's own AI or other products, or from providing your data to others for such purposes.

Amazon's SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.

Technical Protections

Technical protections: encryption and access controls
Protection Implementation
Encryption in transitTLS 1.2+ for all communications
Encryption at restAES-256 for all stored data
Server storageEncrypted at the hardware level
Access controlsCredentials managed through Amazon's identity system; no hardcoded passwords

Governing Agreements

Bells Up AI's use of Amazon services is governed by:

Under the Data Processing Addendum, Amazon acts as a "data processor" — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.


Verify These Claims

We encourage you to review the source documents:

Source documents for verifying privacy claims
Document What It Covers Link
Gemini API Additional Terms of Service (effective March 23, 2026; last updated April 28, 2026) No-training commitment (paid tier), content ownership, data handling View
Gemini API Usage Policies — Abuse Monitoring (last updated June 9, 2026) Data retention (55 days), abuse monitoring, human review View
Google APIs Terms of Service General API terms, monitoring, confidentiality View
Google Data Processing Addendum Data processing obligations for paid services View
Certifications and Security for Gemini Compliance certifications (SOC, ISO, HIPAA) View
AWS Data Processing Addendum Amazon's data handling, confidentiality commitments View

Questions?

If you have questions about how your data is protected when using Gemini models through Bells Up AI, contact us at info@bellsup.ai.


This document describes data handling for Google Gemini models accessed via the Gemini API. Other models available through Bells Up AI have different data flows — see the privacy information page for each model family.

This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.