I sat looking at a Drive folder for longer than I care to admit.
As an indie developer, my working folder holds years of material at the same nesting level: store screenshots that are meant to be public, and invoice copies that are absolutely not. Ask Gemini to "summarize what I worked on this quarter" and both categories are equally in view.
My first instinct was to unshare things. But unsharing takes away the access people legitimately need along with the access I was worried about. It turns out there is a middle option — keep the file shared, and take it out of what Gemini will pull from. Any file owner can flip it today, no admin console required.
Gemini's reach is not configured on the Gemini side
Getting this order wrong sends you looking in the wrong place, so let's settle it first.
Gemini operates with the same access rights as the person using it. In Drive that means files shared with you; in Calendar it means events you can already view. A file you cannot open is a file Gemini cannot open either. Google states this plainly in its documentation on what controls Gemini's access to Workspace data.
So the worry "Gemini might see something it shouldn't" is usually not a Gemini problem at all. It is the earlier problem that your own access surface is wider than you can hold in your head.
I had the order backwards myself. I went hunting for an exclusion list inside Gemini when the thing I needed to look at was Drive permissions.
Keep it shared, turn off download, copy, and print
When a file owner turns off "Viewers and commenters can see the option to download, print, and copy," the file becomes readable but not portable for everyone it is shared with.
The useful part is that Gemini honors that restriction. If the owner has not allowed download, copy, and print, Gemini will not retrieve the file as material for a response — even though the file is still shared with you. The sharing relationship stays intact; only the generation input changes.
The whole thing happens in the Drive UI:
- Select the file, or the whole folder, and open Share
- Click the gear icon in the top right
- Uncheck Viewers and commenters can see the option to download, print, and copy
- Close the dialog and confirm the list of people you shared with has not changed
One caveat worth being honest about: this is not confidentiality. If a person can see the file on screen, they can read it and retype it. What you are closing is the export path, not the reading path. I treat it as a partition that keeps a file from getting swept into an overly broad summary — not as a wall around a secret.
There is a second wrinkle. Even when you set this at the folder level, files added later follow their own owner's settings. If a collaborator drops in a file they own, your restriction does not automatically govern it. Plan on revisiting the folder periodically rather than treating one pass as permanent.
Three boundaries, sorted by who can actually draw them
"Keep Gemini out" means different things depending on what account you hold. Mixing the options together is how people end up reading only about controls they have no access to, so here they are separated.
| Control | Who can set it | What it does | Caveat |
|---|---|---|---|
| Access rights (sharing) | File owner or editor | Stops viewing entirely, so Gemini is excluded as a consequence | Removes the access your collaborators actually needed |
| Download, copy, and print turned off | File owner | Keeps sharing in place while removing the file from what Gemini retrieves | Reading still works. It closes the export path only |
| DLP for Gemini | Workspace admin | Excludes Drive data matching labels or content conditions across the organization | Drive data only for now, and it needs admin rights |
On a personal account, or from any seat without the admin console, the first two are your entire hand.
Admins can now draw the line at the label level
Workspace admins have a mechanism called DLP for Gemini. It restricts Gemini's access to Drive data based on content conditions and labels, applied across the organization. Google's overview of DLP for Gemini has the specifics.
The points worth carrying into a planning conversation:
- Five services are covered: the Gemini app, Gemini in Workspace, Gemini Notebook, Personal Intelligence in Workspace, and Workspace Studio
- Three kinds of input get checked: data Gemini finds on its own, resources the user explicitly points at, and links pasted into a prompt
- Restriction currently applies to Drive data only, with support for other Workspace data types described as coming later
- Rollout started August 20, 2026 for Rapid Release domains (allow up to three days for the feature to appear) and September 1, 2026 for Scheduled Release domains
Being able to draw the boundary at the label level matters more than a feature-list entry suggests. The question that survives every AI rollout discussion is "how much can it actually see," and whether that answer can be written as configuration rather than as a policy people are asked to remember tends to decide the rollout itself.
For individuals and small teams, folder structure is the real boundary
Where admin tooling does not reach, the shape of your folders becomes the access boundary, whether or not you designed it that way.
The first thing I did was not a settings change — it was a move. I split the working folder in two, public-safe material on one side and everything else on the other, and made the second one a place I never point Gemini at. It is an unglamorous step, and it did more than any amount of per-file configuration I layered on afterward.
Here is a ten-minute inventory pass:
- In Drive's search box, type
type:pdfand sort newest first. Invoices, contracts, and ID scans cluster almost entirely in this one format - Move what you find into a single folder that sits outside your existing structure
- Check that folder's sharing list. Cut any link sharing you do not recognize
- For the files that genuinely need to stay shared, apply the download, copy, and print restriction described above
- Ask Gemini something like "list the amounts on the invoices in my Drive." If the answer differs before and after the cleanup, your boundary is doing its job
Step 5 is the one I refuse to skip. Confirming a setting on a settings screen never quite convinces me it took effect. Asking the question and watching the answer come back empty settles it faster.
For files that will keep accumulating — meeting notes, for instance — deciding where they land beforehand saves the sorting pass entirely. I wrote about that angle in Meet's note-taking now covers in-person meetings, so decide the Drive destination first. If your concern is data you send through the API rather than files sitting in Drive, when Gemini API data is used for training, and the paid-tier exception is closer to what you are after.
If you try one thing today, search type:pdf in Drive. The width of your own access surface becomes visible in a few seconds, and every decision after that is easier to make with it in front of you.
Thank you for reading. Permissions work is quiet and unrewarding in the moment, but a line drawn once tends to keep paying off for a long time.