privacy

Google Gemini Reads Your Messages by Default

Google's Gemini AI defaults to accessing WhatsApp, SMS, and phone notifications on Android — and retains data for 72 hours even after you opt out.

Most Android users know Gemini as Google’s AI assistant — the thing that replaced Google Assistant on their phone. What fewer know is that as of mid-2025, Gemini gained default access to notifications from WhatsApp, SMS messages, and phone calls at the operating system level, regardless of what users had set in their Gemini account settings.

This isn’t a buried feature or an edge case. It’s how Gemini ships on Android, by default, for hundreds of millions of users.


What Actually Changed With Gemini’s App Access

Starting in July 2025, Google integrated Gemini more deeply into Android through a feature it calls System Intelligence. This integration gives Gemini access to four categories of apps by default: Phone, Messages (SMS), WhatsApp, and system utilities like volume, alarm, and flashlight controls.

The critical word is “default.” Users don’t choose to enable this. It comes active, and switching it off requires navigating to a non-obvious settings location. Most users who’ve never heard about this change have this access enabled right now.

What Gemini can do through this integration:

  • Read the content of WhatsApp notifications that appear on a user’s screen
  • Send WhatsApp messages and SMS on the user’s behalf via voice or text command
  • Access context from the phone’s call log to inform responses
  • Take actions in connected apps without requiring the user to switch to that app

Google sent emails to Android users explaining the change, but email notifications about privacy feature changes have historically low open rates. The people who know about this integration are disproportionately the people who seek out privacy news — not the majority of Android users.


The 72-Hour Retention Problem

Many people who learned about this change went into their Gemini settings and turned off “Gemini Apps Activity” — the setting that controls whether conversations are stored and used by Google. Reasonable response.

The problem is that disabling Gemini Apps Activity doesn’t disable the third-party app access. The WhatsApp, Messages, and Phone connections persist independently of that setting.

More significantly: even for data that passes through these integrations, Google retains it for up to 72 hours after users disable activity tracking. Google’s stated reason is “safety and security of Gemini Apps” — a backend process that continues regardless of user account settings.

For most data, a 72-hour retention window is a minor technical footnote. For a feature that involves reading the content of private messages, it means that the user’s decision to disable the setting doesn’t eliminate data retention — it delays its end by three days.


What Gemini Can and Cannot Do With Your Messages

Google has been specific about the limits of this access, and the limits are real. But they’re narrower than users might hope.

What Gemini can do:

  • Read the content of WhatsApp notifications that appear on the lock screen or notification shade
  • Send WhatsApp messages and SMS on the user’s behalf via voice or text command
  • Access context from the phone’s call log to produce contextually relevant responses
  • Take actions in connected apps without requiring the user to switch to that app

What Gemini cannot do, per Google’s statements:

  • Proactively scroll through an entire WhatsApp message history unprompted
  • Access the body of end-to-end encrypted messages that haven’t surfaced as notifications
  • Read message history from apps that aren’t listed as connected

The distinction is real but narrower than it appears. On Android, notifications often include full message previews — the entire content of a short WhatsApp message typically appears in the notification. “Reading notifications” is, in practice, reading what your contacts actually wrote to you, in real time, as it arrives.


Why This Feels Different From the Gmail and Drive Integration

Google has offered AI integration with Gmail and Drive for a while, and many users have quietly accepted or ignored those connections. The WhatsApp and Messages integration lands differently for three reasons.

WhatsApp’s encryption promise. WhatsApp uses end-to-end encryption, meaning the company (Meta) cannot read message content in transit. That encryption applies between sender and recipient. Once a message arrives on a device and appears as a notification, it is decrypted — and that’s when Gemini can access it. The encryption that protects messages from WhatsApp’s servers doesn’t protect them from an AI assistant running on the same device.

The intimacy of WhatsApp. WhatsApp is where many people have their most private conversations — family communication, health discussions with close friends, relationship conversations, sensitive planning. The informal nature of direct messaging produces more candid communication than email, which users have historically understood to be scanned for advertising purposes. The expectation of privacy in WhatsApp conversations is higher than in Gmail.

The OS-level framing. Google describes this as System Intelligence — an integration at the operating system level, not a feature the user connected in an app. The mental model “I connected WhatsApp to Gemini” implies a deliberate choice. The mental model “Gemini has access to WhatsApp because it’s built into Android” implies something that happened to users, not something they did.


How to Turn It Off

The setting is real and it works. The process to reach it is less obvious than it should be.

On Android devices with Gemini:

  1. Open the Gemini app
  2. Tap your profile icon → Settings
  3. Find “Connected apps” or “Apps”
  4. Toggle off WhatsApp, Messages, or Phone individually

Alternatively, via the system settings: Settings → Apps → Gemini → Permissions will show device-level access controls. Revoking notification access here is a broader step that limits what Gemini can read regardless of the in-app settings.

The 72-hour retention window cannot be directly disabled. It operates on the backend regardless of account settings, per Google’s current policy documentation.


The Broader Pattern: Default-On AI Access Across Platforms

What’s happening with Gemini isn’t unusual. It reflects a consistent industry pattern: AI assistants are expanding their access to personal context, adding capabilities by default rather than opt-in, and designing retention policies that outlast individual user preferences.

Apple’s Siri has similar access to Messages and WhatsApp on iPhone through Apple Intelligence, though Apple’s stated privacy model emphasizes on-device processing more heavily. Microsoft’s Copilot has access to Outlook and Teams by default on Windows, reading email and calendar data to produce contextually relevant responses. Samsung’s Galaxy AI processes photos, messages, and notes through Samsung’s own AI infrastructure.

The direction across the industry is the same: AI assistants are becoming the connective layer between apps, with broad access to the communications, files, and activities that happen inside them. Each company justifies the defaults as improving user experience. Each relies on users to find and toggle off what they don’t want.


What “Opting Out” Actually Accomplishes

For users who disable the Connected Apps integration: turning off WhatsApp in Gemini’s settings does prevent Gemini from responding to notifications or taking actions in WhatsApp. That’s meaningful.

But the picture isn’t complete with a single toggle.

Other Gemini access — Gmail, Photos, Calendar — is governed by separate settings under the “Personal Intelligence” section introduced in January 2026. Turning off WhatsApp doesn’t affect those. And system-level data that passes through Android’s AI infrastructure may still be subject to policies that differ from per-app toggles.

The practical implication is that a thorough privacy audit of Gemini on Android involves reviewing several settings categories independently: Connected Apps, Personal Intelligence, Gemini Apps Activity, and system app permissions in the Android settings. Most users who think they’ve “turned off” Gemini’s message access have disabled one toggle while leaving others in place.


What to Actually Review on Your Android Device

A practical checklist for Android users concerned about Gemini’s data access:

  1. Connected Apps: Open Gemini → Settings → Connected apps. Review what’s listed and toggle off anything you didn’t explicitly choose.

  2. Personal Intelligence: If visible in Gemini settings, review which Google services (Gmail, Photos, Calendar) are feeding into AI responses and disable what you’re not comfortable with.

  3. Gemini Apps Activity: Turning this off stops Google from storing your Gemini conversation history for the purposes of review and improvement.

  4. Notification access: Via Android settings → Notifications → Special app access → Notification access. Gemini may have notification listener access — revoking this prevents it from reading notification content from any app, not just WhatsApp.

  5. Defaulting back to Google Assistant: On devices that support it, switching the default digital assistant from Gemini to Google Assistant (which doesn’t have the System Intelligence integration) or disabling the digital assistant entirely is the most complete option for users who don’t use the AI assistant features actively.


A Note on Storage Versus Processing

The Gemini access issue is distinct from where personal files and photos live. WhatsApp messages handled through Gemini pass through Google’s AI systems at the OS level. Photos stored in Google Photos are processed through Gemini’s image understanding features. Documents in Google Drive are readable by Copilot/Gemini integrations.

Each of these is a separate pipeline, a separate policy, and a separate toggle.

For users who want to keep personal photos, documents, and memories in a system that isn’t continuously processed by an AI layer, storage choices matter independently of assistant settings. A service that stores files and doesn’t process them through an AI model is a different product category than a cloud platform whose storage feature is part of a broader AI ecosystem.

daftei stores files encrypted in transit with TLS 1.3 and at rest with AES-256. It doesn’t feed stored content into AI models — neither for daftei’s own features nor for any third party. Files stored in daftei don’t form inputs to an AI system that reads, categorizes, or learns from what you’ve uploaded.

That’s not a claim about assistant features, because daftei doesn’t have an AI assistant. It’s a description of what the storage itself does and doesn’t involve.


The Default Problem Is the Point

Google could have launched System Intelligence as an opt-in feature. Every access category — WhatsApp, Messages, Phone — could have required an explicit user action to enable. Many users who would find the features useful would still opt in.

The choice to make these default-enabled, rather than opt-in, is a deliberate product decision. It produces higher adoption rates for AI features and generates more AI-processable data. It also means that the users who benefit from the features are maximized, and the users who’d prefer not to participate bear the cost of finding the settings and turning things off.

That’s the default problem. It’s not unique to Gemini — it’s how the industry has operated for years around tracking, personalization, and AI processing. The burden of privacy is consistently placed on the person who wants it, not the person who wants access.

Understanding what’s enabled by default on your devices is, in 2026, a basic part of knowing what relationship you have with the technology you carry.


What Changes Going Forward

Nothing about this situation is static. Google’s AI product roadmap involves deepening Gemini’s access to more device contexts over time, not narrowing it. Regulatory pressure — the EU AI Act, potential US federal privacy law — may impose constraints on default-on AI access, but regulatory timelines are measured in years.

In the meantime, the access is what it is. Knowing about it, auditing the specific settings it affects, and making deliberate choices about what to disable is the practical response available today.

The place to start is a twenty-minute settings audit on your own Android device. What you find may match what you’d expect — or it may not.

Your memories deserve better than an ad platform.

Try daftei free →
← All posts