In late May 2026, Google began rolling out a replacement for the long-standing Web & App Activity control on search-related data: a new framework called Search Services History, paired with a separate Personalized Recommendations setting (9to5Google, May 26, 2026; Google Search Help: Get started with Search Services History). By late June, coverage identified a nested Save Media sub-toggle inside that framework, and Google’s own support documentation confirms it migrates to on for any account that previously had Web & App Activity turned on — which is most accounts, since that was itself the historical default (9to5Google, June 22, 2026; BleepingComputer, June 24, 2026; TechRepublic). When Save Media is on, Google retains images, audio, and video from your interactions with Search services and uses them to develop and improve its AI models — including the generative AI models behind AI Mode, Lens, Translate, and Search Live — disconnecting the media from your account first and retaining it for up to four years (Google Search Help: Manage your saved media in Search Services History).
TechCrunch described the update as “under-the-radar,” reporting that Google announced it to users only via a customer email in June rather than a more prominent notice (TechCrunch, July 6, 2026).
This is a research-based guide. Facts are drawn from Google’s own support documentation and reporting from 9to5Google, TechCrunch, TechRepublic, Tom’s Guide, BleepingComputer, and Euronews. We did not test these settings ourselves.
What Is Being Captured
When Save Media is on and you are signed into a Google account, Google’s own support documentation and contemporary reporting describe it saving:
- Google Lens — images submitted for search, including screenshots from Circle to Search (BleepingComputer)
- Google Search Live — audio and video recordings from real-time search sessions (Google Search Help)
- Voice search — recordings from spoken queries (Google Search Help)
- Google Translate — spoken phrases entered for speaking-practice sessions (9to5Google)
- Uploaded files — documents and images attached during AI Mode or Ask Maps search interactions (Euronews)
The data is not saved in identifiable form forever. Google’s support page for the setting states that data is “disconnected from your Google Account before it is used to train our AI models or reviewed by our trained service providers,” that Google uses “filters designed to automatically remove a broad range of identifying info or sensitive personal information,” and that saved media used for training is retained for up to four years (Google Search Help: Manage your saved media in Search Services History). That same page notes disabling Save Media does not delete or disconnect media saved before the toggle was switched off.
Four years is a long data retention window, and “disconnected from your account” is not the same as deleted.
Why This Matters for Builders
The personal-privacy story is well covered elsewhere. The builder and enterprise story is less so.
1. Your users’ inputs may be in Google’s training queue
If you build a product that uses Google Lens via the API, or that encourages users to run Google searches as part of your workflow — and those users are signed into Google — their submitted images and audio may now feed Google’s AI training. That is a data-flow your privacy policy, terms of service, and enterprise agreements may not currently disclose.
This does not apply to server-side API calls. Google Cloud’s Vision API documentation states Google does not use customer image content “for any purpose except to provide you with the Vision API service,” that content isn’t used to train or fine-tune models without customer permission, and that the API is covered by the Cloud Data Processing Addendum rather than the consumer Search settings described here (Google Cloud: Vision API data usage). The risk described in this piece is specific to browser-based and mobile interactions where users are signed into a personal Google account, not to Google Cloud API usage.
2. Enterprise teams doing sensitive research face real exposure
Competitive intelligence teams, legal teams, regulatory affairs teams, and client services teams frequently upload screenshots, product images, and documents into Google Lens or Google Search to identify products, extract text, or research suppliers. If those uploads contain:
- Client materials
- Confidential product designs
- Regulatory filings under NDA
- M&A target information
…and the employee is signed into their personal Google account (common on personal laptops or BYOD devices), those materials may now be in a Google AI training corpus for four years.
Enterprise Google Workspace accounts with managed Chrome policies may have different defaults — IT teams should verify whether their domain policies control the Search Services History setting for managed accounts.
3. GDPR and CCPA exposure
This is our own analysis, not a reported fact: we found no formal regulatory complaint or investigation specifically targeting the Save Media default as of this writing. Separately, on December 9, 2025, the European Commission opened a formal antitrust investigation into Google’s use of web publisher and YouTube content to power AI Overviews and AI Mode — a different issue (competition law, publisher/creator compensation for training content) from the consumer Save Media setting covered here (European Commission press release IP/25/2964; Computerworld). We mention it only as evidence that Google’s AI-training data sourcing is under active EU scrutiny generally, not as an investigation into this specific setting.
On the merits: where a company relies on consent as its lawful basis under the GDPR, that consent must be freely given, specific, informed, and given through a clear affirmative action — not inferred from a pre-set default a user never actively chose (GDPR Article 6 and Article 7). Whether Google is instead relying on a different lawful basis (such as legitimate interest) for Save Media, and whether that basis would hold up, is a genuinely open legal question we are not able to resolve here. If you operate a product serving EU users that routes any data through Google Search services, that open question is a reason for your own legal review, not a settled compliance verdict.
How to Opt Out
The setting lives at myactivity.google.com. The path:
- Sign in to your Google account
- Find Search Services History (separate from Web & App Activity)
- To stop all search history collection: turn off Search Services History entirely
- To keep personal search history but stop media capture: leave Search Services History on, find the nested Save Media sub-toggle, and uncheck it
The two controls are separate. Turning off Web & App Activity (the old control) does not affect Search Services History — this is a new framework (Google Search Help: Manage your saved media in Search Services History; TechRepublic).
What Enterprise IT Teams Should Do Now
- Audit managed account policies: Check whether Google Workspace admin controls govern Search Services History for managed accounts, or whether personal account settings override
- Update acceptable-use guidance: Add explicit guidance that employees should not upload confidential, client, or regulated data into Google Search, Lens, or Search Live using personal Google accounts
- Review your privacy policy: If your product routes any user interaction through Google Search services and users are signed in, your data-processing disclosure may need updating
- Check BYOD exposure: Personal devices used for work are the highest-risk surface — employees are signed into personal accounts where corporate policy cannot enforce the Save Media toggle
Context: Google’s Broader AI Data Strategy
This change is part of a broader pattern. Google is systematically expanding the data surface it can use for AI training:
- December 9, 2025: European Commission opens a formal antitrust investigation into Google’s use of publisher and YouTube content for AI (European Commission) — a separate matter from Search Services History, included here only as evidence of the broader pattern
- May 26, 2026: Search Services History and Personalized Recommendations settings begin rolling out, replacing Web & App Activity for Search services (9to5Google)
- June 22, 2026: Reporting identifies the Save Media sub-toggle capturing images, audio, and video by default for migrated accounts (9to5Google)
- July 6–7, 2026: Broader “how to opt out” press coverage begins (TechCrunch; Euronews)
The pattern is familiar from the AI industry broadly: expand what is collected, default new categories to on, provide opt-out mechanisms that require effort to discover. For enterprise builders, the appropriate response is not to trust that defaults will protect you — audit what your users’ data is touching, what those services’ terms permit, and whether your own disclosures are accurate.
The Bottom Line
If your team regularly submits images, documents, or audio into Google Search services, and those team members are signed into personal Google accounts, some of that material may now sit in Google’s AI training pipeline for up to four years. The fix takes two minutes at myactivity.google.com. The audit of your enterprise exposure takes longer, but it should happen now, before a compliance review surfaces it under worse conditions.