# Google Separates Search Privacy Settings, Adds Media Tracking—What Users Need to Know


Google is rolling out granular new privacy controls for its Search services and Google Play, fundamentally restructuring how the company manages saved activity data. The changes, announced via email to users on June 24, 2026, introduce separate toggles for "Search Services History" and "Personalized Recommendations"—but also clarify a significant shift: the tech giant will now systematically save media from user interactions, including images, audio files, and video, for both personalization *and* AI model development.


For privacy-conscious users, the announcement reads as both a win and a warning. Google is finally offering more granular control over activity tracking. But the company is simultaneously expanding what it collects and how it plans to use that data, even as it presents the changes as a privacy improvement.


## The Shift in Google's Data Architecture


Until now, Google managed activity tracking through a single umbrella setting called Web & App Activity. Users could toggle it on or off, but had limited ability to differentiate between various types of tracking. The new model splits that authority into discrete controls:


  • Search Services History: Controls whether Google saves searches, maps activity, shopping queries, flights, hotels, translate usage, news activity, and now *media* from interactions
  • Personalized Recommendations: A separate toggle for whether that saved data personalizes your search experience
  • Save Media subsetting: A new option that explicitly captures images, files, audio, and video from Search interactions

  • The separation itself is not inherently negative—many privacy advocates have long argued for granular controls. However, the timing and scope of these changes warrant scrutiny.


    ## What Google Will Now Track: The Media Expansion


    The most consequential aspect of these changes is Google's explicit expansion into media collection. According to the company's announcement, saved media includes:


  • Visual content: Images from Google Lens searches, screenshots, photos you search with
  • Audio files: Voice queries, ambient audio context from voice interactions, speech samples
  • Video data: Recordings from video-based search interactions or Search Live conversations
  • Other files: Documents and files uploaded or referenced during searches

  • Google frames this as necessary for "interactive product experiences"—revisiting past Lens searches, continuing conversations about discovered songs, or maintaining context in Search Live sessions. These are genuine use cases, but they also represent a meaningful expansion in what the company collects.


    The company states it will apply "robust privacy and security protections" to this media, and users can disable the "Save Media" subsetting at any time. However, Google's fine print carries critical implications.


    ## The AI Training Data Question


    Here lies the thorniest disclosure: saved media, like Search Services History, will be used "to develop and improve Google services and technologies, including AI models and safety measures."


    This is not new for Google—the company has long used aggregated and anonymized data for product improvement. But the explicit mention of AI model training alongside media tracking reveals a key tension in the announcement:


    | Stated Purpose | Actual Use |

    |---|---|

    | Help you revisit past searches | Training data for AI models |

    | Support interactive features | Improving recommendation algorithms |

    | Personalization | Development of future AI safety systems |


    Google does not specify whether media will be anonymized before use in AI training, whether it will be excluded from training, or what safeguards prevent re-identification. The company's approach is consistent with industry practice—but consistency with current practice is not the same as robust privacy protection.


    ## Background and Context: Why Now?


    The timing of these changes reflects several converging pressures:


    1. Regulatory Scrutiny: Regulators globally—from the EU to the UK to the FTC—have intensified investigations into how tech companies use personal data for AI training. Google is under active antitrust investigation in multiple jurisdictions, with data practices at the center of those inquiries.


    2. AI Needs Scale: Training advanced AI models requires massive datasets. Audio, visual, and video data are particularly valuable for multimodal AI systems. As Google invests heavily in AI capabilities, the pressure to systematize collection of these data types increases.


    3. Privacy Control Theater: Offering new privacy controls can serve dual purposes: genuinely empowering users while simultaneously normalizing broader data collection. Users who see granular toggles often feel they have regained control, even when the scope of collection expands.


    4. Search Transformation: Google's shift toward more interactive, multimodal search (Lens, Search Live, voice-first interactions) naturally generates richer data—but also requires transparent disclosure of what's captured.


    ## Technical Details: How the Settings Work


    Google's implementation provides users with new controls accessible through their Google Account settings:


  • Users will see the change roll out "in the next few days"
  • If "Web & App Activity" is currently enabled, the new "Search Services History" setting will automatically default to on
  • The "Personalized Recommendations" toggle defaults to on for existing users
  • Users can disable either setting independently
  • The "Save Media" subsetting can be toggled separately from the broader Search Services History control

  • Important caveat: Turning off Search Services History should stop Google from saving new data, but users should verify this setting took effect and consider requesting deletion of historical media if they have concerns.


    ## Implications for Users and Organizations


    For individual users:

  • Conduct an audit of what you've previously allowed Google to save by visiting myactivity.google.com
  • Review the new settings once they appear and intentionally configure them rather than accepting defaults
  • Understand that "personalization controls" and "data collection" are separate toggles—disabling one doesn't disable the other
  • Consider implications if you use voice search, Google Lens, or other interactive features that now generate saveable media

  • For organizations:

  • Educate employees about these settings, particularly if your security policy involves limiting what user data is saved by third parties
  • Consider whether company device policies should restrict use of Gmail or Google Search accounts that will now save media
  • Review your data governance policies in light of expanded cloud-based media tracking
  • Audit what sensitive information employees may inadvertently search or scan with Lens

  • For privacy-focused users:

  • These changes may warrant switching Search providers (DuckDuckGo, Brave Search, or Ecosia offer alternatives with stronger privacy defaults)
  • If you remain on Google, disable "Save Media" and consider disabling Search Services History entirely
  • Periodically export and review your activity data at takeout.google.com

  • ## Recommendations


    Immediate steps:


    1. Don't assume defaults are safe. When the setting rolls out, explicitly configure both Search Services History and Personalized Recommendations rather than passively accepting defaults.


    2. Disable Save Media if privacy is a concern. This subsetting is the primary expansion in this announcement—disabling it prevents systematic collection of images, audio, and video from your interactions.


    3. Request historical deletion. If you've previously had Web & App Activity enabled, consider exporting your activity data and then requesting deletion through Google Takeout and the My Activity tool.


    4. Understand the trade-off. Disabling these settings may degrade personalization and reduce functionality in interactive search features. Accept this trade-off consciously, or accept the data collection consciously.


    For defenders and administrators:


  • Document which Google services your organization uses and which users have access to sensitive search contexts
  • Update privacy training to reflect that Google now explicitly saves media for AI training purposes
  • Monitor for any policy changes from Google regarding data deletion, retention, or AI training usage
  • Consider whether less-integrated search tools would better fit your organization's privacy posture

  • ---


    ## HackWire Analysis


    Google's announcement exemplifies a pattern we see repeatedly in tech: framing expanded data collection as expanded user control. The new settings are genuinely more granular than before—that's a real improvement. But the expansion into media tracking, coupled with explicit disclosure of AI model training, reveals where the company's actual priorities lie.


    The critical question is not whether Google *can* train AI on this data—it can, and legally, under most current frameworks, it does. The question is whether users understand what they're consenting to. "Robust privacy and security protections" is not a technical specification; it's a commitment vague enough to mean nearly anything. Google doesn't explain whether media is anonymized before AI training, whether users can opt out of AI use while keeping personalization, or what happens if an AI model trained on your audio data is later breached or stolen.


    This matters because media is harder to anonymize than search text. Your voice, unique phrasing patterns, and visual search behavior can be identifiable even after explicit identifiers are stripped. The company's silence on these specifics suggests they haven't solved the technical problem—and are hoping users don't ask.


    The broader pattern: every major tech company is now in an aggressive race to secure training data for AI. Privacy controls that look like customer empowerment are often the price of admission to expanded data collection. Google is being more transparent than some competitors about this shift, which is worth acknowledging. But transparency about an unfavorable trade-off is still a trade-off.


    For defenders, the message is clear: assume third-party cloud services will collect and reuse data more broadly than their privacy policies explicitly state. Adjust threat models accordingly.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Privacy & Data Protection](https://www.hackwire.news/category/privacy-protection) coverage
  • Cross-reference with [Cloud Security](https://www.hackwire.news/category/cloud-security) and [Tech Policy](https://www.hackwire.news/category/tech-policy)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)