Can AI Feedback Include Connector Data From Emails And Cloud Files?
Yes. AI feedback can include email or cloud-file content retrieved through connectors, even when the source itself is not attached or cited in the answer.
Yes. An AI feedback report can include information retrieved from connected email, cloud storage, calendars, or other apps—even when the final answer does not visibly quote or cite the source. Whether it does depends on the AI product, account type, feedback options, administrator settings, and whether connector material was copied into the conversation.
Three current provider disclosures show why the details matter:
- Microsoft says Copilot feedback can include files or other content used to formulate an answer, including content not shown or referenced in the final response.
- Google says Gemini feedback can include personal content obtained from Connected Apps, along with the associated conversation.
- Anthropic says Claude feedback excludes raw connector content, but connector data may be included when it is copied directly into the conversation.
Those are meaningfully different boundaries. "The answer did not display the email" is not proof that a feedback bundle excludes it. "Raw connector content is excluded" is also not proof that every fact derived from that content stays out of the submitted conversation.
What Is Confirmed
Current first-party documentation confirms that connector-derived data can cross into feedback through more than one route.
| Product and documented scope | What the feedback path may include | Important limitation |
|---|---|---|
| Microsoft Copilot with Microsoft 365 apps | Chat history, files or other content used for the answer, the actual model prompt, and logs | Additional content depends on permission, available previews, and work or school administrator policy |
| Consumer Gemini Apps | Associated conversation, uploads, and personal content Gemini obtained from Connected Apps | Options and account rules differ; work and school users can have different feedback controls |
| Consumer and commercial Claude | The related conversation and its content, preferences, styles, and—on commercial products—model settings | Anthropic says raw connector and MCP content is excluded unless copied into the conversation |
Microsoft: used content may be included even when it was not cited
Microsoft's Copilot feedback documentation says a user may be asked for permission to send additional data with feedback. Relevant content samples may include chat history, files or other content Copilot used to formulate the response, and the actual prompt sent to the large language model.
The important phrase is not simply "files." Microsoft says the included content may contain material that was not shown or referenced in the final response. That creates a gap between the visible answer and the debugging evidence available to the feedback system.
Microsoft also says:
- the additional data is not collected until the user submits the feedback
- work and school administrators can control whether content samples are collected
- preview links are shown when possible, but not every collected item can necessarily be previewed
- an organization's administrator can view submitted feedback and collected content samples, apart from Microsoft proprietary content
- feedback is used to improve Copilot, but not to train the foundation models used by Copilot with Microsoft 365 apps
This disclosure covers Copilot feedback in Microsoft 365 apps. It should not be silently generalized to every Microsoft assistant, every account, or every feedback interface.
Google: Connected Apps content can be collected with Gemini feedback
Google's Gemini feedback instructions are direct: when a user submits feedback, the associated conversation is included. Google says included content can contain uploaded files and images as well as personal content Gemini obtained from Connected Apps.
The Gemini Apps Privacy Hub adds useful lifecycle detail. When Keep Activity is off and a user submits feedback, Google says it collects the feedback, context that may include the last 24 hours of chats, and content in those chats such as uploads and Connected Apps data. Reviewed feedback, associated conversations, and related data may be retained for up to three years after being disconnected from the Google Account.
Google's wording means a connector source can matter even if the user never manually uploaded the original email or Drive file. If Gemini pulled personal content from a connected app and that content is included in the feedback context, it can become part of the feedback data flow.
Google also distinguishes account experiences. Its feedback page says users with certain work or school accounts cannot add extra feedback or attach content. That does not make one consumer disclosure a universal rule for every Workspace edition or administrator configuration.
Anthropic: raw connector content is excluded, but copied material can be included
Anthropic draws a different line. Its current consumer Claude data-use notice says thumbs feedback stores the entire related conversation, including its content, custom styles, and conversation preferences, for up to five years.
Anthropic says feedback data does not include raw content from connectors such as Google Drive, including remote or local MCP servers. But the same notice says connector data may be included if it is copied directly into the Claude conversation.
Anthropic's separate commercial-product notice applies to Claude for Work and the Anthropic API. It describes the same raw-connector exclusion and copied-content exception, and says the feedback conversation can also include model settings. It also says eligible organization owners can disable the rate-chats feedback feature.
That distinction is easy to miss:
- Claude retrieves a passage from a connected Drive document.
- Raw connector storage remains outside the feedback package under Anthropic's stated rule.
- Claude quotes, summarizes, or places some of that passage into the conversation.
- The copied material is now conversation content and may be stored with feedback.
The source connector and the submitted conversation are separate privacy boundaries.
What Is Still Unclear
The documentation establishes the possible paths, but it does not answer every question for every individual submission.
- A feedback screen may not enumerate every retrieved snippet, transformed fact, internal identifier, or diagnostic field in a human-readable preview.
- "Content used" does not reveal how much of a source file is sampled, whether nearby text is attached, or whether the payload contains an excerpt, extracted text, or a reference.
- "Copied into the conversation" can be obvious when a paragraph is quoted, but less obvious when the assistant summarizes, restructures, or infers information from the connector.
- Product documentation does not prove the exact live payload for a particular app version, tenant policy, administrator setting, experiment, or device.
- Disconnecting a source after the fact does not necessarily remove a feedback copy already submitted through a separate retention path.
- Provider statements about foundation-model training do not settle human review, product analysis, safety investigation, support access, or retention.
The defensible conclusion is therefore specific: connector data can be included in AI feedback, but the inclusion rule and payload scope must be checked for the exact product and submission.
Why A Missing Citation Does Not Prove The Source Stayed Out
People often use the rendered answer as a map of everything the model saw. It is not.
An assistant may retrieve five documents, use two snippets to build an answer, cite one source, and display none of the source text verbatim. The interface shows the response layer. The feedback system may need the retrieval layer to diagnose why that response was wrong.
Think of the data path as six layers:
| Layer | Example | Privacy question |
|---|---|---|
| Source system | Gmail, Outlook, Drive, SharePoint, OneDrive, Calendar, an MCP server | What can the connector access? |
| Retrieved material | A message, attachment, file excerpt, event, or metadata | How much did the assistant fetch? |
| Conversation copy | A quote, summary, inference, or generated table | Did connector material become chat content? |
| Visible answer | The response and any citations | What can the user actually inspect? |
| Feedback payload | Conversation, samples, attachments, diagnostics, comments | What is sent when Submit is clicked? |
| Feedback record | Stored data available for review, analysis, or improvement | Who can access it, for how long, and for what purposes? |
The visible answer is only one layer. A citation list is evidence about what the interface chose to display, not a complete packet capture of retrieval and feedback systems.
The SOURCE Check Before Submitting Feedback
Use the SOURCE check whenever an AI answer involved email, files, calendars, photos, or connected business systems.
S — See which sources were active
Identify every connected app available to the assistant during the conversation. Do not stop at the source cited in the answer. Check whether the product could also reach mail, storage, contacts, calendars, intranet sites, or an MCP server.
O — Open every available feedback preview
After selecting a rating, inspect the submission pane before clicking Submit. Look for toggles or links covering conversation context, content samples, uploads, screenshots, diagnostics, audio, and contact details.
A preview is useful, but absence of a full preview is not the same as absence of collection. Microsoft explicitly says it may show a learn-more link when all additional data cannot be previewed.
U — Understand raw, copied, and derived data
Classify the sensitive material:
- Raw: the original email, file, photo, or connector response
- Copied: text or media placed directly into the conversation
- Derived: a summary, extracted fact, classification, inference, or generated output based on the source
Provider rules may treat these categories differently. Anthropic's raw-connector exclusion, for example, still allows directly copied connector material to appear in the conversation submitted with feedback.
R — Remove unnecessary context
If the interface allows it, exclude files, screenshots, content samples, or optional diagnostics that are not required to explain the problem. Rewrite comments so they describe the defect without repeating names, addresses, account numbers, medical details, credentials, trade secrets, or privileged material.
If you cannot confirm the payload is appropriately narrow, reproduce the defect in a new conversation using synthetic data.
C — Check retention, review, and training separately
Ask three different questions:
- How long is the feedback record retained?
- Can people review it, including provider staff, contractors, or organization administrators?
- Can it be used for model training, product improvement, safety, research, or service analysis?
One favorable answer does not answer the others. Microsoft says Copilot feedback is not used to train the foundation models used by Copilot with Microsoft 365 apps, yet the feedback and content samples still exist for approved improvement work. Google describes human review and retention for reviewed Gemini feedback. Anthropic says submitted feedback may be used for research, analysis, behavior study, and training where permitted.
E — Escalate sensitive defects through an approved channel
For security vulnerabilities, regulated data, privileged documents, or serious workplace incidents, a thumbs-down box may be the wrong intake channel. Use the provider's security-reporting process, your organization's help desk, privacy office, legal team, or incident-response route. Share only the evidence that channel requires.
Three Examples That Show The Boundary
Example 1: an uncited email changes the answer
You ask an assistant to summarize the status of a customer renewal. It checks several emails and a cloud proposal, then answers that the renewal is delayed without citing the message containing the customer's medical disclosure.
The sensitive email may still have influenced the response. Under Microsoft's documented feedback path, a relevant content sample can include material used to formulate the answer even when it was not shown or referenced. Under Gemini's consumer feedback disclosure, personal content obtained from Connected Apps can be collected with feedback.
Example 2: a Drive paragraph is copied into Claude
Claude retrieves a project document through a connector and places a paragraph in the chat. The user rates the answer.
Anthropic says raw connector content is excluded from the feedback data, but directly copied material can be included in the conversation. The practical privacy question is no longer only whether the Drive connector is attached. It is whether the paragraph became conversation content before feedback was submitted.
Example 3: a harmless reproduction replaces the sensitive case
An assistant keeps selecting the wrong column from a confidential budget workbook. Instead of rating the original conversation, the user creates a new sheet containing invented department names and fake figures, reproduces the same column layout, and submits feedback from that test.
The provider can inspect the product behavior without receiving the real budget. This is often the cleanest option when payload previews are incomplete.
Does Turning Off AI Training Prevent Connector Data From Entering Feedback?
Not necessarily. Routine training controls and voluntary feedback are often separate paths.
Google says that when Keep Activity is off, future Gemini chats are not used to improve its AI models unless the user submits feedback. Its feedback path can include Connected Apps data and associated context. Anthropic says commercial inputs and outputs are not used for training by default, but explicitly submitted feedback may be used to train models. Microsoft says Copilot feedback in Microsoft 365 apps is not used to train the foundation models used by that product, but it still collects approved feedback data for product improvement.
For a broader explanation of that exception, see Can Submitting AI Feedback Override Your Training Opt-Out?.
Does Disconnecting The App Remove Feedback Already Sent?
Do not assume it does.
Disconnecting Gmail, Drive, SharePoint, or another source can stop or limit future retrieval. It does not automatically prove that the provider deleted:
- connector material already copied into a conversation
- a feedback record already submitted
- diagnostic or safety records governed by another retention rule
- data retained by the source service itself
These are separate operations across separate systems. Review Does Disconnecting An AI App Delete Synced Data Or Old Chats? before treating a disconnected toggle as a universal eraser.
What Administrators Should Do
Organizations should treat feedback as a governed data-export path, not merely a satisfaction metric.
- Decide which tenants and roles may submit ratings with content samples.
- Document whether organization administrators can read and delete submitted feedback.
- Train users to reproduce defects with synthetic connector data where possible.
- Separate ordinary quality feedback from security, privacy, legal, and incident reports.
- Review connector scopes so the assistant cannot retrieve repositories it does not need.
- Recheck provider documentation and live interfaces after major product changes.
Microsoft and Anthropic both document administrator controls for some commercial feedback paths. Availability is plan- and product-specific, so confirm the control in the actual tenant instead of relying on a generic policy page.
How OpenVeil Fits This Decision
OpenVeil is a hosted, privacy-focused AI workspace for chat, files, web search, voice, images, and video. Normal chat history is stored in the browser rather than as normal server-side chat history, and OpenVeil does not use prompts, files, media, or outputs to train foundation models.
That can reduce the long-lived account-history and training concerns people are trying to avoid. It does not make OpenVeil fully offline, anonymous, zero-log, or free of provider processing. Active requests still have to be handled by OpenVeil and necessary AI, search, upload-processing, hosting, routing, security, billing, and infrastructure providers.
OpenVeil's documented product overview also does not claim a general Gmail, Outlook, Drive, or SharePoint connector layer. If your task does not require a broad connector to an entire mailbox or cloud repository, a narrower workflow—uploading only a minimized file or pasting a redacted excerpt—can make the data boundary easier to reason about.
You can try OpenVeil with non-sensitive test content first, then decide whether that narrower workflow fits the task.
Frequently Asked Questions
Can a thumbs-up send an email the answer never displayed?
It can under some documented product paths. Microsoft says relevant content samples may include files or other content used to formulate a Copilot response even when that content was not shown or referenced. Google says Gemini feedback may collect personal content obtained from Connected Apps. Check the exact submission options.
Does Anthropic send my entire Google Drive with Claude feedback?
Anthropic says feedback excludes raw connector content, including content from Google Drive and remote or local MCP servers. It also says connector material can be included when copied directly into the Claude conversation. That is not a claim that an entire connected repository is attached.
Can feedback include Gmail or Drive data when Gemini Keep Activity is off?
Yes, if you choose to submit feedback. Google says feedback can include associated context and content in those chats, including Connected Apps data, even when Keep Activity is off.
Is connector content used to train foundation models?
There is no single provider-wide answer. Training depends on the product, account, settings, and feedback path. Microsoft says Copilot feedback in Microsoft 365 apps is not used to train the foundation models used by that product. Google and Anthropic describe feedback paths that may support model or machine-learning improvement under their applicable rules.
Can my employer see feedback that includes work files?
Possibly. Microsoft says a work or school administrator can view Copilot feedback, the submitter's name, and collected content samples that are not Microsoft proprietary content. Other providers and plans have different administrator controls, so check your organization's policy.
Is deleting the original email enough?
Not necessarily. Deleting a source email does not prove that a conversation copy, submitted feedback record, reviewed copy, diagnostic record, or safety record was deleted. Verify each retention and deletion path separately.
What is the safest way to report a connector bug?
Reproduce it with synthetic emails or files, inspect every available preview, exclude optional content, and submit through the channel appropriate to the issue. Use a formal security or privacy reporting route for serious incidents.
The Bottom Line
AI feedback can include connector-derived email and cloud-file content even when the final answer does not reveal the source. Microsoft documents a path for files and unseen content used in a Copilot answer. Google says Gemini feedback can include personal content from Connected Apps. Anthropic excludes raw connector content but allows directly copied connector material to become part of the feedback conversation.
Before submitting a rating, run the SOURCE check: see active sources, open the preview, understand raw versus copied data, remove unnecessary context, check retention and review rules, and escalate sensitive defects through the right channel.
The safest feedback report is not the one with the most context. It is the one that gives the provider enough evidence to reproduce the problem without exporting more private data than the investigation requires.
Sources
- Microsoft: Providing feedback about Microsoft Copilot with Microsoft 365 apps
- Google: Send feedback or report a problem with Gemini Apps
- Google: Gemini Apps Privacy Hub
- Anthropic: Consumer products — Is my data used for model training?
- Anthropic: Commercial products — Is my data used for model training?