Can A Gemini Public Link Make An Uploaded Image Downloadable?

September 3, 2026

Google says an image uploaded to a shared Gemini chat is downloadable. Learn what the public link exposes and what deletion cannot recall.

Yes. If you upload an image to a Gemini chat and then create a public link for that chat, Google says the image is available and downloadable from the shared conversation. Anyone who gets the link can read the shared chat, reshare it, and—subject to Gemini's account and feature rules—continue it in their own account.

Deleting the public link later can stop that Gemini URL from opening. It cannot recall an image someone already downloaded, a screenshot they captured, a copy they reposted, or information they moved into a continued chat.

The practical rule is simple: before creating a Gemini public link, treat every uploaded image and every visible detail in the shared conversation as material that could leave Gemini permanently.

Research cutoff: September 3, 2026 (America/Chicago).

What Is Confirmed

Google's current Gemini chat-sharing guide says sharing a chat creates a public link. Anyone with that link can read the conversation, even if the person who created it did not send the link to them directly.

The same guide states the image rule plainly: when an image is uploaded to a chat and that chat is shared, the uploaded image is available and downloadable from the shared chat.

Google also documents several related facts:

Google's separate image-generation guide confirms that generated images can also be downloaded directly or shared through a public image link. That is a different action from uploading your own image into a chat, but it reinforces the central boundary: an image shown through a public Gemini share is meant to be accessible outside the private chat view.

What Is Still Unclear

Google's help page defines what Gemini makes available. It does not prove everything that may happen after a link is shared.

The public documentation reviewed does not establish:

This is not evidence that every Gemini upload becomes public. The exposure begins when a user deliberately creates a public chat link that includes the uploaded image. Ordinary processing, Gemini Apps Activity, feedback, Workspace sharing, Gems, and public-link sharing are separate data paths with different controls.

What Does A Gemini Public Link Actually Share?

A Gemini public link is a shareable page for a snapshot of a conversation. It is not merely a link to one isolated answer.

Google says that creating the link shares the whole conversation up to the selected response. If the conversation includes an uploaded image, the image travels with that shared view and can be downloaded. If Gemini generated artifacts such as images, video, or Canvas documents from the conversation, those can also appear on the shared page.

That distinction matters because the sensitive item may not be the final answer. A shared conversation can reveal:

An ordinary-looking request such as “summarize this” can therefore expose both the file and its surrounding context when the resulting chat is shared publicly.

Is The Link Public If You Only Send It To One Person?

Yes, in the access-control sense Google documents. It is a public link, not an invitation restricted to one named recipient.

Sending the URL in a private message does not turn it into a private, recipient-bound share. The person can forward it. A copied URL can be pasted into another chat, email, ticket, note, or forum. Someone who was not the intended recipient can read the conversation if they obtain the link while it remains active.

This does not mean Google automatically posts every shared conversation to a search engine. It means the URL itself is the access mechanism. Possession of the link is enough for the shared page Google describes.

For the related discovery risk, see Can Claude Shared Chats Appear In Google Search?. Public-link access and search indexing are different questions, but both begin with content leaving the private chat view.

Does Google Remove Your Name From The Shared Page?

Google says it does not add your name or account to the URL or shared chat page. That is useful, but it is not anonymity.

The conversation or image may identify you without an account label. Examples include:

Removing a Google account name from the page reduces one direct identifier. It does not de-identify the material a person chose to share.

Can Someone Download An Uploaded Photo At Full Quality?

Google's sharing guide confirms that the image is downloadable, but the page reviewed does not promise that every viewer receives the untouched original byte-for-byte file.

Gemini could display or deliver a transformed copy, resized derivative, recompressed image, or different format. The public help text does not publish a universal rule for resolution, metadata preservation, filenames, color profiles, or compression across every supported image and device.

That uncertainty is not a privacy defense. A lower-resolution copy can still expose a face, medical result, contract clause, address, QR code, screen contents, or private photograph. If exact file fidelity matters, test with harmless synthetic data before using the sharing feature—but never use a sensitive original as the test.

What Happens If A Recipient Continues The Shared Chat?

Google says an eligible viewer can continue a shared conversation with Gemini on their own. That continuation is a separate copy or branch in the recipient's experience; it does not edit the creator's frozen public snapshot.

If the recipient has Keep Activity enabled, Google says the continued shared conversation can be stored in that recipient's Gemini Apps Activity. This creates an important deletion boundary:

  1. The creator makes a public snapshot.
  2. The recipient opens it.
  3. The recipient continues the conversation in their own Gemini account.
  4. The creator later deletes the original public link.

Step four can disable the original shared URL. It does not establish deletion of the recipient's continued conversation or any image the recipient already downloaded.

For a deeper treatment of that boundary, read If You Delete A Gemini Public Link, Does A Recipient Keep The Continued Chat?.

Does Deleting The Gemini Public Link Delete The Uploaded Image Everywhere?

No. Deleting the link is a revocation control for the Gemini-hosted public page, not a recall mechanism for copies already made.

After link deletion, Google says attempts to open that shared chat will be told the conversation no longer exists. That is valuable: it prevents the same live public URL from continuing to serve the shared snapshot.

But deletion cannot reliably reach material outside that page, including:

The same principle applies beyond Gemini. Deleting a source record usually does not prove that every derived, exported, reviewed, cached, or recipient-controlled copy is gone. See Does Deleting An AI Chat Delete Uploaded Files Too? for the broader file-lifecycle map.

Does Deleting The Original Gemini Chat Remove Its Public Link?

Do not assume those are the same control.

Google provides a dedicated Your public links area for viewing and deleting public links. That is strong evidence that users should manage the share link directly instead of relying on an unrelated history action.

If the goal is to stop public access, verify the link itself:

  1. Open Gemini's Settings and help area.
  2. Open Your public links.
  3. Delete the specific link, or use Google's option to delete all public links if that scope is intended.
  4. Open the old URL in a signed-out or private browser window.
  5. Confirm that Gemini says the shared chat no longer exists.

Then handle any separate copies according to where they went. A deleted Gemini link does not send remote-delete commands to recipients' devices.

For the source-chat distinction, see Does Deleting A Gemini Chat Delete Its Public Share Link?.

Can A Messaging App Keep A Preview After The Link Is Deleted?

Possibly. When a public URL is pasted into another service, that service may request the page and build a preview. The preview might contain a title, description, thumbnail, or other cached representation.

The Gemini help page does not publish a universal promise that every third-party preview is removed when the creator deletes the public link. Different messaging, social, search, archive, and security-scanning services have their own cache and retention behavior.

This is why link deletion should be paired with containment:

Do not wait for proof that someone misused the image before rotating a visible secret. Once a public copy existed, the secret should be treated as exposed.

A Practical SHARE Check Before Creating The Link

Use this five-part check before making a Gemini conversation public:

S — Scan The Entire Conversation

Review every prompt, response, upload, generated image, video, Canvas document, and quoted detail up to the point being shared. The final response is not the only content at risk.

H — Hide Or Replace Sensitive Material

Use a synthetic or redacted copy when possible. Crop irrelevant areas. Remove faces, signatures, account numbers, addresses, QR codes, access tokens, private filenames, and background details.

Do not rely on blur when the underlying text remains recoverable. For high-risk documents, recreate the needed example with fictional data.

A — Assume The Link Can Travel

Treat “anyone with the link” as an audience you do not control. If forwarding, reposting, or accidental disclosure would be unacceptable, do not create the public link.

R — Revoke And Recheck

When the share is no longer needed, delete the public link from Your public links and test the old URL while signed out. Revocation is complete only for the live link—not for earlier downloads.

E — Escalate Real Exposure

If the image contained credentials, health information, legal material, financial data, customer records, or another person's private data, follow the applicable incident, contractual, legal, and regulatory process. Link deletion alone may not close the event.

How To Test The Behavior Without Exposing A Real Image

A controlled test can show what your current Gemini interface exposes.

Create a harmless image containing unique synthetic markers such as:

PUBLIC-LINK-TEST-2026-09-03
NAME: SAMPLE PERSON
ACCOUNT: 0000-TEST-ONLY

Then:

  1. Start a new Gemini chat with no real personal data.
  2. Upload the synthetic image.
  3. Ask a simple question about it.
  4. Create a public conversation link.
  5. Open the link in a browser where you are signed out of Google.
  6. Check whether the image is visible and whether a download control works.
  7. Inspect the downloaded file's dimensions, format, filename, and metadata.
  8. Continue the chat using a separate test account, if eligible.
  9. Delete the original public link.
  10. Reopen the old URL and confirm the public page is unavailable.
  11. Check whether the already-downloaded file and continued chat remain.

This test establishes current behavior for the accounts, region, device, and interface tested. It does not create a permanent promise about every Gemini plan or future release.

Is A Shared Chat The Same As Sharing A Gem?

No. Google documents shared chats and shared Gems as different features.

A public chat link exposes a snapshot of a conversation, including the uploaded-image behavior discussed here. A shared Gem can expose the Gem's instructions and uploaded knowledge files to users who have access, with access levels and Google Drive sharing involved. Google's Gem-sharing guide warns that users with access can view uploaded files and that editors can change or delete the Gem's instructions and files.

Do not transfer the rules from one feature to the other. Before sharing either one, identify:

Does Turning Off Gemini Activity Prevent Public-Link Downloads?

No documented source reviewed says that it does.

Activity retention, model improvement, public sharing, and recipient downloads are separate controls. Turning off or deleting Gemini Apps Activity may change how Google retains activity associated with an account. It does not retract an image already made downloadable through a public link.

Likewise, a provider's model-training setting is not a sharing permission. A file can be excluded from foundation-model training and still be publicly exposed by a link the user created. Conversely, removing a public link says nothing by itself about training, safety review, operational records, or other retained copies.

For that separation, read Do AI Privacy Settings Apply To Voice, Files, And Images Too?.

Where OpenVeil Fits—and Where It Does Not

OpenVeil is an 18+ hosted AI workspace for people who want chat, files, private search, voice, images, video, and custom personas with a narrower chat-history boundary.

For normal private chat sessions, OpenVeil keeps chat history in the user's browser and does not maintain a server-side chat-history record. OpenVeil does not use prompts, uploaded files, images, audio, selected local-history context, or AI outputs to train foundation models. Active requests still require processing by OpenVeil and necessary AI, search, upload-processing, hosting, routing, security, billing, and infrastructure providers.

That can be a useful fit when the real goal is to privately analyze or discuss an image without creating a persistent provider-side chat-history record. The one-time free preview includes bounded chat, search, upload, voice, transcription, or single-image actions and requires no card.

But OpenVeil does not make a Gemini public link private. It cannot revoke a Gemini link, delete a recipient's copy, stop screenshots, recall downloads, remove third-party previews, or protect an image already posted elsewhere. It is not anonymous, fully offline, a zero-log service, a compliance certification, or a substitute for incident response.

The safer product choice does not cancel the sharing rule: if you deliberately copy sensitive material into a public page, the audience boundary changes.

Frequently Asked Questions

Can anyone download an image from a Gemini shared chat?

Google says an image uploaded to a chat is available and downloadable when that chat is shared through a public link. Anyone who obtains the active link can access the shared page under Google's documented rules.

Does the public link reveal my Google account?

Google says it does not add your name or account to the URL or shared chat page. The image, prompts, answers, posting account, or surrounding context may still identify you.

Does deleting the public link delete downloaded images?

No. It disables the Gemini-hosted shared page, but it cannot recall files, screenshots, reposts, previews, or recipient-controlled copies that already exist.

Can a recipient keep a continued Gemini chat?

Google says eligible viewers can continue a shared conversation on their own. If the recipient has Keep Activity enabled, that continued conversation can be stored in the recipient's Gemini Apps Activity. Deleting the creator's public link does not document deletion of that recipient-side copy.

Is the shared page updated when I edit the original chat?

No. Google says the public page shows the conversation as it appeared when the link was created. Later edits or continuation of the original chat do not update that snapshot.

Are generated Gemini images included too?

Google says shared conversations can include AI-generated artifacts, including images and videos. Its separate image guide also allows generated images to be downloaded or shared by public link.

Does OpenVeil prevent image downloads from public links?

No. OpenVeil offers a different hosted workspace and browser-local normal chat-history boundary. It does not control Gemini, prevent screenshots or downloads, or recall files from recipients.

The Bottom Line

A Gemini public link can make an uploaded image downloadable. Google confirms that behavior in its current sharing documentation.

The link is a public snapshot, not a private invitation. Removing your account name from the page does not de-identify the content. Deleting the link later can stop the Gemini page from serving the image, but it cannot erase copies that already left the page.

Before sharing, inspect the whole conversation, replace sensitive images with synthetic or redacted versions, assume the link can be forwarded, and verify revocation directly. If the image should never be downloadable by an uncontrolled audience, do not put it in a public chat link.

When privacy, account control, uploads, and search matter, OpenVeil gives you a private AI workspace designed for that job.