As an IT administrator, ensuring the privacy and security of your organization's communication tools is a top priority. Google Beam is designed to make remote communication feel more natural and true-to-life by utilizing advanced spatial processing. This document describes how we process, secure, and protect certain data that powers this 3D experience, providing you with the technical oversight necessary for enterprise deployment.
How the technology works
Google Beam uses an array of cameras and microphones to detect the users' face, voice, and their surroundings. Google Beam's algorithm uses face and voice data and certain data derived from face data, voice data and data regarding users' surroundings (such derived data, "Beam Model Data") from the video streams, including to infer depth and create a 3D model of them and their surroundings. This allows the system to adjust perspective in real time and ensure call cameras remain aligned in order to capture people and items in 3D space. Certain Beam Model Data may be considered biometric data in certain jurisdictions.
For additional detail on data collection, use, and storage see the Data Processing section.
Core privacy commitments
Google Beam adheres to the following commitments:
- No advertising: Google doesn't sell your personal information. Beam Model Data is not used for advertising purposes.
- No AI training: Google doesn't use your 3D models or video or audio streams to train its foundational or generative AI models.
Enterprise-grade security
Google Beam protects your data using a defense-in-depth strategy:
- Encryption in transit: All video and audio data streams are encrypted as they travel between the Beam-enabled device and Google Cloud using industry-standard protocols, including Datagram Transport Layer Security (DTLS) and Secure Real-time Transport Protocol (SRTP).
- Hardware-level security: The Google Beam-enabled device employs robust security measures to maintain system integrity and prevent unauthorized tampering with its components.
- Administrative control: Admins manage Google Beam-enabled devices through familiar, centralized tools—the Google Admin console for Meet users or the Zoom web portal for Zoom users.
Data processing
Data handling
Google acts as a data processor for the video and audio streams of a Google Beam call and Beam Model Data. This means that Google will only process this data as instructed by the customer.
Google acts as a data controller for Google Beam data such as account information, billing history, and diagnostic device telemetry, meaning Google may determine the purpose and means of processing.
Data retention and deletion
Video and audio streams processed during users' Google Beam calls are deleted promptly upon termination of the call. Beam Model Data is either deleted promptly upon termination of the call or may be stored locally on the device for up to 72 hours and then deleted.
FAQs
Is this data used to identify me?
No, this data is not used to identify specific individuals.
Where is data processed and stored?
Data processing occurs on your local Google Beam-enabled device and on Google cloud services. Beam Model Data is generated and stored directly on the device. Video and audio streams are sent to a Google cloud service where Google Beam algorithm enables the creation of a 3D model.
How are recordings of Google Beam calls stored?
Recording functionality is only supported on Google Beam-enabled devices for standard video calls at this time and is not supported for 3D Google Beam calls.
If you are using Google Beam for Meet: Recordings are managed in accordance with Meet's security and privacy practices. Learn more about Google Meet Retention policies.
For more details about Google Meet security and privacy and best security practices for meetings, see Google Meet security & privacy for IT admins.
If you are using Google Beam for Zoom: Google doesn't store any recordings of standard video calls for Google Beam for Zoom. See the Zoom documentation for more details about Cloud Recordings and local computer recordings—they are also subject to your organization's Zoom Terms of Service.
Compliance & certifications
Google Beam is built on Google's globally recognized secure infrastructure. We are committed to a robust compliance posture including compliance with applicable local laws and regulations, like GDPR where applicable.
Google Beam is pursuing formal certifications:
- ISO & SOC: We are targeting ISO 27001, ISO 9001, SOC 1, SOC 2, and SOC 3 compliance to be complete at or shortly after our General Availability launch in 2026.
- Industry Standards: We are actively developing our roadmap for additional certifications, such as HIPAA, FedRAMP, and FINRA, to support customers in highly regulated sectors.