Google's AI somehow knew a game secret that existed only in a private Google Doc

Skye Jacobs

Posts: 2,074   +61
Staff
What we know so far: After a player asked Google's AI about unreleased content in his game, an indie developer says it returned a character name that existed only in a private Google Doc. Klub Kofta Studio, the solo developer behind the tower defense game Operation Octo, said the character, called Vantage Tripod, had not been announced or shared with anyone.

The issue began in the game's Discord server, where a player was asking Google's AI questions about Operation Octo. The answers sometimes included details the developer considered unusually specific for a small game.

The developer then asked the player to try questions about content that had not been revealed. Google's AI returned the name Vantage Tripod, according to a Reddit post by Klub Kofta Studio.

"Somehow, the AI spitted out the exact & highly specific character name 'Vantage Tripod', which I had never mentioned to anyone," the developer wrote. "As far as I know, the only place where the info exists in a digital form is inside one of my own Google Docs, and this was NOT me speaking to the AI!"

Posts from the indiedev
community on Reddit

Operation Octo was released on Steam in September 2025. The developer said the game's limited online presence made the answer more alarming, not less.

"My game is not big enough for there to be much noise out there to confuse Google's AI, so I guess that's why it managed to give actual, scarily real leaks on my game (without being confused by online speculations), and I have no idea how it knew all this," the developer wrote.

The developer later told Polygon that the character name was not included in the game's code, files, or Steam data.

Google said it does not use private Workspace material, including Drive files and Docs, to train its foundational AI models, including Gemini. The company said publicly shared documents can be indexed if links appear online where search crawlers can find them. It also pointed to Google Drive's sharing controls, which let users decide who can access individual files.

The available evidence does not establish how Google's AI produced the character name. It could not be independently recreated after the Reddit post circulated. The developer said that later searches began returning the name while citing the Reddit post as the source.

"I'd like to say that my specific case is no longer replicable, and the AI would simply give the name 'Vantage Tripod' then point to the Reddit post as source now," the developer said.

That makes it harder to separate the original response from what the AI can now retrieve from the public web. Once a claim appears in a widely shared post, AI search products can cite that post back to users, even if the original answer remains unexplained.

Google's AI Overviews have increasingly used Reddit material in search results. That can be useful when users are looking for firsthand discussion, but it can also create problems when posts contain rumors, jokes, or unsupported claims.

AI-generated search answers can also be manipulated. A YouTuber last year persuaded Google's AI search to repeat a false claim that Grand Theft Auto 6 would have a "twerk button."

For developers, the case is a reminder that unreleased project information can be difficult to contain once it reaches a public AI answer or online discussion. It also raises a basic question for AI search systems: when a response includes obscure information, users need a clear way to know whether it came from a reliable source, a public document, or the model itself.

Permalink to story:

 
Maybe the author used the name in previous conversations with the chat agents?

This is all bit unscientific. "Random guy on the internet claims google did this." Can't reproduce.
 
Isn’t google known for saying they dont read your emails, but a automated system still collects keywords? This kind of system could connect these words to the game without anyone ”reading” the docs.
 
I don't understand what's the purpose of this article.

Someone on Reddit claimed something outlandish, which happens like a million times daily.
Nobody can confirm the outlandish claim, even the author himself (what a surprise!).

So, once again, the purpose of this article is ....
 
This is definitely interesting, but the headline is getting ahead of the evidence.

If Google’s AI truly pulled an unreleased game name from someone else’s private Google Doc, that’s a massive privacy problem. But right now, we don’t actually know that happened. The name could have leaked through a build, repository, Discord, metadata, shared access, or even something in the prompting we weren’t shown.

The easiest way to test it is simple...put completely made up nonsense names in private Docs that exist nowhere else, then see if unrelated accounts can get Gemini to reveal them.

TechSpot could actually run that experiment themselves and add something useful to the story instead of just regurgitating internet gossip.

If it works, Google has a serious problem. Until then, this is an interesting claim, not proof that Gemini is secretly reading everyone’s private Docs.

TS dropped the article with a title that practically screams “PROVEN” when the evidence is nowhere near that point yet.
 
"Google says it doesn't train AI on private docs, but this developer still can't explain what happened"


This developer can, Google lied and trained its AI on private docs. They took "Don't be evil" out for a reason.
 
"Google says it doesn't train AI on private docs, but this developer still can't explain what happened"


This developer can, Google lied and trained its AI on private docs. They took "Don't be evil" out for a reason.
That’s quite a leap.

“Google says it doesn’t train on private Docs, and this developer can’t explain what happened” does not magically translate into “Google lied and trained on private Docs.”

There are still plenty of other possibilities...leaked builds, repositories, shared access, metadata, prompting we haven’t seen, or some other source entirely.

If someone can reproduce this with completely fabricated information stored only in a private Doc, then we have evidence and Google has a serious problem.

Until then, you’re not proving Google lied...you’re just picking the explanation you already wanted to believe.
 
That’s quite a leap.

“Google says it doesn’t train on private Docs, and this developer can’t explain what happened” does not magically translate into “Google lied and trained on private Docs.”

There are still plenty of other possibilities...leaked builds, repositories, shared access, metadata, prompting we haven’t seen, or some other source entirely.

If someone can reproduce this with completely fabricated information stored only in a private Doc, then we have evidence and Google has a serious problem.

Until then, you’re not proving Google lied...you’re just picking the explanation you already wanted to believe.
Or more likely he's picking the most likely explanation given years of bitter experience from Google maybe?
 
Or more likely he's picking the most likely explanation given years of bitter experience from Google maybe?
And being skeptical of Google is perfectly reasonable. They’ve earned plenty of criticism over the years.

But “Google has done questionable things before” still isn’t evidence that this specific thing happened the way the headline implies. Past behavior can justify suspicion...it doesn’t prove the mechanism.

That’s really my whole point. Test it, reproduce it, establish that genuinely private information can be retrieved by an unrelated account, and then hammer Google with the facts.

Otherwise we’re replacing investigation with “well, it sounds like something Google would do,” which is exactly how gossip becomes accepted as fact. That makes us no better than the gossip train running across the rest of the internet.
 
And being skeptical of Google is perfectly reasonable. They’ve earned plenty of criticism over the years.

But “Google has done questionable things before” still isn’t evidence that this specific thing happened the way the headline implies. Past behavior can justify suspicion...it doesn’t prove the mechanism.

That’s really my whole point. Test it, reproduce it, establish that genuinely private information can be retrieved by an unrelated account, and then hammer Google with the facts.

Otherwise we’re replacing investigation with “well, it sounds like something Google would do,” which is exactly how gossip becomes accepted as fact. That makes us no better than the gossip train running across the rest of the internet.
Just a couple of months ago they added peoples gmail accounts to their training data and made it opt-out with no reasonable notification to people that this was happening... They are the second least ethical company on this planet only toppled by the mighty Meta.
 
Just a couple of months ago they added peoples gmail accounts to their training data and made it opt-out with no reasonable notification to people that this was happening... They are the second least ethical company on this planet only toppled by the mighty Meta.
I’m perfectly willing to criticize Google when the facts support it, but this is exactly why we need to separate facts from internet retellings. This is a retell.

Google did not simply announce, “We’re training Gemini on everyone’s Gmail unless you opt out.” Google explicitly disputed that claim when it circulated, and its Workspace policy still says emails and documents are not used to train the underlying Gemini models without permission.

There is an important nuance...if you deliberately connect Gmail/Drive to Gemini and have Gemini Activity enabled, Google says summaries, excerpts and inferences produced from relevant emails/files may be used to improve and train its models. That is worth scrutinizing. But that is very different from dumping everyone’s entire private Gmail inbox into Gemini’s training set.

And calling Google the “second least ethical company on the planet” may be a fun opinion, but it isn’t evidence for what happened in this particular case.

Distrust Google all you want...I certainly don’t suggest blindly trusting any trillion dollar corporation. Just don’t let distrust substitute for proof, or we’re right back aboard the internet gossip train.
 
Back