It's not an ominous mystery. Google is extremely explicit about what they collect from you and what they do with it.
https://myaccount.google.com/privacy
https://policies.google.com/privacy
I have not seen any evidence that they violate their own policies, even when I worked there a while ago and had internal knowledge.
And yes there is anaudit trail on accessing that stuff.
Logging into production servers is audited and triggers alarms. There's basically no-one who has "root" level access to a large number of boxes (when I left in 2013 there were only a handful of people who could login to arbitrary boxes and systems were being built so that their access would no longer be necessary). Logging into a server that holds live data would be investigated and so would running a custom query against a production database. The goal was to have it basically impossible for an engineer or admin to directly access data on boxes to force people to use the tools.
The tools themselves had a great permission system as well as a way for users to elevate their permissions in emergency (triggering an investigation). It worked well because it was also easy to create dummy databases to develop on (for example by requesting a database extract of your own location data).
In my career to date I have yet to see a more privacy conscious / secure approach to handling customer data.
If I had to trust a company with private data, there is no other company I would trust more to keep it safe from rogue employees and accidental leaks/hacks.
Eg last week: https://www.cnbc.com/2018/10/08/google-reportedly-exposed-pr...
Technically this might have been possible without any Google involvement, I agree with that, but given past involvement of other companies like e.g. AT&T with the NSA, this seems kind of unlikely to me. It just seems more credible to assume that some people in the higher ranks of Google willfully complied, and I wouldn't be surprised if something similar still occurred.
Your understanding of PRISM matches Greenwald's incorrect reporting, which was based on a high school dropout's misreading of some slides he found on the SharePoint system he administered. Greenwald could have gotten the story correct if he had bothered to run the documents by an expert first, but instead he made ridiculous errors like thinking that DITU is a government system running inside the companies' networks instead of the FBI's Data Intercept Technology Unit, whose court-ordered wiretaps PRISM actually accesses.
Whether Google violates their policies today is the wrong question to ask. Nothing about these policies is long-term legally binding for Google and they can be changed on a whim.
While Google includes this language:
> We will not reduce your rights under this Privacy Policy without your explicit consent.
I'm not sure that covers them increasing their own rights to collect, share, and sell data.
Remember - nothing lasts forever. One day Google will be in a financially desperate situation and their investors will demand that they do anything they can to stop the losses. Meanwhile they will have a valuable trove of data on millions of people.
This is not just hypothetical. When Google decided that Google+ was a priority and only real names should be allowed many were forced to de-annonymize formerly anonymous Youtube and Gmail profiles or be removed from the service.
The only real way to assure the security and privacy of data is to not collect it. The only way ensure that the likes of Google/Apple/Facebook won't collect the data is through legislation that gives privacy policies real teeth when they're violated and gives users power to choose to reject changes to these policies in whole or in part.
lineageos?