Earlier quoted context omitted.
...until it's broken into. I suspect that chances of would-be burglars or identity thieves breaking into Google data are pretty slim, in comparison to a home-installed system. OTOH both Google and a private person can be strong-armed by a court order, or even a three-letter agency, to open up their AI knowledge vaults.
The difference is one of targeting. It's like saying "People would never break into a bank, when they could break into someone's house and steal their stuff" It may be easier to break into someone's home-brew system, but generally it would be unlikely to happen unless you were being otherwise targetted. Whereas google has a lot of users data, which could make it a more attractive target.
Just how "home-brew" are we talking here? If there's any web-facing code that you didn't write yourself, whether commercial or open-source or whatever, that's a target for attackers that just scan everything looking for known vulnerable services.
If it is entirely custom, I'm fairly sure there are a few classes of common security errors that can be reasonably well tested for without direct human involvement. Which brings back the threat of attackers just scanning for all available targets.