Skip to content

Acceptable Use & Anti-Spam Policy

Effective 2026-08-17 · Version 2.1

This Acceptable Use & Anti-Spam Policy (the "Policy" or "AUP") governs your use of Lonzo (the "Service"), operated by Vista del Lago Software LLC, a Delaware limited liability company ("we," "us," or "our"). It is incorporated by reference into, and is part of, the Terms of Use. Capitalized terms not defined here have the meanings given in the Terms of Use. If you violate this Policy, we may suspend or terminate your access as described in Section 9 and in the Terms of Use.

This Policy matters especially because the Service acts on your behalf — it sends email to the people you correspond with through your connected Google (Gmail) account as you, organizes your mailbox, and creates, changes, and cancels calendar events that cause Google to notify attendees. Coordination messages the Service originates to third-party participants at your direction also go out through your own connected Gmail account, from your own address. We send mail from our own addresses on lonzo.ai for one purpose: mail about your own account. Because those communications go out under your name or ours, the anti-spam rules in Sections 4 through 7 are central to this Policy.


1. Scope, Applicability & Monitoring

1.1 Who is bound. This Policy applies to everyone who uses the Service, and to anyone you enable or direct to use it. You agree not to violate this Policy and not to help or encourage anyone else to violate it.

1.2 No duty to monitor; right to act. We have no obligation to monitor use of the Service, but we may do so, and we may investigate suspected violations, remove or disable content or actions, rate-limit or block traffic, and suspend or terminate accounts. We may take these steps when we reasonably believe this Policy has been violated.

1.3 Automated enforcement. Because the Service is itself an automated agent, our monitoring and enforcement may be carried out in whole or in part by automated systems.

1.4 Underlying providers' acceptable-use policies. The Service operates on top of, and transmits your content to, third-party providers — in particular Google (Google Workspace / Gmail, Calendar, Contacts, and Tasks APIs) and Amazon Web Services, including Amazon Bedrock, through which AI processing occurs. Your use of the Service is additionally subject to the acceptable-use, prohibited-use, and content policies of those providers, including Google's Terms of Service and API and acceptable-use policies and Amazon's AWS Acceptable Use Policy, AWS Service Terms, and any Amazon Bedrock or AWS-model provider acceptable-use terms, each as they may be updated. You agree not to use the Service in any way that would cause us or you to violate those providers' policies, and a use that is prohibited by an applicable underlying provider's policy is also prohibited under this Policy. Where those policies impose obligations that pass through to end users, you agree to comply with them.


2. Prohibited Uses — System & Service Integrity

You may not, and may not attempt to, or help anyone else:

2.1 probe, scan, or test the vulnerability of the Service or any related system or network, or breach or circumvent any security or authentication measure, except under an authorized security-research program we expressly permit (see Section 2.7);

2.2 reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, architecture, models, prompts, or underlying components of the Service, except to the extent this restriction is prohibited by applicable law or as permitted for authorized security research (see Section 2.7);

2.3 scrape, harvest, crawl, or bulk-extract data or content from the Service, or access data or accounts not intended for you;

2.4 introduce or transmit any virus, worm, malware, or other harmful code, or upload content designed to disrupt, damage, or gain unauthorized access to any system;

2.5 overload, flood, or otherwise impose an unreasonable or disproportionate load on the Service or its infrastructure, or interfere with or disrupt the Service, servers, or networks (including through denial-of-service techniques);

2.6 bypass, disable, or circumvent rate limits, usage limits, access controls, or geographic or account restrictions; use proxies or IP masking to evade blocks; or create accounts by automated means or in bulk, or abuse referrals, trials, promotions, or billing mechanics, except as permitted for authorized security research (see Section 2.7);

2.7 Authorized security research. Notwithstanding Sections 2.1, 2.2, 2.6 and 2.8, good-faith security research conducted in accordance with our Vulnerability Disclosure Policy at lonzo.ai/legal/vulnerability-disclosure, and within its stated scope and rules of engagement, is permitted and authorized (Terms of Use Section 4.4). Report suspected vulnerabilities to security@lonzo.ai. Sections 2.3, 2.4 and 2.5 are not carved out and continue to apply in full: research does not authorize reaching another person's data or account, transmitting harmful code, or degrading the Service, and the policy's rules of engagement say the same thing.

Why this carve-out names four Sections and not one. Until 2026-08-17 it named only Section 2.1, and the Vulnerability Disclosure Policy puts things in scope that Section 2.1 does not reach — our Android application's local storage and inter-process surface, which cannot be examined without the analysis Section 2.2 prohibits, and the behavior of an AI assistant that can send mail as you, whose most serious failure mode is a crafted input that makes it act outside your instructions. A prompt-injection finding is the highest-severity report this Service can receive, and Section 2.8 forbade looking for it with no exception. So we invited research and then prohibited it a page later, which is the worst of both: a researcher reading carefully would stop, and one who did not would rely on a safe harbor with a hole in it.

2.8 Protecting the AI system. You may not attempt to manipulate, jailbreak, or subvert the Service's AI systems or the underlying inference infrastructure — for example, through prompt injection or crafted inputs — to (a) cause the Service to take actions you are not authorized to take or that violate this Policy, (b) extract system prompts, model weights, or non-public system behavior, (c) generate content prohibited by this Policy, or (d) send communications the recipient has not consented to receive, except as permitted for authorized security research (see Section 2.7) — a prompt-injection weakness is a vulnerability, and we would rather a researcher demonstrate one to us against their own test account than leave it for someone with no interest in telling us. You may not use the Service to generate spam, abuse, or other prohibited content at scale.


3. Prohibited Uses — Wrongful & Illegal Conduct

You may not use the Service to, or to help anyone:

3.1 violate any applicable law or regulation, including data-protection, anti-bribery, anti-corruption, anti-money-laundering, export-control, or sanctions laws;

3.2 harass, threaten, stalk, bully, defame, or intimidate any person, or promote violence or hatred against any person or group on the basis of a protected characteristic;

3.3 impersonate any person or entity, misrepresent your affiliation with any person or entity, or deceptively disguise AI-generated content as human-authored where doing so is misleading or unlawful;

3.4 commit or facilitate fraud, phishing, deceptive schemes, or pyramid or other unlawful monetization schemes;

3.5 infringe or misappropriate any patent, copyright, trademark, trade secret, or other intellectual-property or proprietary right, or violate any person's privacy or publicity rights (see the Copyright, DMCA & Trademark Policy);

3.6 produce, store, or transmit content that sexually exploits or endangers minors (real or depicted); promote terrorism, terrorist organizations, or hate groups; encourage or glorify self-harm, eating disorders, or suicide; distribute non-consensual intimate images or deceptive deepfakes; or distribute gratuitously graphic or violent content;

3.7 use AI outputs to make or support automated decisions that produce legal or similarly significant effects about a person (for example, in credit, employment, housing, insurance, or healthcare) without meaningful human review; and

3.8 publish or gather other people's private, confidential, or personal information without authorization; and

3.9 rely on the Service to process protected health information or other special-category data. We do not offer a HIPAA Business Associate Agreement (BAA), and the Service is not designed or authorized for use as a HIPAA-covered service. You may not use the Service to create, receive, maintain, transmit, or otherwise process, and you may not rely on the Service to safeguard, any "protected health information" (PHI) as defined under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, unless we have signed a written agreement (including a BAA) expressly permitting it — which we do not currently offer. The same restriction applies to other categories of especially sensitive or regulated data whose processing requires a separate written agreement or heightened safeguards we have not agreed to provide, including (as examples) data subject to the Gramm-Leach-Bliley Act, payment-card data subject to PCI DSS, or biometric data regulated by statutes such as the Illinois Biometric Information Privacy Act. If health or other special-category information incidentally appears in your mailbox or other connected Google data, the Service may process it only as part of providing the Service to you and subject to the Privacy Policy; but you must not use the Service as a system of record for, or to knowingly route, such data, and you are responsible for any regulated data you introduce.


4. Anti-Spam — No Unsolicited or Abusive Communications

Because the Service sends email — through your connected Google (Gmail) account as you, both to the people you correspond with and to the participants of coordination you initiate — you may not use the Service to:

4.1 send spam or unsolicited bulk or commercial email or messages, chain letters, or duplicate or saturation content;

4.2 mail-bomb, flood, or otherwise send communications intended or likely to overwhelm, harass, or disrupt any recipient or system;

4.3 send communications with forged, spoofed, or misleading headers, sender identities, routing information, or subject lines, or otherwise disguise the origin of a message;

4.4 send phishing messages or communications designed to deceive recipients into disclosing information or taking harmful action;

4.5 use the Service's send-on-behalf capability to contact a recipient who has opted out of, unsubscribed from, or asked not to receive communications, or to evade or circumvent any recipient's opt-out; or

4.6 send communications at a volume or rate that, in our reasonable judgment, is abusive, and we may impose and enforce rate limits and outbound-volume limits and block or throttle traffic to protect recipients, our systems, and our sending reputation.


5. No Contacting People Outside the Service Without Permission

5.1 You may not use email addresses, phone numbers, or other contact or personal information that you surface, obtain, or access through the Service to contact people outside the Service without that person's express permission, and you may not export or use such information to build mailing or contact lists for use outside the Service.

5.2 Coordination outreach. Where the Service, at your direction, contacts third-party participants (for example, people drawn from your contacts) to help arrange a meeting or event you are organizing, that capability may be used only for legitimate, expected, transactional coordination of the specific event you are arranging. It may not be used for marketing, advertising, promotion, or any communication unrelated to the coordination you initiated. You are responsible for having a lawful basis to contact each third party, and outreach content is limited to the transactional coordination details of your event. Coordination messages the Service originates are sent as you, through your own connected Gmail account, and are subject to Section 6.1(c).

5.3 Our reciprocal commitment. We do not use the contact information of third-party participants that the Service surfaces or that you provide to send them our own marketing.


6. CAN-SPAM, Opt-Out & SMS Controls (Outbound Communications)

Where our systems transmit communications on your behalf, both you and we must comply with applicable communications laws. Accordingly:

6.1 Email / CAN-SPAM. Email leaves the Service on four distinct paths, and different rules apply to each. All outbound email, on every path, must have accurate header and sender information.

(a) Sent as you, through your own Gmail account. Email the Service sends to the people you correspond with is originated from your own connected Google (Gmail) account and is sent only after you have approved that send, through the human-approval boundary described in the Terms of Use — here, by reviewing the message itself. It goes out from you, with your own address in the From header. You are responsible for the accuracy and honesty of the sender identity and content of each message you approve or direct, and unsubscribe and opt-out requests must be honored.

(b) Sent by us from a Lonzo address. We also operate our own sending addresses on lonzo.ai, and we use them for one purpose: service and account mail — address verification, password reset, and similar messages about your own account, sent to the address on your account. These are transactional messages that form part of providing the Service: they are not marketing, we will not use them to advertise to you, and you cannot opt out of them for as long as you hold an account.

(c) Coordination messages to third-party participants. Where the Service originates a coordination message to a third-party participant at your direction (Section 5.2), it is sent as you, through your own connected Gmail account — your own address is in the From header, and a participant who replies replies into your mailbox. Every such coordination message carries: a visible unsubscribe link in its footer; and a List-Unsubscribe header (an HTTPS one-click URI where one can be minted, with a mailto: fallback, both addressing the same opt-out). You may not remove, disable, or circumvent either of them, and no setting turns either of them off. One further element — the line that describes Lonzo as the assistant coordinating on your behalf — is an attribution preference you can turn off in your settings; turning it off does not and cannot suppress the two compliance elements above, and we distinguish them here because the difference is what makes the setting safe to offer. Because the message goes out from your address and not ours, it identifies you as its sender and carries no Lonzo postal address; you are responsible for the sender identity these messages present, as you are on path (a).

(d) An unsubscribe request you asked us to send. When you ask to be taken off a sender's mailing list and that list publishes a mailto: unsubscribe address, the Service sends one request to it as you, through your own connected Gmail account, after you confirm the action and the sender or domain it applies to. The message is not a commercial message and carries no content of yours: its subject and body are the single word unsubscribe, and it is addressed only to the address that sender published for unsubscribing. It is sent once, per sender you name; it is never sent to the people you correspond with; and where a setting has the Service deal with bulk mail automatically, the Service files the sender away with a mail filter and sends nothing. You may not use this path to send anything other than an unsubscribe request, and the Service provides no way to do so.

Opt-outs apply across paths. An opt-out is permanent and never expires, and it is not limited to the message, event, or task that prompted it — once a recipient opts out of a medium, we stop sending to them on that medium for every later message from your account, on every path described in this Section. An opt-out a recipient gives to one account does not by itself silence a different account that independently holds that recipient's address, because a recipient's record belongs to the account that holds it. Separately and in addition, an address that reports as spam a message we sent from one of our own addresses (path (b)) is added to our email provider's suppression list, which stops the entire Service from sending to that address from our addresses. A provider suppression entry is retained indefinitely by design — it holds the address and the reason, nothing more — because discarding it is how the sending would silently resume; being keyed to the address rather than to an account, it therefore survives an account deletion. The per-account opt-out record is the other one: it never expires and no setting turns it off, but it is part of the account data of the account that holds it, so it is removed when that account is deleted, along with that account's ability to send at all. The Data Retention & Deletion Policy states both. A spam report against a message sent through your own Gmail account (paths (a), (c) and (d)) goes to Google, affects your own sending reputation, and does not reach that provider list — which is why the unsubscribe link and header on path (c) are the controls that register an opt-out with us.

A reply asking us to stop is itself an opt-out. On path (c) a participant's reply lands in your mailbox rather than on our unsubscribe route, so the unsubscribe link and header cannot be the only controls that work: every coordination reply is read, before it is routed anywhere else, for a fixed list of phrasings — "wrong number," "not me," "you have the wrong person," "unsubscribe," "stop emailing me," "take me off" and the like. A match records the opt-out that the pre-send check above reads, stops the outreach to that address, and tells you why it stopped. The list is matched literally rather than interpreted, which is what makes it reliable and also what bounds it: a phrasing it does not carry reaches you as an ordinary reply, and the Guest & Participant Terms, Section 7, tells participants exactly that. You may not instruct or configure the Service to disregard such a reply, and re-adding an address that opted out in order to contact it again is a violation of this Policy.

6.2 SMS / TCPA (not currently offered). The Service sends no SMS or text messages. If it later sends SMS or text messages on your behalf, those messages require the recipient's consent as required by law, must honor STOP / START and similar opt-out and opt-in keywords, may not contain marketing or promotional content, and must comply with applicable carrier and messaging-aggregator acceptable-use policies (for example, the messaging provider's AUP) and with the TCPA and CTIA guidelines. Additional SMS terms may be set out in a separate SMS policy.

6.3 Rate limits and controls. We maintain rate limits and other technical controls to prevent abuse of these features. You may not circumvent them, and we may adjust or enforce them at any time. Misuse of the send-on-behalf, coordination-outreach, or calendar-notification features to spam, harass, or deceive recipients is a serious violation of this Policy and may result in immediate suspension or termination.

The Service's only outbound communications channel is email — it sends no SMS. Email leaves on the four paths described in Section 6.1: sent as you, through your own connected Gmail account, with your own address in the From header — to the people you correspond with, as a coordination message to the participants of coordination you initiate, and as an unsubscribe request to a list you asked to leave; and sent by us from a Lonzo address, for account and service mail only.


7. Calendar Notifications

The Service creates, changes, and cancels calendar events, and Google may automatically email affected attendees. You may not use assistant-driven calendar activity — for example, repeated creation, rescheduling, or cancellation of events — to spam, harass, or disrupt attendees, or to cause them to receive unwanted communications. You are responsible for the events you or the Service create, change, or cancel and for the notifications they generate.


8. Trademarks & Branding

You may not use the Lonzo, Lonzo Agenda, Lonzo Assistant, or Lonzo.AI names, logos, taglines, or other marks without our prior written permission, and you may not remove, obscure, or alter any of our proprietary notices or branding. Full trademark terms are in the Copyright, DMCA & Trademark Policy.


9. Enforcement, Reporting & Consequences

9.1 Consequences. If we determine, in our reasonable judgment, that you have violated this Policy, we may take any action we consider appropriate, including removing or disabling content or actions, imposing rate limits, suspending or terminating your account, revoking the authorization you granted under the Terms of Use, and reporting to law enforcement. Severe or illegal violations may result in immediate termination without notice. We may report and remove child sexual-abuse material as required by law.

9.2 Reporting abuse. To report a suspected violation of this Policy, contact us at abuse@lonzo.ai. We may, but are not obligated to, act on any report.

9.3 Disclosure. We may disclose information about suspected violations to law enforcement or affected third parties as permitted or required by law and as described in the Privacy Policy.


10. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated as described in the Terms of Use, and your continued use of the Service after a change takes effect means you accept the updated Policy.


11. Contact

Vista del Lago Software LLC 18381 Vista del Lago, Yorba Linda, CA 92886, USA Abuse / anti-spam reports: abuse@lonzo.ai · General / legal: legal@lonzo.ai


All legal documents · Help · Lonzo home