AI & Data-Training Disclosure
Effective 2026-08-18 · Version 2.7This disclosure explains how Lonzo (the "Service"), operated by Vista del Lago Software LLC, uses artificial intelligence to process your data: which models we use and where they run, what data is sent to them, whether your data is used to train any model, how a human stays in the loop, and the limits of AI output. It forms part of, and should be read with, our Privacy Policy (see its Section 6) and our Google API Services Limited Use Disclosure.
1. What the AI does
Lonzo is an AI executive assistant that works over your connected Google account (Gmail, Calendar, Contacts, and Tasks). Its AI features include summarizing and triaging mail, extracting and organizing the people and commitments in your data into a memory graph, drafting replies and messages in your voice, suggesting and preparing calendar events and tasks, and answering your questions in natural language. These features rely on large language models and text-embedding models.
2. Which models we use, and where inference runs
All model inference for the Service is performed through Amazon Web Services' managed AI platform, AWS Bedrock. We use the following model families on Bedrock:
- Amazon Nova — for fast, lightweight reasoning and classification;
- Anthropic Claude — for higher-quality reasoning and drafting;
- Amazon Titan (text embeddings) — to generate the vector embeddings used to organize and search your memory graph.
Where the AI runs. On every plan, the assistant's orchestration runs on our server-side infrastructure (the "Reactor") and the actual model inference is executed by AWS Bedrock. The prompt content sent to the model — which can include the data described in Section 3 — therefore transits to AWS on every plan. We do not run the language models on your device, and we do not represent that your data stays on your device. Your device performs only local presentation work (rendering and ordering your Agenda, and an offline read cache of what it has already been shown).
3. What data is sent to the models
To perform a given AI task, we send the model only the content needed for that task, which may include:
- Gmail content — subject lines, message body text, and sender and recipient information;
- Calendar data — event titles, dates, times, attendees, and descriptions;
- Contacts data — names and related contact details used for context;
- Tasks data — task lists and items;
- Prompts derived from your memory graph — the AI-derived concepts and relationships built from your data, which may contain personal data about you and about third parties;
- Your instructions and questions to the assistant.
Voice is transcribed by your device, not by us. When you speak to the assistant, your device's own speech-recognition service produces the transcript (see the Privacy Policy, Section 3(g), for what that service may do with the audio), and only the resulting text is ever sent to a model. We do not send or store your voice audio. We do not create or store voiceprints or any other biometric identifiers.
Embeddings. We use the Amazon Titan embedding model to convert your content into vector embeddings that power search and context retrieval within your memory graph.
4. Training — is your data used to train models?
We separate two distinct questions: whether we train our own ("first-party") models on your content, and whether the third-party model providers on Bedrock train on it.
4.1 First-party training (by Vista del Lago Software LLC)
We do not use the content of your connected Google account, your voice text, or your derived memory to train first-party Lonzo models. If we ever wish to use your content to improve our own models, we will do so only on an explicit opt-in basis, with clear notice and a control you can turn off.
4.2 Third-party training and retention (by Bedrock model providers)
We send your content to the model providers on AWS Bedrock (Amazon and Anthropic) only to generate the response you requested, not to help them build their models.
Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.
"By default" is doing real work in that sentence, so here is what would change it. Bedrock's zero-retention posture is the default and not a law of physics: there are features a customer like us can switch on that would make prompt or response content persist, and until 2026-08-18 this section named none of them, which left an unconditional-sounding promise resting on three settings we had never written down anywhere.
- Request logging. AWS offers a switch that copies every prompt and every response into the customer's own logs. Turning it on would not change what AWS retains, so the sentence above would stay literally true while your mail, your calendar and whatever health or family detail they contain sat in an ordinary log store — outside the per-account encryption described in Privacy Policy Section 10, and outside the deletion process described in our Data Retention & Deletion Policy. It is off. The credentials our servers run with are restricted to asking a model for a response and cannot turn it on; changing that takes a deliberate change to our infrastructure definition, which is the thing the check below reads.
- Prompt caching. A model call can ask AWS to keep part of the prompt for a few minutes so that a follow-up call is cheaper and faster. That is a performance feature, and an appealing one — which is exactly why it is named here: it would be added for speed by someone with no reason to be thinking about this page, and it does mean prompt content is held after a request completes. We do not use it.
- Content filters. A Bedrock guardrail evaluates prompts and responses in a separate service that keeps its own record of what it blocked. We use none.
How you can hold us to that. Since 2026-08-18 an automated check fails our build if our inference code acquires a cache point or a guardrail, if anything in our infrastructure definition enables request logging, or if the permissions our servers hold widen beyond asking an allow-listed model for a response. The same check requires this section to still say what it says — so the mechanism cannot be switched on and this page quietly left standing. What it cannot see is a setting typed directly into a cloud console by someone with administrative access, which is why the written instruction not to do it sits in the infrastructure and inference files that person would be editing, and the check requires it to be there.
4.3 Our retention of your assistant conversations
Separately from training, this section states plainly whether we store your assistant conversations — the prompts you send and the responses you receive:
- Every plan (server-side). Your assistant conversation history is stored on our server-side infrastructure (the "Reactor"), protected by the encryption controls described in Privacy Policy Section 10, and retained until you delete it or close your account — it is under your control. You can delete a single conversation in the app at any time, and ask us to delete your entire history by writing to privacy@lonzo.ai. On account deletion it is removed from our live systems with the rest of your data, and residual copies age out of our encrypted backups on the rolling 90-day cycle; see the Data Retention & Deletion Policy, which also states what we deliberately do not claim about key destruction.
- On your device. Your device may hold a local cache of conversations and Agenda content it has already displayed, so the app works offline. You can clear it by uninstalling the Service or through your device's own app-storage controls.
This first-party retention is distinct from the third-party Bedrock zero-retention posture described in Section 4.2: Bedrock retains no prompt or response content after a request completes, whereas the conversation history described here is what we keep so the assistant has continuity across your sessions. See Privacy Policy Section 9 (Data retention) for how this fits our overall retention practices.
5. Consent
We capture your explicit AI-processing consent at the Google-connect step, as a separate tick. Every surface that offers to connect a Google account shows, on the same screen as the Connect control: which third-party AI models your content is sent to and where they run (Section 2), that your content is not used to train them and is not retained by them after each request (Section 4), that nothing is sent until you connect an account, and that your mail and calendar will often contain sensitive details — health appointments, religious or political activity, trade-union membership — which are processed along with everything else. A link to this full disclosure sits beside it.
Beneath that is a separate checkbox, unticked by default. The Connect control does nothing until you tick it. Your agreement is therefore a distinct act rather than a consequence of signing up, of accepting our Terms, or of Google's own permission screen — which grants Google's API access and says nothing about our AI processing. The tick is one act with two purposes: it is the third-party-processor permission this disclosure is about, and it is the explicit consent under GDPR Art. 9(2)(a) that Privacy Policy Section 7 relies on for special-category data incidentally present in your account. One decision about one set of data, so one record.
What we record. That you agreed, when, the revision of this disclosure you were shown, and the version of the Privacy Policy published at that moment. The record is held against your account where you cannot alter it, and it is shared across surfaces — agreeing in the setup flow is not asked again on the Account screen, and vice versa. If a write does not land, the box stays unticked and Connect stays inert: we will not report a consent we did not store.
Reviewing or changing your choice. The tick is shown, reflecting what we actually hold, on every screen that offers to connect — including the Reconnect prompt shown when a permission is missing. To withdraw, disconnect your Google account (Account → Connections → Disconnect), which revokes our access and stops further processing, or delete your account. That is one action, as easy as the one tick that gave the consent. We do not offer a setting that keeps the connection live while withholding this consent, because the consent is the condition on which the connected account is processed at all — a switch that appeared to withhold it while processing continued would be worse than none. Withdrawing does not affect processing carried out before withdrawal.
Any first-party training would require a separate, strictly opt-in consent (Section 4.1), which we would build as a real control before relying on it. Accounts connected before this step existed carry no consent record; we do not create one retroactively, and they are asked at their next connect or re-authorization.
6. Human in the loop; no solely-automated significant decisions
Lonzo uses AI to analyze your communications and generate recommendations and drafts, but a human stays in control of consequential actions. In particular, the assistant will not send an email on your behalf without your review and approval — outbound messages and other significant actions cross a human-approval boundary before they take effect. The assistant sends mail as you, through your connected Gmail account, only after you approve.
We do not make decisions that produce legal or similarly significant effects on you solely by automated means. You remain responsible for reviewing, approving, and acting on AI-generated output.
Your right to human review (GDPR Art. 22). Where the GDPR applies, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. Consistent with the human-approval boundary above, you may obtain human intervention, express your point of view, and contest any such decision by contacting us at privacy@lonzo.ai. This mirrors the corresponding right described in Privacy Policy Section 12.
7. Accuracy and no reliance
AI output can be wrong. Summaries, drafts, extracted memory, suggested events and tasks, and answers may be inaccurate, incomplete, or out of date, and may not reflect the current state of your mailbox, calendar, or the world. AI output is provided on an "as is" basis, without warranty of accuracy or fitness for a particular purpose. You are responsible for reviewing AI output before you rely on it, send it, or act on it. Do not rely on the Service for professional advice (legal, financial, medical, or otherwise). This disclosure is subject to the limitations of liability and disclaimers in our Terms of Use.
8. Human review of your content
We do not routinely have humans read your content. Any access to your connected-account content or derived memory is purpose-bound — authorized only for a specific declared purpose, such as a support request you initiate, or a genuine security, abuse, or legal need — and every such access is recorded in an immutable audit log on our servers. Because decryption is purpose-bound (see Privacy Policy Section 10), even internal access is gated rather than open-ended.
9. The derived-memory graph
To understand context across your mail, calendar, contacts, and tasks, the Service builds a derived-memory graph: an AI-generated store of concepts, relationships, and embeddings drawn from your data. This graph may contain personal data, including personal data about third parties who appear in your account. It is protected by the same encryption, retention, and deletion practices as your other content (see Privacy Policy Sections 9 and 10), is subject to your privacy rights, and — consistent with Section 4.1 — is not used to train first-party models. You can have your derived memory wiped by writing to privacy@lonzo.ai, and it is removed from our live systems when you delete your account, on the same schedule and with the same limits as the rest of your data (see the Data Retention & Deletion Policy).
10. Your controls
- Connect or disconnect your Google account, and revoke our access at any time from your Google Account permissions (see Privacy Policy Section 5).
- Review and approve (or reject) drafts and outbound actions before they take effect.
- Request deletion of your account and all the data we hold — from Account → Delete account in the app, or from a public page needing no sign-in at lonzo.ai/delete-account. Either route records a request that a person then carries out; the in-app control files it and deletes nothing itself. When the deletion is carried out it removes your derived memory along with everything else.
- Have your derived memory wiped, or your conversation history deleted, on request to privacy@lonzo.ai. These are request-based; there is no in-product control for either, and we would rather tell you than have you look for one.
- Turn off the footer that identifies Lonzo on messages the Service originates on your behalf (Section 11), in your settings.
11. AI transparency (EU AI Act)
You are interacting with an AI system. Lonzo is an artificial-intelligence system. When you use the assistant, you are communicating with AI-driven software — not a human — and its summaries, drafts, suggestions, and answers are generated by AI models.
AI-generated drafts are presented for your review. Any email reply, message, event, or task the assistant prepares is AI-generated content presented to you for review before it takes effect. Nothing is sent or applied to your account until you approve it (see Section 6). Drafts are shown to you inside the assistant surface, which is identified as the assistant throughout, so their origin is clear at the point you review them.
What we do and do not mark. Where the Service originates a message to another person at your direction — a coordination or scheduling message, as distinct from a reply you approve and send as yourself — that message carries a footer identifying Lonzo as the assistant coordinating on your behalf, unless you turn the footer off in your settings. We do not embed machine-readable provenance metadata or watermarks (for example C2PA manifests) in generated text, and we do not claim to. Mail you approve and send from your own Gmail account is sent as you, and is not separately marked as AI-assisted.
These statements are made to meet the transparency obligations of the EU AI Act (Art. 50) for interaction with an AI system and for AI-generated content. Where Art. 50's machine-readable marking obligation applies to us and becomes enforceable, we will implement it and describe it here rather than assert it in advance.
12. Changes and contact
We may update this disclosure as our AI practices evolve; material changes will be communicated as described in our Privacy Policy. Questions about our use of AI can be sent to privacy@lonzo.ai.