Consumer Health Data Privacy Policy
Effective 2026-08-17 · Version 1.4This is a separate, standalone policy, published because Washington's My Health My Data Act (RCW 19.373) and Nevada's SB 370 (NRS 603A.400–603A.550) require a distinct consumer-health-data notice rather than a section inside a general privacy policy. It applies in addition to our Privacy Policy, which governs everything else. Where this policy and the Privacy Policy describe the same processing, this one is the more specific and controls for consumer health data.
It is written for residents of Washington and Nevada, whose laws create these specific obligations, but the commitments in it are how we behave for everyone. We are Vista del Lago Software LLC, a Delaware limited liability company, of 18381 Vista del Lago, Yorba Linda, CA 92886, USA, offering the Service under the Lonzo name. Health-data contact: privacy@lonzo.ai.
1. The short version
Lonzo is an assistant for your email, calendar, contacts, and tasks. We do not ask for health information, we have no health feature, and we do not try to work out anything about your health. But if you connect a mailbox and a calendar, health-related things are in there — a message from a clinic, a calendar entry for a dental appointment, a pharmacy receipt — and an assistant that reads your mail reads those too. Washington and Nevada law treats that category of information as consumer health data whatever the reason it reached us, so it is covered here.
Four commitments, stated up front because they are the ones that matter:
- We do not sell consumer health data. Ever, to anyone, for anything. No exceptions, no "sharing for cross-context advertising," no data brokers. We have no advertising business, and we do not intend to acquire one.
- We do not use it to infer, score, profile, or predict anything about your health, and we do not build health profiles or health-related audience segments.
- We do not use it, or anything else in your account, to train AI models — ours or anyone else's. That commitment covers all of your data and is set out in the AI & Data-Training Disclosure.
- We do not track where you are, and we operate no geofence around a health-care facility or anywhere else — so those prohibitions in both statutes are ones we have no mechanism to violate. The Service has no location permission on any platform, requests none, and computes nothing about where you have been. What it does receive is a place you wrote down: the location field of a calendar event, an address inside a message. That is content you gave us, not a position we observed, and because the statutes' definition of health data reaches the address of a clinic appointment, Section 3 states plainly what happens to it.
2. What "consumer health data" means here
Both statutes define it broadly: personal information linkable to a consumer that identifies their past, present, or future physical or mental health status. That reaches more than diagnoses — it includes health conditions and treatment, medications, bodily functions and vital signs, health-related surgeries and procedures, use or purchase of medication, health-care services sought or received including the precise location of any attempt to acquire them, reproductive and sexual health information, gender-affirming care information, biometric data, genetic data, and any inference drawn from any of the above.
Two of those categories we hold no substrate for at all: we collect no biometric data and no genetic data. Nothing in the Service captures a fingerprint, a face template, a voiceprint, or genetic information, and nothing in it accepts an upload of one.
The microphone is the one place that deserves a precise sentence rather than a reassuring one. The mobile app and the web app both let you dictate instead of typing, so the Service does have a microphone affordance. What it does not have is your audio: the transcription is performed by your device's or your browser's own speech service, and only the resulting text reaches us. We never receive, transmit, or store voice audio, and we create no voiceprint, speaker model, or other biometric identifier from it — not for health purposes and not for any other purpose. Where that audio goes before it becomes text is a property of your device, not of the Service, and Section 3 states it.
3. What can reach us, and how
We do not have a health-data collection point. What we have is a connected mailbox and calendar, so the categories below are what can arrive incidentally, inside content you already have:
| Category | How it can reach us | What it looks like in practice |
|---|---|---|
| Health-care services sought or received | Content of email in your connected Gmail mailbox; events in your connected Google Calendar | An appointment confirmation, a message from a provider's office, a calendar entry naming a clinic |
| Health conditions, treatment, diagnoses, medications | The same | A message discussing a condition, a prescription notification, a pharmacy receipt |
| Reproductive or sexual health information; gender-affirming care information | The same | Any of the above where that is the subject |
| Bodily functions, vital signs, symptoms, measurements | The same | A lab result or a wearable's summary email that happens to land in your inbox |
| Contacts who are health-care providers | Your connected Google Contacts | A contact card for a doctor's office |
| Anything you type to the assistant | Your own messages to the assistant | Asking it to reschedule a medical appointment |
| Anything you say to the assistant | Dictation in the composer, which your device's or browser's own speech service turns into text before it reaches us | Saying "move my oncology appointment to Thursday" instead of typing it |
Sources. Every one of these has exactly one of three sources: the Google account you chose to connect, what you type to the assistant, and what you dictate to it. We buy no data, we obtain none from data brokers, we scrape none, and we receive none from any third party other than Google acting on your instruction. Our full list of service providers is at Sub-processors.
Voice: the words reach us, the audio does not. Dictation is a real third route by which health-related content can arrive — a spoken request about an appointment is consumer health data just as a typed one is, and it is treated identically once it is text. The audio itself is a different matter, and the honest version has two halves. We never receive it. Transcription is performed by the speech service built into your device or your browser, and only the text is sent to us; we do not receive, transmit, or store voice audio, and we derive no voiceprint from it. But that service is not always local. Depending on your device and its settings, it may transcribe on the device or send the audio to whoever provides it — on most Android phones, Google — under that provider's privacy policy and not under this one. We are not a party to that processing and cannot promise anything about it; we can only tell you it happens, so that you can decide not to dictate something you would not want handled that way. Typing is always available, on every surface where dictation is. Privacy Policy, Section 3(g), states the same thing for all content.
Location: never where you are; sometimes where you wrote you would be. The definition above includes "the precise location of a consumer's attempt to acquire health-care services," which makes this the second place that deserves a precise sentence rather than a reassuring one. We do not locate you. The Service has no location permission on any platform and requests none, reaches no geolocation interface in either the mobile app or the browser, operates no geofence, does no geocoding, and computes no proximity between you and any place — so we cannot tell that you attended anything. The only locational thing we derive at all is the coarse network origin of a request, which is retained in bounded technical logs (see Section 7), is never associated with health-related content, and is never used for any health purpose. But a calendar event carries a place you typed, and we store it. A dental appointment whose event names the clinic, or a provider's email giving its address, arrives as part of that event or that message: the event's location is stored with the rest of the record, is searchable like the rest of it, and is one of the fields we put into the short summary that makes an event findable — so it reaches the model along with the event, exactly as the event's title does. Where that is health-related it is consumer health data under this policy in full: not sold, not used to infer anything about your health, not used to target you, and removed with the record (Section 7). The distinction that matters is that this is your own writing coming back to you rather than an observation we made of your movements — but it is not nothing, and a policy that called it "no location data" would be describing a Service we do not operate.
4. Why we process it, and what we will not do with it
The only purpose is the one you asked for: operating the Service you enabled — reading your mail so it can be triaged, summarized, drafted against, and scheduled; finding what you asked for; and doing the things you told it to do. Health-related content is processed for that and nothing else. It is not a separate product feature; it is content passing through the same pipeline as everything else in your mailbox.
We do not, with consumer health data:
- sell it, in any sense either statute defines, including any exchange for anything of value;
- share it for advertising, cross-context behavioral advertising, or any marketing purpose, ours or anyone else's;
- use it to train, fine-tune, or evaluate any AI model (the AI & Data-Training Disclosure is the operative commitment and it applies to all of your data);
- infer or score health status from it, or build health segments, or use it to make or support any decision about you;
- use it to target you, in the app or anywhere else;
- collect it through a geofence, use location to detect a visit to a health-care facility, or treat an address you wrote in an event as evidence that you went there; or
- hand it to a data broker.
5. Who it goes to
Consumer health data goes only where the rest of your content goes, and only because the Service cannot work otherwise:
- Google — because the data lives in your Google account. Reading it is the Service; nothing is copied to Google that was not already there.
- Amazon Web Services, including Amazon Bedrock for AI processing, as our infrastructure and model-hosting provider. Bedrock does not retain the content of our requests to train its models, and our agreement with AWS does not permit it to.
- Our email provider, for mail we send you or send at your direction.
Each is a service provider or processor acting on our instructions under contract, not an independent recipient free to use your data for its own purposes. The complete, current list — with what each does and where it operates — is at Sub-processors, which is the same list for health-related content as for everything else.
No one else. We disclose consumer health data to no other third party except as Section 6 describes.
One thing this list deliberately does not cover, because it is not ours to disclose: if you dictate rather than type, your device's or browser's own speech service handles the audio before we ever see anything, and on many devices that means sending it to the provider of that service. That is a processing relationship between you and your device, not a disclosure by us — the audio never reaches us, so we cannot pass it on — but it is real, and Section 3 describes it rather than leaving you to find it out. It is not on the Sub-processors list because that list is of processors acting on our instructions, and this one is not.
6. Legal process
We may disclose data, including consumer health data, where a law compels it, but a request touching health data gets our narrowest reading of it. Consistent with our Privacy Policy:
- We require valid legal process and disclose the minimum the process actually compels.
- We will not treat a request as valid because it is inconvenient to challenge, and we will resist an overbroad one.
- Where the law permits it, we will notify you before disclosing, and where we are barred from notifying you we will say so as soon as the bar lifts.
- We publish nothing about individual accounts.
We recognize why this matters specifically for reproductive-health and gender-affirming-care information, and both statutes were written with that in mind. Our position is the one above, applied without exception.
7. How long we keep it
Consumer health data is not retained on a separate schedule, because it is not stored separately — it is content inside your account. The full schedule is in the Data Retention & Deletion Policy; the parts that matter here:
- Content stays for as long as your account does, and is removed when you have your account deleted.
- Technical and usage logs are bounded to 30 days, and in no case more than 90.
- Nothing health-related is retained after deletion other than what that policy identifies as surviving for a legal reason — billing and tax records (which contain no health content) and email-provider suppression entries (an email address and a bounce or spam-complaint reason, and nothing else). The per-account opt-out record is not in that set: it is your account's data and is removed with your account.
That policy is also honest about the mechanism: deletion means removal from the live system and expiry from backups on a stated schedule, and we do not claim a cryptographic-erasure guarantee we cannot perform. We would rather you read the accurate version than a reassuring one.
8. Consent, and how to withdraw it
How consent is given today. Washington and Nevada require consent to collect consumer health data beyond what is necessary to provide a service you requested, and separate authorization to sell it (which we do not do, so no authorization is ever sought). Consent is given by a separate, unticked checkbox shown beside the Connect control, on every screen that offers to connect a Google account. The line directly above the box tells you, before you tick it, that your mail and calendar will often contain sensitive details — health appointments, religious or political activity, union membership — and that those are processed along with everything else; the label you tick then says you agree to Lonzo processing your Google data, including any sensitive details it contains, with those AI models. The Connect control does nothing until you tick it, so the agreement is a deliberate act of its own rather than a by-product of signing up or of Google's own permission screen. Google's screen then names the specific permissions being granted; you can decline either one, with no consequence beyond the Service not working. Nothing is read before you complete both.
We record that you agreed, when, and which version of our Privacy Policy was published at that moment, held against your account where you cannot alter it. If that record cannot be written, the box stays unticked and Connect stays inert — we will not proceed on a consent we did not store.
We are precise about the limits of that. That one agreement authorizes the whole of the Service's access, including to health-related content that happens to be in the mailbox. There is no toggle that admits your calendar but excludes your medical appointments, because the assistant reads the mailbox as a whole — the checkbox is a consent to that, not a filter. If a narrower grant matters to you, the honest options are to connect an account that does not contain that content, or not to connect one. Accounts connected before this control existed carry no such record; we do not create one retroactively, and they are asked at their next connect or re-authorization.
Withdrawing consent. Two mechanisms, both real:
- Disconnect the Google account, or revoke the grant at Google. You can revoke Lonzo's access from your Google Account's security settings at any time, without telling us, and the access ends immediately. That stops all further collection.
- Write to privacy@lonzo.ai and ask us to stop. We will.
Withdrawing consent stops collection going forward. To have what we already hold deleted, use Section 9 — withdrawal and deletion are different requests, and we will not treat one as the other.
9. Your rights, and how to exercise them
Under Washington's My Health My Data Act and Nevada SB 370 you have the right to:
- Confirm whether we are collecting, sharing, or selling your consumer health data, and access it, including a list of all third parties with whom we have shared or sold it and contact information for each;
- Withdraw consent to our collection and sharing of it (Section 8);
- Have it deleted, including from our archived and backup systems, and have us pass the deletion request to our processors and affiliates; and
- Not be discriminated against for exercising any of these. We will not degrade the Service, change your price, or refuse you as a customer because you asked.
How. Email privacy@lonzo.ai with the address on your account. We will verify that the request is yours, which for an account holder normally means confirming from the account's own email address, and we will not ask for more information than the verification needs. An authorized agent may make a request on your behalf with your written permission.
One of these four has a control in the app, and three do not. The deletion right can be raised from Account → Delete account, which asks you to confirm and then records the request against your signed-in session — so there is no address to verify and no confirmation mail to wait for. It is a way of asking, not a way of doing: it files an attributed request, deletes nothing itself, and leaves your account and your access exactly as they were until a person carries the erasure out. Confirming and accessing your health data, obtaining the list of third parties, and appealing a refusal have no in-app control, because we have not built one — those go by email and a person handles each. Withdrawing consent is different again and has two real mechanisms of its own, in Section 8.
Timing. We respond within 45 days, and may extend once by a further 45 days where the request is complex, in which case we will tell you why within the first 45.
If we refuse. We will tell you why, and you may appeal by replying to our response or writing to privacy@lonzo.ai with "Appeal" in the subject. We will decide the appeal within 45 days and explain the outcome in writing. If we deny the appeal, you may complain to the Washington State Attorney General (Washington residents) or the Nevada Attorney General (Nevada residents), and we will tell you how in our decision.
A limit worth stating. Deleting consumer health data means deleting the content it lives in — the message, the event, the contact card. We cannot delete a health-related sentence out of an email and leave the rest of it, and we cannot delete anything from your own Google account, which is not ours to write to. What we can delete is what we hold. If what you want removed is the underlying message, it has to be deleted in Gmail; we will say so rather than let you believe we did more than we did.
10. Employees, contractors, and access
Access to production systems containing customer content is limited to personnel who need it, is authenticated with multi-factor authentication, and is logged. Health-related content carries no special access channel — and equally, no exemption. Our security posture and its limits, including what has and has not been independently audited, are described in Security at Lonzo.
11. What this Service is not
Lonzo is not a health-care service, and it is not for handling health data on purpose.
- We are not a HIPAA covered entity or business associate. We do not offer a Business Associate Agreement, and we have none in place with any customer or with AWS.
- The Acceptable Use & Anti-Spam Policy, Section 3.9, prohibits using the Service to process protected health information or to act as a system of record for it. That prohibition is not undermined by this policy: this policy exists because health-related content incidentally reaches a general-purpose assistant, not because doing so deliberately is permitted.
- The Service gives no medical advice. Nothing it produces is a diagnosis, a treatment recommendation, or a substitute for a clinician, and it should not be relied on as any of those.
12. Children
The Service is not directed to children, and account holders must be at least 16. We do not knowingly collect consumer health data from a child. If you believe we have, write to privacy@lonzo.ai and we will delete it.
13. Changes to this policy
We may update this policy. If we make a material change to how we collect, use, share, or retain consumer health data, we will update the effective date and version above, notify account holders by email or in-app notice before the change takes effect, and — as both statutes require — obtain your consent before applying the change to data already collected, rather than applying a new purpose to old data on the strength of a posted notice.
14. Contact
Vista del Lago Software LLC 18381 Vista del Lago, Yorba Linda, CA 92886, USA
- Consumer health data requests, and appeals: privacy@lonzo.ai
- Everything else: support@lonzo.ai