Skip to content

Google API Services Limited Use Disclosure

Effective 2026-08-18 · Version 2.2

1. Limited Use commitment

Lonzo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The Service is operated by Vista del Lago Software LLC, a Delaware limited liability company, of 18381 Vista del Lago, Yorba Linda, CA 92886, USA, which offers the Service under the Lonzo name. Questions about this disclosure: privacy@lonzo.ai.

2. Google scopes we request, and why

Lonzo is an AI executive assistant that works across your Google account. We request only the scopes needed to provide the features you use:

Gmail

  • gmail.modify (RESTRICTED scope) — to read your mail so the assistant can summarize, triage, and answer questions about it, and to organize it (apply labels, archive) and send messages on your behalf after you approve them. This scope grants both read and write access to your mailbox, which is why Google classifies it as restricted and subjects it to heightened review. It is the only Gmail content scope we ask for: because it already covers reading, sending, and label changes, no narrower Gmail scope is requested alongside it.
  • gmail.settings.basic — to create and delete the message filters you ask us to create, and to read the filters already on your account so we do not duplicate or fight them. This is how "always silence this sender", "always surface this sender", and "send this sender to spam" are made to hold everywhere you read your mail, not just inside Lonzo. We never edit or delete a filter you wrote yourself. This is a separate permission — gmail.modify does not include it — and without it those preferences are kept inside Lonzo only.

Calendar, Contacts, and Tasks

  • calendar.events — to read and manage your calendar events so the assistant can surface your schedule and create, update, or remove events at your direction.
  • calendar.readonly — to read your calendars and their metadata (including calendars you do not write to) so the assistant has full visibility of your schedule when reasoning about your availability and commitments.
  • calendar.freebusy — to read when you are busy or free, without reading the details of those events, so the assistant can propose meeting times that do not conflict with your existing commitments.
  • contacts — to read your contacts so the assistant can recognize who is writing to you, address people by name, autocomplete recipients, and help with scheduling; and to create or update a contact at your direction (for example, saving someone you have just started corresponding with). We never delete a contact. Lonzo has no contact-deletion path at all: no code in the Service can construct such a request, and that absence is enforced by an automated test on every build.
  • tasks — to read and manage your Google Tasks, which is where your reminders live: adding, listing, and completing a reminder in Lonzo reads and writes your Google Tasks.

Sign-in

  • openid, profile, email — the standard OpenID Connect sign-in scopes, so we can identify your account and, where you have set no name or picture of your own in Lonzo, show the name and profile picture from your Google account. These carry no access to your mail, calendar, contacts, or tasks.

We request only what these features require — ten scopes in total: seven Google data scopes and the three standard sign-in scopes. Where one scope covers a job, we do not also ask for the narrower ones beside it. Google remains the authoritative source of your data; the Service works from and acts on your Google account rather than replacing it.

You can grant these individually. Google's consent screen lets you approve some and decline others. We accept a partial grant rather than refusing to connect: the features your grant covers work, and Lonzo tells you plainly which ones it cannot do and offers to reconnect. Declining Gmail access, though, leaves the assistant with no mail to work from — that is the permission the Agenda is built on.

3. How we meet the four Limited Use requirements

Our actual data practices satisfy each of Google's four Limited Use requirements:

(1) Allowed use — to provide or improve user-facing features only. We use the data we receive from Google APIs solely to provide and improve the user-facing features of Lonzo — reading and organizing your mail, managing your calendar and tasks, drafting replies, and building the memory that gives the assistant context. We do not use Google user data for any unrelated purpose.

(2) Allowed transfer — only as necessary, and only to compliant providers. We do not transfer Google user data except: as necessary to provide or improve the Service; to comply with applicable law; or as part of a merger, acquisition, or sale of assets with notice to users. The one material transfer we make to provide the Service is to Amazon Web Services (AWS Bedrock), our cloud inference provider, which runs the AI models (Amazon Nova, Anthropic Claude, and Amazon Titan embeddings) that power the assistant. AWS acts as our service provider under contractual obligations, and it is identified on our subprocessor list at lonzo.ai/legal/subprocessors.

Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.

(3) No advertising. We do not use Google user data for serving advertisements of any kind — no personalized, retargeted, or interest-based advertising. We do not operate an advertising business over your Google data.

(4) No human reading, except in limited cases. We do not allow humans to read your Google user data, except: (a) with your affirmative consent (for example, to help you with a support issue); (b) as necessary for security purposes, to investigate abuse, or to comply with applicable law; or (c) where the data is aggregated and anonymized, or where reading is required to provide or maintain the Service and it is not feasible to do so otherwise. In practice, access to your data is purpose-bound — decryption is authorized only for a specific declared purpose — and every such access on our servers is recorded in an immutable audit log (see our Privacy Policy and security page, which states the one decryption that is not logged: the app's own, on your device).

4. Our commitment on advertising, human reading, and training

Consistent with the requirements above:

  • No ads. We never use your Gmail, Calendar, Contacts, or Tasks data to serve advertising.

  • No routine human reading. No one on our team routinely reads your mail or other Google data; any access is purpose-bound, gated by your consent or a genuine security/abuse/legal need, and audit-logged.

  • No first-party training on your Google data. We do not use your Google user data to train first-party Lonzo models. If we ever offer such use, it will be strictly opt-in (see the AI & Data-Training Disclosure).

  • No third-party training or retention by the Bedrock model providers. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers, and Bedrock operates on a zero-data-retention basis by default, retaining no prompt or response content after a request completes (see Section 3(2) above and the AI disclosure §4.2).

5. What our Gmail write access does, and how we handle mail

Because gmail.modify is a restricted read-and-write scope, we state precisely what we do with it:

  • Read — to summarize, triage, search, and answer questions about your mail, and to build your derived memory graph.
  • Organize — to apply and remove labels and to archive messages at your direction; these changes are reflected in Gmail.
  • Send as you — to send messages from your account. Every outbound message requires your review and approval. The assistant never sends autonomously; a human-approval boundary sits before any send.

How mail content is stored. We do process message bodies (unlike products that read only headers), so we protect them accordingly. A Gmail message body we fetch is held in the working memory of the process that fetched it for 15 minutes and is not written to disk, to our object store, or to any durable pointer — so for the cache there is no copy at rest to protect. Until 2026-08-18 this page said bodies were cached as "encrypted pointers with an approximate 30-day time-to-live", describing a durable cache we designed and never enabled. The mail content we do store at rest is the conversation the assistant is asked to work on: to reply to a thread it reads that thread's messages and keeps them as the conversation it is replying in, for as long as your account exists, deleted when you delete the conversation or the account. That copy, your OAuth tokens, and everything else derived from your Google data are protected by per-actor envelope encryption (a per-account AES-256-GCM data key, itself wrapped by a key-encryption key held in AWS Key Management Service and backed by hardware security modules, bound to your account by encryption context), with data in transit protected by TLS — 1.3 on the app's own transport and between our internal services, 1.3-preferred with 1.2 accepted at the public HTTPS edge — and by mutual TLS internally. Google remains the authoritative source of your mail; if you stop using the Service or revoke access, we stop reading and acting on your mailbox. See the Privacy Policy for retention and security detail.

What happens on disconnect or revocation. There are two ways this happens, they do not work the same way, and the difference is worth stating rather than averaging.

  • You disconnect inside the app. We call Google's revocation endpoint for the stored token, clear both the access token and the refresh token from our storage so that no usable secret remains at rest, and tear down the mail and calendar sync for your account.
  • You revoke our access from your Google Account permissions page. Google stops honoring our token the moment you do it, so access ends when you revoke it, not when we notice — nothing we hold can read your mailbox after that point. Google's refusal is also how we learn: the next time we try to use the token we clear both tokens from our storage in the same way as above and mark the connection revoked, which is what makes the app ask you to reconnect instead of appearing connected. Until such an attempt happens the token is already dead at Google and stays sealed in our storage, unusable, until it is cleared or your data is deleted. The sync stops with the credential — it can read nothing without one — and the sync machinery itself is cleaned up the next time it runs rather than at the instant you revoked.

Either way, no further reading or acting on your mailbox occurs, and cached Google content already held is gone within 15 minutes — the cache is not refreshed, because nothing is fetching it any more. Disconnecting does not remove the conversations the assistant has already worked on, which stay in your account with everything else you made in it; the paragraph below is the control for those.

Disconnecting keeps your Lonzo account, so it is not by itself a deletion — that is the point of having it as a separate control. To have the cached content and the derived memory built from it destroyed, delete your account. On handling your request we remove your account and its data from our live systems, within 30 days; residual copies in our encrypted backups age out on the rolling 90-day purge cycle, so deletion is complete across live systems and backups within 90 days. (This page said 30 days for both until 2026-08-17; 30 is one of three backup windows and the nightly database export keeps its copy for 90, so the longer number is the one that bounds the promise.) We do not destroy a per-account encryption key as part of that, so we do not tell you your data becomes mathematically unrecoverable the moment you ask — the reasoning is in the retention policy below. You can ask for that deletion from Account → Delete account inside the app, which records the request from your signed-in session and deletes nothing by itself — a person carries the erasure out, and you keep access until they have — or from a public page needing no sign-in and no app install, at lonzo.ai/delete-account. You can also ask us to wipe the derived memory while keeping your account, by writing to privacy@lonzo.ai. See Privacy Policy Section 9 (Data retention) and the Data Retention & Deletion Policy for the full detail.

6. Security assessment and verification

Because we use a restricted scope (gmail.modify), Lonzo is subject to Google's OAuth verification and an annual Cloud Application Security Assessment (CASA) at Tier 2, performed by a Google-designated assessor.

Current status: OAuth verification and the CASA Tier 2 assessment are in progress and not yet completed, and we make no claim to be "Google-verified" or CASA-assessed until they are. We will update this section when they complete.

7. Where this disclosure appears

To make this commitment easy to find for you and for Google's reviewers, we publish it in three places:

  • In-app, at the Google connect / OAuth grant point — the Limited Use statement in Section 1 appears next to the button you use to connect your Google account, alongside plain-language explanations of why each scope is requested (Section 2).
  • In our public Privacy Policy — which cross-references this disclosure and is linked from the app and from the Google OAuth consent screen.
  • On our public security/trust page at lonzo.ai/legal/security-overview, and at the canonical disclosure URL lonzo.ai/legal/google-limited-use-disclosure.

We keep the published disclosure URL stable for Google's re-verification, and version this disclosure alongside the Privacy Policy.

8. Contact

Questions about our use of Google APIs and Limited Use compliance can be sent to privacy@lonzo.ai.


All legal documents · Help · Lonzo home