Skip to content

Privacy Policy

Effective 2026-08-18 · Version 2.4 · Last updated 2026-08-18

1. Introduction and scope

Lonzo ("Lonzo," the "Service") is an AI executive assistant that works across your connected Google account — Gmail, Google Calendar, Google Contacts, and Google Tasks — to help you read and organize mail, schedule and manage events, draft replies, and keep track of the people and commitments in your life. This Privacy Policy explains what personal data we collect when you use the Service, how and why we process it, the choices and rights you have, and where your data is processed.

This Policy applies to the Lonzo application (web and any native shells), our websites, and related services that link to it. It does not apply to Google's own services, to any third-party service you separately connect, or to third parties' independent handling of your data. Your use of the Service is also governed by our Terms of Use and, where applicable, our Data Processing Addendum.

Because the Service reads and acts on the contents of your mailbox, calendar, contacts, and tasks, please read Sections 3 (what we collect), 4 (where processing happens), and 6 (AI processing) carefully.

2. Who we are (controller and roles)

The entity responsible for the Service is Vista del Lago Software LLC, a Delaware limited liability company that operates the Service under the Lonzo name, located at 18381 Vista del Lago, Yorba Linda, CA 92886, USA ("we," "us," "our").

Our role under data protection law depends on the data in question:

  • Consumer users — account data. We are the controller of the account data we collect to run our business relationship with you — your account and identity data, billing data, and technical, usage, and log data. We decide the purposes and means of processing this data.
  • Consumer users — connected-account content. For the content of your connected Google account — your Gmail messages, calendar events, contacts, tasks, and the derived memory generated from them — we process that content solely to provide the user-directed service you ask for, not for our own purposes. This content is processed on our servers on every plan (Section 4).
  • Business/team customers. Where you access the Service through a business or team account, we act as a processor under our Data Processing Addendum for the data the customer directs us to process, and the customer is the controller.

If you access the Service through an organization (for example, an employer or a business account), that organization is the controller of your data and its own policies may also apply.

For data protection inquiries, contact us at privacy@lonzo.ai — that is our data-protection contact. We have not appointed a Data Protection Officer, as one is not required for our processing, and we say so rather than point you at an office that does not exist. If you are in the EU, UK, or Switzerland, Section 15 states the status of our Article 27 representative designation and where to send a request you would otherwise address to a representative.

3. Personal data we collect

We collect the categories of data below. The categories drawn from your connected Google account are the most sensitive; we describe how we protect them throughout this Policy.

CategoryWhat it includesSource
(a) Account and identity dataYour name, email address, profile information, and the identifiers we use to authenticate you and bind activity to your identity.You / Google sign-in
(b) Billing dataYour subscription tier and status, and the purchase and subscription tokens Google Play provides. Google Play is our only payment channel and holds your payment method directly — we receive no payment-card data of any kind.Google Play
(c) Google Gmail dataThe content and metadata of your Gmail messages — subject lines, message bodies, sender and recipient information, labels, and thread structure — accessed under the RESTRICTED gmail.modify scope, which also lets us label, archive, and send mail on your behalf after your approval, and the sender filters we create and delete at your direction under gmail.settings.basic.Google APIs
(d) Google Calendar dataYour calendar events, including titles, dates, times, attendees, and descriptions, accessed under the calendar.events and calendar.readonly scopes, and your busy/free times (without event details) under calendar.freebusy.Google APIs
(e) Google Contacts dataYour contacts, including names, email addresses, and related details, accessed under the contacts scope.Google APIs
(f) Google Tasks dataYour task lists and task items, accessed under the tasks scope.Google APIs
(g) Voice inputWhen you speak to the assistant, your speech is transcribed to text by your device's own speech-recognition service — the recognizer built into your phone's operating system, or your browser's speech API. Depending on your device and its settings, that service may transcribe the audio on the device or send it to the provider of that service (on most Android phones, Google) under that provider's privacy policy; it is never sent to us. Only the resulting text reaches the Service. We do not receive, transmit, or store your voice audio.Your device
(h) Derived memoryA knowledge graph of concepts, relationships, and vector embeddings that the Service derives from your Google data to understand context and answer questions. This derived memory may contain personal data, including personal data about you and about third parties who appear in your mailbox, calendar, or contacts.Generated by the Service
(i) OAuth tokensThe Google OAuth access and refresh tokens that authorize the Service to act on your connected account (see Section 5).Google (on your authorization)
(j) Technical, usage, and log dataIP address, device and browser information, timestamps, feature usage, diagnostics, and error logs.Automatic

Third-party personal data. Your mailbox, calendar, and contacts necessarily contain personal data about other people. When you connect your Google account, you direct us to process that third-party data to provide the Service to you. You are responsible for having an appropriate basis to share that data with us.

Sensitive Personal Information (CPRA). Under the California Privacy Rights Act (CPRA), the contents of your Gmail messages and your account credentials — including your Google OAuth access and refresh tokens — are "Sensitive Personal Information" (SPI), because your mail contents can reveal categories such as the contents of communications and, incidentally, information a mailbox may disclose about you. We use and disclose this SPI only to perform the Service you have requested — reading, organizing, drafting, and answering questions over your connected account — and for the compatible operational purposes (security, fraud prevention, and service delivery) that California law permits without triggering the right to limit. Because we do not use SPI to infer characteristics about you, and use it only for these permitted purposes, the CPRA "right to limit the use of Sensitive Personal Information" does not apply to our processing; we nonetheless describe your related choices and controls in Section 12. We do not use your Sensitive Personal Information to infer characteristics about you, and we do not sell or share it.

4. Where processing happens

Your connected-account content is processed on our servers on every plan. This is a material privacy fact, so we state it plainly rather than by implication.

  • Server-side (all plans). Your mailbox, calendar, contacts, and tasks content is read and processed on our server-side infrastructure (the "Reactor"), where it is protected by the encryption controls described in Section 10. Access to your Google account is performed only by our servers; the application on your device never holds a Google credential and never calls Google's APIs itself.
  • On your device. Your device performs local presentation work — rendering and ordering your Agenda, and an offline read cache of content it has already been shown — and holds your identity keys (see the Cookie & Local Storage Notice).

We do not represent that your data stays on your device. The AI reasoning steps call a cloud inference provider (AWS Bedrock) to run the language and embedding models, so the prompt content sent to the model — which can include your mailbox, calendar, contacts, tasks, and derived-memory content — transits to AWS. See Section 6 and the AI & Data-Training Disclosure for detail.

Change note. An earlier version of this Policy described a free tier whose processing ran on your device. That tier no longer exists: the Service is offered as paid subscription plans, and processing is server-side for all of them. This section replaces the previous on-device/server-side tier distinction.

5. Google OAuth tokens and your control

To act on your connected Google account, we store Google OAuth access and refresh tokens, including a refresh token for the RESTRICTED gmail.modify scope. These tokens are held encrypted using the envelope-encryption model described in Section 10.

We request the following ten scopes — seven over your Google data, and the three standard sign-in scopes. Where one scope covers a job, we do not also request the narrower ones beside it:

  • gmail.modify (RESTRICTED) — to read your mail and to organize it (label, archive) and send messages on your behalf after your approval. This is the only Gmail content scope we request: because it already covers reading, sending, and label changes, no narrower Gmail scope is requested alongside it;
  • gmail.settings.basic — to create and delete the sender filters you ask for (always-silence / always-surface / route-to-spam rules), and to read your existing filters so we do not duplicate them; we never edit or delete a filter you wrote yourself, and the gmail.modify scope does not cover mailbox settings;
  • calendar.events — to read and manage your calendar events;
  • calendar.readonly — to read your calendars and event details for scheduling context;
  • calendar.freebusy — to read when you are busy or free, without the details of those events, so proposed meeting times do not conflict with your existing commitments;
  • contacts — to read your contacts for context, autocomplete, and scheduling, and to create or update a contact at your direction (we never delete a contact — the Service has no contact-deletion path);
  • tasks — to read and manage your Google Tasks, which is where your Lonzo reminders are stored;
  • openid, profile, email — standard OpenID Connect sign-in, to identify your account and to show your Google name and picture where you have set none of your own. These carry no access to your mail, calendar, contacts, or tasks.

You can revoke our access at any time from your Google Account permissions page (myaccount.google.com/permissions). Revoking access immediately stops our ability to read from or act on your connected account. For how we handle deletion after revocation, see Section 9.

6. AI processing (summary)

The Service uses AI models to summarize, organize, draft, and answer questions over your data. All model inference — on every plan — is performed through AWS Bedrock, using the Amazon Nova, Anthropic Claude, and Amazon Titan (embeddings) model families. Content sent to these models can include your Gmail, Calendar, Contacts, and Tasks data and prompts derived from your memory graph. Voice is transcribed by your device's own speech service (Section 3(g)), and only the resulting text is ever sent to a model.

This section is a summary. Our full disclosure of which models we use, what data is sent, our human-in-the-loop approval boundary, our first-party and third-party training posture, and the accuracy limits of AI output is set out in the AI & Data-Training Disclosure, which forms part of this Policy.

Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.

7. How and why we use data, and our legal bases

We use personal data for the purposes below. For users protected by the EU/UK GDPR, we identify the legal basis for each purpose.

PurposeData usedLegal basis (GDPR)
Provide the assistant: read and organize mail, schedule, draft replies, manage tasks and contacts, answer questionsGoogle data (c–f), derived memory (h), voice text (g), account data (a)Performance of a contract (Art. 6(1)(b))
Build and maintain the derived-memory graph that powers contextGoogle data (c–f)Performance of a contract (Art. 6(1)(b))
Authenticate you and maintain security, prevent fraud and abuseAccount data (a), tokens (i), technical/usage data (j)Legitimate interests (Art. 6(1)(f))
Bill and manage subscriptionsBilling data (b), account data (a)Performance of a contract; legal obligation (Art. 6(1)(b), (c))
Provide support and respond to requestsAccount data (a), relevant content you sharePerformance of a contract; legitimate interests
Maintain, secure, and improve the Service's operationTechnical/usage/log data (j)Legitimate interests (Art. 6(1)(f))
Comply with law and respond to lawful requestsAs requiredLegal obligation (Art. 6(1)(c))
Any use of your content to train first-party models (see Section 6 / AI disclosure)As applicableConsent (Art. 6(1)(a))

Special-category data (GDPR Art. 9). A mailbox, calendar, or contact list unavoidably contains information that may qualify as special-category data under Article 9 GDPR — for example, correspondence that reveals health conditions, religious or political views, trade-union membership, or sexual orientation. We do not seek out or target such data, but because we process the whole of your connected account at your direction, we cannot exclude it. Our Article 9(2) condition for processing this data is your explicit consent under Art. 9(2)(a), and we now obtain it through a dedicated consent control rather than by treating the act of connecting as consent.

Before you can connect a Google account, the Service shows you — on the same screen as the Connect control, on every surface that offers one — which third-party AI models your content will be sent to, that your content is not used to train them, and that your mail and calendar will often contain sensitive details such as health appointments, religious or political activity, or trade-union membership. Beneath that disclosure is a separate, unticked checkbox. The Connect control does nothing until you tick it: your agreement is a distinct act, not a consequence of signing up or of accepting our Terms, and it is not bundled into Google's own permission screen (which grants Google's API access and says nothing about our processing).

When you tick it we record, against your account and where you cannot alter it, that you agreed, when you agreed, and which version of this Policy was published at that moment — read from the published document itself rather than assumed — so that we can demonstrate what you consented to, as Art. 7(1) requires. If we cannot determine that version, we decline to record the consent and the Connect control stays inert; we would rather ask you again than hold a record naming a document nobody verified.

Withdrawing. You withdraw by disconnecting your Google account (Account → Connections → Disconnect; see Sections 5 and 12) or by deleting your account. That is one action, as easy as the one tick that gave it, and it revokes our access and stops further processing — it does not affect processing carried out before withdrawal. We do not offer a control that keeps the connection open while withholding this consent, because there is none to offer: consent under Art. 9(2)(a) is the condition on which we process the connected account at all, so withdrawing it and disconnecting are the same act.

We remain precise about one limit. There is no toggle that admits your calendar but excludes your medical appointments — the assistant reads the connected account as a whole. If you would prefer that we not process a particular sensitive thread or event at all, the reliable way to achieve that is not to connect that account. Accounts connected before this control existed carry no such record, and we do not manufacture one; they are asked at their next connect or re-authorization.

We do not use your Google data for advertising or marketing. We do not use the content of your Gmail, Calendar, Contacts, or Tasks to serve advertisements, and we do not sell it. This is also a requirement of Google's Limited Use policy (see the Google API Services Limited Use Disclosure).

No first-party training. We do not use your connected-account content to train first-party Lonzo models, and if we ever do, it will be strictly opt-in. See the AI & Data-Training Disclosure for the full posture.

8. Sharing and subprocessors

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only as follows:

  • Service providers (subprocessors) who process data on our behalf under contractual obligations consistent with this Policy — most significantly Amazon Web Services, which provides our cloud inference (AWS Bedrock: Amazon Nova, Anthropic Claude, and Amazon Titan embeddings) and hosting. We maintain a subprocessor list at lonzo.ai/legal/subprocessors, which we update as our vendor set changes.
  • Legal and compliance — where we reasonably believe disclosure is required to comply with law, legal process, or a lawful government request, or to protect the rights, safety, or security of users, the public, or the Service.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy that provides comparable protection.

We require our subprocessors to protect your data and to use it only to provide services to us.

CCPA/CPRA categories of personal information. For the purpose of the California Consumer Privacy Act, the personal information we collect (described in Section 3) maps to the following statutory categories:

  • Identifiers — name, email address, account identifiers, IP address, and OAuth tokens (Section 3(a), (i), (j)).
  • Commercial information — your subscription tier, status, and billing references (Section 3(b)).
  • Internet or other electronic network activity — feature usage, diagnostics, timestamps, and log data (Section 3(j)).
  • Geolocation data — only coarse location that may be inferred from your IP address; we do not collect precise geolocation.
  • Sensitive Personal Information — the contents of your Gmail messages and your account credentials (see Section 3 and the SPI subsection).
  • Content of communications — your Gmail, Calendar, Contacts, and Tasks content (Section 3(c)–(f)).
  • Inferences — the derived-memory graph of concepts, relationships, and embeddings the Service builds from your data (Section 3(h)).

We collect these categories from the sources identified in Section 3 (you, Google sign-in and APIs, Google Play billing, your device, and automatic collection). We disclose personal information in the above categories to our subprocessors (most significantly AWS) for a business purpose — to host and operate the Service and run AI inference — under contracts that restrict their use of it. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, in any category.

De-identified and aggregated data. We may create de-identified or aggregated data (for example, aggregate usage statistics and service-quality metrics) that does not identify you or any individual, and we may use and retain such data for operating, securing, analyzing, and improving the Service. Where we do so, we will maintain the data in de-identified form, will not attempt to re-identify it except as permitted by law to test our de-identification, and will contractually prohibit recipients from re-identifying it. For the avoidance of doubt, de-identified and aggregated data is not a route around our training posture: creating or using de-identified/aggregated data does not authorize training first-party models on your connected-account content, which remains governed by the no-first-party-training default described in Section 7 and the AI & Data-Training Disclosure (any first-party training would be strictly opt-in).

8A. Marketing communications

We may send you promotional email — for example, product announcements, feature updates, tips, and offers related to the Service. You can opt out of promotional email at any time by using the unsubscribe link in the message or by changing your notification preferences in your settings; we will honor your choice promptly. For users in the EU/UK, we send promotional email on the basis of your consent or, where permitted (for example, to our existing customers about similar services), our legitimate interests, and you may object to such processing at any time.

Service and security emails are not opt-outable. Certain messages are necessary to operate the Service and are not marketing — for example, transactional and account notices, billing and receipt messages, security and privacy alerts, changes to our legal terms, and responses to your requests. You will continue to receive these while you have an account, regardless of your promotional-email choices.

We do not market to the people in your mailbox or contacts. We never add email addresses or contact details that we find in your Gmail, calendar, or contacts to our own marketing lists, and we do not send marketing or promotional messages to those people. Addresses drawn from your connected account are used only to provide the user-directed features you ask for.

9. Data retention

We keep personal data only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. Specific behaviors:

  • Gmail message bodies that we cache to provide the Service are held in the working memory of the process that fetched them, for 15 minutes, and are not written to disk, to our object store, or to any durable pointer. The cache expires sooner if the message changes, if you disconnect Google, or when the process restarts. Google remains the authoritative source of your mail; caching is a performance measure, not a system of record. (Until 2026-08-18 this Policy said "encrypted pointers with a rolling 30-day time-to-live", which described a durable cache we designed and never enabled. The window is far shorter than we said — and the next bullet is the part that sentence left out.)
  • The messages of an email conversation the assistant works on are not covered by that cache, and this is the one place where the corrected sentence above is less reassuring than the one it replaced. To answer or reply to a thread, the assistant reads the messages of that thread and keeps them as the conversation it is replying in. That conversation is stored for as long as your account exists, contributes to your derived memory, and is deleted when you delete the conversation in the app or when your account is deleted — the retention stated in the AI conversation and prompt history bullet below, not the retention of a cache.
  • Content-addressed storage vs. mutable pointers. Our storage model uses immutable content-addressed objects ("Vault") together with mutable, single-head pointers ("Pins"). Immutable objects are retained until no longer referenced and are subject to garbage collection; mutable pointers are updated or removed as your data changes and on deletion.
  • Individual deletions. When you delete an item, we remove it from our live systems. Residual copies persist in our encrypted backups until those age out on the rolling 90-day backup cycle.
  • Derived memory is retained for as long as your account is active and you continue to use the Service, and is deleted when you close your account (subject to the exceptions below) or, sooner, on a wipe request to privacy@lonzo.ai — there is no in-product control for it, and Section 12 states the routes.
  • AI conversation and prompt history is retained until you delete it or close your account. In the app you can delete a single conversation; deleting the whole history is a request to privacy@lonzo.ai, as Section 12 states. On account deletion it is removed from live systems on the same schedule as the rest of your account data.
  • Data stored on your own device is listed store by store, with its own retention, in the Cookie & Local Storage Notice — Section 1 for the browser, Section 1A for the mobile app, which stores more because it is local-first. In outline: signing out of the mobile app clears the credentials, the read cache and the connection certificates and asks it to forget the local-first store, keeping only writes that have not yet reached our servers (on an offline device those are the only copy, so discarding them would destroy something you made); clearing app data through your device's settings removes everything including those. Until 2026-08-17 this Policy said only that locally cached data persisted "until you uninstall", which understated both what is stored and what signing out already removes.
  • Account data is retained for the life of your account.
  • Authentication and security audit events are retained for 90 days, and in no case more than 12 months.
  • Technical and usage logs (IP address, device and browser information, diagnostics, error logs) are retained for 30 days, and in no case more than 90 days.
  • Billing, payment, and tax records — your subscription tier and status and the Google Play purchase references, with no payment-card data — are retained for 7 years as tax and accounting law requires. These survive an account deletion, and are minimized to what the legal obligation needs.
  • Email opt-outs and suppression entries. These are two different records with two different lives, and which one an address ends up in depends on which sending path the message left on (Acceptable Use & Anti-Spam Policy, Section 6.1). (i) An opt-out a recipient gives you — through the unsubscribe link or header on a coordination message, or by replying to ask us to stop — is recorded against your account's own record of that recipient. It never expires and cannot be turned off for as long as your account exists, and it holds the fact of the opt-out and the medium it applies to. But it belongs to the account that holds it: it is part of your account data, so it is removed when your account is deleted — as is that account's ability to send anything further. It does not by itself silence a different account that independently holds the same address. (ii) An entry on our email provider's suppression list is created when an address hard-bounces, or reports as spam a message we sent from one of our own lonzo.ai addresses. That entry is keyed to the address rather than to any account, covers our own sending addresses for the whole Service, holds the address and the reason and nothing more, is retained indefinitely by design — discarding it is how the sending would silently resume, so we rely on Art. 17(3) GDPR (compliance with a legal obligation, and the exercise of the right itself) to keep it — and survives an account deletion. We operate no address-keyed suppression list of our own beyond that provider list.
  • Support correspondence. When you email our support address we keep a case record — your address, your subject line, and our notes on how it was handled — for 30 days after the case is closed, or 180 days from the last activity while it is still open. This record is not encrypted under your per-account keys, because anyone can write to support, including someone with no account; the bound is therefore the time limit. That applies to a deletion request as well, since deletion is requested by email. And when we cannot answer you automatically, or you ask to be put through to a person, the text of what you wrote is sent on to a company mailbox so that someone can read it and reply — that copy is ordinary work email, held for 180 days from the last activity on the escalation. Detail: Data Retention & Deletion Policy.

Account closure and deletion timing. When you request account deletion, you can cancel by replying to us at any point before we carry it out; after that it cannot be reversed. On handling your request we remove your account and its data from our live systems and revoke the Google authorization and stored tokens that went with it. That removal completes within 30 days. Residual copies persist in encrypted backups until those age out on the rolling 90-day backup cycle, so full deletion across live systems and backups completes within 90 days. The two numbers differ because they are different mechanisms — one is an action we take, the other a window we wait out — and the 90 days is the longest of three backup windows, which is why it is the one we publish. Until 2026-08-17 this policy said 30 for both; that was the shortest window stated as though it covered all three, and the retention policy explains what changed and why we did not shorten the backups instead.

One thing we do not claim. Destroying an encryption key unique to your account would render every residual copy of your key-protected data unreadable the instant the key was gone — it would not reach the search-index rows described in Section 10, which are not encrypted under that key. We do not currently do that as part of deletion. Your data key is unique to your account, but the key-encryption key that protects it is a single managed key in AWS Key Management Service, shared across accounts and bound to yours cryptographically rather than held as a separate destroyable key per account. So we describe deletion as removal from live systems within 30 days plus expiry from backups within 90, and we do not tell you your data becomes mathematically unrecoverable at the moment you ask. The reasoning, and the categories a deletion does not reach, are in the Data Retention & Deletion Policy.

We do not retain an identifiable account-lifecycle record beyond the deletion window: any lifecycle log kept for security or audit purposes is de-identified. These timings do not apply where retention is required by law (including the billing and suppression entries above) or is needed to resolve disputes or enforce agreements.

10. Security

We protect your data with a defense-in-depth program built around per-actor envelope encryption:

  • Envelope encryption. Each actor's data is encrypted with a dedicated AES-256-GCM data key, and that data key is itself wrapped by a key-encryption key held in AWS Key Management Service and backed by hardware security modules, whose plaintext never exists in our application processes. The key-encryption key is a single managed key bound to each account cryptographically — your account's identity is part of the encryption context that must match before your data key can be unwrapped — rather than a separate key per account; Section 9 explains why that distinction matters for deletion. Your Google data and OAuth tokens are protected under this model, as are the items your derived memory (Section 3(h)) is built from.
  • One exception, stated rather than implied: the search index. To make your data searchable by meaning, we keep an index in which each indexed item contributes a short text excerpt, the vector embedding computed from that excerpt, and a small map of projected fields used for filtering. Those rows are not encrypted under your account's data key, because a value encrypted that way cannot be searched by similarity or filtered by a database query. They are still confined to your own account — every query is restricted to your authenticated identity — the item itself remains encrypted in the primary store, field names that indicate a secret are dropped before a row is written, and the index is excluded from the database exports we take for backup (a residual copy does persist in the encrypted daily snapshots of the database machine's disks, and ages out inside the same window as the backups in Section 9). What they are not protected by is your data key, which also means a read of them produces no entry in the audit log below. Our security overview describes this exception and its limits in full.
  • Purpose-bound decryption. Decryption is authorized only for a specific, declared purpose; there is no general standing ability to read your content.
  • Immutable audit log. Access to protected data on our servers is recorded in an immutable, tamper-evident audit log. Decryption that the app performs on your own device — of the encrypted cache of content it has already fetched for you, and of anything you wrote while offline — is not recorded there, because the log lives in a store only our backbone may write to and a phone that buffered undeliverable entries would eventually have to refuse your own reads. Our security overview states that exception in full, and our Cookie & Local Storage Notice lists what the app keeps on the device and when it is cleared.
  • Encryption in transit. All network traffic is protected with TLS. Every connection our own software terminates — the app's live transport and all internal service-to-service traffic — is TLS 1.3, because those run over QUIC, which permits no earlier version; the public HTTPS edge prefers TLS 1.3 and still accepts TLS 1.2 for older devices, and accepts nothing below it. Internal service-to-service traffic uses mutual TLS (mTLS). See Security at Lonzo for why we state the two cases separately.

No routine human access to your content occurs. Any access by our personnel is purpose-bound, gated by your consent or a legitimate security, abuse, or legal need, and audit-logged. We describe our controls further on our security/trust page at lonzo.ai/legal/security-overview. No system is perfectly secure, and we cannot guarantee absolute security.

Breach notification. In the event of a personal-data breach affecting your information, we will notify affected users and the relevant supervisory authorities or regulators without undue delay and within the timeframes required by applicable law.

11. International data transfers

We are based in, and process data in, the United States, and our cloud infrastructure (AWS) is located in the United States. If you are in the EU, UK, or Switzerland, your data will be transferred to and processed in the United States and other countries whose laws may differ from your own.

Where we transfer personal data out of the EEA, UK, or Switzerland, we rely primarily on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss adaptations as applicable). The SCCs are governed by the law of Ireland, and the competent supervisory authority is the Irish Data Protection Commission. We additionally intend to rely on the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework once we self-certify; we are not yet certified and do not rely on the Framework until we are listed.

12. Your privacy rights

Depending on where you live, you have some or all of the following rights. We honor these rights regardless of where you live to the extent practicable.

If you are in the EU, UK, or Switzerland (GDPR), you may: access your data; correct inaccurate data; request erasure; restrict or object to processing (including processing based on legitimate interests); request portability; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your supervisory authority. We aim to respond within one month.

If you are in California (CCPA/CPRA) or a comparable U.S. state, you may: know and access the personal information we collect and how we use and disclose it; correct inaccurate personal information; delete your personal information; and opt out of the "sale" or "sharing" of personal information and of certain profiling. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We aim to respond within 45 days (extendable as permitted by law). We do not discriminate against you for exercising your rights.

If you are in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), or Oregon (OCPA) — or another U.S. state with a comprehensive privacy law — you have, to the extent the applicable law provides, the rights to: access and confirm whether we process your personal data; correct inaccuracies; delete your personal data; obtain a portable copy of the data you provided; and opt out of the processing of your personal data for purposes of (i) targeted advertising, (ii) the "sale" of personal data, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, do not process it for targeted advertising, and do not use it for such profiling. We aim to respond within 45 days (extendable by an additional period where the law permits).

If you are in Washington (My Health My Data Act) or Nevada (SB 370), health-related information that reaches us through your connected mailbox, calendar, or contacts is "consumer health data" under those laws whatever the reason it reached us, and it carries its own rights — to confirm and access it, to obtain a list of every third party it has been shared with, to withdraw consent to its collection, and to have it deleted, including from backups. Those rights, the categories involved, our commitment never to sell consumer health data, and a precise account of location — that we cannot observe where you are, but that a place you typed into a calendar event is held like the rest of that event — are set out in a separate document those statutes require: the Consumer Health Data Privacy Policy. Read it if any of this applies to you; it is more specific than this Policy and controls where the two describe the same processing.

Automated decision-making and profiling. We do not make decisions producing legal or similarly significant effects about you solely by automated means; a human stays in control of consequential actions (see Section 6 and the AI & Data-Training Disclosure). Where the GDPR applies, you have the right under Article 22 not to be subject to a decision based solely on automated processing that produces such effects, including the right to obtain human intervention, to express your point of view, and to contest the decision. Where a U.S. state law provides it, you may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. To exercise these rights, contact us as described below.

Right to appeal (U.S. state laws). If we decline to act on your request, you may appeal that decision. To appeal, contact us at privacy@lonzo.ai within a reasonable time, and describe the request and the decision you are appealing. We will review the appeal and respond in writing with our decision and the reasons for it within 45 days of receipt (extendable by an additional 60 days where reasonably necessary, with notice to you). If we deny your appeal, we will provide a method to contact, or otherwise inform you of your ability to complain to, your state Attorney General or applicable regulator.

Global Privacy Control (GPC). We honor recognized opt-out preference signals, including GPC, as an opt-out of sale/share where applicable.

"Do Not Track." Some browsers transmit a "Do Not Track" (DNT) signal. There is no common industry standard for how to respond to DNT, and we do not currently respond to DNT signals; however, we do honor recognized opt-out preference signals such as GPC as described above.

California "Shine the Light" (Cal. Civ. Code §1798.83). California residents may request information about our disclosure, if any, of personal information to third parties for their own direct-marketing purposes. We do not disclose your personal information to third parties for their direct-marketing purposes. You may direct any such request to privacy@lonzo.ai.

Exercising your rights. Submit a request by emailing privacy@lonzo.ai. Deletion has two further routes to the same request: Account → Delete account in the app, which asks you to confirm and then records the request from your signed-in session, and lonzo.ai/delete-account, a public page that needs no sign-in and no app install. All three reach the same place, because the erasure itself is carried out by a person — the in-app control files the request and deletes nothing by itself, and you keep access to your account until we act on it. We will verify your identity before acting on a request, which for an in-app request the session has already done. You may use an authorized agent where the law permits. In the app you can also disconnect your connected Google account (Account → Connections), which revokes our access, and delete an individual assistant conversation. Deleting your whole conversation history, wiping your derived memory, and exporting your data are handled on request to privacy@lonzo.ai rather than by an in-app control; your device's local cache is cleared by uninstalling the app.

Third-party (non-user) data. Your mailbox, calendar, and contacts contain personal data about other people who are not our users. For data that exists only because it is in your account — a message someone sent you, a contact card you keep — those individuals exercise their data-subject rights through you, the account holder; we assist you in responding to such requests but do not have an independent relationship with those individuals.

One exception, and it is deliberate. Where the Service itself contacts a third party at your direction — coordination outreach to a meeting participant — we do not treat that person as someone else's problem. We initiated the contact, so we accept responsibility for the outreach and the guest session it creates, we give that person the Article 14 notice they are owed at the point of contact, and we action their access, objection, and deletion requests directly rather than redirecting them to you. Their rights, and the mechanics, are in the Guest & Participant Terms.

13. Children and age

The Service is not directed to children. You must be at least 16 years old to use the Service, and by using it you represent that you meet that minimum age. We do not knowingly collect personal data from anyone under 16. If we become aware that a user is below the applicable minimum age (or under 13 in any event), we will disable the account and delete the associated personal data. Our minimum age is enforced by representation, not verification: the minimum age is stated in our Terms (Section 1.3), and it is disclosed again at the point of sign-up, where the sign-in screen states the minimum age alongside links to these documents and — if you create an account with an email address and password — asks you to confirm it. We do not collect a date of birth and we do not run a third-party age check. We record that the minimum-age representation was presented and made when your account is created.

How we would come to know, stated accurately. Today the routes are human ones: a report to privacy@lonzo.ai, something a user tells us, or anything else that reaches a person here. We do not currently consume an app-store age signal automatically — the app-store frameworks that supply one are being adopted on their own timetables, and we have not built the handler that would read one and act on it. When we do, it will be to avoid acquiring "actual knowledge" of an under-13 user under COPPA, and this Section will say so in the present tense. We would rather tell you that a mechanism is not yet in place than describe one as if it were.

14. Cookies and local storage

Our application and websites use cookies, local storage, and similar technologies to keep you signed in, remember your preferences, and understand usage. Our detailed disclosure and your choices are described in our Cookie & Local Storage Notice at lonzo.ai/legal/cookie-localstorage-notice. We set no server cookies and use no third-party analytics or advertising technology, so no cookie-based "sale" or "share" of personal information occurs.

15. Changes, contact, and representatives

Changes. We may update this Policy from time to time. If we make material changes, we will notify you through the Service or by other appropriate means and update the "Last updated" date above.

Contact. For questions or requests, contact us at privacy@lonzo.ai or Vista del Lago Software LLC, 18381 Vista del Lago, Yorba Linda, CA 92886, USA.

EU/UK representative and DPO. The EEA and UK are within scope of this Policy, and we are therefore required to designate a representative under Article 27 GDPR and UK GDPR. That designation is in progress and is not yet complete, so no representative organization is named here today; we state this rather than imply an appointment we have not made. Until it is complete, direct any request you would address to a representative to privacy@lonzo.ai (attn: "EU Representative" / "UK Representative") — we will handle it on the same terms and within the same deadlines. We will publish the representative's name and registered EEA and UK addresses in this section as soon as the designation is in place. We have not appointed a Data Protection Officer, as one is not required for our processing; our data-protection contact is privacy@lonzo.ai.


All legal documents · Help · Lonzo home