Skip to content

Acceptable Use & Anti-Spam Policy

Effective 2026-07-28 · Version 1.0

This Acceptable Use & Anti-Spam Policy (the "Policy" or "AUP") governs your use of Lonzo (the "Service"), operated by Vista del Lago Software LLC, a Delaware limited liability company ("we," "us," or "our"). It is incorporated by reference into, and is part of, the Terms of Use. Capitalized terms not defined here have the meanings given in the Terms of Use. If you violate this Policy, we may suspend or terminate your access as described in Section 9 and in the Terms of Use.

This Policy matters especially because the Service acts on your behalf — it sends email through your connected Google (Gmail) account as you, organizes your mailbox, and creates, changes, and cancels calendar events that cause Google to notify attendees. Because those communications are transmitted through your own Google account, the anti-spam rules in Sections 4 through 7 are central to this Policy.


1. Scope, Applicability & Monitoring

1.1 Who is bound. This Policy applies to everyone who uses the Service, and to anyone you enable or direct to use it. You agree not to violate this Policy and not to help or encourage anyone else to violate it.

1.2 No duty to monitor; right to act. We have no obligation to monitor use of the Service, but we may do so, and we may investigate suspected violations, remove or disable content or actions, rate-limit or block traffic, and suspend or terminate accounts. We may take these steps when we reasonably believe this Policy has been violated.

1.3 Automated enforcement. Because the Service is itself an automated agent, our monitoring and enforcement may be carried out in whole or in part by automated systems.

1.4 Underlying providers' acceptable-use policies. The Service operates on top of, and transmits your content to, third-party providers — in particular Google (Google Workspace / Gmail, Calendar, Contacts, and Tasks APIs) and Amazon Web Services, including Amazon Bedrock, through which AI processing occurs. Your use of the Service is additionally subject to the acceptable-use, prohibited-use, and content policies of those providers, including Google's Terms of Service and API and acceptable-use policies and Amazon's AWS Acceptable Use Policy, AWS Service Terms, and any Amazon Bedrock or AWS-model provider acceptable-use terms, each as they may be updated. You agree not to use the Service in any way that would cause us or you to violate those providers' policies, and a use that is prohibited by an applicable underlying provider's policy is also prohibited under this Policy. Where those policies impose obligations that pass through to end users, you agree to comply with them.


2. Prohibited Uses — System & Service Integrity

You may not, and may not attempt to, or help anyone else:

2.1 probe, scan, or test the vulnerability of the Service or any related system or network, or breach or circumvent any security or authentication measure, except under an authorized security-research program we expressly permit (see Section 2.7);

2.2 reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code, architecture, models, prompts, or underlying components of the Service, except to the extent this restriction is prohibited by applicable law;

2.3 scrape, harvest, crawl, or bulk-extract data or content from the Service, or access data or accounts not intended for you;

2.4 introduce or transmit any virus, worm, malware, or other harmful code, or upload content designed to disrupt, damage, or gain unauthorized access to any system;

2.5 overload, flood, or otherwise impose an unreasonable or disproportionate load on the Service or its infrastructure, or interfere with or disrupt the Service, servers, or networks (including through denial-of-service techniques);

2.6 bypass, disable, or circumvent rate limits, usage limits, access controls, or geographic or account restrictions; use proxies or IP masking to evade blocks; or create accounts by automated means or in bulk, or abuse referrals, trials, promotions, or billing mechanics;

2.7 Authorized security research. Notwithstanding Section 2.1, good-faith security research conducted in accordance with a vulnerability-disclosure program we publish, and within its stated scope and rules, is permitted. Report suspected vulnerabilities to security@lonzo.ai.

2.8 Protecting the AI system. You may not attempt to manipulate, jailbreak, or subvert the Service's AI systems or the underlying inference infrastructure — for example, through prompt injection or crafted inputs — to (a) cause the Service to take actions you are not authorized to take or that violate this Policy, (b) extract system prompts, model weights, or non-public system behavior, (c) generate content prohibited by this Policy, or (d) send communications the recipient has not consented to receive. You may not use the Service to generate spam, abuse, or other prohibited content at scale.


3. Prohibited Uses — Wrongful & Illegal Conduct

You may not use the Service to, or to help anyone:

3.1 violate any applicable law or regulation, including data-protection, anti-bribery, anti-corruption, anti-money-laundering, export-control, or sanctions laws;

3.2 harass, threaten, stalk, bully, defame, or intimidate any person, or promote violence or hatred against any person or group on the basis of a protected characteristic;

3.3 impersonate any person or entity, misrepresent your affiliation with any person or entity, or deceptively disguise AI-generated content as human-authored where doing so is misleading or unlawful;

3.4 commit or facilitate fraud, phishing, deceptive schemes, or pyramid or other unlawful monetization schemes;

3.5 infringe or misappropriate any patent, copyright, trademark, trade secret, or other intellectual-property or proprietary right, or violate any person's privacy or publicity rights (see the Copyright & DMCA Policy);

3.6 produce, store, or transmit content that sexually exploits or endangers minors (real or depicted); promote terrorism, terrorist organizations, or hate groups; encourage or glorify self-harm, eating disorders, or suicide; distribute non-consensual intimate images or deceptive deepfakes; or distribute gratuitously graphic or violent content;

3.7 use AI outputs to make or support automated decisions that produce legal or similarly significant effects about a person (for example, in credit, employment, housing, insurance, or healthcare) without meaningful human review; and

3.8 publish or gather other people's private, confidential, or personal information without authorization; and

3.9 rely on the Service to process protected health information or other special-category data. We do not offer a HIPAA Business Associate Agreement (BAA), and the Service is not designed or authorized for use as a HIPAA-covered service. You may not use the Service to create, receive, maintain, transmit, or otherwise process, and you may not rely on the Service to safeguard, any "protected health information" (PHI) as defined under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, unless we have signed a written agreement (including a BAA) expressly permitting it — which we do not currently offer. The same restriction applies to other categories of especially sensitive or regulated data whose processing requires a separate written agreement or heightened safeguards we have not agreed to provide, including (as examples) data subject to the Gramm-Leach-Bliley Act, payment-card data subject to PCI DSS, or biometric data regulated by statutes such as the Illinois Biometric Information Privacy Act. If health or other special-category information incidentally appears in your mailbox or other connected Google data, the Service may process it only as part of providing the Service to you and subject to the Privacy Policy; but you must not use the Service as a system of record for, or to knowingly route, such data, and you are responsible for any regulated data you introduce.


4. Anti-Spam — No Unsolicited or Abusive Communications

Because the Service sends email through your connected Google (Gmail) account as you, you may not use the Service to:

4.1 send spam or unsolicited bulk or commercial email or messages, chain letters, or duplicate or saturation content;

4.2 mail-bomb, flood, or otherwise send communications intended or likely to overwhelm, harass, or disrupt any recipient or system;

4.3 send communications with forged, spoofed, or misleading headers, sender identities, routing information, or subject lines, or otherwise disguise the origin of a message;

4.4 send phishing messages or communications designed to deceive recipients into disclosing information or taking harmful action;

4.5 use the Service's send-on-behalf capability to contact a recipient who has opted out of, unsubscribed from, or asked not to receive communications, or to evade or circumvent any recipient's opt-out; or

4.6 send communications at a volume or rate that, in our reasonable judgment, is abusive, and we may impose and enforce rate limits and outbound-volume limits and block or throttle traffic to protect recipients, our systems, and our sending reputation.


5. No Contacting People Outside the Service Without Permission

5.1 You may not use email addresses, phone numbers, or other contact or personal information that you surface, obtain, or access through the Service to contact people outside the Service without that person's express permission, and you may not export or use such information to build mailing or contact lists for use outside the Service.

5.2 Coordination-outreach feature (not currently offered). If and when we enable a coordination-outreach feature — under which the Service, at your direction, contacts third-party participants (for example, people drawn from your contacts) to help arrange a meeting or event you are organizing — that feature may be used only for legitimate, expected, transactional coordination of the specific event you are arranging. It may not be used for marketing, advertising, promotion, or any communication unrelated to the coordination you initiated. You are responsible for having a lawful basis to contact each third party, and outreach content is limited to the transactional coordination details of your event.

5.3 Our reciprocal commitment. We do not use the contact information of third-party participants that the Service surfaces or that you provide to send them our own marketing.


6. CAN-SPAM, Opt-Out & SMS Controls (Outbound Communications)

Where our systems transmit communications on your behalf, both you and we must comply with applicable communications laws. Accordingly:

6.1 Email / CAN-SPAM. All outbound email is originated from your own connected Google (Gmail) account and is sent only after you review and approve the send through the human-approval boundary described in the Terms of Use — the Service sends no email from any Lonzo mail identity of its own. Outbound email must have accurate header and sender information. Email is sent so that it is sent from you; you are responsible for the accuracy and honesty of the sender identity and content of each message you approve or direct, and unsubscribe and opt-out requests will be honored. If we later introduce any outreach the Service itself originates, it will carry a functioning opt-out mechanism and a List-Unsubscribe header, which you may not remove, disable, or circumvent.

6.2 SMS / TCPA (not currently offered). The Service sends no SMS or text messages. If it later sends SMS or text messages on your behalf, those messages require the recipient's consent as required by law, must honor STOP / START and similar opt-out and opt-in keywords, may not contain marketing or promotional content, and must comply with applicable carrier and messaging-aggregator acceptable-use policies (for example, the messaging provider's AUP) and with the TCPA and CTIA guidelines. Additional SMS terms may be set out in a separate SMS policy.

6.3 Rate limits and controls. We maintain rate limits and other technical controls to prevent abuse of these features. You may not circumvent them, and we may adjust or enforce them at any time. Misuse of the send-on-behalf or calendar-notification features (or, if a coordination-outreach feature is later offered, that feature) to spam, harass, or deceive recipients is a serious violation of this Policy and may result in immediate suspension or termination.

The only outbound channel in the Service is email sent through your own connected Gmail account: it is sent by you, as you, with your own address in the From header. The Service sends no email from an identity of its own and sends no SMS.


7. Calendar Notifications

The Service creates, changes, and cancels calendar events, and Google may automatically email affected attendees. You may not use assistant-driven calendar activity — for example, repeated creation, rescheduling, or cancellation of events — to spam, harass, or disrupt attendees, or to cause them to receive unwanted communications. You are responsible for the events you or the Service create, change, or cancel and for the notifications they generate.


8. Trademarks & Branding

You may not use the Lonzo, Lonzo Agenda, Lonzo Agent, or Lonzo.AI names, logos, taglines, or other marks without our prior written permission, and you may not remove, obscure, or alter any of our proprietary notices or branding. Full trademark terms are in the Copyright & DMCA Policy.


9. Enforcement, Reporting & Consequences

9.1 Consequences. If we determine, in our reasonable judgment, that you have violated this Policy, we may take any action we consider appropriate, including removing or disabling content or actions, imposing rate limits, suspending or terminating your account, revoking the authorization you granted under the Terms of Use, and reporting to law enforcement. Severe or illegal violations may result in immediate termination without notice. We may report and remove child sexual-abuse material as required by law.

9.2 Reporting abuse. To report a suspected violation of this Policy, contact us at abuse@lonzo.ai. We may, but are not obligated to, act on any report.

9.3 Disclosure. We may disclose information about suspected violations to law enforcement or affected third parties as permitted or required by law and as described in the Privacy Policy.


10. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated as described in the Terms of Use, and your continued use of the Service after a change takes effect means you accept the updated Policy.


11. Contact

Vista del Lago Software LLC 18381 Vista del Lago, Yorba Linda, CA 92886, USA Abuse / anti-spam reports: abuse@lonzo.ai · General / legal: legal@lonzo.ai


All legal documents · Help · Lonzo home