Skip to content

Privacy Policy

Effective 2026-08-09 · Version 1.2 · Last updated 2026-08-09

1. Introduction and scope

Lonzo ("Lonzo," the "Service") is an AI executive assistant that works across your connected Google account — Gmail, Google Calendar, Google Contacts, and Google Tasks — to help you read and organize mail, schedule and manage events, draft replies, and keep track of the people and commitments in your life. This Privacy Policy explains what personal data we collect when you use the Service, how and why we process it, the choices and rights you have, and where your data is processed.

This Policy applies to the Lonzo application (web and any native shells), our websites, and related services that link to it. It does not apply to Google's own services, to any third-party service you separately connect, or to third parties' independent handling of your data. Your use of the Service is also governed by our Terms of Service and, where applicable, a Data Processing Agreement.

Because the Service reads and acts on the contents of your mailbox, calendar, contacts, and tasks, please read Sections 3 (what we collect), 4 (where processing happens), and 6 (AI processing) carefully.

2. Who we are (controller and roles)

The entity responsible for the Service is Vista del Lago Software LLC, a Delaware limited liability company that operates the Service under the Lonzo name, located at 18381 Vista del Lago, Yorba Linda, CA 92886, USA ("we," "us," "our").

Our role under data protection law depends on the data in question:

  • Consumer users — account data. We are the controller of the account data we collect to run our business relationship with you — your account and identity data, billing data, and technical, usage, and log data. We decide the purposes and means of processing this data.
  • Consumer users — connected-account content. For the content of your connected Google account — your Gmail messages, calendar events, contacts, tasks, and the derived memory generated from them — we process that content solely to provide the user-directed service you ask for, not for our own purposes. This content is processed on our servers on every plan (Section 4).
  • Business/team customers. Where you access the Service through a business or team account, we act as a processor under our Data Processing Agreement for the data the customer directs us to process, and the customer is the controller.

If you access the Service through an organization (for example, an employer or a business account), that organization is the controller of your data and its own policies may also apply.

For data protection inquiries, contact us at privacy@lonzo.ai. If you are in the EU, UK, or Switzerland, see Section 15 for our representative and Data Protection Officer contact.

3. Personal data we collect

We collect the categories of data below. The categories drawn from your connected Google account are the most sensitive; we describe how we protect them throughout this Policy.

CategoryWhat it includesSource
(a) Account and identity dataYour name, email address, profile information, and the identifiers we use to authenticate you and bind activity to your identity.You / Google sign-in
(b) Billing dataYour subscription tier and status, and the purchase and subscription tokens Google Play provides. Google Play is our only payment channel and holds your payment method directly — we receive no payment-card data of any kind.Google Play
(c) Google Gmail dataThe content and metadata of your Gmail messages — subject lines, message bodies, sender and recipient information, labels, and thread structure — accessed under the RESTRICTED gmail.modify and gmail.readonly scopes, which also let us label, archive, and (under gmail.send) send mail on your behalf, and your basic Gmail settings — the labels and sender filters we manage at your direction — under gmail.settings.basic.Google APIs
(d) Google Calendar dataYour calendar events, including titles, dates, times, attendees, and descriptions, accessed under the calendar.events and calendar.readonly scopes.Google APIs
(e) Google Contacts dataYour contacts, including names, email addresses, and related details, accessed under the contacts scope.Google APIs
(f) Google Tasks dataYour task lists and task items, accessed under the tasks scope.Google APIs
(g) Voice inputWhen you speak to the assistant, your device transcribes your speech to text locally in your browser. Only the resulting text is processed. We do not transmit or store your voice audio on our servers.Your device
(h) Derived memoryA knowledge graph of concepts, relationships, and vector embeddings that the Service derives from your Google data to understand context and answer questions. This derived memory may contain personal data, including personal data about you and about third parties who appear in your mailbox, calendar, or contacts.Generated by the Service
(i) OAuth tokensThe Google OAuth access and refresh tokens that authorize the Service to act on your connected account (see Section 5).Google (on your authorization)
(j) Technical, usage, and log dataIP address, device and browser information, timestamps, feature usage, diagnostics, and error logs.Automatic

Third-party personal data. Your mailbox, calendar, and contacts necessarily contain personal data about other people. When you connect your Google account, you direct us to process that third-party data to provide the Service to you. You are responsible for having an appropriate basis to share that data with us.

Sensitive Personal Information (CPRA). Under the California Privacy Rights Act (CPRA), the contents of your Gmail messages and your account credentials — including your Google OAuth access and refresh tokens — are "Sensitive Personal Information" (SPI), because your mail contents can reveal categories such as the contents of communications and, incidentally, information a mailbox may disclose about you. We use and disclose this SPI only to perform the Service you have requested — reading, organizing, drafting, and answering questions over your connected account — and for the compatible operational purposes (security, fraud prevention, and service delivery) that California law permits without triggering the right to limit. Because we do not use SPI to infer characteristics about you, and use it only for these permitted purposes, the CPRA "right to limit the use of Sensitive Personal Information" does not apply to our processing; we nonetheless describe your related choices and controls in Section 12. We do not use your Sensitive Personal Information to infer characteristics about you, and we do not sell or share it.

4. Where processing happens

Your connected-account content is processed on our servers on every plan. This is a material privacy fact, so we state it plainly rather than by implication.

  • Server-side (all plans). Your mailbox, calendar, contacts, and tasks content is read and processed on our server-side infrastructure (the "Reactor"), where it is protected by the encryption controls described in Section 10. Access to your Google account is performed only by our servers; the application on your device never holds a Google credential and never calls Google's APIs itself.
  • On your device. Your device performs local presentation work — rendering and ordering your Agenda, and an offline read cache of content it has already been shown — and holds your identity keys (see the Cookie & Local-Storage Notice).

We do not represent that your data stays on your device. The AI reasoning steps call a cloud inference provider (AWS Bedrock) to run the language and embedding models, so the prompt content sent to the model — which can include your mailbox, calendar, contacts, tasks, and derived-memory content — transits to AWS. See Section 6 and the AI & Data-Training Disclosure for detail.

Change note. An earlier version of this Policy described a free tier whose processing ran on your device. That tier no longer exists: the Service is offered as paid subscription plans, and processing is server-side for all of them. This section replaces the previous on-device/server-side tier distinction.

5. Google OAuth tokens and your control

To act on your connected Google account, we store Google OAuth access and refresh tokens, including a refresh token for the RESTRICTED gmail.modify and gmail.readonly scopes. These tokens are held encrypted using the envelope-encryption model described in Section 10.

We request the following eleven scopes — eight over your Google data, and the three standard sign-in scopes:

  • gmail.modify (RESTRICTED) — to read your mail and to organize it (label, archive) and send messages on your behalf after your approval;
  • gmail.readonly (RESTRICTED) — read access to your mail, requested alongside gmail.modify so the assistant's read paths work on a grant carrying read access;
  • gmail.send — to send the messages you approve, checked as its own permission before any send;
  • gmail.settings.basic — to manage mail filters (always-silence / always-surface sender rules) at your direction; the gmail.modify scope does not cover mailbox settings;
  • calendar.events — to read and manage your calendar events;
  • calendar.readonly — to read your calendars and event details for scheduling context;
  • contacts — to read your contacts for context, autocomplete, and scheduling;
  • tasks — to read and manage your task lists;
  • openid, profile, email — standard OpenID Connect sign-in, to identify your account and to show your Google name and picture where you have set none of your own. These carry no access to your mail, calendar, contacts, or tasks.

You can revoke our access at any time from your Google Account permissions page (myaccount.google.com/permissions). Revoking access immediately stops our ability to read from or act on your connected account. For how we handle deletion after revocation, see Section 9.

6. AI processing (summary)

The Service uses AI models to summarize, organize, draft, and answer questions over your data. All model inference — on every plan — is performed through AWS Bedrock, using the Amazon Nova, Anthropic Claude, and Amazon Titan (embeddings) model families. Content sent to these models can include your Gmail, Calendar, Contacts, and Tasks data and prompts derived from your memory graph. Voice is transcribed on your device, and only the resulting text is ever sent to a model.

This section is a summary. Our full disclosure of which models we use, what data is sent, our human-in-the-loop approval boundary, our first-party and third-party training posture, and the accuracy limits of AI output is set out in the AI & Data-Training Disclosure, which forms part of this Policy.

Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.

7. How and why we use data, and our legal bases

We use personal data for the purposes below. For users protected by the EU/UK GDPR, we identify the legal basis for each purpose.

PurposeData usedLegal basis (GDPR)
Provide the assistant: read and organize mail, schedule, draft replies, manage tasks and contacts, answer questionsGoogle data (c–f), derived memory (h), voice text (g), account data (a)Performance of a contract (Art. 6(1)(b))
Build and maintain the derived-memory graph that powers contextGoogle data (c–f)Performance of a contract (Art. 6(1)(b))
Authenticate you and maintain security, prevent fraud and abuseAccount data (a), tokens (i), technical/usage data (j)Legitimate interests (Art. 6(1)(f))
Bill and manage subscriptionsBilling data (b), account data (a)Performance of a contract; legal obligation (Art. 6(1)(b), (c))
Provide support and respond to requestsAccount data (a), relevant content you sharePerformance of a contract; legitimate interests
Maintain, secure, and improve the Service's operationTechnical/usage/log data (j)Legitimate interests (Art. 6(1)(f))
Comply with law and respond to lawful requestsAs requiredLegal obligation (Art. 6(1)(c))
Any use of your content to train first-party models (see Section 6 / AI disclosure)As applicableConsent (Art. 6(1)(a))

Special-category data (GDPR Art. 9). A mailbox, calendar, or contact list unavoidably contains information that may qualify as special-category data under Article 9 GDPR — for example, correspondence that reveals health conditions, religious or political views, trade-union membership, or sexual orientation. We do not seek out or target such data, but because we process the whole of your connected account at your direction, we cannot exclude it. Our Article 9(2) condition for processing this data is your explicit consent under Art. 9(2)(a). We capture this explicit consent at the Google-connect step: when you authorize the Service, you affirmatively agree to the AI processing of your connected-account content, including any special-category data incidentally present in it, as described here and in the AI & Data-Training Disclosure. You may withdraw that consent at any time by disconnecting your Google account (see Sections 5 and 12); withdrawal does not affect processing carried out before withdrawal.

We do not use your Google data for advertising or marketing. We do not use the content of your Gmail, Calendar, Contacts, or Tasks to serve advertisements, and we do not sell it. This is also a requirement of Google's Limited Use policy (see the Google API Services Limited Use Disclosure).

No first-party training. We do not use your connected-account content to train first-party Lonzo models, and if we ever do, it will be strictly opt-in. See the AI & Data-Training Disclosure for the full posture.

8. Sharing and subprocessors

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We disclose personal data only as follows:

  • Service providers (subprocessors) who process data on our behalf under contractual obligations consistent with this Policy — most significantly Amazon Web Services, which provides our cloud inference (AWS Bedrock: Amazon Nova, Anthropic Claude, and Amazon Titan embeddings) and hosting. We maintain a subprocessor list at lonzo.ai/legal/subprocessors, which we update as our vendor set changes.
  • Legal and compliance — where we reasonably believe disclosure is required to comply with law, legal process, or a lawful government request, or to protect the rights, safety, or security of users, the public, or the Service.
  • Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy or a successor policy that provides comparable protection.

We require our subprocessors to protect your data and to use it only to provide services to us.

CCPA/CPRA categories of personal information. For the purpose of the California Consumer Privacy Act, the personal information we collect (described in Section 3) maps to the following statutory categories:

  • Identifiers — name, email address, account identifiers, IP address, and OAuth tokens (Section 3(a), (i), (j)).
  • Commercial information — your subscription tier, status, and billing references (Section 3(b)).
  • Internet or other electronic network activity — feature usage, diagnostics, timestamps, and log data (Section 3(j)).
  • Geolocation data — only coarse location that may be inferred from your IP address; we do not collect precise geolocation.
  • Sensitive Personal Information — the contents of your Gmail messages and your account credentials (see Section 3 and the SPI subsection).
  • Content of communications — your Gmail, Calendar, Contacts, and Tasks content (Section 3(c)–(f)).
  • Inferences — the derived-memory graph of concepts, relationships, and embeddings the Service builds from your data (Section 3(h)).

We collect these categories from the sources identified in Section 3 (you, Google sign-in and APIs, Google Play billing, your device, and automatic collection). We disclose personal information in the above categories to our subprocessors (most significantly AWS) for a business purpose — to host and operate the Service and run AI inference — under contracts that restrict their use of it. We do not sell your personal information, and we do not share it for cross-context behavioral advertising, in any category.

De-identified and aggregated data. We may create de-identified or aggregated data (for example, aggregate usage statistics and service-quality metrics) that does not identify you or any individual, and we may use and retain such data for operating, securing, analyzing, and improving the Service. Where we do so, we will maintain the data in de-identified form, will not attempt to re-identify it except as permitted by law to test our de-identification, and will contractually prohibit recipients from re-identifying it. For the avoidance of doubt, de-identified and aggregated data is not a route around our training posture: creating or using de-identified/aggregated data does not authorize training first-party models on your connected-account content, which remains governed by the no-first-party-training default described in Section 7 and the AI & Data-Training Disclosure (any first-party training would be strictly opt-in).

8A. Marketing communications

We may send you promotional email — for example, product announcements, feature updates, tips, and offers related to the Service. You can opt out of promotional email at any time by using the unsubscribe link in the message or by changing your notification preferences in your settings; we will honor your choice promptly. For users in the EU/UK, we send promotional email on the basis of your consent or, where permitted (for example, to our existing customers about similar services), our legitimate interests, and you may object to such processing at any time.

Service and security emails are not opt-outable. Certain messages are necessary to operate the Service and are not marketing — for example, transactional and account notices, billing and receipt messages, security and privacy alerts, changes to our legal terms, and responses to your requests. You will continue to receive these while you have an account, regardless of your promotional-email choices.

We do not market to the people in your mailbox or contacts. We never add email addresses or contact details that we find in your Gmail, calendar, or contacts to our own marketing lists, and we do not send marketing or promotional messages to those people. Addresses drawn from your connected account are used only to provide the user-directed features you ask for.

9. Data retention

We keep personal data only as long as necessary for the purposes described in this Policy, and then delete or de-identify it. Specific behaviors:

  • Gmail message bodies that we cache to provide the Service are stored as encrypted pointers with a rolling 30-day time-to-live, after which the cached body is evicted. Google remains the authoritative source of your mail; caching is a performance and continuity measure, not a system of record.
  • Content-addressed storage vs. mutable pointers. Our storage model uses immutable content-addressed objects ("Vault") together with mutable, single-head pointers ("Pins"). Immutable objects are retained until no longer referenced and are subject to garbage collection; mutable pointers are updated or removed as your data changes and on deletion.
  • Individual deletions and trash. When you delete an item, it is recoverable from trash for 7 days, after which it is crypto-shredded (rendered irrecoverable by destroying the associated encryption key).
  • Derived memory is retained for as long as your account is active and you continue to use the Service, and is deleted when you delete it or close your account (subject to the exceptions below).
  • AI conversation and prompt history is retained until you delete it or close your account — you control it and can delete a single conversation or all of it. On account deletion it is purged via crypto-shred.
  • Locally cached data persists on your device until you uninstall the Service; you control it directly, and it is also cleared through your device's own app-storage controls.
  • Account, billing, and log data is retained for the life of your account and for a limited period afterward as needed for legal, accounting, security, and audit purposes.

Account closure and deletion timing. On account closure, your account is recoverable for a 7-day grace period. At the end of the grace period we destroy the per-actor encryption key (crypto-shred), which renders the associated content irrecoverable; residual encrypted backup copies — already unreadable once the key is destroyed — age out on a rolling 30-day backup cycle. Full deletion across live systems and backups completes within 30 days. We do not retain an identifiable account-lifecycle record beyond this window: any lifecycle log kept for security or audit purposes is de-identified. These timings do not apply where retention is required by law or is needed to resolve disputes or enforce agreements.

10. Security

We protect your data with a defense-in-depth program built around per-actor envelope encryption:

  • Envelope encryption. Each actor's data is encrypted with a dedicated AES-256-GCM data key, and that data key is itself wrapped by a key-encryption key held in a hardware security module (HSM). Your Google data, OAuth tokens, and derived memory are protected under this model.
  • Purpose-bound decryption. Decryption is authorized only for a specific, declared purpose; there is no general standing ability to read your content.
  • Immutable audit log. Access to protected data is recorded in an immutable, tamper-evident audit log.
  • Encryption in transit. All network traffic is protected with TLS 1.3, and internal service-to-service traffic uses mutual TLS (mTLS).

No routine human access to your content occurs. Any access is purpose-bound, gated by your consent or a legitimate security, abuse, or legal need, and audit-logged. We describe our controls further on our security/trust page at lonzo.ai/legal/security-overview. No system is perfectly secure, and we cannot guarantee absolute security.

Breach notification. In the event of a personal-data breach affecting your information, we will notify affected users and the relevant supervisory authorities or regulators without undue delay and within the timeframes required by applicable law.

11. International data transfers

We are based in, and process data in, the United States, and our cloud infrastructure (AWS) is located in the United States. If you are in the EU, UK, or Switzerland, your data will be transferred to and processed in the United States and other countries whose laws may differ from your own.

Where we transfer personal data out of the EEA, UK, or Switzerland, we rely primarily on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss adaptations as applicable). The SCCs are governed by the law of Ireland, and the competent supervisory authority is the Irish Data Protection Commission. We additionally intend to rely on the EU-U.S., UK Extension, and Swiss-U.S. Data Privacy Framework once we self-certify; we are not yet certified and do not rely on the Framework until we are listed.

12. Your privacy rights

Depending on where you live, you have some or all of the following rights. We honor these rights regardless of where you live to the extent practicable.

If you are in the EU, UK, or Switzerland (GDPR), you may: access your data; correct inaccurate data; request erasure; restrict or object to processing (including processing based on legitimate interests); request portability; and withdraw consent where processing is based on consent. You also have the right to lodge a complaint with your supervisory authority. We aim to respond within one month.

If you are in California (CCPA/CPRA) or a comparable U.S. state, you may: know and access the personal information we collect and how we use and disclose it; correct inaccurate personal information; delete your personal information; and opt out of the "sale" or "sharing" of personal information and of certain profiling. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We aim to respond within 45 days (extendable as permitted by law). We do not discriminate against you for exercising your rights.

If you are in Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), or Oregon (OCPA) — or another U.S. state with a comprehensive privacy law — you have, to the extent the applicable law provides, the rights to: access and confirm whether we process your personal data; correct inaccuracies; delete your personal data; obtain a portable copy of the data you provided; and opt out of the processing of your personal data for purposes of (i) targeted advertising, (ii) the "sale" of personal data, and (iii) profiling in furtherance of decisions that produce legal or similarly significant effects. We do not sell personal data, do not process it for targeted advertising, and do not use it for such profiling. We aim to respond within 45 days (extendable by an additional period where the law permits).

Automated decision-making and profiling. We do not make decisions producing legal or similarly significant effects about you solely by automated means; a human stays in control of consequential actions (see Section 6 and the AI & Data-Training Disclosure). Where the GDPR applies, you have the right under Article 22 not to be subject to a decision based solely on automated processing that produces such effects, including the right to obtain human intervention, to express your point of view, and to contest the decision. Where a U.S. state law provides it, you may opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. To exercise these rights, contact us as described below.

Right to appeal (U.S. state laws). If we decline to act on your request, you may appeal that decision. To appeal, contact us at privacy@lonzo.ai within a reasonable time, and describe the request and the decision you are appealing. We will review the appeal and respond in writing with our decision and the reasons for it within 45 days of receipt (extendable by an additional 60 days where reasonably necessary, with notice to you). If we deny your appeal, we will provide a method to contact, or otherwise inform you of your ability to complain to, your state Attorney General or applicable regulator.

Global Privacy Control (GPC). We honor recognized opt-out preference signals, including GPC, as an opt-out of sale/share where applicable.

"Do Not Track." Some browsers transmit a "Do Not Track" (DNT) signal. There is no common industry standard for how to respond to DNT, and we do not currently respond to DNT signals; however, we do honor recognized opt-out preference signals such as GPC as described above.

California "Shine the Light" (Cal. Civ. Code §1798.83). California residents may request information about our disclosure, if any, of personal information to third parties for their own direct-marketing purposes. We do not disclose your personal information to third parties for their direct-marketing purposes. You may direct any such request to privacy@lonzo.ai.

Exercising your rights. Submit a request by emailing privacy@lonzo.ai. You can also request deletion of your account without logging in, and without installing the app, at lonzo.ai/delete-account. We will verify your identity before acting on a request. You may use an authorized agent where the law permits. In the app you can also disconnect your connected Google account (Account → Connected), which revokes our access, and delete an individual assistant conversation. Deleting your whole conversation history, wiping your derived memory, and exporting your data are handled on request to privacy@lonzo.ai rather than by an in-app control; your device's local cache is cleared by uninstalling the app.

Third-party (non-user) data. Your mailbox, calendar, and contacts contain personal data about other people who are not our users. Those individuals exercise their data-subject rights through you, the account holder; we assist you in responding to such requests but do not have an independent relationship with those individuals.

13. Children and age

The Service is not directed to children. You must be at least 16 years old to use the Service, and by using it you represent that you meet that minimum age. We do not knowingly collect personal data from anyone under 16. If we become aware — including through an age signal provided by an app store — that a user is below the applicable minimum age (or under 13 in any event), we will disable the account and delete the associated personal data. Our minimum age is enforced by representation, not verification: the minimum age is stated in our Terms (Section 1.3), and it is disclosed again at the point of sign-up, where the sign-in screen states the minimum age alongside links to these documents and — if you create an account with an email address and password — asks you to confirm it. We do not collect a date of birth and we do not run a third-party age check. We record that the minimum-age representation was presented and made when your account is created. We consume app-store age signals only to avoid "actual knowledge" of an under-13 user under COPPA.

14. Cookies and local storage

Our application and websites use cookies, local storage, and similar technologies to keep you signed in, remember your preferences, and understand usage. Our detailed disclosure and your choices are described in our Cookie & Local Storage Notice at lonzo.ai/legal/cookie-localstorage-notice. We set no server cookies and use no third-party analytics or advertising technology, so no cookie-based "sale" or "share" of personal information occurs.

15. Changes, contact, and representatives

Changes. We may update this Policy from time to time. If we make material changes, we will notify you through the Service or by other appropriate means and update the "Last updated" date above.

Contact. For questions or requests, contact us at privacy@lonzo.ai or Vista del Lago Software LLC, 18381 Vista del Lago, Yorba Linda, CA 92886, USA.

EU/UK representative and DPO. The EEA and UK are within scope and we have appointed an Article 27 representative; until the named representative organization and its registered EEA/UK address are published, you may reach the representative via privacy@lonzo.ai (attn: "EU Representative" / "UK Representative"). We will publish the representative's name and registered address here once appointed. We have not appointed a Data Protection Officer, as one is not required for our processing; our data-protection contact is privacy@lonzo.ai.


All legal documents · Help · Lonzo home