AI & Data-Training Disclosure
Effective 2026-08-09 · Version 1.1This disclosure explains how Lonzo (the "Service"), operated by Vista del Lago Software LLC, uses artificial intelligence to process your data: which models we use and where they run, what data is sent to them, whether your data is used to train any model, how a human stays in the loop, and the limits of AI output. It forms part of, and should be read with, our Privacy Policy (see its Section 6) and our Google API Services Limited Use Disclosure.
1. What the AI does
Lonzo is an AI executive assistant that works over your connected Google account (Gmail, Calendar, Contacts, and Tasks). Its AI features include summarizing and triaging mail, extracting and organizing the people and commitments in your data into a memory graph, drafting replies and messages in your voice, suggesting and preparing calendar events and tasks, and answering your questions in natural language. These features rely on large language models and text-embedding models.
2. Which models we use, and where inference runs
All model inference for the Service is performed through Amazon Web Services' managed AI platform, AWS Bedrock. We use the following model families on Bedrock:
- Amazon Nova — for fast, lightweight reasoning and classification;
- Anthropic Claude — for higher-quality reasoning and drafting;
- Amazon Titan (text embeddings) — to generate the vector embeddings used to organize and search your memory graph.
Where the AI runs. On every plan, the assistant's orchestration runs on our server-side infrastructure (the "Reactor") and the actual model inference is executed by AWS Bedrock. The prompt content sent to the model — which can include the data described in Section 3 — therefore transits to AWS on every plan. We do not run the language models on your device, and we do not represent that your data stays on your device. Your device performs only local presentation work (rendering and ordering your Agenda, and an offline read cache of what it has already been shown).
3. What data is sent to the models
To perform a given AI task, we send the model only the content needed for that task, which may include:
- Gmail content — subject lines, message body text, and sender and recipient information;
- Calendar data — event titles, dates, times, attendees, and descriptions;
- Contacts data — names and related contact details used for context;
- Tasks data — task lists and items;
- Prompts derived from your memory graph — the AI-derived concepts and relationships built from your data, which may contain personal data about you and about third parties;
- Your instructions and questions to the assistant.
Voice is transcribed on your device. When you speak to the assistant, transcription happens locally in your browser, and only the resulting text is ever sent to a model. We do not send or store your voice audio. We do not create or store voiceprints or any other biometric identifiers.
Embeddings. We use the Amazon Titan embedding model to convert your content into vector embeddings that power search and context retrieval within your memory graph.
4. Training — is your data used to train models?
We separate two distinct questions: whether we train our own ("first-party") models on your content, and whether the third-party model providers on Bedrock train on it.
4.1 First-party training (by Vista del Lago Software LLC)
We do not use the content of your connected Google account, your voice text, or your derived memory to train first-party Lonzo models. If we ever wish to use your content to improve our own models, we will do so only on an explicit opt-in basis, with clear notice and a control you can turn off.
4.2 Third-party training and retention (by Bedrock model providers)
We send your content to the model providers on AWS Bedrock (Amazon and Anthropic) only to generate the response you requested, not to help them build their models.
Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.
4.3 Our retention of your assistant conversations
Separately from training, this section states plainly whether we store your assistant conversations — the prompts you send and the responses you receive:
- Every plan (server-side). Your assistant conversation history is stored on our server-side infrastructure (the "Reactor"), protected by the encryption controls described in Privacy Policy Section 10, and retained until you delete it or close your account — it is under your control. You can delete a single conversation in the app at any time, and ask us to delete your entire history by writing to privacy@lonzo.ai; all of it is purged via crypto-shred when you close your account.
- On your device. Your device may hold a local cache of conversations and Agenda content it has already displayed, so the app works offline. You can clear it by uninstalling the Service or through your device's own app-storage controls.
This first-party retention is distinct from the third-party Bedrock zero-retention posture described in Section 4.2: Bedrock retains no prompt or response content after a request completes, whereas the conversation history described here is what we keep so the assistant has continuity across your sessions. See Privacy Policy Section 9 (Data retention) for how this fits our overall retention practices.
5. Consent
We capture your explicit AI-processing consent at the Google-connect step. When you connect your Google account, we present an explicit consent step through which you affirmatively agree to the AI processing of your connected-account content described in this disclosure — including any special-category data incidentally present in your mailbox (see Privacy Policy Section 7, which relies on GDPR Art. 9(2)(a) explicit consent). You can review or change your choice at any time in your settings, including by disconnecting your Google account, and any first-party training would require a separate, strictly opt-in consent. Withdrawing consent does not affect processing carried out before withdrawal.
6. Human in the loop; no solely-automated significant decisions
Lonzo uses AI to analyze your communications and generate recommendations and drafts, but a human stays in control of consequential actions. In particular, the assistant will not send an email on your behalf without your review and approval — outbound messages and other significant actions cross a human-approval boundary before they take effect. The assistant sends mail as you, through your connected Gmail account, only after you approve.
We do not make decisions that produce legal or similarly significant effects on you solely by automated means. You remain responsible for reviewing, approving, and acting on AI-generated output.
Your right to human review (GDPR Art. 22). Where the GDPR applies, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects on you. Consistent with the human-approval boundary above, you may obtain human intervention, express your point of view, and contest any such decision by contacting us at privacy@lonzo.ai. This mirrors the corresponding right described in Privacy Policy Section 12.
7. Accuracy and no reliance
AI output can be wrong. Summaries, drafts, extracted memory, suggested events and tasks, and answers may be inaccurate, incomplete, or out of date, and may not reflect the current state of your mailbox, calendar, or the world. AI output is provided on an "as is" basis, without warranty of accuracy or fitness for a particular purpose. You are responsible for reviewing AI output before you rely on it, send it, or act on it. Do not rely on the Service for professional advice (legal, financial, medical, or otherwise). This disclosure is subject to the limitations of liability and disclaimers in our Terms of Service.
8. Human review of your content
We do not routinely have humans read your content. Any access to your connected-account content or derived memory is purpose-bound — authorized only for a specific declared purpose, such as a support request you initiate, or a genuine security, abuse, or legal need — and every such access is recorded in an immutable audit log. Because decryption is purpose-bound (see Privacy Policy Section 10), even internal access is gated rather than open-ended.
9. The derived-memory graph
To understand context across your mail, calendar, contacts, and tasks, the Service builds a derived-memory graph: an AI-generated store of concepts, relationships, and embeddings drawn from your data. This graph may contain personal data, including personal data about third parties who appear in your account. It is protected by the same encryption, retention, and deletion practices as your other content (see Privacy Policy Sections 9 and 10), is subject to your privacy rights, and — consistent with Section 4.1 — is not used to train first-party models. You can have your derived memory wiped by writing to privacy@lonzo.ai, and it is destroyed by crypto-shred when you delete your account.
10. Your controls
- Connect or disconnect your Google account, and revoke our access at any time from your Google Account permissions (see Privacy Policy Section 5).
- Review and approve (or reject) drafts and outbound actions before they take effect.
- Request deletion of your account and all the data we hold, from a public page needing no sign-in at lonzo.ai/delete-account — this destroys your derived memory along with everything else.
- Have your derived memory wiped, or your conversation history deleted, on request to privacy@lonzo.ai.
- Manage any AI consent or training preference in your settings (where such a control is offered — see Section 5).
11. AI transparency (EU AI Act)
You are interacting with an AI system. Lonzo is an artificial-intelligence system. When you use the assistant, you are communicating with AI-driven software — not a human — and its summaries, drafts, suggestions, and answers are generated by AI models.
AI-generated drafts are presented for your review. Any email reply, message, event, or task the assistant prepares is AI-generated content presented to you for review before it takes effect. Nothing is sent or applied to your account until you approve it (see Section 6). We may label AI-generated drafts as such within the interface so their origin is clear.
These statements are made to meet the transparency obligations of the EU AI Act (Art. 50) for interaction with an AI system and for AI-generated content. If further provenance or labeling disclosures become required for users in the EEA or the UK, we will add them here.
12. Changes and contact
We may update this disclosure as our AI practices evolve; material changes will be communicated as described in our Privacy Policy. Questions about our use of AI can be sent to privacy@lonzo.ai.