Skip to content

Consumer Health Data Privacy Policy

Effective 2026-08-16 · Version 1.1

This is a separate, standalone policy, published because Washington's My Health My Data Act (RCW 19.373) and Nevada's SB 370 (NRS 603A.400–603A.550) require a distinct consumer-health-data notice rather than a section inside a general privacy policy. It applies in addition to our Privacy Policy, which governs everything else. Where this policy and the Privacy Policy describe the same processing, this one is the more specific and controls for consumer health data.

It is written for residents of Washington and Nevada, whose laws create these specific obligations, but the commitments in it are how we behave for everyone. We are Vista del Lago Software LLC, a Delaware limited liability company, of 18381 Vista del Lago, Yorba Linda, CA 92886, USA, offering the Service under the Lonzo name. Health-data contact: privacy@lonzo.ai.


1. The short version

Lonzo is an assistant for your email, calendar, contacts, and tasks. We do not ask for health information, we have no health feature, and we do not try to work out anything about your health. But if you connect a mailbox and a calendar, health-related things are in there — a message from a clinic, a calendar entry for a dental appointment, a pharmacy receipt — and an assistant that reads your mail reads those too. Washington and Nevada law treats that category of information as consumer health data whatever the reason it reached us, so it is covered here.

Four commitments, stated up front because they are the ones that matter:

  1. We do not sell consumer health data. Ever, to anyone, for anything. No exceptions, no "sharing for cross-context advertising," no data brokers. We have no advertising business, and we do not intend to acquire one.
  2. We do not use it to infer, score, profile, or predict anything about your health, and we do not build health profiles or health-related audience segments.
  3. We do not use it, or anything else in your account, to train AI models — ours or anyone else's. That commitment covers all of your data and is set out in the AI & Data-Training Disclosure.
  4. We collect no location data of any kind, so the geofencing prohibitions in both statutes are not something we comply with so much as something we have no way to violate. We operate no geofence around any health-care facility, and we cannot, because the Service never receives your location.

2. What "consumer health data" means here

Both statutes define it broadly: personal information linkable to a consumer that identifies their past, present, or future physical or mental health status. That reaches more than diagnoses — it includes health conditions and treatment, medications, bodily functions and vital signs, health-related surgeries and procedures, use or purchase of medication, health-care services sought or received including the precise location of any attempt to acquire them, reproductive and sexual health information, gender-affirming care information, biometric data, genetic data, and any inference drawn from any of the above.

Two of those categories we hold no substrate for at all: we collect no biometric data and no genetic data. Nothing in the Service captures a fingerprint, a face template, a voiceprint, or genetic information, and nothing in it accepts an upload of one.

3. What can reach us, and how

We do not have a health-data collection point. What we have is a connected mailbox and calendar, so the categories below are what can arrive incidentally, inside content you already have:

CategoryHow it can reach usWhat it looks like in practice
Health-care services sought or receivedContent of email in your connected Gmail mailbox; events in your connected Google CalendarAn appointment confirmation, a message from a provider's office, a calendar entry naming a clinic
Health conditions, treatment, diagnoses, medicationsThe sameA message discussing a condition, a prescription notification, a pharmacy receipt
Reproductive or sexual health information; gender-affirming care informationThe sameAny of the above where that is the subject
Bodily functions, vital signs, symptoms, measurementsThe sameA lab result or a wearable's summary email that happens to land in your inbox
Contacts who are health-care providersYour connected Google ContactsA contact card for a doctor's office
Anything you type to the assistantYour own messages to the assistantAsking it to reschedule a medical appointment

Sources. Every one of these has exactly one source: the Google account you chose to connect, plus what you type to the assistant yourself. We buy no data, we obtain none from data brokers, we scrape none, and we receive none from any third party other than Google acting on your instruction. Our full list of service providers is at Sub-processors.

Precise location: none. The definition above includes "the precise location of a consumer's attempt to acquire health-care services." We do not collect precise geolocation, coarse geolocation, or any location data. The Service has no location permission, requests none, and derives nothing locational beyond the coarse network origin of a request, which is retained in bounded technical logs (see Section 7) and is never associated with health-related content or used for any health purpose.

4. Why we process it, and what we will not do with it

The only purpose is the one you asked for: operating the Service you enabled — reading your mail so it can be triaged, summarized, drafted against, and scheduled; finding what you asked for; and doing the things you told it to do. Health-related content is processed for that and nothing else. It is not a separate product feature; it is content passing through the same pipeline as everything else in your mailbox.

We do not, with consumer health data:

  • sell it, in any sense either statute defines, including any exchange for anything of value;
  • share it for advertising, cross-context behavioral advertising, or any marketing purpose, ours or anyone else's;
  • use it to train, fine-tune, or evaluate any AI model (the AI & Data-Training Disclosure is the operative commitment and it applies to all of your data);
  • infer or score health status from it, or build health segments, or use it to make or support any decision about you;
  • use it to target you, in the app or anywhere else;
  • collect it through a geofence or use location to detect a visit to a health-care facility; or
  • hand it to a data broker.

5. Who it goes to

Consumer health data goes only where the rest of your content goes, and only because the Service cannot work otherwise:

  • Google — because the data lives in your Google account. Reading it is the Service; nothing is copied to Google that was not already there.
  • Amazon Web Services, including Amazon Bedrock for AI processing, as our infrastructure and model-hosting provider. Bedrock does not retain the content of our requests to train its models, and our agreement with AWS does not permit it to.
  • Our email provider, for mail we send you or send at your direction.

Each is a service provider or processor acting on our instructions under contract, not an independent recipient free to use your data for its own purposes. The complete, current list — with what each does and where it operates — is at Sub-processors, which is the same list for health-related content as for everything else.

No one else. We disclose consumer health data to no other third party except as Section 6 describes.

6. Legal process

We may disclose data, including consumer health data, where a law compels it, but a request touching health data gets our narrowest reading of it. Consistent with our Privacy Policy:

  • We require valid legal process and disclose the minimum the process actually compels.
  • We will not treat a request as valid because it is inconvenient to challenge, and we will resist an overbroad one.
  • Where the law permits it, we will notify you before disclosing, and where we are barred from notifying you we will say so as soon as the bar lifts.
  • We publish nothing about individual accounts.

We recognize why this matters specifically for reproductive-health and gender-affirming-care information, and both statutes were written with that in mind. Our position is the one above, applied without exception.

7. How long we keep it

Consumer health data is not retained on a separate schedule, because it is not stored separately — it is content inside your account. The full schedule is in the Data Retention & Deletion Policy; the parts that matter here:

  • Content stays for as long as your account does, and is removed when you have your account deleted.
  • Technical and usage logs are bounded to 30 days, and in no case more than 90.
  • Nothing health-related is retained after deletion other than what that policy identifies as surviving for a legal reason — billing and tax records (which contain no health content) and opt-out suppression entries (which contain an email address and the fact of an opt-out, and nothing else).

That policy is also honest about the mechanism: deletion means removal from the live system and expiry from backups on a stated schedule, and we do not claim a cryptographic-erasure guarantee we cannot perform. We would rather you read the accurate version than a reassuring one.

8. Consent, and how to withdraw it

How consent is given today. Washington and Nevada require consent to collect consumer health data beyond what is necessary to provide a service you requested, and separate authorization to sell it (which we do not do, so no authorization is ever sought). Consent is given by a separate, unticked checkbox shown beside the Connect control, on every screen that offers to connect a Google account. Its label tells you, before you tick it, that your mail and calendar will often contain sensitive details — health appointments among them — and that they are processed along with everything else. The Connect control does nothing until you tick it, so the agreement is a deliberate act of its own rather than a by-product of signing up or of Google's own permission screen. Google's screen then names the specific permissions being granted; you can decline either one, with no consequence beyond the Service not working. Nothing is read before you complete both.

We record that you agreed, when, and which version of our Privacy Policy was published at that moment, held against your account where you cannot alter it. If that record cannot be written, the box stays unticked and Connect stays inert — we will not proceed on a consent we did not store.

We are precise about the limits of that. That one agreement authorizes the whole of the Service's access, including to health-related content that happens to be in the mailbox. There is no toggle that admits your calendar but excludes your medical appointments, because the assistant reads the mailbox as a whole — the checkbox is a consent to that, not a filter. If a narrower grant matters to you, the honest options are to connect an account that does not contain that content, or not to connect one. Accounts connected before this control existed carry no such record; we do not create one retroactively, and they are asked at their next connect or re-authorization.

Withdrawing consent. Two mechanisms, both real:

  1. Disconnect the Google account, or revoke the grant at Google. You can revoke Lonzo's access from your Google Account's security settings at any time, without telling us, and the access ends immediately. That stops all further collection.
  2. Write to privacy@lonzo.ai and ask us to stop. We will.

Withdrawing consent stops collection going forward. To have what we already hold deleted, use Section 9 — withdrawal and deletion are different requests, and we will not treat one as the other.

9. Your rights, and how to exercise them

Under Washington's My Health My Data Act and Nevada SB 370 you have the right to:

  • Confirm whether we are collecting, sharing, or selling your consumer health data, and access it, including a list of all third parties with whom we have shared or sold it and contact information for each;
  • Withdraw consent to our collection and sharing of it (Section 8);
  • Have it deleted, including from our archived and backup systems, and have us pass the deletion request to our processors and affiliates; and
  • Not be discriminated against for exercising any of these. We will not degrade the Service, change your price, or refuse you as a customer because you asked.

How. Email privacy@lonzo.ai with the address on your account. There is no self-service control for these requests, because we have not built one — a person handles each one. We will verify that the request is yours, which for an account holder normally means confirming from the account's own email address, and we will not ask for more information than the verification needs. An authorized agent may make a request on your behalf with your written permission.

Timing. We respond within 45 days, and may extend once by a further 45 days where the request is complex, in which case we will tell you why within the first 45.

If we refuse. We will tell you why, and you may appeal by replying to our response or writing to privacy@lonzo.ai with "Appeal" in the subject. We will decide the appeal within 45 days and explain the outcome in writing. If we deny the appeal, you may complain to the Washington State Attorney General (Washington residents) or the Nevada Attorney General (Nevada residents), and we will tell you how in our decision.

A limit worth stating. Deleting consumer health data means deleting the content it lives in — the message, the event, the contact card. We cannot delete a health-related sentence out of an email and leave the rest of it, and we cannot delete anything from your own Google account, which is not ours to write to. What we can delete is what we hold. If what you want removed is the underlying message, it has to be deleted in Gmail; we will say so rather than let you believe we did more than we did.

10. Employees, contractors, and access

Access to production systems containing customer content is limited to personnel who need it, is authenticated with multi-factor authentication, and is logged. Health-related content carries no special access channel — and equally, no exemption. Our security posture and its limits, including what has and has not been independently audited, are described in Security at Lonzo.

11. What this Service is not

Lonzo is not a health-care service, and it is not for handling health data on purpose.

  • We are not a HIPAA covered entity or business associate. We do not offer a Business Associate Agreement, and we have none in place with any customer or with AWS.
  • The Acceptable Use & Anti-Spam Policy, Section 3.9, prohibits using the Service to process protected health information or to act as a system of record for it. That prohibition is not undermined by this policy: this policy exists because health-related content incidentally reaches a general-purpose assistant, not because doing so deliberately is permitted.
  • The Service gives no medical advice. Nothing it produces is a diagnosis, a treatment recommendation, or a substitute for a clinician, and it should not be relied on as any of those.

12. Children

The Service is not directed to children, and account holders must be at least 16. We do not knowingly collect consumer health data from a child. If you believe we have, write to privacy@lonzo.ai and we will delete it.

13. Changes to this policy

We may update this policy. If we make a material change to how we collect, use, share, or retain consumer health data, we will update the effective date and version above, notify account holders by email or in-app notice before the change takes effect, and — as both statutes require — obtain your consent before applying the change to data already collected, rather than applying a new purpose to old data on the strength of a posted notice.

14. Contact

Vista del Lago Software LLC 18381 Vista del Lago, Yorba Linda, CA 92886, USA

  • Consumer health data requests, and appeals: privacy@lonzo.ai
  • Everything else: support@lonzo.ai

All legal documents · Help · Lonzo home