Data Retention & Deletion Policy
Effective 2026-07-28 · Version 1.0This policy states, for each type of data Vista del Lago Software LLC holds, how long we keep it, why, and how it is destroyed. It supports our obligations under the GDPR storage-limitation principle (Art. 5(1)(e)), the deletion clause of our Data Processing Addendum (DPA §11), deletion rights under US state privacy laws, and the app-store requirement for a publicly reachable account-deletion path.
We commit to concrete retention periods rather than open-ended "as long as necessary" language, because our architecture already enforces most of these limits automatically.
What "deletion" means here
Your data is protected by per-actor envelope encryption: each account's data is encrypted under keys unique to that account. We delete by crypto-shred — destroying that account's key hierarchy (its key-encryption key and data key). Crypto-shred neutralizes your data at rest regardless of where a copy lives — primary storage and every backup are ciphertext under the same key hierarchy, so once the keys are destroyed there is no location from which the data can be recovered. (Google, as the authoritative source of your synced email, calendar, contacts, and tasks, is a separate system and is not touched by our deletion — see below.)
Deletion happens in two stages:
- Recoverable trash window. When you request deletion, your account first enters a recoverable "trash" state for 7 days. During this window you can restore the account, and the crypto-shred has not yet occurred.
- Crypto-shred (irreversible). After the 7-day trash window ends, we destroy the per-actor key hierarchy. From this point the data is irrecoverable — not a soft-delete flag, and no copy in any backup can be recovered.
The "irrecoverable" claim therefore applies after the 7-day trash window closes and the crypto-shred completes.
Retention schedule
| Data type | Retention period | Why | How it is deleted |
|---|---|---|---|
| Cached Gmail message bodies | Approximately 30-day time-to-live, held as encrypted Pins and garbage-collected | We hold a short-lived working cache to power the assistant; Google remains the authoritative source | Auto-expiry on TTL + garbage collection; crypto-shred on account deletion |
| Email/Calendar/Contacts/Tasks (authoritative copy) | Held by Google, not Vista del Lago Software LLC — we keep caches only | Google is the system of record | Not applicable — deleting Lonzo data does not touch your Google account |
| Derived memory / assistant-generated context | Life of the account (subject to your deletion of the underlying data) | Powers personalization and continuity of the assistant | Crypto-shred on account deletion |
| Account data (identity, settings, preferences) | Retained while the account is active | Needed to operate your account | Crypto-shred on account deletion |
| Authentication audit events | At least 90 days (minimum) | Security, fraud prevention, and incident investigation | Purged after the retention window |
| Account-lifecycle log | De-identified after account deletion — no identifiable lifecycle record is retained beyond the 30-day deletion window | Security, compliance, and audit record of account creation, key events, and deletion | De-identified (stripped of personal identifiers) so what remains is non-personal; see legal-basis note below |
| Per-actor encrypted data (general) | Life of the account | Powers the Service | Crypto-shred — destroy the per-actor key hierarchy; irrecoverable |
| Encrypted backups | 30-day rolling purge cycle | Resilience and disaster recovery | Purged on the 30-day backup cycle; also neutralized earlier by crypto-shred of the per-actor key |
The 30-day backup-purge figure here matches the security overview page and DPA Annex II; if it changes, update all three together.
Google is the authoritative source
For email, calendar, contacts, and tasks, Google is the authoritative source and Vista del Lago Software LLC holds caches only. Deleting your Lonzo account destroys our caches of that data; your Gmail, Calendar, and Contacts in Google are untouched and remain exactly as you left them. Conversely, deleting data in Google does not by itself alter Vista del Lago Software LLC's records beyond the normal cache-refresh behavior.
How to delete your data
By request. You can request deletion of your account and all associated Lonzo-held data at any time, without obstacles, by emailing support@lonzo.ai from the address on the account. We verify that the request comes from the account's own address and then initiate deletion: your account enters the 7-day recoverable trash window, and deletion then crypto-shreds your per-actor keys as described above.
Public deletion URL (no app install required). In line with app-store requirements, you can request account and data deletion from a public web page without installing or signing into the app: lonzo.ai/delete-account. The page describes what is deleted and the timeline.
Deletion-completion timeline (SLA)
Once you initiate deletion, we complete crypto-shred of your per-actor key hierarchy and neutralization of your data in backups within thirty (30) days. The sequence fits inside that SLA with margin: a 7-day recoverable grace/trash window, then immediate crypto-shred of the live per-actor keys once the grace window closes, and residual encrypted backup copies age out on the 30-day backup purge cycle (already unreadable from the moment the key is shredded). 7 days + immediate live shred + ≤30-day backup age-out all complete within the 30-day SLA. This SLA is reconciled with the deletion/return window in our DPA (DPA §11, also 30 days) — the two documents state the same number, and if either changes both must be updated together. Legal-hold exceptions below may extend retention of specific records required by law.
Retention exceptions (legal hold)
We may retain data beyond the periods above where retention is required by applicable law, subject to a legal hold, or reasonably necessary to establish, exercise, or defend legal claims, prevent fraud or abuse, or enforce our agreements. Any data retained under this exception stays encrypted and access-restricted and is deleted once the basis for retention no longer applies.
The authentication audit events (≥90 days) are retained under this legitimate-interest / legal-obligation basis as security and compliance records. The account-lifecycle log is de-identified after account deletion — stripped of personal identifiers so that what remains is a non-personal record of account events, with no identifiable lifecycle record retained beyond the 30-day deletion window. We do not keep a permanent identifiable record of your account lifecycle, which resolves any tension with your Art. 17 right to erasure: the identifiable record is removed on deletion, and only a de-identified, non-personal event record remains.
Changes to this policy
We may update this policy from time to time. The current version and its date appear at the top of this page; material changes will be reflected here with an updated date.