Google API Services Limited Use Disclosure
Effective 2026-08-09 · Version 1.11. Limited Use commitment
Lonzo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The Service is operated by Vista del Lago Software LLC
2. Google scopes we request, and why
Lonzo is an AI executive assistant that works across your Google account. We request only the scopes needed to provide the features you use:
Gmail
gmail.modify(RESTRICTED scope) — to read your mail so the assistant can summarize, triage, and answer questions about it, and to organize it (apply labels, archive) and send messages on your behalf after you approve them. This scope grants both read and write access to your mailbox, which is why Google classifies it as restricted and subjects it to heightened review.gmail.readonly(RESTRICTED scope) — read access to your mail, requested alongsidegmail.modifyso that the assistant's read paths (summarizing, triage, search) work on a grant that carries read access even where a write grant is unavailable or has been narrowed.gmail.send— to send the messages you approve from your account. Requested separately fromgmail.modifyso that sending is grantable on its own and is checked as its own permission before any send.gmail.settings.basic— to read and apply your basic Gmail settings (such as labels, filters, and send-as / signature settings) so the assistant's organizing and drafting behavior aligns with how your mailbox is set up.
Calendar, Contacts, and Tasks
calendar.events— to read and manage your calendar events so the assistant can surface your schedule and create, update, or remove events at your direction.calendar.readonly— to read your calendars and their metadata (including calendars you do not write to) so the assistant has full visibility of your schedule when reasoning about your availability and commitments.calendar.freebusy— to read when you are busy or free, without reading the details of those events, so the assistant can propose meeting times that do not conflict with your existing commitments.contacts— to read your contacts so the assistant can provide context, autocomplete recipients, and help with scheduling.tasks— to read and manage your Google Tasks so the assistant can track and update your to-dos.
Sign-in
openid,profile,email— the standard OpenID Connect sign-in scopes, so we can identify your account and, where you have set no name or picture of your own in Lonzo, show the name and profile picture from your Google account. These carry no access to your mail, calendar, contacts, or tasks.
We request only what these features require — twelve scopes in total: nine Google data scopes and the three standard sign-in scopes. Google remains the authoritative source of your data; the Service works from and acts on your Google account rather than replacing it.
3. How we meet the four Limited Use requirements
Our actual data practices satisfy each of Google's four Limited Use requirements:
(1) Allowed use — to provide or improve user-facing features only. We use the data we receive from Google APIs solely to provide and improve the user-facing features of Lonzo — reading and organizing your mail, managing your calendar and tasks, drafting replies, and building the memory that gives the assistant context. We do not use Google user data for any unrelated purpose.
(2) Allowed transfer — only as necessary, and only to compliant providers. We do not transfer Google user data except: as necessary to provide or improve the Service; to comply with applicable law; or as part of a merger, acquisition, or sale of assets with notice to users. The one material transfer we make to provide the Service is to Amazon Web Services (AWS Bedrock), our cloud inference provider, which runs the AI models (Amazon Nova, Anthropic Claude, and Amazon Titan embeddings) that power the assistant. AWS acts as our service provider under contractual obligations, and it is identified on our subprocessor list at lonzo.ai/legal/subprocessors.
Prompts and responses are processed by Amazon Web Services via Amazon Bedrock. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers; Bedrock operates on a zero-data-retention basis by default and retains no prompt or response content after a request completes. Inference is performed within AWS's United States Region set. AWS processes this data under the AWS GDPR Data Processing Addendum, which incorporates the EU Standard Contractual Clauses.
(3) No advertising. We do not use Google user data for serving advertisements of any kind — no personalized, retargeted, or interest-based advertising. We do not operate an advertising business over your Google data.
(4) No human reading, except in limited cases. We do not allow humans to read your Google user data, except: (a) with your affirmative consent (for example, to help you with a support issue); (b) as necessary for security purposes, to investigate abuse, or to comply with applicable law; or (c) where the data is aggregated and anonymized, or where reading is required to provide or maintain the Service and it is not feasible to do so otherwise. In practice, access to your data is purpose-bound — decryption is authorized only for a specific declared purpose — and every access is recorded in an immutable audit log (see our Privacy Policy and security page).
4. Our commitment on advertising, human reading, and training
Consistent with the requirements above:
-
No ads. We never use your Gmail, Calendar, Contacts, or Tasks data to serve advertising.
-
No routine human reading. No one on our team routinely reads your mail or other Google data; any access is purpose-bound, gated by your consent or a genuine security/abuse/legal need, and audit-logged.
-
No first-party training on your Google data. We do not use your Google user data to train first-party Lonzo models. If we ever offer such use, it will be strictly opt-in (see the AI & Data-Training Disclosure).
-
No third-party training or retention by the Bedrock model providers. Under the AWS Service Terms, content sent to Bedrock is not used to train the underlying foundation models and is not shared with the third-party model providers, and Bedrock operates on a zero-data-retention basis by default, retaining no prompt or response content after a request completes (see Section 3(2) above and the AI disclosure §4.2).
5. What our Gmail write access does, and how we handle mail
Because gmail.modify is a restricted read-and-write scope (and gmail.readonly a restricted read scope), we state precisely what we do with them:
- Read — to summarize, triage, search, and answer questions about your mail, and to build your derived memory graph.
- Organize — to apply and remove labels and to archive messages at your direction; these changes are reflected in Gmail.
- Send as you — to send messages from your account. Every outbound message requires your review and approval. The assistant never sends autonomously; a human-approval boundary sits before any send.
How mail content is stored. We do process message bodies (unlike products that read only headers), so we protect them accordingly. Gmail message bodies that we cache are stored as encrypted pointers with an approximate 30-day time-to-live and are protected by per-actor envelope encryption (an AES-256-GCM data key wrapped by an HSM-held key-encryption key), with data in transit protected by TLS 1.3 / mutual TLS. Google remains the authoritative source of your mail; if you stop using the Service or revoke access, we stop reading and acting on your mailbox. See the Privacy Policy for retention and security detail.
What happens on disconnect or revocation. When you disconnect your Google account or revoke our access (from your Google Account permissions page or within the app), we immediately stop accessing your account: the stored token is revoked at Google's revocation endpoint, every copy of it is stripped from our storage, and the background sync that watched your mail and calendar is torn down. No further reading or acting on your mailbox occurs. Cached Google content already held then ages out on its ordinary approximately 30-day time-to-live and is not refreshed, because nothing is fetching it any more.
Disconnecting keeps your Lonzo account, so it is not by itself a deletion — that is the point of having it as a separate control. To have the cached content and the derived memory built from it destroyed, delete your account, which crypto-shreds them: the per-actor encryption key is destroyed at the end of the 7-day recoverable window, which renders the associated content irrecoverable, and full deletion across live systems and residual encrypted backups completes within 30 days. You can request that from a public page needing no sign-in and no app install, at lonzo.ai/delete-account. You can also ask us to wipe the derived memory while keeping your account, by writing to privacy@lonzo.ai. See Privacy Policy Section 9 (Data retention) and the Data Retention & Deletion Policy for the full detail.
6. Security assessment and verification
Because we use restricted scopes (gmail.modify and gmail.readonly), Lonzo is subject to Google's OAuth verification and an annual Cloud Application Security Assessment (CASA) at Tier 2, performed by a Google-designated assessor.
Current status: OAuth verification and the CASA Tier 2 assessment are in progress and not yet completed, and we make no claim to be "Google-verified" or CASA-assessed until they are. We will update this section when they complete.
7. Where this disclosure appears
To make this commitment easy to find for you and for Google's reviewers, we publish it in three places:
- In-app, at the Google connect / OAuth grant point — the Limited Use statement in Section 1 appears next to the button you use to connect your Google account, alongside plain-language explanations of why each scope is requested (Section 2).
- In our public Privacy Policy — which cross-references this disclosure and is linked from the app and from the Google OAuth consent screen.
- On our public security/trust page at lonzo.ai/legal/security-overview, and at the canonical disclosure URL lonzo.ai/legal/google-limited-use-disclosure.
We keep the published disclosure URL stable for Google's re-verification, and version this disclosure alongside the Privacy Policy.
8. Contact
Questions about our use of Google APIs and Limited Use compliance can be sent to privacy@lonzo.ai.