Privacy Policy
Effective July 25, 2026
Who we are
Lanza AI ("Lanza," "we," "us," or "our") is an AI marketing service for doctors and small medical practices, available at lanzaai.com. Lanza is a product of Endurant Healthspan, Inc., a Delaware corporation, the entity responsible for your data under this policy.
This Privacy Policy explains what information we collect, how we use it, and the choices you have. If you have questions, contact us at privacy@lanzaai.com.
Information we collect
Account information: email address, password (stored securely by our auth provider), and sign-in method (email or Google).
Practice profile: specialty, location, practice name, marketing goals, voice preferences, brand details, and other information you provide during onboarding.
Connected channels: OAuth tokens and metadata needed to manage your social media accounts, video channels, Google Business Profile, advertising accounts, and related integrations. We do not receive or store your social media passwords when you connect through official platform authorization.
Content and workflow data: draft posts, approval decisions, publishing schedules, and performance summaries generated inside Lanza.
Billing information: subscription status and payment details processed by Stripe. We do not store full credit card numbers on our servers.
Usage data: log data such as IP address, browser type, pages visited, feature usage, and session replays of interactions with the Lanza interface. Rendered text, form and text-entry values, images, video, and canvas content are masked or blocked in session replays, and we do not record network request or response bodies.
Information we do not collect
Lanza is built for healthcare marketing, not clinical care. We do not ask you to enter patient names, diagnoses, treatment records, insurance details, or other protected health information (PHI).
Do not upload patient records, clinical notes, or identifiable patient information into Lanza. If PHI is submitted despite this policy, we will take steps to delete it and may suspend the account.
Platform data we access (by platform)
When you connect a channel, Lanza accesses and stores only the data and tokens needed to provide the features you request, and only for the accounts you authorize. By platform:
- Meta (Facebook, Instagram, Threads): account profile and identifiers, the content you publish, and post analytics/insights. Used to publish and read analytics for the accounts you authorize, under the Meta Platform Terms and Developer Policies.
- TikTok: your creator and profile information (such as nickname, avatar, privacy options, interaction settings, and maximum video duration) and the content you publish. Used to publish the videos you direct and to show you accurate posting options.
- X (Twitter): account profile, the posts you publish, and post analytics. Used to publish and read analytics for your account.
- LinkedIn: profile information, the posts and articles you publish, and analytics. Used to publish on your behalf; we obtain your consent before accessing your LinkedIn content.
- YouTube (Google): channel profile, the videos you publish, and video analytics. Used to publish and read analytics for your channel.
- Google Business Profile: business profile, locations, reviews, and local insights. Used to align content with local patient discovery.
- Google Ads and Meta Ads (when connected): ad account identifiers and campaign performance metrics such as impressions, clicks, and spend. Used to report and, where enabled, manage your campaigns.
- Google Search Console (when connected read-only): the selected property identifier, search queries, page URLs reduced to their origin and path (query strings and fragments are removed), clicks, impressions, click-through rate, average position, date ranges, and sync time. Lanza uses these fields to show observed search visibility and derived query or page opportunities.
- Google Analytics 4 (when connected read-only): the selected property identifier, sessions, engaged sessions, engagement rate, configured key-event counts and rates, default channel groups, landing-page paths without query strings or fragments, date ranges, and sync time. Lanza does not infer that a configured key event is an appointment or revenue event.
- For Search Console and Google Analytics, Lanza stores a normalized, practice-scoped last-good cache so the Your Brand view can remain useful during a temporary refresh failure. The cache includes the metrics and provenance described above, but no OAuth token. Google OAuth credentials remain encrypted and server-side in Lanza's integration backend.
- OAuth access tokens for all connected channels are stored server-side by our backend, encrypted in transit and at rest, and are never exposed to your browser.
How we use your information
We use your information to operate Lanza: authenticate your account, generate marketing content in your practice voice, prepare posts for your review, publish approved content to connected channels, read analytics, process subscriptions, and provide support.
We may use aggregated or de-identified usage data to improve product reliability and features. We do not sell your personal information.
AI processing and no model training
Lanza uses third-party AI providers to generate marketing drafts based on your practice profile and the channel context you provide. Your prompts and practice inputs may be sent to these providers solely to deliver the service, under their enterprise/API terms.
We do not use data received from connected-platform APIs (including Google, YouTube, Meta, TikTok, X, or LinkedIn) to develop, train, or improve generalized machine learning or artificial intelligence models. Platform data is used only to provide the user-facing features you request. We do not use your account content to train public AI models.
Google API Services and Limited Use
Lanza's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Search Console and Google Analytics connections use read-only access. Removing one of these properties in Lanza deletes its saved Search Presence cache and local property link, but does not revoke a shared Google OAuth grant or interrupt another Google connector such as YouTube. You can revoke the full Lanza Google grant from your Google Account permissions.
Lanza uses YouTube API Services. By using Lanza's YouTube features, you also agree to be bound by the YouTube Terms of Service, and your information is handled in accordance with the Google Privacy Policy.
You can review or revoke Lanza's access to your Google and YouTube data at any time through the Google security settings page. For questions or complaints about how we handle Google or YouTube data, contact privacy@lanzaai.com.
Meta platform data
When you connect a Meta channel (Facebook, Instagram, or Threads), Lanza accesses and stores only the data and tokens needed to publish and read analytics for the accounts you authorize, and uses that data solely to provide the service in accordance with the Meta Platform Terms and Developer Policies.
We do not sell Meta platform data, use it for surveillance, or use it to build or augment user profiles. If you remove Lanza from a Meta platform, Meta notifies us through our deauthorize and data deletion callbacks, and we delete the associated tokens and account linkage.
TikTok data
When you connect TikTok, Lanza accesses your creator and profile information and publishes the content you direct, under TikTok's developer terms. You control each post's visibility and interaction settings.
We use TikTok data only to provide the service and delete the related tokens and account linkage when you disconnect TikTok or delete your account.
Service providers
We rely on a small set of trusted service providers to operate Lanza, covering hosting and infrastructure, database and authentication, payment processing, product analytics and session replay (PostHog), and AI generation. These providers process data only to provide services to us, under confidentiality and data-protection obligations, and are not permitted to use it for their own purposes. We may add or change providers as the product evolves.
Each platform you connect has its own privacy policy. When you connect a channel, you authorize Lanza to interact with that platform on your behalf according to its terms.
Cookies and tracking
We use a small number of cookies and similar technologies, kept to what the service needs:
- Essential and authentication cookies that keep you securely signed in. The service does not work without these.
- Payment cookies set during checkout and for fraud prevention when you manage your subscription.
- Product analytics and session replay: we use first-party analytics identifiers to understand pages visited, feature usage, errors, and interactions within Lanza. Session replay masks rendered text and form values, blocks images, video, and canvas content, and does not record network request or response bodies. We do not use this data for cross-site advertising or retargeting.
Embedded platform content
Some pages may display content or previews from connected platforms. Where that happens, the platform may set its own cookies or collect data about your browsing under its own policies. Most browsers let you block or delete cookies through their settings; blocking essential cookies will prevent you from signing in. Because we do not use cross-site advertising or tracking cookies, there is no interest-based advertising to opt out of.
HIPAA and healthcare data
Lanza supports HIPAA-aware marketing workflows: approval before publishing, no PHI in the product by design, and educational marketing content rather than clinical records.
Lanza is not a covered entity and is not offered as a Business Associate for clinical data. You remain responsible for the accuracy, compliance, and appropriateness of content you approve and publish, including compliance with state medical board advertising rules.
No sale, no surveillance, no ad retargeting
We do not sell, rent, or license your personal information or platform data. We do not use platform data for surveillance, to build or augment advertising profiles, to retarget or serve interest-based advertising, or to discriminate against any person.
We only share platform data as you direct (for example, to publish to a channel you connected), with the service providers described above, for security purposes, or as required by law.
How to delete your data
You can delete the data Lanza holds at any time. You have a clearly marked way to request deletion through any of the following:
- Disconnect a channel in-app: open Settings, then Connectors, and disconnect a channel. For Google Search Console or Google Analytics, this immediately removes the selected property link and its normalized Search Presence cache from Lanza; the shared Google OAuth grant and other Google connectors remain intact. For publishing channels, disconnecting removes or disables the account's access credentials as described in the confirmation dialog.
- Remove Lanza from Meta: in your Facebook or Instagram settings open Apps and Websites (for Threads, Account, then Website permissions) and remove Lanza. Meta then notifies us through our deauthorize and data deletion callbacks, and we delete the associated tokens and account linkage and return a confirmation code.
- Revoke the full Google grant: use the Google security settings page. This revokes Lanza's shared Google access, which may include YouTube, Search Console, and Google Analytics. To request deletion of any remaining account data after an external revocation, email privacy@lanzaai.com; we complete verified deletion requests within 30 days.
- Revoke from TikTok, X, or LinkedIn: remove Lanza in that platform's connected-apps settings. For X, we keep cached content in sync and delete or update it within 24 hours of a request; for LinkedIn, we delete content and tokens immediately on request or when you close your account.
- Delete your entire account: email privacy@lanzaai.com or support@lanzaai.com from the address on your account. We disconnect all connected channels and delete your account data within 30 days.
Retention
We retain account and practice data while your subscription is active and for a reasonable period afterward to meet legal, billing, and security obligations. We may retain limited records where required for legal, billing, or security purposes.
While a Search Console or Google Analytics property remains connected, we retain its normalized last-good metrics and provenance and replace them as the connection refreshes. Removing that property in Lanza deletes those cached rows immediately. Disconnecting one read-only Google property does not revoke the shared Google grant; revoke the full grant through Google Account permissions.
Note that content already published to a platform lives on that platform; deleting Lanza data does not remove posts from Instagram, Facebook, Threads, TikTok, X, LinkedIn, or YouTube. Remove those directly on each platform.
Your rights
Depending on where you live, you may have the right to access, correct, delete, or export personal information we hold about you, and to opt out of certain processing.
California residents (under the CCPA) and residents of Virginia and other states with comprehensive privacy laws have rights to know, access, correct, delete, and port their personal information, and not to be discriminated against for exercising them. We have not sold personal information or shared it for cross-context behavioral advertising in the preceding 12 months.
To exercise these rights, email privacy@lanzaai.com. We will respond within a reasonable timeframe.
Security
We use industry-standard safeguards including encryption in transit and at rest, access controls, and scoped database permissions. OAuth access tokens for connected channels are encrypted and stored server-side, and are never exposed to your browser.
No online service can guarantee perfect security, but we design Lanza so patient health information is not part of the system.
International users
Lanza is operated from the United States, and your information is processed and stored in the United States. By using Lanza, you understand that your information will be processed in the United States, which may have different data protection rules than your country.
Children
Lanza is a business service for medical practices and is not directed to individuals under 18. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. Continued use of Lanza after changes means you accept the updated policy.
Contact
Questions about privacy? Email privacy@lanzaai.com.