Privacy Policy
Last updated:
Effective date: August 4, 2026
Wolf Consulting Group of Colorado, LLC (“Company,” “we,” “us,” or “our”) operates The Smart Shoebox and its websites, applications, personal forwarding addresses, AI tools, sharing features, integrations, and related services (collectively, the “Service”).
This Privacy Policy explains how we collect, use, disclose, and retain personal information. The Service is designed to read and organize documents, so the information you submit may be highly personal and may concern other people. Please decide carefully what to submit and share.
1. Scope
This Policy applies to the United States consumer Service. It does not apply to third-party services governed by their own privacy policies.
The Service is a general document organizer. It is not a healthcare provider, financial institution, credit-reporting agency, insurer, law firm, professional adviser, records custodian, or archival service. It is not offered for use by a HIPAA covered entity or business associate under a Business Associate Agreement.
2. Information we collect
Depending on how you use the Service, we may collect:
- Account information: name, email address, account and authentication identifiers, settings, preferences, time zone, home location, nearest airport, approved senders, invitations, plan, and forwarding-address handle. Our identity provider processes credentials; we generally do not receive your password.
- User Content: emails and their headers, bodies, attachments, and images; uploaded documents and photos; notes, voice recordings and transcripts; chats; corrections, tags, trips, sharing instructions; and information about other people contained in that material.
- Derived information: extracted text and fields, classifications, summaries, embeddings, relationships, tags, locations, itineraries, alerts, calendar events, search data, duplicate indicators, confidence scores, and other organizational or analytical results.
- Device and operational information: IP address, browser and device information, session and request data, timestamps, feature use, message identifiers, sender-authentication and spam signals, processing results, security events, model and token usage, performance, cost, errors, and diagnostics. Technical logs may incidentally contain limited User Content.
- Location information: browser location if you permit it, and addresses or locations contained in User Content, used for features such as trips, maps, time zones, and weather.
- Information from others and connected services: information provided by someone who emails your forwarding address, invites you, shares or contributes content, or uses a connected service involving you.
User Content may include sensitive financial, health, insurance, identity, travel, family, or account information. You choose what to submit. If you submit information about another person, you are responsible for having the rights and permissions required by our Terms of Service and applicable law.
3. How we use information
We may use personal information to:
- provide, personalize, operate, maintain, and support the Service;
- receive, store, read, classify, extract, summarize, search, connect, organize, and display User Content;
- create trips, alerts, calendar events, tags, embeddings, and responses;
- follow your sharing, invitation, export, and integration instructions;
- authenticate accounts and enforce eligibility, sender, storage, plan, and usage controls;
- communicate about the Service, account activity, security, support, invitations, alerts, and changes;
- prevent, detect, investigate, and respond to fraud, spam, abuse, security incidents, illegal activity, and violations of our Terms;
- troubleshoot, test, analyze, and improve the Service’s reliability, safety, performance, and features;
- comply with law, enforce agreements, and protect rights, safety, property, and Service integrity; and
- evaluate or complete a financing, merger, acquisition, reorganization, asset transfer, or similar transaction.
We may use aggregated or de-identified information for lawful business purposes. We do not sell personal information, use User Content for targeted advertising, or use User Content to train our own general-purpose AI models. We do not currently use advertising cookies or cross-context behavioral advertising tools.
4. AI and automated processing
AI processing is central to the Service. We and our providers may process document text and images, temporary file links, voice recordings, chat prompts, retrieved excerpts, and derived information to provide classification, extraction, transcription, embeddings, search, summaries, connections, and answers.
We configure and require providers handling User Content not to use it to train their general-purpose models, subject to their contracts, terms, settings, and policies. Providers may temporarily retain information for security, abuse prevention, legal compliance, or service operation. Providers and models may change and may process information in jurisdictions different from yours.
AI and sensitive-data tools are imperfect. They may miss, misclassify, duplicate, or expose information. A redaction, label, warning, or absence of one is not a guarantee that content is complete, private, accurate, or safe to share. Unless a feature expressly says otherwise, the original document remains unchanged and may be processed before a redaction or warning is created.
5. How we disclose information
We may disclose personal information:
- At your direction: to people you invite or share with, connected services, or destinations you select. Recipients may copy, download, screenshot, retransmit, or misuse information. Revoking access cannot retrieve copies already received.
- To service providers: providers that support identity, hosting, databases, file storage, email, AI models and gateways, transcription, embeddings, security, error monitoring, maps, geocoding, time zones, weather, search, calendar integrations, support, and payments if paid plans are offered. They receive information reasonably necessary to perform services for us and operate under their own terms, policies, and contractual obligations.
- For legal, safety, and enforcement purposes: when we believe disclosure is reasonably necessary to comply with law or legal process; enforce agreements; collect amounts owed; investigate misuse; or protect rights, safety, property, or Service integrity.
- For a corporate transaction: to advisers, lenders, investors, counterparties, or successors involved in a financing, merger, acquisition, reorganization, bankruptcy, asset transfer, or similar event.
- In aggregated or de-identified form: when information is not reasonably linked to an individual. We will not attempt to re-identify it except to test de-identification or as permitted by law.
We do not currently share personal information with third parties for their own targeted advertising.
6. Consumer health data
If you submit health-related content, we may collect consumer health data such as medical records, conditions, diagnoses, symptoms, treatments, medications, vaccinations, providers, appointments, bills, insurance claims, reproductive or sexual health information, mental-health information, and other health information contained in or derived from User Content. Depending on the content, related identity, location, biometric, or genetic information may also be consumer health data.
We receive this information from you; from people who send, share, or contribute content at your direction; from services you connect; and from the documents, communications, and other information the Service processes or derives. Uploading, forwarding, recording, or otherwise submitting health-related content requests that we process it to provide the organizational features you selected.
We use consumer health data to receive, store, organize, search, summarize, connect, display, and secure your content; provide requested features and support; follow your sharing or integration instructions; and comply with law. We may disclose the categories described above to the service-provider categories in Section 5 as reasonably necessary to provide and secure the Service, to people or services you direct, or for the legal and safety purposes described in this Policy. We do not sell consumer health data, use it for advertising, or currently share it with Company affiliates.
Where applicable, you may ask whether we collect or disclose your consumer health data; request access to or deletion of it; request a list of recipients; or withdraw consent for future collection or disclosure. Withdrawing consent may require us to stop providing affected features. Submit a request to info@wolf-cg.com. We may verify your identity and authority. Deletion from archived or backup systems may be delayed as permitted by law.
9. Retention and deletion
We retain information for as long as reasonably necessary to provide and secure the Service, maintain legitimate business records, comply with law, resolve disputes, enforce agreements, and complete the purposes described in this Policy. Retention varies by data type, account status, provider, legal obligation, and operational need.
When you delete a document or account, we initiate deletion from active systems through the Service’s available controls. Deletion may not be immediate or complete in every location. Information may remain for a limited period in backups, recovery systems, provider systems, caches, security and fraud records, logs, legal holds, deletion records, or copies retained by recipients. We may retain information where law permits or requires and may retain aggregated or de-identified information.
We retain limited evidence of legal acceptance and related security or dispute records, which may include the accepted document version and hash, timestamp, and pseudonymous account, email, or IP evidence, even after account deletion when reasonably necessary to establish consent, comply with law, or resolve disputes.
Account deletion does not delete information already sent to a connected service or copied by someone with whom you shared. Providers process deletion under their own retention schedules and obligations.
10. Your choices and privacy rights
The Service may let you access, correct, delete, export, share, or unshare certain information; manage approved senders and communications; deny browser location; and disconnect integrations.
Depending on where you live and whether applicable legal requirements are met, you may have rights to request access, correction, deletion, portability, information about processing or recipients, withdrawal of consent, or an appeal, and to opt out of certain sales, targeted advertising, sharing, or profiling. We do not currently sell personal information or use it for targeted advertising.
Submit privacy requests to info@wolf-cg.com. We may verify your identity, residence, and authority; decline or limit a request where law permits; and retain a record of the request. An authorized agent may be required to provide proof of authority. We will respond as required by applicable law. You may appeal a denied request by replying to our decision and stating that you are appealing.
11. Children and changes
The Service is only for people age 18 or older. We do not knowingly allow children to create accounts. If we learn that a child created an account, we may suspend it and delete associated information, subject to legal and technical retention.
We may update this Policy as the Service, providers, technology, or law changes. We will post the revised version and update the effective date. We will provide additional notice or obtain consent when required by law. If a change materially affects how we use previously collected information, we will handle that information as required by applicable law.
12. Contact
Questions, privacy requests, complaints, and security reports may be sent to:
Wolf Consulting Group of Colorado, LLC
info@wolf-cg.com