WiseTomorrow

Legal

Privacy Policy

Version
Version 1.7.0
Date
Effective date: September 21, 2026

Effective date: the date this version was published on this page.


At a glance

  • What we do. We store the information you choose to organize. When you tell us to, we release it to people you choose. That is the core of the service, so we do not say "we never share your information." We share it in three ways, described in Section 5:
    • with service providers that run the service for us;
    • with people you direct us to, such as your Trusted People; and
    • when the law requires it.
  • What we don't do. We do not sell your personal information. We do not use your stored Wise Box content or account information for advertising. We do not use your stored content to train AI models. Public shopping-page advertising measurement is described in Section 3.
  • Encryption, and its limits. We encrypt your information in transit and at rest, and add a second layer of encryption to your most sensitive fields. We are not an end-to-end encrypted service: our systems can decrypt your information to show it to you and to release it under your instructions.
  • Identity checks. People who ask for access must verify their identity through a third-party provider, which may collect ID images and biometric data under its own consent.

1. Who we are and what this Policy covers

1.1 Dark Ecommerce Labs, LLC, which operates WiseTomorrow ("WiseTomorrow", "we", "us"), located at 826 Hampton Wood Ct, Sarasota, FL 34232, is responsible for the personal information described in this Policy.

1.2 This Policy covers personal information about:

  • (a) Owners: people who create a WiseTomorrow account or buy a Wise Box;
  • (b) Trusted People: people an Owner designates, whose details the Owner gives us;
  • (c) Requesters: people who start an access request, whether or not they match a Trusted Person;
  • (d) other people named in an Owner's content; and
  • (e) visitors to our website.

1.3 Owners decide their content. For the content Owners store in their Wise Box, the Owner decides what to upload and whom to release it to. We process that content to provide the service and follow the Owner's instructions.

2. Information we collect

2.1 Account and contact information (Owners)

WhatWhyStored how
Legal first and last name; preferred (display) nameIdentify you; personalize the service. Your first name or display name is shown to anyone who scans your Wise Card and to your Trusted PeopleDatabase, encrypted at rest
Email addressSign-in, account notices, access-request noticesDatabase, encrypted at rest
PasswordSign-inStored only as a salted bcrypt hash; we cannot see your password
Two-step verification settingsAccount securityDatabase; the secret is encrypted
Mobile phone numberAccount security and contact; once you verify it, text-message alerts about access requests and security, and one-time codesDatabase, encrypted at rest
Country and state/regionService eligibility; applicable law and taxesDatabase, encrypted at rest
Date of birth (optional)If you provide it, we use it to check that supporting documents submitted under a condition you chose match your details, and to help confirm your identity if you contact us about your accountDatabase, encrypted at rest
Interface languageShow the site in your languageDatabase; a language cookie

"Encrypted at rest" means the database storage is encrypted by our cloud provider. The additional application-level encryption described in Section 4.2 applies only to the fields listed there.

2.2 Content you store

  • Section names, notes and instructions (including your "Start Here" note);
  • files you upload (documents, PDFs, photos, spreadsheets, text, audio and video) with their titles, tags and file notes; and
  • anything else you type or upload.

Your content may include sensitive information: financial account details, insurance and property records, government ID numbers, health information, passwords or access instructions, and information about other people. You decide whether to store it.

2.3 Information about Trusted People (provided by Owners)

When you designate a Trusted Person you give us their:

  • legal first and last name;
  • relationship to you;
  • email address;
  • mobile number (optional); and
  • date of birth (optional; if provided, we compare it with the date of birth on the requester's verified ID).

We also keep the choices you make for that person: what they may receive, the release conditions, and whether they are told about other Trusted People's requests and may raise concerns.

We use this information to match and verify a person who later asks for access, and to send them notices. We do not contact a Trusted Person when they are designated. We first contact them when:

  • they start an access request;
  • a request is made in their name (we send a notice to a contact channel the requester did not use, with a "This wasn't me" link);
  • another of your Trusted People starts an access request, if you chose for them to be told (they receive a notice so they can raise a concern, if you allowed that); or
  • access is granted to them, is about to end, is renewed, or is revoked.

The first message we send to a Trusted Person includes a link to this Policy. A Trusted Person may ask us to remove them as a Trusted Person, and we will tell the Owner.

2.4 Requesters (people who ask for access)

WhatSourceWhy
Name as entered; email address and/or phone numberYouMatch you to a Trusted Person; contact you
One-time codes sent to confirm your email address or phone number (stored only as a one-way hash)Generated by usConfirm you control the contact details the Owner gave us
IP address; browser and device information (user agent)AutomaticallySecurity, fraud prevention, audit trail
Identity-verification result, the name and date of birth on your verified ID, and a provider reference numberOur identity-verification providerConfirm you are the designated person; prevent fraud; keep a record of the decision
Supporting documents you upload, where the Owner requires them (for example, a death certificate or court order)YouCheck whether the Owner's condition appears to be met; keep a record of the decision
Your acceptance of the Trusted Person Access Terms and your certificationsYouRecord of your certifications
Which information you viewed and downloaded, and whenAutomaticallyAudit trail for the Owner and for legal purposes

When you verify online, we do not receive or store images of your ID or your selfie, or any biometric identifier. Those are collected and processed by our identity-verification provider (Section 5.1). If you cannot verify online and ask us for our alternative process, you send copies of identity documents to us directly and join a video call with our team. We use those copies only to verify your identity, do not use them to create a biometric identifier, and delete them within 90 days of our decision; we keep a record of the decision.

2.5 Concerns and reports

If you raise a concern about an access request, or report that a request was made in your name without your knowledge ("This wasn't me"), we collect your report, the reason you give, the date and time, and your IP address and browser information. We use it to pause or stop the request, to investigate, and to keep a record of what happened.

2.6 Purchase and billing information

  • Wise Box purchases: Stripe collects your payment card and shipping details on its hosted checkout page. We receive and keep an order reference, amount, currency, status and dates.
  • Care subscriptions: a Stripe customer ID, subscription status, plan, billing dates and a record of your consent to automatic renewal. We give Stripe your name and email to create the customer record.
  • Payment event records: we keep only a minimal record of the payment events Stripe sends us (such as the event identifier, type and status), and delete it after 90 days.
  • We never receive or store your full card number.

2.7 Wise Card information

  • card identifiers and the printed Recovery ID;
  • activation, revocation and replacement dates; and
  • when the card's page is used to start an access request.

2.8 Device, log and usage information

  • Server and security logs: IP address, date and time, requested page, browser/user agent, and referring page. Our web server keeps these logs for up to 30 days. We remove secret codes and access links from the web addresses we log.
  • Rate-limiting records: your IP address and identifiers such as the card or request being used, kept briefly to block abusive traffic.
  • Account activity and audit logs:
    • sign-ins and failed sign-ins (with the email stored as a one-way hash, plus IP address);
    • changes to Trusted People, authorizations and access settings;
    • uploads, downloads and deletions;
    • access requests, verification outcomes, reviews, holds, approvals, denials, grants and revocations;
    • legal acceptances; and
    • administrative actions.
  • Notice delivery records: whether each access-request notice and reminder was delivered, bounced or failed, so that we can confirm a notice reached the Owner before information is released automatically.
  • Product and marketing measurement. We measure how features and pages are used, and which marketing channel brought a visitor to us: the source category, campaign tag, landing page and device type. Core product measurement uses a first-party cookie and first-party event data sent to and stored by WiseTomorrow. Meta Pixel measures public shopping-page views, product views, checkout starts and verified purchases and may use those events to optimize Facebook and Instagram ads. Where an opt-in control is available, Google Ads, TikTok and Pinterest tags do not load before permission. Advertising providers may receive ad click identifiers, public shopping-page addresses, browser/network information including IP address, and verified purchase amount, currency and an opaque order reference. We do not send these providers names, emails, payment details, account details or Wise Box contents. Advertising tags are not loaded into the private application. Google ad personalization is disabled, and we do not enable advanced matching. Google processes information under its Privacy Policy, TikTok under its Privacy Policy, Pinterest under its Privacy Policy, and Meta under its Privacy Policy. Measurement events do not include your name, email or account ID. We honor Do Not Track and Global Privacy Control signals by not sending measurement events for that browser. See the Cookie Policy.

2.9 Communications

  • Emails and text messages we send you: our email and text-message providers process their content and delivery status.

Text messages. We text a mobile number only after you verify it and agree to receive texts in your account settings. We send security alerts, access-request alerts and one-time codes — no marketing. Message frequency varies. Message and data rates may apply. Reply HELP for help or STOP to opt out. We do not sell, rent or share your mobile number or your text-message opt-in and consent with any third party for their marketing or promotional purposes. Our text-message provider processes your number only to deliver our messages.

  • Bounce and spam-complaint records: the email address, reason and date. We keep these so we stop sending to addresses that cannot receive mail.
  • Support messages: anything you send to us.

For each agreement you accept, we record:

  • the document and version;
  • a digital fingerprint of the text you were shown;
  • the date and time;
  • your IP address and browser information; and
  • your session reference.

For Trusted Person authorizations, we also record the exact release scope, release conditions and other choices you confirmed, how you re-confirmed your identity, and which notice channels were verified at the time (see Section 14 of the Trusted Person Authorization and Disclosure Agreement). We record your choice about disclosure to fiduciaries in the same way.

3. How we use information

We use personal information to:

  1. Provide the service: create and secure your account; store, organize, display and export your content; process purchases and subscriptions.
  2. Carry out your instructions: run the access-request process and disclose information to Trusted People under the Trusted Person Authorization and Disclosure Agreement.
  3. Verify identity and prevent fraud: match requesters to designations; verify identity; review supporting documents; detect suspicious activity; place security holds.
  4. Communicate: send security alerts, access-request notices and reminders, one-time codes, billing and service messages, and replies to support requests. If we send you marketing emails, you can opt out at any time; service messages are not optional.
  5. Keep records and resolve disputes: keep evidence of what you authorized and what happened, and respond to claims.
  6. Comply with law and protect rights: meet legal, tax and accounting obligations; respond to lawful requests; enforce our Terms.
  7. Improve the service: understand, in aggregate, how features are used and which channels bring visitors, and fix problems.

Data we won't use for these purposes. We do not use your stored content for advertising, sell it, or use it to train artificial-intelligence models. We do not make decisions producing legal or similarly significant effects about you solely by automated means. Identity-verification results are automated, but a failed or flagged verification can be reviewed by a person on request.

4. How we store and protect information

4.1 Where it is stored. Our systems are hosted by Amazon Web Services in the United States.

4.2 Encryption. What we do:

  • In transit: connections to our website and application use HTTPS/TLS. Connections between our application and database are encrypted.
  • At rest: our database storage, server disks and file storage are encrypted by our cloud provider (AES-256).
  • Additional application-level encryption. We encrypt the following with a key unique to your Wise Box, using AES-256-GCM:
    • the contents of your notes;
    • section names;
    • file names, titles and tags;
    • Trusted People's names, relationships, email addresses, phone numbers and dates of birth;
    • requesters' names; and
    • verified names and dates of birth from identity checks.
  • Each Wise Box key is itself protected by a master key held in AWS Key Management Service. Records of your authorizations are encrypted with a separate key, so that they survive the deletion of your Wise Box as described in Section 6.

4.3 What encryption does not do.

  • Not end-to-end. Our application can decrypt your information so that it can show it to you, create exports, and release it to Trusted People. A compromise of our application servers or of our cloud account could expose information.
  • Uploaded files are not covered by the per-Wise-Box key. They are encrypted at rest by our file-storage provider, not by the additional application-level encryption described above.
  • Lookup hashes are not anonymous. Email addresses and phone numbers of Trusted People and requesters are also stored as keyed one-way hashes so that we can match them. Hashes are pseudonymous, not anonymous: we, or someone with our key and a list of candidate addresses, could test whether one matches.

4.4 Other safeguards:

  • access controls that separate each customer's data;
  • two-step verification for Owners, and multi-factor authentication for our staff;
  • short-lived download links;
  • rate limiting;
  • security headers;
  • audit logging;
  • restricted, logged production access; and
  • monitoring and alerts.

Our Security page explains these in plain language. No system is completely secure, and we cannot guarantee that information will never be accessed without authorization.

4.5 Staff access.

  • Our support tools do not display the contents of your Wise Box.
  • Staff who review access requests see only the information needed for the review, not the contents of your Wise Box.
  • A small number of authorized personnel with production-system access could technically access information in order to operate, secure or repair the service, or to comply with law. That access is restricted to what the task requires, and it is logged.

5. When we disclose information

Because releasing your information to people you choose is the purpose of WiseTomorrow, we separate three different kinds of disclosure.

5.1 Disclosures needed to operate the service (service providers)

We share information with companies that process it on our behalf, under contracts that limit their use of it:

ProviderWhat they doInformation involved
Amazon Web ServicesHosting, database, file storage, key management, email delivery, bounce notifications, monitoringAll categories stored in our systems; email recipients and content
Amazon Web Services (AWS End User Messaging SMS)Text-message deliveryPhone number, message content, delivery status
Stripe, Inc.Payment processing, hosted checkout, subscriptionsName, email, payment and shipping details, purchase data
Stripe, Inc. (Stripe Identity)Identity verification for requestersID document images, selfie, biometric comparison data, name, date of birth and other details on the ID, device and network data, collected directly by Stripe; a reference number sent by us
Shipping carriers and fulfillment partnersDelivering Wise Box ordersName, shipping address, order details
Professional advisersLegal, accounting, audit, insuranceAs needed for the engagement, under confidentiality

Identity-verification provider as an independent party. Our identity-verification provider may process requesters' ID images and biometric information under its own privacy notice and consent. The requester will see that notice before starting verification.

5.2 Disclosures you direct

  • To your Trusted People. When the release conditions you selected are met, we disclose the information within the release scope you selected for that Trusted Person under your Authorization Agreement: the sections you chose, including notes and files, which the Trusted Person can view and, if you allowed it, download. We also disclose your first name or display name.
  • To your other Trusted People. When one Trusted Person's request passes identity verification, we tell those of your other active Trusted People whom you chose to be told that a request was made, and by whom (using the name you entered for that person). If you allowed it, we tell them they can raise a concern.
  • To the person named in a request. We tell the Trusted Person in whose name a request was made, so they can report it if it wasn't them.
  • To you, about requesters. We tell you who asked for access and show you the status and history of each request. You can download a copy of your authorization and request history.
  • To anyone who scans your Wise Card. They see your first name or display name and the card's Recovery ID.
  • When you export or share. You can download your own data and files.

5.3 Disclosures required or permitted by law

We may disclose information without your instruction when we believe in good faith that it is necessary to:

  • (a) comply with law or legal process, such as a subpoena, court order or search warrant. We review requests for legal validity. Where lawful and practical, we will notify you before disclosing your content;
  • (b) respond to fiduciaries, consistent with your choice. The Authorization Agreement lets you allow or prohibit disclosure to a court-appointed personal representative or other fiduciary, and we follow that choice where applicable law allows. Some laws may require disclosure unless you prohibited it. For example, Florida's Fiduciary Access to Digital Assets Act may require us to disclose certain digital assets of a deceased Florida user to the court-appointed personal representative of the estate on proper documentation, unless the user prohibited it;
  • (c) protect against fraud or security threats. This includes sharing information about a fraudulent access attempt with the affected Owner, the person whose identity was misused, our identity-verification provider, and law enforcement;
  • (d) prevent imminent harm. In an emergency involving danger of death or serious physical injury, we may disclose information to authorities to the extent the law allows;
  • (e) enforce our agreements and protect the rights, property or safety of WiseTomorrow, our users or others; or
  • (f) a corporate transaction. In a merger, acquisition, financing, reorganization, bankruptcy or sale of assets, information may be transferred to the successor. The successor must honor this Policy and existing Trusted Person authorizations, or give you notice and a chance to delete your account before any material change.

5.4 What we don't do

  • We do not sell personal information.
  • We do not share personal information for cross-context behavioral advertising.
  • We do not give advertisers or data brokers access to your stored content. Public shopping-page Meta measurement and optional Google Ads, TikTok and Pinterest conversion measurement are described in Section 3 and the Cookie Policy.

6. How long we keep information

InformationRetention
Account information and contentWhile your account is open. When you delete your account, deletion is scheduled 14 days later so you can change your mind. After that, removed from active systems within 30 days, and from backups within a further 35 days
Items you delete (trash)Kept in trash for 30 days so you can restore them, then permanently deleted
Data exportsDeleted 24 hours after creation
Trusted Person detailsWhile the designation exists. After removal, kept with the related authorization records (below)
Authorization, access-request and disclosure records (who you authorized; what scope and conditions; your fiduciary disclosure choice; verification outcomes; supporting documents; concerns and reports; notices; approvals, denials, grants, revocations; what was viewed and downloaded)For as long as your account exists, plus 7 years, to provide evidence if a disclosure is questioned
Verified date of birth from identity checks90 days after the request is decided, then deleted. The verification outcome and verified name stay with the request record
IP addresses in audit records2 years, then removed or truncated. Records underlying an active dispute or investigation are kept until it is resolved
Web server logs30 days
One-time codes and action links (stored as hashes)Deleted 30 days after expiry
Billing and order records7 years (tax and accounting)
Payment event records received from Stripe90 days
Measurement events (page views, clicks and conversions, without names, emails or account IDs)12 months, then deleted
Email bounce and complaint recordsAs long as needed to avoid sending to that address
Legal acceptance recordsLife of the account plus 7 years
BackupsDatabase backups retained 7 days; previous versions of stored files retained 30 days

We may keep information longer when the law requires it, or when it is needed for a pending legal claim, investigation or dispute.

7. Your choices and rights

7.1 For all users. Wherever you live in the United States, you can:

  • access your information: view it in your account, or request a copy;
  • download your content: files individually, and notes and details through export;
  • download a copy of your authorization and access-request history;
  • correct your information in your account settings;
  • delete your content, or delete your account from Settings (you have 14 days to change your mind);
  • change or withdraw Trusted Person authorizations at any time. Disclosures already made cannot be undone;
  • opt out of marketing emails; and
  • appeal a decision we make about a privacy request, by replying to our decision or emailing support@wisetomorrow.com with "Appeal" in the subject.

7.2 State privacy laws. Residents of a growing number of states, including California, Colorado, Connecticut, Oregon, Texas, Virginia and others, have rights under comprehensive privacy laws. We honor the rights above for all U.S. users whether or not a law applies to us. Where a state law applies, you may also have the right to:

  • confirm whether we process your personal information;
  • obtain it in a portable format;
  • opt out of sale, targeted advertising and certain profiling (we do not do these);
  • limit use of sensitive personal information (we use it only to provide the service you request); and
  • not be discriminated against for exercising your rights.

7.3 Sensitive data. We process sensitive personal information only to provide the service you asked for, for security and fraud prevention, and as required by law. That includes information you choose to store, and identity-verification data about requesters. Where a state law requires consent to process sensitive data, we get it through your agreement to store the information and your Authorization Agreement, or through the identity-verification consent given to us and to our provider.

7.4 How to make a request. Email support@wisetomorrow.com or write to 826 Hampton Wood Ct, Sarasota, FL 34232.

  • We will verify your identity, normally by confirming control of your account email. We may ask for more for sensitive requests.
  • An authorized agent may make a request with your signed permission, and we may verify with you directly.
  • We respond within 45 days and may extend by 45 days where the law allows.

7.5 Requests about someone else's Wise Box. If you are a Trusted Person or requester, you may ask about the information we hold about you. You cannot use a privacy request to obtain an Owner's content. We may withhold information where disclosing it would reveal another person's personal information or compromise security.

7.6 Personal representatives of a deceased Owner. See Section 5.3(b). Contact support@wisetomorrow.com.

7.7 If someone used your identity to request access. If you believe someone used your name, documents or contact details in a WiseTomorrow access request, use the "This wasn't me" link in the notice you received, or email support@wisetomorrow.com.

  • We will stop the request and end any access granted under it, flag the records as disputed, and correct how the records describe you.
  • We will keep the evidence needed to investigate. We may share it with law enforcement at your request, or as Section 5.3 allows.

8. Cookies, Do Not Track and Global Privacy Control

  • Cookies we use:
    • a sign-in session cookie;
    • session cookies for people requesting or using Trusted Person access;
    • a language preference cookie; and
    • a first-party marketing-attribution cookie;
    • a cookie remembering your ad-measurement choice; and
    • Google, TikTok and Pinterest conversion cookies, only if you opt in on public shopping pages.
  • See the Cookie Policy for details.
  • Signals we honor. We honor Global Privacy Control and Do Not Track signals by turning off measurement for that browser.

9. Children

The service is not directed to children under 13, and we do not knowingly collect personal information from them through account registration. Owners may choose to store information about their children, such as birth certificates or school records, in their Wise Box. That is the Owner's content, handled under this Policy. If you believe a child under 13 has created an account, contact support@wisetomorrow.com and we will delete it.

10. People outside the United States

The service is intended for U.S. residents. If you use it or are named in it from outside the United States, your information will be transferred to, stored and processed in the United States, where data-protection laws may differ from those in your country.

11. Security incidents

If a security breach affects your personal information, we will notify you and the relevant authorities as required by law. For Florida residents, that includes the notice timelines of Fla. Stat. § 501.171.

12. Changes to this Policy

We may update this Policy. We will post the new version with its effective date. For material changes, we will notify you by email or in the app before the change takes effect. We will not use your information in a materially different way than described here, for information collected before the change, without your consent where the law requires it.

13. Contact

Privacy questions and requests: support@wisetomorrow.com

Mail: Dark Ecommerce Labs, LLC, Attn: Privacy, 826 Hampton Wood Ct, Sarasota, FL 34232

Security reports: support@wisetomorrow.com