Privacy Policy
1. Who we are
CorroborateMe is operated as a CNR Code product. Contact: support@cnrcode.com. Where a company customer uses our login-link or OIDC features for their end users, that company is typically the controller of end-user identity data for their app; we process it to provide the Service on their instructions.
2. Data we collect
- Console accounts: email and authentication artifacts (session tokens, optional OAuth / passkey credentials).
- Companies: company name/slug, memberships, plan and billing references, API key hashes (not raw keys after mint), integration secrets (encrypted at rest), webhook allowlists, and audit/usage records.
- Login-link end users: email, password hashes, OTPs (short-lived), passkeys, login session metadata, and delivery outcomes (redirect, webhook, etc.).
- Technical: IP and request metadata needed for security, rate limiting, Turnstile bot checks, and operations.
3. How we use data
We use personal data to authenticate users, operate companies and APIs, meter usage, bill paid plans, prevent abuse, comply with law, and improve reliability. We do not sell personal data.
4. Processors and subprocessors
Infrastructure runs on Cloudflare (Workers, D1, KV, R2, Email Routing / sending as configured, Turnstile). Payments go through Stripe. Optional Google or Apple sign-in shares only what those providers return when you (or an end user) choose those methods. Agents and customer apps you authorize may receive identity assertions you configure.
5. Cookies and local storage
We use session cookies (and related browser storage) for console and company login-link sessions. Turnstile may set cookies required for bot protection. We do not use third-party advertising cookies.
6. Retention and deletion
We retain data while accounts and companies are active and as needed for security, billing, and legal obligations. Company owners can soft-delete a company (grace period, then hard wipe) and erase individual login-link end users. See product docs on GDPR-style erasure. Archived audit batches may retain limited identifiers until object lifecycle expiry. Contact support@cnrcode.com for access or deletion requests we cannot complete in-product.
7. International transfers
Processing may occur in the regions where Cloudflare and our processors operate. By using the Service you acknowledge that transfers may be necessary to provide it.
8. Security
We hash API keys, encrypt integration secrets, and use standard controls appropriate to a hosted auth service. No method of transmission or storage is perfectly secure; protect your keys and invite only trusted admins.
9. Children
The Service is not directed to children under 16 (or the equivalent minimum age in your jurisdiction). Do not use it to create accounts for such children.
10. Changes
We may update this Policy by posting a revised version here with a new date. Continued use after the effective date means you accept the update.
CorroborateMe ┬╖ Pricing ┬╖ Terms ┬╖ Privacy ┬╖ support@cnrcode.com