Privacy Policy

1. Who we are

CorroborateMe is operated as a CNR Code product. Contact: support@cnrcode.com. Where a company customer uses our login-link or OIDC features for their end users, that company is typically the controller of end-user identity data for their app; we process it to provide the Service on their instructions.

2. Data we collect

3. How we use data

We use personal data to authenticate users, operate companies and APIs, meter usage, bill paid plans, prevent abuse, comply with law, and improve reliability. We do not sell personal data.

4. Processors and subprocessors

Infrastructure runs on Cloudflare (Workers, D1, KV, R2, Email Routing / sending as configured, Turnstile). Payments go through Stripe. Optional Google or Apple sign-in shares only what those providers return when you (or an end user) choose those methods. Agents and customer apps you authorize may receive identity assertions you configure.

5. Cookies and local storage

We use session cookies (and related browser storage) for console and company login-link sessions. Turnstile may set cookies required for bot protection. We do not use third-party advertising cookies.

6. Retention and deletion

We retain data while accounts and companies are active and as needed for security, billing, and legal obligations. Company owners can soft-delete a company (grace period, then hard wipe) and erase individual login-link end users. See product docs on GDPR-style erasure. Archived audit batches may retain limited identifiers until object lifecycle expiry. Contact support@cnrcode.com for access or deletion requests we cannot complete in-product.

7. International transfers

Processing may occur in the regions where Cloudflare and our processors operate. By using the Service you acknowledge that transfers may be necessary to provide it.

8. Security

We hash API keys, encrypt integration secrets, and use standard controls appropriate to a hosted auth service. No method of transmission or storage is perfectly secure; protect your keys and invite only trusted admins.

9. Children

The Service is not directed to children under 16 (or the equivalent minimum age in your jurisdiction). Do not use it to create accounts for such children.

10. Changes

We may update this Policy by posting a revised version here with a new date. Continued use after the effective date means you accept the update.