Corobate LLC North Carolina, USA · partners@corobate.com
Terms of Service Privacy Policy Licence Notice All legal documents Back to the site

Privacy Policy

Corobate LLC · North Carolina, USA

APPROVED AND ADOPTED BY THE PRINCIPAL — 10 August 2026

Written from the code and adopted by the principal, who is pro se and takes responsibility for what he publishes. The open items are named at the foot of this document — they are specific clauses, not a pending credential.


1. The unusual thing about this product, stated first

A sealed record cannot be edited or deleted. That is the product: a chain that can be altered is not a chain, and a receipt that can be quietly withdrawn attests to nothing.

This has a consequence you should understand before you use it. Where personal data enters a sealed record, we cannot remove it by deletion. What we can do is redact — the content is removed, the record continues to verify, and it states that redaction occurred.

Design accordingly: put identifiers in a record, not personal detail.

2. What is collected

In a sealed record: whatever you submit as evidence, plus the actor identifiers of who observed and who decided. We do not add anything.

On a public verification page: the receipt you paste. The verifier does the work on your own machine — it re-derives the receipt there rather than sending it anywhere. Verification requires no account and we do not require the receipt to reach us.

This is a document describing what the verifier does; it is not the verifier. This page performs no cryptography and makes no claim about any record of yours. The page that does the work is the one to judge, and it is checked on every harness run.

On the demonstration pages: a local browser store under attestedassets_db_v1, and page-usage events. These are not part of any sealed record and must never become one — a usage event is not evidence.

If you register: the company name, email and terms acceptance you provide.

2a. What the delivered applications keep in your browser

The three delivered application packages — AttestedAssets, Stock Risk Receipt and TellmeTiresias — are separate from the pages above and keep more than they did. Everything in this list stays in your browser, on your machine; none of it reaches us. It is listed because a policy that names one store while the software writes seven is not a shorter policy, it is a wrong one.

StoreHeld byWhat it is
attestedassets_db_v1AttestedAssetsthe working set of records you have created
attestedassets_config_v1AttestedAssetsyour settings for that application
tt_f08_theme, tt_f08_seenStock Risk Receiptdisplay theme, and which notices you have dismissed
tt_f08_proxyStock Risk Receiptthe address of a data proxy, if you set one
tt_dark, tt:tip:…TellmeTiresiasdisplay theme, and which tips you have dismissed
tt_anthropic_keyTellmeTiresiasan API key you supply, if you use the research assistant

On tt_anthropic_key specifically. If you enter an Anthropic API key to use the research assistant, that key is held in your browser's local storage. It is not encrypted there and it is not sent to us. Browser local storage is readable by anything else running on that origin, so treat it as you would a key in a configuration file on the same machine: use a key scoped to this purpose, and clear it when you are done.

2b. Where the delivered applications send data

The demonstration pages and the public verifier make no network requests at all. The delivered applications do, and to different places for different reasons:

context you attach to it, to api.anthropic.com, using the key you supplied. That is a third party with its own terms and its own retention policy, and what you send leaves your machine. Nothing else in TellmeTiresias does this; the rest of the application does not call it.

run and point it at. Where that server is, and what it retains, is yours.

data.sec.gov, api.stlouisfed.org, stooq.com, query2.finance.yahoo.com, api.twelvedata.com, www.alphavantage.co, and search.patentsview.org or patents.google.com where a filing is referenced. These receive the symbol or identifier being looked up.

hazards.fema.gov, epqs.nationalmap.gov, the NHTSA vehicle services (vpic.nhtsa.dot.gov, api.nhtsa.gov, www.nhtsa.gov), data.sec.gov, emma.msrb.org and cgmix.uscg.mil, and — where you have deployed it — your own instance at api.attestedassets.com or attestedassets.com. These receive the address, coordinate or identifier being resolved.

fonts.gstatic.com.

at start-up. This is worth knowing for two reasons: it is a request to a third party before you have done anything, and on a machine with no network the page renders blank rather than reporting a problem. That is a defect on our side, not a setting on yours, and it is recorded as one.

None of these is us. We do not receive a copy of what you send them, and we cannot tell you what they retain — each has its own policy. If you are operating somewhere that forbids this traffic, the desktop shells for AttestedAssets and Stock Risk Receipt restrict outbound requests to the federal hosts named above, and the public verifier makes none at all.

Derived from the shipped packages by AUDIT-PACK/check-legal-surface.js, which fails the build if a delivered surface writes a store or contacts an origin this policy does not name.

3. What is not collected

We do not collect a receipt in order to verify it. We do not require an account to verify. We do not sell data. We do not use your sealed content to train anything.

4. Redaction, and what it can and cannot do

Redaction removes content and leaves a record that still verifies and says it was redacted. It cannot remove the fact that a record exists, because the chain would then not verify — and a chain that stops verifying is indistinguishable from a chain that was tampered with.

A statutory erasure right may be satisfiable by redaction and may not be. That is a question for counsel and it is the most important open question in this document.

5. Retention

Sealed records persist for as long as you keep them. We do not silently expire a record; where evidence is stale the record says so rather than becoming quietly worthless.

6. Sharing

A receipt you hand to a counterparty is a document you have shared. We are not a party to that. The receipt discloses only the entries the decision actually relied on, and no more.

7. Lawful basis and your choices

Where the GDPR or a similar regime applies, our basis for processing what you submit is performance of the contract in the Terms of Service, and for telemetry on demonstration pages, legitimate interest in knowing whether the demonstration works — which you may object to, and which never enters a sealed record.

You may request access to what we hold, correction of what is wrong, an export, and restriction of processing. Erasure is answered by §4 and its answer is partial, which is stated there rather than promised here and withdrawn later.

8. International transfer

Data you submit is processed in the United States. Where you are in a jurisdiction that restricts transfer, the deployment option that resolves it is running the software yourself — the engine has no runtime dependencies and does not call home, so a self-hosted deployment transfers nothing.

9. Sub-processors

We use none for sealed content. Sealing, gating and verification run in the software you hold. Where we host, hosting and payment providers are named on request and before you subscribe.

10. Security and breach

Access to hosted systems is limited to named individuals. A breach of a sealed record is detectable rather than deniable — that is what the chain is for — and where we detect one we will tell affected parties without undue delay and, where required, within seventy-two hours of becoming aware.

What a breach cannot do is silently alter a record. An altered record stops verifying, and the verification is done by parties we do not control.

11. Children

The service is not directed to children and we do not knowingly collect their data. Where a caregiver submits evidence about a minor, the caregiver is the controller of that content and the terms in §1 about immutability apply to it with particular force. Consider carefully what belongs in a permanent record.

12. Retention of telemetry

Demonstration telemetry and registration details are kept while you are a customer and for twelve months after, then deleted. This is ordinary data and it deletes ordinarily — the immutability in §1 applies to sealed records and to nothing else.

13. Contact

Corobate LLC, Hendersonville, North Carolina, USA, is the controller for data you submit to a hosted deployment. Where you run the software yourself, you are the controller and we process nothing.


Notes

§1 and §4 carry the hard question and it is not a drafting problem. Sealed records cannot be deleted; redaction removes content and leaves a verifying record that says redaction occurred. Whether that satisfies a statutory erasure right is answered by choosing which jurisdictions to serve and which deployment model to offer, not by wording. §8's self-hosted option is the practical answer where transfer or erasure is strict: we hold nothing, so there is nothing for us to erase.

§2's separation is enforced, not promised. Demonstration telemetry never enters a sealed record, and the action register prints that disposition on every build.

<!-- XP:legal:privacy-tail -->

Corobate LLC · North Carolina, USA · partners@corobate.com
Rendered from 25-legal/ by 33-admin/build-legal-pages.js. The markdown in that directory is the document; this page is a rendering of it.