Corobate — the attestation layer for machine & AI decisions · by AttestedAssets Patent pending — U.S. Patent Application No. 19/747,068. Effective: [effective date] · Version 1.0
Provider: Stanley Smith, a sole proprietor doing business as AttestedAssets. Contact: partners@corobate.com · verify.corobate.com. Based in North Carolina, USA; governed by North Carolina law. A draft for your review before publication; confirm any GDPR/CCPA representative details if you serve EU/California users.
The product is built to minimize what leaves your control. The AttestedAssets applications are local-first — receipts and ledgers live on your device — and Corobate, when embedded by a partner, holds no relationship with that partner's end customer. This section describes the limited data we do handle.
Applications (end users). Receipts, ledgers, and the evidentiary inputs you enter are stored locally on your device. Publishing a receipt is an explicit act you take; until then it is not shared. If you create an account or pay, we handle the account email and payment details needed to provide and bill the service (payment is processed by our payment provider; we do not store full card numbers).
Partner / OEM. For business partners we handle ordinary business-contact and account information (names, work emails, company, integration and billing details) needed to run the relationship. Because Corobate renders under the partner's brand and does not sit between the partner and their customer, we do not receive the partner's end-customer identities through normal operation.
Verification tools. Public verification at verify.corobate.com operates on the receipt content presented to it; it does not require an account.
Automatically. Like most services we collect limited technical logs (e.g., IP, device/browser type, timestamps) needed for security, fraud prevention, and reliability.
To provide, secure, bill, and support the Service; to communicate about the account and material changes; and to meet legal obligations. We do not sell personal information, and the applications do not serve advertising.
Application data is local-first. Where the Service holds credentials or keys, they are encrypted — in the applications, API keys live in the application's main process and are OS-keychain encrypted where the platform supports it, never exposed to page contexts. Data in transit is protected with TLS. No system is perfectly secure, and we work to industry-standard practices; a partner's security addendum (residency, key custody, SOC-type posture, SLA) is set in the partner agreement.
We share personal information only with service providers who help us run the Service (e.g., payment processing, hosting) under contract, and where required by law. In a business transfer, information may pass to the successor entity under this policy.
You can access, correct, export, or delete account information by contacting us; because application receipts are stored on your device, you control those directly. Depending on your jurisdiction you may have additional rights (access, portability, erasure, objection) and the right to complain to a data-protection authority. To exercise any of these, email partners@corobate.com.
We keep account and transaction records only as long as needed to provide the Service and meet legal obligations. The Service is intended for adults and business users, not children. If you use the Service from outside the country where it is operated, information may be processed there under appropriate safeguards.
Material changes will be posted with a revised effective date and, for account holders, notified by email. Questions or requests: partners@corobate.com.