OREOASIS← Home
Effective 26 July 2026

Abuse & takedown

Verify pages are public by design — that's what makes a receipt provable to someone who wasn't there. Their contents are written by the customer who issued the receipt, not by us. If a page carries something that shouldn't be public, report it and we'll act.

Report a page

Email founders@oreoasis.com with the verify URL (or receipt number), what's wrong with it, and how to reach you. Reports about personal data, sexual content involving minors, or an active threat go to the top of the queue — say so in the subject line.

We aim to acknowledge within two business days and to resolve within five. Oreoasis is a small operation; that's a commitment we can actually keep, not an enterprise SLA.

What we'll remove

  • The payload display. We can stop serving the human-readable contents of a receipt — the summary and claim fields — on its public page. That is the part a report is usually about.
  • Unlawful content, personal data published by mistake, impersonation, malicious links. Same mechanism: the display goes.
  • Repeat offenders. An account that keeps publishing this way gets suspended.

What stays — and why

  • The hash and the chain position. They contain no readable content. Removing them would silently break every other receipt in that chain, including receipts belonging to people who did nothing wrong.
  • The public log entry. Anchors are written to public transparency logs — Sigstore's Rekor and OpenTimestamps. Nobody can erase those, including us. That is the property that makes a receipt worth anything: a proof that could be quietly withdrawn is not a proof.

So a reported page ends up honest rather than blank: the verdict and the chain still check out, and the contents are no longer displayed. If you need the underlying data deleted from our systems as well, that's an erasure request — see Privacy.

This is also why the SDK hashes content locally and why we tell customers, repeatedly, not to put personal data in a receipt payload: the safe design is to prove what happened without publishing who it happened to.

If you issued the receipt

Email us from the address on the account and we'll withdraw the display — today that's an operator action rather than a dashboard button, and we'd rather say so than imply a control that isn't built yet. The same line applies either way: the display is yours to withdraw, the proof is not.

Security reports

A vulnerability isn't an abuse report. Send those to /security.txt — good-faith research is welcome and we won't threaten you for it.

Related: Terms · Privacy · Refunds · Trust