Resources Docs Free Blog Contact
Log inGet started
Legal Documentation

Cookie Policy

Last Updated: September 22, 2026 Effective: July 12, 2026

This Cookie Policy explains how Sentinel Edge Networks LTD, registered in England and Wales under company number 17150600 ("Maskbreak", "we", "us"), uses cookies, browser storage, scripts, and similar technologies on maskbreak.com and associated subdomains ("the Website").

1. What Are Cookies?

Cookies are small text files placed on your device when you visit a website. Similar technologies include browser local storage, session storage, and JavaScript-based signals used for security purposes. We use these technologies for sign-in, security, requested interface preferences, and optional live chat. Local storage, fingerprinting, and pixels are not outside privacy rules simply because they are not traditional cookies.

2. Storage We Use

2.1 Sign-in and interface storage

We use localStorage for sign-in and selected preferences, and sessionStorage for state needed within a browser tab. The purpose and circumstances determine whether an exception to consent applies, not the storage technology. Security functionality and convenience preferences are listed separately below. Local storage has no automatic expiry unless the application or browser removes it.

The browser stores the sign-in JWT; the server stores a token hash, account identifier, IP address and user agent in a session record for authentication and revocation. Server-side session records are separate from browser storage. The short-lived OAuth cookies below bind redirect sign-in to your browser; they do not replace the JWT in localStorage.

Key and storage Purpose Duration Type
sentinel_token (localStorage) Stores your JWT authentication token to keep you logged into the dashboard. Cleared on logout. Token valid for 24 hours; the stored entry remains until logout, application cleanup, or browser-data deletion Essential
__Host-maskbreak_oauth_g, __Host-maskbreak_oauth_gh, __Host-maskbreak_oauth_a0 (cookies) Random security values that bind a Google, GitHub or Auth0 sign-in redirect to the browser that started it. Secure, HttpOnly and SameSite=Lax; used only when you start that sign-in method, not for tracking. 5 minutes for Google/GitHub; 15 minutes for Auth0; cleared when the callback is validated Essential
scta_dismissed_v1 Remembers that you dismissed the sticky call-to-action bar on blog and comparison pages so it stays hidden on later visits. Until cleared Preference
stl_cmdk_seen Remembers that you have seen the dashboard command palette. Older browsers may still hold retired stl_setup_hide and stl_setup_sdk preferences; the console no longer reads or writes them. Until cleared Preference
mb_lang, mb_console_lang:<account ID> (localStorage) Your selected website language and, separately, the console language you explicitly choose for each account in this browser (EN, DE, or ET). New accounts start in English. The account identifier scopes this local preference; it is not sent to an advertising service. Until changed or cleared Preference
stl_dash_v1, stl_set_v1, stl_sec_v1, stl_mem_v1, stl_email, mb_console_account (sessionStorage) Recent signed-in console responses and your displayed email, so navigating between account pages does not start from a blank screen. This can include account, key, usage, session, or team information available to your account. Browser-tab session; refreshed or cleared by the application, and cleared on logout Account
_sentinel_invite, _sentinel_next (sessionStorage) Preserves an organisation invitation and the requested account-page destination while you sign in; removed when consumed. Until consumed or the tab session ends Account
pg-auto, sm-human (sessionStorage) Avoids repeating the API playground’s automatic demo or an interface animation within the same tab. Browser-tab session Interface
_sntl_mcl_v Version marker set by pages that run our security SDK (homepage scanner, IP-lookup tool, API docs, dashboard) so stale security-SDK storage is cleared once after a key rotation. Contains only a version number. Until cleared Essential

2.2 Security & Fraud Prevention

Security SDKs operate on signup, login, account, API-playground, IP-lookup and scanner surfaces, and on the contact and public-interest forms. They process network signals (such as IP address, connection type, VPN/proxy status) and device signals (such as browser characteristics, tampering, and automation indicators) to authenticate users, prevent abuse, and provide a security feature the visitor or customer requested.

These technologies are used only for security and fraud-prevention purposes, not advertising. The homepage scanner starts automatically with a network-only pass. Deeper device intelligence starts when the scanner is visible or the visitor interacts with it; because the scanner is near the top of the homepage, this can happen immediately. More detail about lawful bases, recipients, and retention is in our Privacy Policy.

We also check passwords against the Have I Been Pwned breach database during signup and password reset. Only a partial hash of the password is sent (k-anonymity) — your actual password is never transmitted.

If you wish to object to this processing under GDPR Article 21, please contact us at support@maskbreak.com. Note that objecting may prevent you from using certain features of the platform.

2.3 Analytics and advertising

We set no advertising cookies and do not run Microsoft Clarity, Google Analytics or retargeting pixels. Widgo chat includes visitor analytics and, since 22 September 2026, loads by itself on public marketing pages, as described below; browsers sending Global Privacy Control get a button instead. Widgo session replay is disabled.

Google Ads measurement is disabled as of 6 September 2026. The advertising tag, its queued configuration, conversion-event calls, and connection hints have been removed from public pages, signup, and the dashboard, including the page generators. Google Sign-In remains available as a separate authentication option.

Before this change, Google Ads ran with its consent settings denied but could still send cookieless measurement pings. Those pings could include request and device information; they were not equivalent to “no data collected”. Disabling the tag prevents new tag-generated measurement from the updated pages; it does not retrospectively erase information already received by Google. We will not reintroduce optional advertising or analytics technology without updating this notice and implementing any required consent controls.

2.4 Optional AI chat and visitor analytics

Since 22 September 2026 the Widgo chat launcher loads by itself on public marketing pages once the page has finished loading. It does not load on sign-in, private account or result pages, on pages whose address carries a code or key, or when your browser sends the Global Privacy Control signal; in that case a plain “Chat” button appears and Widgo loads only if you press it. We do not reuse a previous Crisp choice. Email support remains available without using the chat.

Once loaded, Widgo processes request IP, browser/device characteristics, pages, referrer and campaign information and interaction timing, and, if you write to it, chat content and volunteered contact details. Its script creates a browser-derived identifier and uses visitor analytics, including possible company-level identification. Session replay is disabled; microphone access is blocked by our site permissions policy. This optional analytics is separate from Maskbreak’s security checks.

The widget uses widgo_sid in cookies (up to one year) and localStorage, and may use widgo_verified_<organisation> cookies (up to 400 days) and localStorage for its human check. Configuration and availability caches use widgo_cfg_ and widgo_gone_ prefixes. Open/closed and greeting state use sessionStorage; layout preferences may use localStorage. Local storage can remain until cleared; browser limits may shorten these durations. These identifiers are created by Widgo’s script when it loads, not by Maskbreak.

Closing the widget does not stop its background activity. To keep Widgo from loading, enable Global Privacy Control in your browser or block cdn.widgo.ai with a content blocker; neither erases previously stored cookies, local storage or chat transcripts. Clear relevant site data in your browser to remove stored identifiers, and email support@maskbreak.com for access or deletion requests. Widgo’s privacy policy describes its processing and retention.

Previous provider: Crisp was replaced on 8 September 2026. Its existing crisp-client/ cookies and historical support records are not deleted by switching providers; clear site data or contact us as above. The old mb_chat_open preference no longer starts any chat.

3. Third-Party Services

The following third-party services are integrated and may process data from your device:

Provider Purpose Data Processed Privacy Policy
Network intelligence provider Network-layer fraud detection: VPN, residential proxy, datacenter, and Tor exit detection. Powers the core /v1/evaluate endpoint. IP address, ASN, encrypted SDK token from your browser Named to customers under DPA
Device intelligence provider Device-layer intelligence: browser tampering, antidetect detection, bot/automation, emulator/VM, incognito. Loaded from a maskbreak.com subdomain; if that load is blocked, the browser falls back to the provider’s own domain. Browser/device characteristics, IP address, pseudonymous identifiers and security signals Named to customers under DPA
Cloudflare CDN, DDoS protection, and DNS for maskbreak.com. Cloudflare may set __cf_bm for bot management (expires after 30 minutes of inactivity) and cf_clearance to remember a passed challenge (duration depends on the challenge-passage configuration). These are not necessarily session-only cookies. IP address, request metadata, TLS handshake fingerprint cloudflare.com/privacypolicy
Railway Application hosting and runtime infrastructure. Server logs, IP address railway.com/legal/privacy
Turso Managed cloud database (libSQL). Stores account and session records, API keys, evaluation records, and keyed abuse-prevention counters. Server-side data only — does not interact with your browser turso.tech/privacy
Amazon Web Services (S3) Encrypted nightly database backups for disaster recovery, EU Stockholm region (eu-north-1), with a 60-day retention commitment; implementation verification remains pending. Server-side data only — does not interact with your browser aws.amazon.com/privacy
Resend Transactional email delivery (OTP codes, password resets, contact-form receipts). Recipient email address and message content, including information you submit in a support or programme application resend.com/privacy
Widgo Public-page AI chat and visitor analytics, loaded automatically on public marketing pages; a button instead under Global Privacy Control (Section 2.4). Replay is disabled. Chat content, volunteered contact details, IP, browser/device identifiers, page/referrer/campaign data and interaction timing — from page load on public marketing pages; chat content only if you write to it Widgo privacy policy
Google Sign-In (OAuth) Optional "Sign in with Google" authentication. Email, name, Google account ID policies.google.com/privacy
GitHub Sign-In (OAuth) Optional "Sign in with GitHub" authentication, where enabled and offered on the sign-in page. Used only when you choose that sign-in method. Email, name, GitHub account ID docs.github.com — privacy statement
Auth0 (Okta) Optional emailed sign-in link, where offered. Used only when you request that sign-in method. Email address, authentication transaction, and request metadata needed to complete sign-in auth0.com/privacy
Have I Been Pwned Password breach check during signup and password reset using k-anonymity. Our server sends only the first 5 characters of the SHA-1 hash to Have I Been Pwned; your password and the rest of the hash never leave our infrastructure. Partial password hash prefix only haveibeenpwned.com/Privacy

Our specialised detection providers are listed by category: the composition of our detection stack is confidential security information. Customers can request the full named list, with each vendor's privacy policy, under their Data Processing Agreement — published self-serve at maskbreak.com/dpa — by emailing support@maskbreak.com; countersigned copies are available from the same address.

4. How to control storage

4.1 Browser settings

You can clear localStorage and cookies via your browser's developer tools or settings. Note that clearing sentinel_token will log you out of the dashboard. Instructions for major browsers:

5. International Transfers

Some providers, including Resend, Railway, Cloudflare, and Google or GitHub Sign-In, may process data outside the UK and European Economic Area. Where required, we use an applicable adequacy regulation or contractual safeguards. See our Privacy Policy or contact us for more information.

6. Your rights

Information about access, correction, deletion, restriction, portability, objection, automated profiling, and complaints is set out in our Privacy Policy. Rights requests can be sent to support@maskbreak.com.

7. Changes to This Policy

We may update this Cookie Policy when our technology or legal obligations change. Material changes will be highlighted on the Website or sent to account holders where appropriate. The "Last Updated" date at the top reflects the most recent revision.

8. Contact

Sentinel Edge Networks LTD — Data Protection

support@maskbreak.com

134a West Hendon Broadway, London, NW9 7AA, United Kingdom · Company number: 17150600