This Cookie Policy explains how Sentinel Edge Networks LTD, registered in England and Wales under company number 17150600 ("Maskbreak", "we", "us"), uses cookies, browser storage, scripts, and similar technologies on maskbreak.com and associated subdomains ("the Website").
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. Similar technologies include browser local storage, session storage, and JavaScript-based signals used for security purposes. We use these technologies for sign-in, security, requested interface preferences, and optional live chat. Local storage, fingerprinting, and pixels are not outside privacy rules simply because they are not traditional cookies.
2. Storage We Use
2.1 Sign-in and interface storage
We use localStorage for sign-in and selected preferences, and sessionStorage for state needed within a browser tab. The purpose and circumstances determine whether an exception to consent applies, not the storage technology. Security functionality and convenience preferences are listed separately below. Local storage has no automatic expiry unless the application or browser removes it.
The browser stores the sign-in JWT; the server stores a token hash, account identifier, IP address and user agent in a session record for authentication and revocation. Server-side session records are separate from browser storage. The short-lived OAuth cookies below bind redirect sign-in to your browser; they do not replace the JWT in localStorage.
| Key and storage | Purpose | Duration | Type |
|---|---|---|---|
sentinel_token (localStorage) |
Stores your JWT authentication token to keep you logged into the dashboard. Cleared on logout. | Token valid for 24 hours; the stored entry remains until logout, application cleanup, or browser-data deletion | Essential |
__Host-maskbreak_oauth_g, __Host-maskbreak_oauth_gh, __Host-maskbreak_oauth_a0 (cookies) |
Random security values that bind a Google, GitHub or Auth0 sign-in redirect to the browser that started it. Secure, HttpOnly and SameSite=Lax; used only when you start that sign-in method, not for tracking. | 5 minutes for Google/GitHub; 15 minutes for Auth0; cleared when the callback is validated | Essential |
scta_dismissed_v1 |
Remembers that you dismissed the sticky call-to-action bar on blog and comparison pages so it stays hidden on later visits. | Until cleared | Preference |
stl_cmdk_seen |
Remembers that you have seen the dashboard command palette. Older browsers may still hold retired stl_setup_hide and stl_setup_sdk preferences; the console no longer reads or writes them. |
Until cleared | Preference |
mb_lang, mb_console_lang:<account ID> (localStorage) |
Your selected website language and, separately, the console language you explicitly choose for each account in this browser (EN, DE, or ET). New accounts start in English. The account identifier scopes this local preference; it is not sent to an advertising service. | Until changed or cleared | Preference |
stl_dash_v1, stl_set_v1, stl_sec_v1, stl_mem_v1, stl_email, mb_console_account (sessionStorage) |
Recent signed-in console responses and your displayed email, so navigating between account pages does not start from a blank screen. This can include account, key, usage, session, or team information available to your account. | Browser-tab session; refreshed or cleared by the application, and cleared on logout | Account |
_sentinel_invite, _sentinel_next (sessionStorage) |
Preserves an organisation invitation and the requested account-page destination while you sign in; removed when consumed. | Until consumed or the tab session ends | Account |
pg-auto, sm-human (sessionStorage) |
Avoids repeating the API playground’s automatic demo or an interface animation within the same tab. | Browser-tab session | Interface |
_sntl_mcl_v |
Version marker set by pages that run our security SDK (homepage scanner, IP-lookup tool, API docs, dashboard) so stale security-SDK storage is cleared once after a key rotation. Contains only a version number. | Until cleared | Essential |
2.2 Security & Fraud Prevention
Security SDKs operate on signup, login, account, API-playground, IP-lookup and scanner surfaces, and on the contact and public-interest forms. They process network signals (such as IP address, connection type, VPN/proxy status) and device signals (such as browser characteristics, tampering, and automation indicators) to authenticate users, prevent abuse, and provide a security feature the visitor or customer requested.
These technologies are used only for security and fraud-prevention purposes, not advertising. The homepage scanner starts automatically with a network-only pass. Deeper device intelligence starts when the scanner is visible or the visitor interacts with it; because the scanner is near the top of the homepage, this can happen immediately. More detail about lawful bases, recipients, and retention is in our Privacy Policy.
We also check passwords against the Have I Been Pwned breach database during signup and password reset. Only a partial hash of the password is sent (k-anonymity) — your actual password is never transmitted.
If you wish to object to this processing under GDPR Article 21, please contact us at support@maskbreak.com. Note that objecting may prevent you from using certain features of the platform.
2.3 Analytics and advertising
We set no advertising cookies and do not run Microsoft Clarity, Google Analytics or retargeting pixels. Widgo chat includes visitor analytics and, since 22 September 2026, loads by itself on public marketing pages, as described below; browsers sending Global Privacy Control get a button instead. Widgo session replay is disabled.
Google Ads measurement is disabled as of 6 September 2026. The advertising tag, its queued configuration, conversion-event calls, and connection hints have been removed from public pages, signup, and the dashboard, including the page generators. Google Sign-In remains available as a separate authentication option.
Before this change, Google Ads ran with its consent settings denied but could still send cookieless measurement pings. Those pings could include request and device information; they were not equivalent to “no data collected”. Disabling the tag prevents new tag-generated measurement from the updated pages; it does not retrospectively erase information already received by Google. We will not reintroduce optional advertising or analytics technology without updating this notice and implementing any required consent controls.
2.4 Optional AI chat and visitor analytics
Since 22 September 2026 the Widgo chat launcher loads by itself on public marketing pages once the page has finished loading. It does not load on sign-in, private account or result pages, on pages whose address carries a code or key, or when your browser sends the Global Privacy Control signal; in that case a plain “Chat” button appears and Widgo loads only if you press it. We do not reuse a previous Crisp choice. Email support remains available without using the chat.
Once loaded, Widgo processes request IP, browser/device characteristics, pages, referrer and campaign information and interaction timing, and, if you write to it, chat content and volunteered contact details. Its script creates a browser-derived identifier and uses visitor analytics, including possible company-level identification. Session replay is disabled; microphone access is blocked by our site permissions policy. This optional analytics is separate from Maskbreak’s security checks.
The widget uses widgo_sid in cookies (up to one year) and localStorage, and may use widgo_verified_<organisation> cookies (up to 400 days) and localStorage for its human check. Configuration and availability caches use widgo_cfg_ and widgo_gone_ prefixes. Open/closed and greeting state use sessionStorage; layout preferences may use localStorage. Local storage can remain until cleared; browser limits may shorten these durations. These identifiers are created by Widgo’s script when it loads, not by Maskbreak.
Closing the widget does not stop its background activity. To keep Widgo from loading, enable Global Privacy Control in your browser or block cdn.widgo.ai with a content blocker; neither erases previously stored cookies, local storage or chat transcripts. Clear relevant site data in your browser to remove stored identifiers, and email support@maskbreak.com for access or deletion requests. Widgo’s privacy policy describes its processing and retention.
Previous provider: Crisp was replaced on 8 September 2026. Its existing crisp-client/ cookies and historical support records are not deleted by switching providers; clear site data or contact us as above. The old mb_chat_open preference no longer starts any chat.
3. Third-Party Services
The following third-party services are integrated and may process data from your device:
| Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Network intelligence provider | Network-layer fraud detection: VPN, residential proxy, datacenter, and Tor exit detection. Powers the core /v1/evaluate endpoint. |
IP address, ASN, encrypted SDK token from your browser | Named to customers under DPA |
| Device intelligence provider | Device-layer intelligence: browser tampering, antidetect detection, bot/automation, emulator/VM, incognito. Loaded from a maskbreak.com subdomain; if that load is blocked, the browser falls back to the provider’s own domain. |
Browser/device characteristics, IP address, pseudonymous identifiers and security signals | Named to customers under DPA |
| Cloudflare | CDN, DDoS protection, and DNS for maskbreak.com. Cloudflare may set __cf_bm for bot management (expires after 30 minutes of inactivity) and cf_clearance to remember a passed challenge (duration depends on the challenge-passage configuration). These are not necessarily session-only cookies. |
IP address, request metadata, TLS handshake fingerprint | cloudflare.com/privacypolicy |
| Railway | Application hosting and runtime infrastructure. | Server logs, IP address | railway.com/legal/privacy |
| Turso | Managed cloud database (libSQL). Stores account and session records, API keys, evaluation records, and keyed abuse-prevention counters. | Server-side data only — does not interact with your browser | turso.tech/privacy |
| Amazon Web Services (S3) | Encrypted nightly database backups for disaster recovery, EU Stockholm region (eu-north-1), with a 60-day retention commitment; implementation verification remains pending. | Server-side data only — does not interact with your browser | aws.amazon.com/privacy |
| Resend | Transactional email delivery (OTP codes, password resets, contact-form receipts). | Recipient email address and message content, including information you submit in a support or programme application | resend.com/privacy |
| Widgo | Public-page AI chat and visitor analytics, loaded automatically on public marketing pages; a button instead under Global Privacy Control (Section 2.4). Replay is disabled. | Chat content, volunteered contact details, IP, browser/device identifiers, page/referrer/campaign data and interaction timing — from page load on public marketing pages; chat content only if you write to it | Widgo privacy policy |
| Google Sign-In (OAuth) | Optional "Sign in with Google" authentication. | Email, name, Google account ID | policies.google.com/privacy |
| GitHub Sign-In (OAuth) | Optional "Sign in with GitHub" authentication, where enabled and offered on the sign-in page. Used only when you choose that sign-in method. | Email, name, GitHub account ID | docs.github.com — privacy statement |
| Auth0 (Okta) | Optional emailed sign-in link, where offered. Used only when you request that sign-in method. | Email address, authentication transaction, and request metadata needed to complete sign-in | auth0.com/privacy |
| Have I Been Pwned | Password breach check during signup and password reset using k-anonymity. Our server sends only the first 5 characters of the SHA-1 hash to Have I Been Pwned; your password and the rest of the hash never leave our infrastructure. | Partial password hash prefix only | haveibeenpwned.com/Privacy |
Our specialised detection providers are listed by category: the composition of our detection stack is confidential security information. Customers can request the full named list, with each vendor's privacy policy, under their Data Processing Agreement — published self-serve at maskbreak.com/dpa — by emailing support@maskbreak.com; countersigned copies are available from the same address.
4. How to control storage
4.1 Browser settings
You can clear localStorage and cookies via your browser's developer tools or settings. Note that clearing sentinel_token will log you out of the dashboard. Instructions for major browsers:
5. International Transfers
Some providers, including Resend, Railway, Cloudflare, and Google or GitHub Sign-In, may process data outside the UK and European Economic Area. Where required, we use an applicable adequacy regulation or contractual safeguards. See our Privacy Policy or contact us for more information.
6. Your rights
Information about access, correction, deletion, restriction, portability, objection, automated profiling, and complaints is set out in our Privacy Policy. Rights requests can be sent to support@maskbreak.com.
7. Changes to This Policy
We may update this Cookie Policy when our technology or legal obligations change. Material changes will be highlighted on the Website or sent to account holders where appropriate. The "Last Updated" date at the top reflects the most recent revision.
8. Contact
134a West Hendon Broadway, London, NW9 7AA, United Kingdom · Company number: 17150600