This Cookie Policy explains how Sentinel Edge Networks LTD, registered in England and Wales under company number 17150600 ("Maskbreak", "we", "us"), uses cookies, browser storage, scripts, and similar technologies on maskbreak.com and associated subdomains ("the Website").
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. Similar technologies include browser local storage, session storage, and JavaScript-based signals used for security purposes. We use a minimal set of these technologies — only what is strictly necessary to operate the platform securely.
2. Storage We Use
2.1 Strictly Necessary (localStorage)
We use browser localStorage (not traditional cookies) to keep you logged in and remember your preferences. This does not require consent under the ePrivacy Directive as it is essential to the service you requested.
| Key (localStorage) | Purpose | Duration | Type |
|---|---|---|---|
sentinel_token |
Stores your JWT authentication token to keep you logged into the dashboard. Cleared on logout. | 24 hours / until logout | Essential |
scta_dismissed_v1 |
Remembers that you dismissed the sticky call-to-action bar on blog and comparison pages so it stays hidden on later visits. | Until cleared | Preference |
stl_setup_hide, stl_review_hide, stl_setup_sdk, stl_cmdk_seen |
Dashboard interface preferences — hiding the setup checklist and remembering that you have seen the command palette. Set only inside the logged-in dashboard. | Until cleared | Preference |
2.2 Security & Fraud Prevention
Security SDKs operate on signup, login, account, API-playground, IP-lookup, and scanner surfaces. They process network signals (such as IP address, connection type, VPN/proxy status) and device signals (such as browser characteristics, tampering, and automation indicators) to authenticate users, prevent abuse, and provide a security feature the visitor or customer requested.
These technologies are used only for security and fraud-prevention purposes, not advertising. The homepage scanner starts with a network-only pass; deeper device intelligence is deferred until the scanner is visible or the visitor interacts with it. More detail about lawful bases, recipients, and retention is in our Privacy Policy.
We also check passwords against the Have I Been Pwned breach database during signup and password reset. Only a partial hash of the password is sent (k-anonymity) — your actual password is never transmitted.
If you wish to object to this processing under GDPR Article 21, please contact us at [email protected]. Note that objecting may prevent you from using certain features of the platform.
2.3 Analytics and advertising
We load no analytics tools and set no advertising cookies. We do not run Microsoft Clarity, Google Analytics, retargeting pixels, or session-replay tools.
Since 19 July 2026 our public pages load the Google Ads measurement tag in Consent Mode v2 with all storage permanently denied (ad_storage, ad_user_data, ad_personalization, and analytics_storage are all "denied", and no consent-granting control exists on the Website). In this mode the tag sets no cookies and stores nothing on your device; Google receives only cookieless, aggregated pings used to statistically model ad-campaign conversions. No advertising profile of you is created and no cross-site identifier is used. Because no optional analytics or advertising storage occurs, the Website still does not display a cookie-consent banner.
3. Third-Party Services
The following third-party services are integrated and may process data from your device:
| Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Network intelligence provider | Network-layer fraud detection: VPN, residential proxy, datacenter, and Tor exit detection. Powers the core /v1/evaluate endpoint. |
IP address, ASN, encrypted SDK token from your browser | Named to customers under DPA |
| Device intelligence provider | Device-layer intelligence: browser tampering, antidetect detection, bot/automation, emulator/VM, incognito. Loaded first-party from maskbreak.com. |
Browser/device fingerprint, IP address, anonymized signals | Named to customers under DPA |
| Cloudflare | CDN, DDoS protection, and DNS for maskbreak.com. Cloudflare may set __cf_bm (bot management) and cf_clearance as essential session cookies. |
IP address, request metadata, TLS handshake fingerprint | cloudflare.com/privacypolicy |
| Railway | Application hosting and runtime infrastructure. | Server logs, IP address | railway.app/legal/privacy |
| Turso | Managed cloud database (libSQL). Stores account records, API keys, and aggregated lookup metadata. | Server-side data only — does not interact with your browser | turso.tech/privacy |
| Resend | Transactional email delivery (OTP codes, password resets, contact-form receipts). | Email address, IP address | resend.com/privacy |
| Google Sign-In (OAuth) | Optional "Sign in with Google" authentication. | Email, name, Google account ID | policies.google.com/privacy |
| GitHub Sign-In (OAuth) | Optional "Sign in with GitHub" authentication. | Email, name, GitHub account ID | docs.github.com — privacy statement |
| Have I Been Pwned | Password breach check during signup and password reset using k-anonymity. We send only the first 5 characters of the SHA-1 hash; your password and the rest of the hash never leave your device. | Partial password hash prefix only | haveibeenpwned.com/Privacy |
Our specialised detection providers are listed by category: the composition of our detection stack is confidential security information. Customers receive the full named list, with each vendor's privacy policy, as part of their Data Processing Agreement — published self-serve at maskbreak.com/dpa, with countersigned copies available from [email protected].
4. How to control storage
4.1 Browser settings
You can clear localStorage and cookies via your browser's developer tools or settings. Note that clearing sentinel_token will log you out of the dashboard. Instructions for major browsers:
5. International Transfers
Some providers, including Resend, Railway, Cloudflare, and Google or GitHub Sign-In, may process data outside the UK and European Economic Area. Where required, we use an applicable adequacy regulation or contractual safeguards. See our Privacy Policy or contact us for more information.
6. Your rights
Information about access, correction, deletion, restriction, portability, objection, automated profiling, and complaints is set out in our Privacy Policy. Rights requests can be sent to [email protected].
7. Changes to This Policy
We may update this Cookie Policy when our technology or legal obligations change. Material changes will be highlighted on the Website or sent to account holders where appropriate. The "Last Updated" date at the top reflects the most recent revision.
8. Contact
134a West Hendon Broadway, London, NW9 7AA, United Kingdom · Company number: 17150600