Resources Docs Free Blog Contact
Log inGet started

Sub-processors

Everyone who processes data on Maskbreak's behalf, what they do, and what they touch; processing regions are stated in Annex C of the DPA. New sub-processors that process customer data are announced at least 30 days in advance, with right to object — the change log below is the public record.

Last updated 22 September 2026 · maintained by Sentinel Edge Networks LTD

Current sub-processors

ProviderPurposeData touched
CloudflareCDN, TLS termination, edge caching, first-pass scanner verdict at the edgeRequest metadata (IP, headers) in transit
RailwayApplication hostingAll application traffic and data in transit
TursoPrimary database (managed libSQL), encrypted at restAccount data, hashed lookup records
ResendTransactional email (verification, notices)Email address, message content
Widgo (Widgo, Inc., United States)AI chat and visitor analytics, loaded automatically on public marketing pages since 22 September 2026 (a plain button instead under Global Privacy Control). Session replay disabled; no widget on private account or sign-in pages.Chat content, volunteered details, IP, browser/device identifiers, page/referrer/campaign data and interaction timing. Not supplied with Maskbreak account, API-key or evaluation records. Provider privacy policy
Crisp (Crisp IM SAS, France) — legacy records onlyFormer live-chat provider, replaced on 8 September 2026; no new browser widget loading.Historical chat transcripts and metadata while needed for support or legal obligations; access and deletion requests remain available.
Amazon Web Services (S3)Encrypted nightly database backups for disaster recovery — EU Stockholm region (eu-north-1)Full encrypted database snapshots; 60-day retention commitment, with the implementation review still open
GoogleOptional Google Sign-In only. Google Ads measurement was removed on 6 September 2026.OAuth identity assertion and sign-in request metadata when this option is used
GitHubSign-In only (OAuth), where offered — not currently enabled in production, so GitHub receives nothing until it is; no analytics, no advertisingOAuth identity assertion (when enabled)
Auth0 (Okta)“Email me a sign-in link” — passwordless sign-in and signup, where offered. Auth0 sends the one-time link and confirms the address; Maskbreak then issues its own session. Behind configuration: it receives nothing unless the option is enabled and usedEmail address, authentication transaction, and sign-in request metadata when used
Have I Been PwnedPassword breach check via k-anonymity5-character SHA-1 prefix only — never the password
Network & device intelligence providersVPN/proxy classification and device-integrity signals for evaluationsRequest network metadata; named to customers on request under the DPA (support@maskbreak.com)
Fonts are self-hosted. Google Ads remains removed. Widgo chat loads on public marketing pages and includes visitor analytics; replay is disabled. Google Sign-In is separate. See the Privacy Policy and Cookie Policy for storage and chat details.

Change log

DateChange
2026-09-22Widgo chat now loads automatically on public marketing pages instead of behind a per-page consent notice, so the same public visit data reaches Widgo from page load rather than from a click. Nothing changed for sign-in, private account or result pages (no widget), for customer API or evaluation records (never supplied), or for session replay (still disabled). Browsers sending Global Privacy Control get a plain “Chat” button and Widgo loads only when it is pressed. Privacy Policy §4 and §5, Cookie Policy §2.4, the trust page and the security whitepaper were updated in the same change.
2026-09-08Replaced new Crisp chat with consent-gated Widgo AI chat on reviewed public marketing pages. Replay is disabled; private/account pages offer email support. Widgo receives consenting visitors’ chat and visit data, not customer API/evaluation records. Historical Crisp support records are preserved. Updated privacy, cookies, DPA Annex C and security disclosures. This optional website service is distinct from processing customer end-user evaluations.
2026-09-06Moved abuse-sensitive rate limits and email-send budgets into the existing application database using keyed hashes. The application no longer sends rate-limit keys to Upstash; previously written keys remain subject to their existing short expiry. No new sub-processor was added. Updated the Privacy Policy with the security records and cleanup schedule.
2026-09-06Removed Google Ads measurement from public pages, signup, the dashboard, and shared page generators. Google Sign-In remains available. Corrected the current privacy, cookie, and security notices; earlier dated entries below describe historical use, not the current setup. Clarified same-tab chat continuation. No new sub-processor was introduced.
2026-09-04Added Crisp (live chat). The chat button on every page loads nothing until it is clicked; from that click Crisp receives what the person types plus their IP address, browser details and current page. It never touches customer API or evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §2.4 and §3 were updated in the same change.
2026-09-02Added Auth0 (emailed one-time sign-in link, where offered). The integration shipped on 2026-09-01 behind configuration, like GitHub Sign-In: Auth0 receives the account holder’s email address only when the option is enabled and used, and nothing otherwise. Completeness correction — the code landed before this list was updated.
2026-08-29Clarified two rows without adding or removing anyone. GitHub: the sign-in integration exists in the codebase but no GitHub OAuth app is configured in production, so the option is not shown and GitHub receives no data; it stays on the list so that notice has already been given if it is enabled. Google: the row now also names the cookieless Google Ads measurement tag (Consent Mode v2, all storage denied) that public pages and the signed-in dashboard have loaded since 2026-07-19 and that Privacy Policy §5 and Cookie Policy §2.3 already disclose. The Privacy Policy, Cookie Policy, Terms, DPA and security whitepaper were corrected and re-dated in the same change.
2026-08-02Added and removed Dreamdata (business-to-business marketing attribution) on the same day. It was live on public marketing pages for approximately 30 minutes. During that window its account-level component sent page URL, page title, canonical URL, referring URL and the requesting IP address to Dreamdata, which uses them to estimate the organisation a visit came from. Its visitor-level component was gated behind analytics consent, which this site does not grant — with one exception we want to be explicit about: the gate is read from Google’s consent framework, so a visitor whose browser blocked Google Tag Manager would have had the visitor-level component, including form tracking, initialise normally. It never ran on the console or on any signed-in page, and it received no customer API or evaluation data at any point. It has been fully removed; no Dreamdata code, endpoint or Content-Security-Policy entry remains. Recorded here for completeness rather than because any obligation attaches to a provider that is no longer used.
2026-07-19Added GitHub (Sign-In only, OAuth) — an optional “Sign in with GitHub” for Maskbreak accounts. It touches only the account holder’s own OAuth identity assertion, never customer end-user evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §3 were updated in the same change.
2026-07-18Added Upstash (rate-limit state) and Amazon Web Services / S3 (encrypted nightly backups). Both were already live infrastructure — this is a completeness correction to the published list, not a new-processor onboarding, so the 30-day advance-notice clause does not apply. Privacy Policy §5 and the security whitepaper were updated in the same change.
2026-07-16Page published. List matches the sub-processors already disclosed in the Privacy Policy — no additions or removals.

Getting notified

Customers who have asked to be notified (email support@maskbreak.com) receive direct notification of sub-processor changes. Everyone else can watch this page or the changelog — any change lands in both at least 30 days before a new data-processing sub-processor goes live.

Questions or objections: support@maskbreak.com.