Sub-processors
Everyone who processes data on Maskbreak's behalf, what they do, and what they touch; processing regions are stated in Annex C of the DPA. New sub-processors that process customer data are announced at least 30 days in advance, with right to object — the change log below is the public record.
Last updated 8 September 2026 · maintained by Sentinel Edge Networks LTD
Current sub-processors
| Provider | Purpose | Data touched |
|---|---|---|
| Cloudflare | CDN, TLS termination, edge caching, first-pass scanner verdict at the edge | Request metadata (IP, headers) in transit |
| Railway | Application hosting | All application traffic and data in transit |
| Turso | Primary database (managed libSQL), encrypted at rest | Account data, hashed lookup records |
| Resend | Transactional email (verification, notices) | Email address, message content |
| Widgo (Widgo, Inc., United States) | Optional AI chat and visitor analytics on public marketing pages after explicit consent on each page. Session replay disabled; no widget on private account or sign-in pages. | Chat content, volunteered details, IP, browser/device identifiers, page/referrer/campaign data and interaction timing. Not supplied with Maskbreak account, API-key or evaluation records. Provider privacy policy |
| Crisp (Crisp IM SAS, France) — legacy records only | Former live-chat provider, replaced on 8 September 2026; no new browser widget loading. | Historical chat transcripts and metadata while needed for support or legal obligations; access and deletion requests remain available. |
| Amazon Web Services (S3) | Encrypted nightly database backups for disaster recovery — EU Stockholm region (eu-north-1) | Full encrypted database snapshots; 60-day retention commitment, with the implementation review still open |
| Optional Google Sign-In only. Google Ads measurement was removed on 6 September 2026. | OAuth identity assertion and sign-in request metadata when this option is used | |
| GitHub | Sign-In only (OAuth), where offered — not currently enabled in production, so GitHub receives nothing until it is; no analytics, no advertising | OAuth identity assertion (when enabled) |
| Auth0 (Okta) | “Email me a sign-in link” — passwordless sign-in and signup, where offered. Auth0 sends the one-time link and confirms the address; Maskbreak then issues its own session. Behind configuration: it receives nothing unless the option is enabled and used | Email address, authentication transaction, and sign-in request metadata when used |
| Have I Been Pwned | Password breach check via k-anonymity | 5-character SHA-1 prefix only — never the password |
| Network & device intelligence providers | VPN/proxy classification and device-integrity signals for evaluations | Request network metadata; named to customers on request under the DPA (support@maskbreak.com) |
Fonts are self-hosted. Google Ads remains removed. Optional Widgo chat includes visitor analytics only after consent; replay is disabled. Google Sign-In is separate. See the Privacy Policy and Cookie Policy for storage and chat details.
Change log
| Date | Change |
|---|---|
| 2026-09-08 | Replaced new Crisp chat with consent-gated Widgo AI chat on reviewed public marketing pages. Replay is disabled; private/account pages offer email support. Widgo receives consenting visitors’ chat and visit data, not customer API/evaluation records. Historical Crisp support records are preserved. Updated privacy, cookies, DPA Annex C and security disclosures. This optional website service is distinct from processing customer end-user evaluations. |
| 2026-09-06 | Moved abuse-sensitive rate limits and email-send budgets into the existing application database using keyed hashes. The application no longer sends rate-limit keys to Upstash; previously written keys remain subject to their existing short expiry. No new sub-processor was added. Updated the Privacy Policy with the security records and cleanup schedule. |
| 2026-09-06 | Removed Google Ads measurement from public pages, signup, the dashboard, and shared page generators. Google Sign-In remains available. Corrected the current privacy, cookie, and security notices; earlier dated entries below describe historical use, not the current setup. Clarified same-tab chat continuation. No new sub-processor was introduced. |
| 2026-09-04 | Added Crisp (live chat). The chat button on every page loads nothing until it is clicked; from that click Crisp receives what the person types plus their IP address, browser details and current page. It never touches customer API or evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §2.4 and §3 were updated in the same change. |
| 2026-09-02 | Added Auth0 (emailed one-time sign-in link, where offered). The integration shipped on 2026-09-01 behind configuration, like GitHub Sign-In: Auth0 receives the account holder’s email address only when the option is enabled and used, and nothing otherwise. Completeness correction — the code landed before this list was updated. |
| 2026-08-29 | Clarified two rows without adding or removing anyone. GitHub: the sign-in integration exists in the codebase but no GitHub OAuth app is configured in production, so the option is not shown and GitHub receives no data; it stays on the list so that notice has already been given if it is enabled. Google: the row now also names the cookieless Google Ads measurement tag (Consent Mode v2, all storage denied) that public pages and the signed-in dashboard have loaded since 2026-07-19 and that Privacy Policy §5 and Cookie Policy §2.3 already disclose. The Privacy Policy, Cookie Policy, Terms, DPA and security whitepaper were corrected and re-dated in the same change. |
| 2026-08-02 | Added and removed Dreamdata (business-to-business marketing attribution) on the same day. It was live on public marketing pages for approximately 30 minutes. During that window its account-level component sent page URL, page title, canonical URL, referring URL and the requesting IP address to Dreamdata, which uses them to estimate the organisation a visit came from. Its visitor-level component was gated behind analytics consent, which this site does not grant — with one exception we want to be explicit about: the gate is read from Google’s consent framework, so a visitor whose browser blocked Google Tag Manager would have had the visitor-level component, including form tracking, initialise normally. It never ran on the console or on any signed-in page, and it received no customer API or evaluation data at any point. It has been fully removed; no Dreamdata code, endpoint or Content-Security-Policy entry remains. Recorded here for completeness rather than because any obligation attaches to a provider that is no longer used. |
| 2026-07-19 | Added GitHub (Sign-In only, OAuth) — an optional “Sign in with GitHub” for Maskbreak accounts. It touches only the account holder’s own OAuth identity assertion, never customer end-user evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §3 were updated in the same change. |
| 2026-07-18 | Added Upstash (rate-limit state) and Amazon Web Services / S3 (encrypted nightly backups). Both were already live infrastructure — this is a completeness correction to the published list, not a new-processor onboarding, so the 30-day advance-notice clause does not apply. Privacy Policy §5 and the security whitepaper were updated in the same change. |
| 2026-07-16 | Page published. List matches the sub-processors already disclosed in the Privacy Policy — no additions or removals. |
Getting notified
Customers who have asked to be notified (email support@maskbreak.com) receive direct notification of sub-processor changes. Everyone else can watch this page or the changelog — any change lands in both at least 30 days before a new data-processing sub-processor goes live.
Questions or objections: support@maskbreak.com.