Sub-processors
Everyone who processes data on Maskbreak's behalf, what they do, and what they touch; processing regions are stated in Annex C of the DPA. New sub-processors that process customer data are announced at least 30 days in advance, with right to object — the change log below is the public record.
Last updated 22 September 2026 · maintained by Sentinel Edge Networks LTD
Current sub-processors
| Provider | Purpose | Data touched |
|---|---|---|
| Cloudflare | CDN, TLS termination, edge caching, first-pass scanner verdict at the edge | Request metadata (IP, headers) in transit |
| Railway | Application hosting | All application traffic and data in transit |
| Turso | Primary database (managed libSQL), encrypted at rest | Account data, hashed lookup records |
| Resend | Transactional email (verification, notices) | Email address, message content |
| Widgo (Widgo, Inc., United States) | AI chat and visitor analytics, loaded automatically on public marketing pages since 22 September 2026 (a plain button instead under Global Privacy Control). Session replay disabled; no widget on private account or sign-in pages. | Chat content, volunteered details, IP, browser/device identifiers, page/referrer/campaign data and interaction timing. Not supplied with Maskbreak account, API-key or evaluation records. Provider privacy policy |
| Crisp (Crisp IM SAS, France) — legacy records only | Former live-chat provider, replaced on 8 September 2026; no new browser widget loading. | Historical chat transcripts and metadata while needed for support or legal obligations; access and deletion requests remain available. |
| Amazon Web Services (S3) | Encrypted nightly database backups for disaster recovery — EU Stockholm region (eu-north-1) | Full encrypted database snapshots; 60-day retention commitment, with the implementation review still open |
| Optional Google Sign-In only. Google Ads measurement was removed on 6 September 2026. | OAuth identity assertion and sign-in request metadata when this option is used | |
| GitHub | Sign-In only (OAuth), where offered — not currently enabled in production, so GitHub receives nothing until it is; no analytics, no advertising | OAuth identity assertion (when enabled) |
| Auth0 (Okta) | “Email me a sign-in link” — passwordless sign-in and signup, where offered. Auth0 sends the one-time link and confirms the address; Maskbreak then issues its own session. Behind configuration: it receives nothing unless the option is enabled and used | Email address, authentication transaction, and sign-in request metadata when used |
| Have I Been Pwned | Password breach check via k-anonymity | 5-character SHA-1 prefix only — never the password |
| Network & device intelligence providers | VPN/proxy classification and device-integrity signals for evaluations | Request network metadata; named to customers on request under the DPA (support@maskbreak.com) |
Fonts are self-hosted. Google Ads remains removed. Widgo chat loads on public marketing pages and includes visitor analytics; replay is disabled. Google Sign-In is separate. See the Privacy Policy and Cookie Policy for storage and chat details.
Change log
| Date | Change |
|---|---|
| 2026-09-22 | Widgo chat now loads automatically on public marketing pages instead of behind a per-page consent notice, so the same public visit data reaches Widgo from page load rather than from a click. Nothing changed for sign-in, private account or result pages (no widget), for customer API or evaluation records (never supplied), or for session replay (still disabled). Browsers sending Global Privacy Control get a plain “Chat” button and Widgo loads only when it is pressed. Privacy Policy §4 and §5, Cookie Policy §2.4, the trust page and the security whitepaper were updated in the same change. |
| 2026-09-08 | Replaced new Crisp chat with consent-gated Widgo AI chat on reviewed public marketing pages. Replay is disabled; private/account pages offer email support. Widgo receives consenting visitors’ chat and visit data, not customer API/evaluation records. Historical Crisp support records are preserved. Updated privacy, cookies, DPA Annex C and security disclosures. This optional website service is distinct from processing customer end-user evaluations. |
| 2026-09-06 | Moved abuse-sensitive rate limits and email-send budgets into the existing application database using keyed hashes. The application no longer sends rate-limit keys to Upstash; previously written keys remain subject to their existing short expiry. No new sub-processor was added. Updated the Privacy Policy with the security records and cleanup schedule. |
| 2026-09-06 | Removed Google Ads measurement from public pages, signup, the dashboard, and shared page generators. Google Sign-In remains available. Corrected the current privacy, cookie, and security notices; earlier dated entries below describe historical use, not the current setup. Clarified same-tab chat continuation. No new sub-processor was introduced. |
| 2026-09-04 | Added Crisp (live chat). The chat button on every page loads nothing until it is clicked; from that click Crisp receives what the person types plus their IP address, browser details and current page. It never touches customer API or evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §2.4 and §3 were updated in the same change. |
| 2026-09-02 | Added Auth0 (emailed one-time sign-in link, where offered). The integration shipped on 2026-09-01 behind configuration, like GitHub Sign-In: Auth0 receives the account holder’s email address only when the option is enabled and used, and nothing otherwise. Completeness correction — the code landed before this list was updated. |
| 2026-08-29 | Clarified two rows without adding or removing anyone. GitHub: the sign-in integration exists in the codebase but no GitHub OAuth app is configured in production, so the option is not shown and GitHub receives no data; it stays on the list so that notice has already been given if it is enabled. Google: the row now also names the cookieless Google Ads measurement tag (Consent Mode v2, all storage denied) that public pages and the signed-in dashboard have loaded since 2026-07-19 and that Privacy Policy §5 and Cookie Policy §2.3 already disclose. The Privacy Policy, Cookie Policy, Terms, DPA and security whitepaper were corrected and re-dated in the same change. |
| 2026-08-02 | Added and removed Dreamdata (business-to-business marketing attribution) on the same day. It was live on public marketing pages for approximately 30 minutes. During that window its account-level component sent page URL, page title, canonical URL, referring URL and the requesting IP address to Dreamdata, which uses them to estimate the organisation a visit came from. Its visitor-level component was gated behind analytics consent, which this site does not grant — with one exception we want to be explicit about: the gate is read from Google’s consent framework, so a visitor whose browser blocked Google Tag Manager would have had the visitor-level component, including form tracking, initialise normally. It never ran on the console or on any signed-in page, and it received no customer API or evaluation data at any point. It has been fully removed; no Dreamdata code, endpoint or Content-Security-Policy entry remains. Recorded here for completeness rather than because any obligation attaches to a provider that is no longer used. |
| 2026-07-19 | Added GitHub (Sign-In only, OAuth) — an optional “Sign in with GitHub” for Maskbreak accounts. It touches only the account holder’s own OAuth identity assertion, never customer end-user evaluation data, so the 30-day advance-notice clause for data-processing sub-processors does not apply. Privacy Policy §5 and Cookie Policy §3 were updated in the same change. |
| 2026-07-18 | Added Upstash (rate-limit state) and Amazon Web Services / S3 (encrypted nightly backups). Both were already live infrastructure — this is a completeness correction to the published list, not a new-processor onboarding, so the 30-day advance-notice clause does not apply. Privacy Policy §5 and the security whitepaper were updated in the same change. |
| 2026-07-16 | Page published. List matches the sub-processors already disclosed in the Privacy Policy — no additions or removals. |
Getting notified
Customers who have asked to be notified (email support@maskbreak.com) receive direct notification of sub-processor changes. Everyone else can watch this page or the changelog — any change lands in both at least 30 days before a new data-processing sub-processor goes live.
Questions or objections: support@maskbreak.com.