Legal
Effective October 2026
Sparrow Technology Ltd uses the third parties below to run Decloak. Each processes only the data needed for its function, under a contract that requires appropriate data protection. This list forms part of our Data Processing Addendum and is described in our Privacy Policy.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase | Authentication and database hosting | Account email, passkey data, scans, findings, team and settings data | Ireland (AWS eu-west-1) |
| Render | Application, worker and queue hosting | All service data in transit and in the job queue | United States (Oregon) |
| Stripe | Subscription billing and payments | Email, billing details, plan | United States / EEA (Stripe) |
| Browserless | Headless browser rendering of scanned pages and PDF generation | URL being scanned, page content, report HTML for PDFs | United States |
| Groq | AI models for report summaries, agent reasoning, and remediation text | Scan findings and evidence snippets (no credentials or billing data) | United States |
| Modal | Isolated sandboxes for AI Pentesting (Enterprise, opt-in per scan) | Target URL and finding details for the scan being confirmed | United States |
| DigitalOcean | Hosts our out-of-band canary server used to confirm SSRF/XXE during AI Pentesting | Callback requests from the target to a unique canary hostname | United Kingdom (London) |
| SendGrid (Twilio) | Transactional and onboarding email delivery | Email address, name, report links | United States |
| Slack | Internal operational alerts (sign-ups, scans, billing events, errors) | Name and email of the user, scanned URL, plan | United States / EEA |
| Google (Analytics, Search Console) | Aggregate site analytics (only after cookie consent) and our own search performance reporting | Usage data via cookies; no scan data | United States / EEA |
| Advertising measurement (only after cookie consent) | Browser pixel data; server-side sign-up and purchase events (no email) | United States | |
| X Corp. | Advertising measurement (only after cookie consent) | Browser pixel data; server-side purchase event with a SHA-256 hashed email and X click ID | United States |
| Endorsely | Referral and affiliate attribution | Referral identifier, purchase attribution | United States |
We query public sources that receive no personal data: the National Vulnerability Database (CVE lookups by software version) and public Certificate Transparency logs via crt.sh (subdomain discovery, using only the scanned domain).
We update this page when we add or replace a subprocessor and change the effective date above. Customers with an account can ask to be emailed about changes by writing to support@decloak.dev, and may object to a new subprocessor on reasonable data protection grounds as set out in the Data Processing Addendum.