Last Updated: June 30, 2026
This page lists the third-party sub-processors VirtMCU (operated by Refract Systems, Inc.) engages to process personal information when providing the Service. We impose data-protection obligations on each sub-processor by contract and disclose changes per our Privacy Policy and DPA. We do not sell personal information and do not share it for cross-context behavioral advertising. To be notified of changes to this list, contact privacy@virtmcu.com.
The engine runs entirely on Google Cloud Platform. It processes only an opaque API token hash, operational/usage log metadata, edge request metadata (including client IP), and — transiently, to run each simulation — the customer's uploaded firmware/source (Customer Content). It holds no account identity or payment data.
| Sub-processor | Purpose | Data categories | Region |
|---|---|---|---|
| Google Cloud — GKE + Agones (Google LLC) | Per-session compute (engine, QEMU nodes, coordinator, MCP bridge); hosts and executes uploaded firmware transiently | Customer Content (transient), token hash, session-shape usage metadata | us-central1 (US) |
| Google Cloud — Cloud Run | Stateless frontdoor and cloud-compile service | Token hash, compile source (transient), request metadata | us-central1 (US) |
| Google Cloud — L7 Gateway, Cloud Armor, Certificate Manager | TLS termination, WAF/DDoS protection, edge routing | Request metadata incl. client IP address, user-agent | US / Google global edge |
| Google Cloud — Secret Manager | Storage of the API token-hash set and shared secrets | Token hashes, secrets | US |
| Google Cloud — Cloud Logging | Operational and usage log capture | Token hash, request/session metadata, edge logs incl. client IP | US |
The control plane knows who you are and what you paid. It never runs simulations or sees firmware.
| Sub-processor | Purpose | Data categories | Region |
|---|---|---|---|
| Firebase (Google) — Authentication & Firestore (Google LLC) | Account authentication (Google Sign-In / passwordless email); account, subscription, and API-key-hash storage | Email, authentication profile, subscription/tier status, API key hashes, account metadata | us-central (US) |
| Stripe — Managed Payments (merchant of record) (Stripe, Inc.; Stripe Payments Europe, Ltd. where applicable) | Subscription payment processing; calculation and remittance of sales tax / VAT / GST as merchant of record | Payment/card data (held by Stripe, not by VirtMCU), billing name and address, email, transaction and tax records | Global (Stripe) |
Merchant-of-record note: because Stripe is the merchant of record, Stripe is an independent controller for payment data and issues invoices in its own name; VirtMCU never receives or stores full card details.
Google Cloud and Firebase are Google services; both operate under Google's Cloud Data Processing Addendum. Stripe operates under the Stripe Data Processing Agreement / Services Agreement. VirtMCU relies on the EU Standard Contractual Clauses and the UK IDTA for transfers of EEA/UK personal data to the United States, as described in the Privacy Policy and the DPA.