Sub-processors

Last Updated: June 30, 2026

AI-assisted and operator-reviewed. This disclosure has not been reviewed by a licensed attorney and is not legal advice. It is the maintained sub-processor list, in force.

SUB-PROCESSORS

This page lists the third-party sub-processors VirtMCU (operated by Refract Systems, Inc.) engages to process personal information when providing the Service. We impose data-protection obligations on each sub-processor by contract and disclose changes per our Privacy Policy and DPA. We do not sell personal information and do not share it for cross-context behavioral advertising. To be notified of changes to this list, contact privacy@virtmcu.com.

SIMULATION ENGINE (DATA PLANE — api.virtmcu.com)

The engine runs entirely on Google Cloud Platform. It processes only an opaque API token hash, operational/usage log metadata, edge request metadata (including client IP), and — transiently, to run each simulation — the customer's uploaded firmware/source (Customer Content). It holds no account identity or payment data.

Sub-processorPurposeData categoriesRegion
Google Cloud — GKE + Agones (Google LLC)Per-session compute (engine, QEMU nodes, coordinator, MCP bridge); hosts and executes uploaded firmware transientlyCustomer Content (transient), token hash, session-shape usage metadataus-central1 (US)
Google Cloud — Cloud RunStateless frontdoor and cloud-compile serviceToken hash, compile source (transient), request metadataus-central1 (US)
Google Cloud — L7 Gateway, Cloud Armor, Certificate ManagerTLS termination, WAF/DDoS protection, edge routingRequest metadata incl. client IP address, user-agentUS / Google global edge
Google Cloud — Secret ManagerStorage of the API token-hash set and shared secretsToken hashes, secretsUS
Google Cloud — Cloud LoggingOperational and usage log captureToken hash, request/session metadata, edge logs incl. client IPUS

CONTROL PLANE (IDENTITY & BILLING — virtmcu.com)

The control plane knows who you are and what you paid. It never runs simulations or sees firmware.

Sub-processorPurposeData categoriesRegion
Firebase (Google) — Authentication & Firestore (Google LLC)Account authentication (Google Sign-In / passwordless email); account, subscription, and API-key-hash storageEmail, authentication profile, subscription/tier status, API key hashes, account metadataus-central (US)
Stripe — Managed Payments (merchant of record) (Stripe, Inc.; Stripe Payments Europe, Ltd. where applicable)Subscription payment processing; calculation and remittance of sales tax / VAT / GST as merchant of recordPayment/card data (held by Stripe, not by VirtMCU), billing name and address, email, transaction and tax recordsGlobal (Stripe)

Merchant-of-record note: because Stripe is the merchant of record, Stripe is an independent controller for payment data and issues invoices in its own name; VirtMCU never receives or stores full card details.

INFRASTRUCTURE / PLATFORM NOTE

Google Cloud and Firebase are Google services; both operate under Google's Cloud Data Processing Addendum. Stripe operates under the Stripe Data Processing Agreement / Services Agreement. VirtMCU relies on the EU Standard Contractual Clauses and the UK IDTA for transfers of EEA/UK personal data to the United States, as described in the Privacy Policy and the DPA.