AlterAntiX

Privacy Policy

Version 1.0 · Effective date: to be set at launch

This document is the Privacy Policy specific to the AlterAntiXproduct. Softprox's corporate website (softprox.com) has its own privacy policy, which covers only that website.

1. Who we are

AlterAntiX is a product of SOFTPROX TECNOLOGIA LTDA, Brazilian company registration (CNPJ) 63.643.557/0001-60, headquartered in Goiânia, Goiás, Brazil ("Softprox," "we," "us"). We are the data controller for the personal data described in this Privacy Policy.

This policy is issued under Brazil's Lei Geral de Proteção de Dados(Law No. 13,709/2018 — "LGPD"), Brazil's general data protection law, broadly equivalent to the EU's GDPR. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with its own data protection law, additional rights under that law may also apply to you — contact us (section 9) to exercise them.

Privacy contact: [email protected]

2. What AlterAntiX is, and why the architecture matters for your privacy

AlterAntiX is an anti-detect browser: a desktop application that lets you create and manage multiple browser profiles, each with an independent technical fingerprint and proxy configuration. It is used for legitimate management of multiple digital-marketing accounts, QA testing, market research, and personal privacy.

Most of your usage data never reaches our servers — it stays stored locally, on your own computer, encrypted with your master password. This policy explains exactly what stays local, what does travel to us (and why), and what — even when it does travel — remains unreadable to us because it is end-to-end encrypted (E2EE).

A note on terminology
When this document and the product refer to a "browser fingerprint," we mean a set of simulated technical browser settings (user agent, fonts, WebGL, screen resolution, time zone, etc.) used to differentiate browsing profiles — this is not biometric data about a natural person(such as a fingerprint scan, iris pattern, or facial recognition), which Brazilian law classifies as sensitive personal data. We do not collect or process anyone's biometric data.

3. Data we process

3.1 Account and license data (reaches us)

When you create an account to use AlterAntiX, we collect:

  • Email address;
  • Password (stored hashed, never in plain text) or authentication link, depending on your chosen login method;
  • Unique user identifier;
  • License tier/plan (Free, Pro, Business, etc.) and subscription status;
  • Account creation date and recent access timestamps, for security and support.

Purpose: authenticate your access and unlock the features of your plan.
Legal basis: performance of a contract — this is the minimum data necessary to provide the service you signed up for.
Where it lives: Supabase infrastructure (our authentication/database processor — see section 5).

3.2 Payment and subscription data

Billing for your AlterAntiX license is processed by LemonSqueezy, which acts as the Merchant of Record (MoR) — meaning LemonSqueezy is the official seller of record for your license, collects applicable taxes, and directly processes your payment data (card number, billing address, etc.) under its own privacy policy.

Softprox never receives or stores your full card data. What we receive from LemonSqueezy, via webhook, is the minimum needed to provision your license: the email associated with the purchase, the subscription identifier, the plan purchased, and its status (active/canceled/past due).

Purpose: provision and maintain your license.
Legal basis: performance of a contract and legal/tax obligation, where applicable.

3.3 Data that stays on your device — never reaches Softprox

All operational content of your browsing profiles is stored locally, in a SQLite database on your own computer, encrypted with AES-256 under your master password:

  • Browser profiles (name, settings, simulated technical fingerprint);
  • Cookies and sessions from the sites you visit inside each profile;
  • Proxy credentials (host, port, username, password);
  • Notes and profile/team organization;
  • Application activity log (profile launch/stop history).

Softprox has no access to this content, cannot read it remotely, and holds no copy of it on any server, unless you voluntarily enable Cloud Sync or Cookies Sync (section 3.4).

Important notice about your master password
Your master password is never sent to our servers and cannot be recovered by us. If you lose it and have not enabled Cloud Sync (which also depends on that same password to restore data on another device), your locally stored data becomes permanently inaccessible — including to us. That is the price of real privacy: not even we can bypass it.

3.4 Cloud Sync and Cookies Sync (E2EE, optional features — Pro tier and above)

If you enable these features, AlterAntiX backs up your profiles, proxies, teams, and/or session cookies to Supabase Storage — but encrypted on your own device before upload, using a key derived from your master password (PBKDF2-SHA512 + AES-256-GCM). What reaches Supabase is an encrypted blob; neither Softprox nor Supabase holds the key to read it.

The minimal technical metadata visible for storage purposes (not the content itself): synced object identifier, sync timestamp, and file size.

Opt-in, off by default. Cookies only sync if you choose that mode in the profile settings; new profiles default to a mode that does not upload cookies to the cloud.

Purpose: let you recover your profiles on another device or after reinstalling the app.
Legal basis: consent — you actively opt in to this feature and can disable it at any time in settings.

3.5 Automation API

The local automation API runs exclusively on 127.0.0.1(your own computer's loopback interface). It sends no data to Softprox — it is a fully local feature for controlling your own profiles via scripts.

3.6 Contact and support

If you email us at [email protected], we process the content of your message (and any name/email you provide) to respond to your request.

Legal basis: legitimate interest in providing adequate support, and performance of a contract when the request concerns a service you already purchased.

3.7 Update checks

The app periodically checks our distribution server for new versions, sending the current app version and your operating system/architecture — technical information needed to determine which update package to offer. This request is not used to identify or profile you individually.

3.8 Data we do not currently collect

AlterAntiX currently does not send automatic crash reports or usage telemetry to our servers. If this changes in the future, we will update this policy before enabling the feature, detailing what would be collected, for what purpose, and under what legal basis — and you will be notified of the change.

4. Summary — purpose, legal basis, and retention by category

Email, password (hash), license tier
Purpose
Authentication and plan provisioning
Legal basis
Performance of a contract
Retention
For as long as the account exists; up to 30 days after cancellation, before final deletion
Minimal subscription data from LemonSqueezy (email, subscription ID, status)
Purpose
Provision/maintain the license
Legal basis
Performance of a contract + tax obligation
Retention
For as long as the subscription exists + applicable Brazilian tax retention period
Profiles, cookies, proxies, credentials, fingerprints (local, encrypted SQLite)
Purpose
Product operation on your device
Legal basis
Performance of a contract — but this data NEVER reaches Softprox
Retention
Entirely controlled by you, on your device
Encrypted Cloud Sync / Cookies Sync blobs (Supabase Storage)
Purpose
Cross-device backup/restore
Legal basis
Consent — opt-in feature
Retention
For as long as you keep the feature enabled; up to 30 days after disabling
Support email content
Purpose
Respond to your request
Legal basis
Legitimate interest / performance of a contract
Retention
24 months
Update-check log (app version, OS/architecture)
Purpose
Serve the correct update
Legal basis
Legitimate interest (service operation)
Retention
Standard short-lived server log

5. Who we share data with — processors and sub-processors

We work with vendors who process data on our behalf:

  • Supabase, Inc. — account authentication, license/tier database, and storage of the encrypted Cloud Sync/Cookies Sync blobs.
  • LemonSqueezy — Merchant of Record for the license; an independent controller of your payment data (see section 3.2), under its own privacy policy.

We do not sell, rent, or share your data with third parties for advertising or marketing purposes.

6. International data transfers

Supabase and LemonSqueezy may process and store data outside Brazil (typically in the United States, depending on each vendor's infrastructure). This constitutes an international transfer of personal data, which Brazilian law (LGPD, art. 33) only permits under specific safeguards — in this case, supported by these vendors' contractual clauses and data-protection guarantees.

If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with its own data protection law, additional rights under that law may also apply to you; contact us through the channel in section 9 to exercise them.

7. Security

  • Locally stored data is encrypted with AES-256 under your master password; we do not hold the key.
  • Cloud Sync/Cookies Sync data is end-to-end encrypted (E2EE) before it leaves your device.
  • Account passwords are stored with strong hashing, never in plain text.
  • Internal access to systems hosting account data is restricted to staff who strictly need it.

No system is risk-free. In the event of a security incident affecting personal data, we follow the Brazilian data protection authority's (ANPD) incident procedure: notifying the ANPD and affected data subjects within 3 (three) business days of becoming aware of the incident.

8. Your rights as a data subject

Under Brazilian law (LGPD, art. 18), you may, at any time and free of charge:

  1. Confirm whether we process any of your data;
  2. Access the data we hold about you;
  3. Correct incomplete, inaccurate, or outdated data;
  4. Request anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data;
  5. Request portability of your data to another provider;
  6. Request deletion of data processed based on your consent (e.g., disable Cloud Sync and delete the backups);
  7. Know who we have shared your data with;
  8. Be informed of the possibility of not giving consent and the consequences of that choice;
  9. Withdraw your consent at any time, as easily as it was given.

Important: for data that stays exclusively on your device (section 3.3), you already have full, immediate control — you can edit, export, or delete it directly in the app, without needing to ask us.

Simplified-format requests are answered immediately; a complete response is provided within 15 days.

9. How to reach us

To exercise any of these rights, ask questions, or raise any privacy matter:

[email protected]

The Data Protection Officer (DPO), as required by LGPD art. 41, can be reached at the institutional email above. No individual has been named to the role yet — the institutional channel centralizes and handles every privacy matter.

10. Minors

AlterAntiX is intended for users 18 years of age or older. We do not knowingly collect data from children or teenagers.

11. Changes to this policy

We may update this policy as the product evolves. Material changes will be communicated in the app or by email before they take effect. The date at the top of this document always reflects the version in force.

This policy works together with our Terms of Use — read both documents before using AlterAntiX.