Skip to policy content
Privacy notice

Privacy Policy

Last updated: August 23, 2026 · Version 2.0

A factual privacy policy based on an audit of the services currently implemented by aMathyzin.

The Portuguese version prevails for legal purposes in Brazil.

Exercise your privacy rights

Send a verified request to our privacy channel. You can also update account data, end sessions, unlink Discord, and manage browser notifications in the product.

Section 1

Controller and scope of this Policy

Who determines processing and which services are covered.

aMathyzin is the controller of personal data processed in operating the website and its services. For privacy questions or requests, email contato@amathyzin.com.br with the subject “Privacy”.

This Policy covers the website, user accounts, public profiles, downloads, blog, purchases, advertiser portal, sign-in integrations, notifications, and aMathyzin Premium Tweak (APT) execution. It does not replace the policies of third-party services.

Section 2

Account, profile, and authentication data

Data needed to create, protect, and personalize your account.

When you register, we process your username, email address, password stored as a hash, optional brand name, creation date, and verification status. We also process session data, user agent, and sign-in history to protect access.

In your profile, you may provide a bio, avatar, social links and, when enabled, optional public-profile data such as location, pronouns, date of birth, language, skills, certifications, and links. Information marked public may be displayed to profile visitors.

Section 3

Google and Discord sign-in

Data received when you choose social authentication.

For Google, the requested scopes are openid, email and profile; we receive the account identifier, email, name and profile picture to create or link your account.

For Discord, the requested scopes are identify and email; we receive an identifier, username, email and avatar. If you link Discord and are eligible, the identifier may also be used to grant a Premium role or send a configured server message.

Section 4

Purchases, payments, and advertiser portal

Data needed to charge, deliver digital products, and run campaigns.

For digital-product purchases, we process your name, email, product, amount, order status, transaction IDs, PIX QR Code, and delivery token. The system is not designed to store a full card number; the transaction is processed by payment providers.

In the advertiser portal, we process account data, brand, campaign, destination URL, creatives, logo, brief, price, status, credits, and operational billing data. This is needed to contract, review, and deliver the campaign.

Section 6

Advertising, impressions, and clicks

Aggregated measurement of first-party ads and third-party scripts when enabled.

Third-party advertising and measurement scripts load in accordance with privacy settings and user consent.

For first-party ads, we record an IP hash, approximate country, referrer, ad, event type, and date/time. The purpose is delivery measurement, fraud detection, and aggregate advertiser reporting — we do not provide direct visitor identification to advertisers.

The site contains code that can load Google AdSense, PropellerAds, Monetag, and Admandala based on the active page configuration. These vendors may process identifiers and browsing data under their own policies.

Section 7

APT, license, and remote execution

Data used to protect access to aMathyzin Premium Tweak.

To provide APT, we process the application username, password hash, hardware identifiers (HWID, when used), last sign-in date, and execution tokens. This data is used to validate license, security, and access to the purchased product.

The execution link is individual, expires after 15 minutes, and is invalidated after one use. Execution updates the account-use record. The application does not collect, access, or transfer personal files or computer content.

Section 8

Cookies, local storage, and notifications

Session technologies and browser-controlled preferences.

We use a session refresh cookie and temporary OAuth state cookies for authentication and request-forgery protection. The browser may also store an access token, local session marker, post-login return, temporary checkout state, and local preferences.

If you allow notifications, we process the push subscription, its public keys, and user agent to send alerts. You may revoke permission in browser settings and unsubscribe.

Technologies identified in the code
TechnologyPurposeObserved duration
user_refreshRefresh an authenticated sessionAccording to server-side token expiry
dc_state / g_statePrevent OAuth CSRF10 minutes
dc_locale / g_localeKeep language during OAuth callback10 minutes
Local/session storageSession, checkout, preferences and login returnUntil app or browser cleanup; varies by key
Section 9

Purposes and legal bases

The legal rationale supporting each processing category.

For advertising, metrics, and international transfers, we apply data minimization, transparency, and safeguards appropriate to the activity.

We process personal data only when there is a legitimate purpose and an applicable legal basis. The table below is a reference matrix for activities found in the audit.

Proposed legal-basis matrix
ProcessingPurposeLegal basis
Account, sign-in, and deliveryProvide the requested serviceContract performance and preliminary procedures
Purchase, billing, and receiptsProcess the order and meet applicable dutiesContract performance; legal/regulatory obligation when applicable
Logs, fraud prevention, and securityProtect users, systems, and rightsLegitimate interests and establishment/exercise of rights
Aggregated metricsMeasure usage and ad deliveryLegitimate interests, subject to minimization and balancing assessment
Push and optional technologiesSend alerts or enable non-essential advertisingConsent, where applicable
Section 10

Sharing and subprocessors

Partners that may receive data to perform specific services.

We share only the minimum necessary for the disclosed purpose. We do not sell personal data and do not authorize advertisers to directly identify visitors through campaign metrics.

Third parties identified in the audit
ServicePurposePartner policy
Mercado PagoPIX and implemented digital-product paymentsView
StripeInternational card checkoutView
AsaasAdvertiser-portal PIX billingView
ResendTransactional emailsView
Google and DiscordSocial sign-in; Google Ads when enabled; Discord integrationOwn policies
Cloudflare TurnstileAnti-automation verification in formsOwn policy
Section 11

International transfers

When partners may process data outside Brazil.

Some partners may process data outside Brazil according to their infrastructure, including Stripe, Google, Discord, Resend, Cloudflare, and advertising networks. The specific location may vary by service and configuration.

When an international transfer occurs, aMathyzin will seek to adopt the applicable legal mechanism under LGPD Article 33, with compatible security, transparency, and documentation measures.

Section 12

Retention and deletion

How long we keep data and when it may be erased.

We keep data only as long as needed for the purposes in this Policy, legal or regulatory obligations, fraud prevention, and the establishment or exercise of rights. Deleting an account does not erase data that must be retained for those reasons.

APT tokens expire after 15 minutes and are single-use; OAuth state cookies expire after 10 minutes; OTP codes expire after 1 hour; and sign-in history is limited to the latest 20 records. Transaction and connection records are retained according to statutory retention periods.

Section 13

Security and incidents

Observed technical safeguards and response to relevant events.

The platform uses HTTPS, password hashes, expiring tokens, Secure/HttpOnly/SameSite refresh cookies, CAPTCHA, request rate limiting, additional administrative authentication, access control, and security logging.

No system is completely invulnerable. If a security incident presents relevant risk or harm, aMathyzin will assess the event and take applicable communications and measures, including to the ANPD and data subjects where required by law.

Section 14

Data-subject rights and how to exercise them

Practical channels to control your data under the LGPD.

You may request confirmation of processing, access, correction, anonymization, blocking or deletion where applicable, portability, information about sharing, withdrawal of consent, and review of automated decisions, where they exist.

To exercise your rights, email contato@amathyzin.com.br with the subject “Privacy — [request type]”, preferably from the account email address. We may request proportionate information to verify your identity and protect your account.

Within the product, you may also edit profile data, change your password, unlink Discord, end sessions, and revoke browser notifications. If the response is not satisfactory, you may complain to the ANPD, without prejudice to other legal remedies.

Section 15

Children, teenagers, and policy changes

Heightened protection and transparency about changes to this Policy.

The platform is intended for users aged 13 and older and is not directed at children. If you are a parent or legal guardian and identify improper processing of a minor’s data, please contact us through our privacy channel.

We may update this Policy to reflect changes in the product, partners, or law. Material changes will be published with a new date and version; when needed, we will also use available communication channels.

aMathyzin
Sign In