Features

Profiles and fingerprintProxiesHollyProxyTDS.ceo trackerTeam and permissionsLive view and remote controlCookies and auto warm-up2FA vaultAutomation and APIEncryption

Solutions

Affiliate marketingMarketplaces and e-commerceSMM and social mediaAgencies and teamsHelpPartnersPricing Download for macOS Web dashboard

Privacy Policy

Last updated:

What data GetAntik collects, what is encrypted on your device and hidden from us, what the server sees in plain form, who we share data with, and how to exercise your rights.

1. Who we are and what this covers

This policy explains how GetAntik (“we”, “us”) processes personal data when you use the GetAntik app, the web dashboard at account.getantik.com, the server at api.getantik.com and the website getantik.com (together, the “Service”).

GetAntik is the controller of your personal data. For any question about your data, write to [email protected].

If you are a team member, the team Owner and other members can see some data about your work. See section 7.

2. The short version

  • Profile browser data, profile proxy passwords, 2FA keys and profile notes are encrypted on your device with your account password. We store them but cannot read them.
  • We do not sell data, show ads or use advertising or analytics cookies.
  • The server sees what the Service cannot work without: your account, profile names and settings, team membership, the activity log, payments and support tickets.

3. Data we receive

Account and sign-in:

  • your email address and interface language;
  • your password, stored only as an Argon2id hash; we never store the password itself;
  • if you sign in with Google, the email address and internal ID of your Google account (we do not request any other Google account data);
  • if two-factor authentication is on, the TOTP secret (stored on the server) and hashes of your recovery codes;
  • sessions: a hash of the token, the device name, the client type (app or web dashboard), and when the session was created and last used;
  • API keys (Team plan), stored as hashes;
  • a hash of the identifier of each computer you sign in from, with the first and last sign-in time. It enforces the one-free-account-per-computer rule; the identifier itself never reaches us;
  • your referral code and who invited you.

3.1. Profiles: what the server sees in plain form

To sync profiles and show them in lists, the server stores in plain form:

  • profile name, group, tags and status;
  • fingerprint, launch and behavior settings, the list of extensions, the auto warm-up schedule and tracker link settings;
  • the profile proxy’s type, host, port and username (but not its password);
  • service data: owner, team, assignee, who holds the profile open and on which device, the size and version of stored data, and when the profile was created, changed, launched and moved to Trash.

3.2. Profiles: what is encrypted on your device

  • Profile browser data: cookies, open tabs, history, site storage and the rest of the profile folder.
  • The profile’s proxy password, 2FA keys (2FA vault) and notes.
  • Encryption happens on your device before upload (Argon2id to derive a key from your password, XChaCha20-Poly1305 to encrypt). Your account key is protected by your password; profile keys are protected by the account key and, for team profiles, by the team key. The server only stores encrypted data and wrapped keys.
  • If you sign in only with Google and have not set a password, there is no account key yet: until you set one, profile data is uploaded without end-to-end encryption and is protected only by server-side storage encryption, whose key we hold. The same applies to profiles created before encryption was introduced, until the app re-encrypts them.
  • Stored profile data is also encrypted on the server with a server key, as an extra layer.

3.3. Account recovery

When your account key is created, the app also encrypts a copy of it with the public recovery key of our support team. The private half of that key is kept offline and is not on the server, so the server alone cannot decrypt your key.

If you forget your password, support can restore your access with the offline recovery key after verifying that the account is yours: your account key is re-protected with a new password and all sessions end. We use this only at your request.

Profiles protected by their own profile password cannot be recovered this way: their key is stored neither on the server nor with support.

3.4. Teams

  • The team name, members, their roles, permissions and limits, and invites (the invitee’s email).
  • The team activity log: who opened, closed or transferred profiles, changed permissions, started live view, bought proxies and so on, when, and from which device.
  • Team profile templates.
  • The team’s shared proxy list: hosts and usernames are stored in plain form, passwords are encrypted with a server key so that team members can use them.
  • The team’s HollyProxy key, if an Admin connected one. It is encrypted with a server key, because the server makes requests to HollyProxy on the team’s behalf. HollyProxy spending per member appears in the team’s spending view.

3.5. Live view

During live view, screen frames are encrypted on the member’s device with a key only the viewer can open, and pass through the server in transit. The server cannot read them and does not store them. The fact of viewing (who watched whose profile and when) is recorded in the team activity log.

3.6. Payments

  • Your balance, transaction history (top-ups, plan, profile and seat purchases, promo codes, referral rewards), top-up invoices and their status.
  • When you top up, we send the payment provider (Stripe for cards, PayPage for cryptocurrency) the amount, your account email, the invoice reference and your language. The provider processes card, wallet and transaction data and tells us the payment status. We never receive or store card numbers.

3.7. Support and email

  • The text of your support tickets and the conversation about them. Support staff see tickets and a short account card (plan, team, last activity).
  • Records of the emails we send you (codes, receipts, warnings, invites, support replies) and their delivery.

3.8. Technical data

  • IP address. It is used to protect against password and code guessing (counters are kept briefly in server memory) and may appear in server logs. The Service runs behind Cloudflare, which also processes IP addresses and technical request data.
  • When checking for updates, the app sends its version, platform, architecture, update channel and language.
  • Search queries in the website’s help center are sent to our server to find matching articles.
  • We do not embed third-party analytics or advertising trackers in the app, the website or the web dashboard.

3.9. What stays on your computer

The app keeps the following in its data folder on your computer: profiles and their browser data, settings, and your personal HollyProxy and TDS.ceo API keys. Personal integration keys are never sent to our server.

4. Why we use data

  • To provide the Service: sign-in, profile sync, teams, live view and support. This is necessary to perform our contract with you (the Terms of Use).
  • To keep the Service secure and prevent abuse: protection against password guessing, the one-free-account rule, investigating violations. This is our legitimate interest.
  • To accept payments and keep records of transactions, to perform the contract and meet legal requirements.
  • To send service emails: codes, receipts, payment warnings, invites and support replies. We do not send marketing emails without your consent.
  • To fix bugs and improve the Service based on technical data. This is our legitimate interest.
  • To comply with the law and lawful requests from authorities.

5. Who we share data with

We do not sell or rent out personal data. We share it only with those who help run the Service, and only as much as they need:

  • Cloudflare: content delivery and attack protection; requests to the website, web dashboard and server pass through it.
  • Mailgun: sending email.
  • Stripe: accepting card payments.
  • PayPage: accepting cryptocurrency payments.
  • Google: if you sign in with Google.
  • HollyProxy: if an Admin connected a HollyProxy key to your team, the server sends requests to HollyProxy on the team’s behalf.
  • Hosting providers whose servers run the Service.
  • Authorities, where the law requires it (see the Acceptable Use Policy).
  • A successor, in case of reorganization, sale or transfer of the Service; this policy will keep applying to your data.

6. International transfers

Our providers may process data in different countries. We choose providers that protect data adequately and share with them only what they need to do their job.

7. If you are a team member

A team is controlled by its Owner. The Owner and members with the relevant permissions see the activity log, including your actions with profiles and your device names. The Owner, and anyone the Owner gives the permission, can start live view and two-way remote control of a profile you have open. You will see a notice, and the viewing is recorded in the log.

Team profile data belongs to the team. For questions about how a team uses your data, contact its Owner.

8. How long we keep data

Account data is kept while the account exists. Deleted profiles stay in Trash for 30 days. Unpaid invoices expire after one hour, and a record remains in your history. Server logs are kept for a limited time needed for security and troubleshooting. See Account, Team and Data Deletion for details.

9. Security

  • End-to-end encryption of profile data on your device, plus storage encryption on the server.
  • Passwords, recovery codes, session tokens and API keys are stored only as hashes.
  • Protection against password and code guessing, two-factor authentication, and signing out other sessions.
  • No system is perfectly secure. If we learn of a breach affecting your data, we will notify you and act as the law requires.

10. Your rights

Depending on the laws of your country, you may: find out what data we hold about you and get a copy; correct inaccurate data; delete your account and data; restrict or object to processing; withdraw consent where processing is based on consent; and complain to a data protection authority.

You can change some data yourself in the app and the web dashboard. For anything else, write to [email protected] from your account email. We may ask you to confirm the account is yours, and we will reply within 30 days.

Please note: we cannot read data encrypted on your device, so we cannot provide it in decrypted form. It is available to you in the app.

11. Age restriction

The Service is for people aged 18 and over. We do not knowingly collect data from minors. If you learn that a minor has created an account, tell us and we will delete it.

12. Cookies

We do not use advertising or analytics cookies. What the website and web dashboard store in your browser is described in the Cookie Policy.

13. Changes to this policy

We update this policy when the Service or the law changes. The new version is published on this page with a new date. We notify you of material changes in advance by email or in the Service.

14. Contact

Operator: GetAntik

Email: [email protected]