Obrix

Privacy Policy

Last updated: October 7, 2026

This Policy explains how Obrix, a service of CodexaFlow (Vinicius Alves Velasco LTDA), CNPJ 65.845.312/0001-41, handles personal data on https://useobrix.app, on the dashboard at https://my.useobrix.app and in the iPhone and Android apps. In short: we collect only what Obrix needs to work, we do not sell data and we do not use advertising tracking.

1. Who is responsible for the data

CodexaFlow is the controller of your account data (name, email, sign-in) and of your company's registration data in Obrix.

The data you enter about your own clients (names, contacts, addresses and IDs used in quotes, projects and charges) belongs to your company. For that data your company is the controller and CodexaFlow acts as a processor, handling it only to provide the service, under your instructions and this Policy.

Data protection officer (DPO): [email protected].

2. Data we process

  • Account: name, email, password (stored only as a cryptographic hash, never in plain text), preferred language and email verification status.
  • Company: name, tax ID, phone, email, address, logo, color and quote preferences; team members and invitations (email and role).
  • Data you enter about your clients: name, email, phone, tax ID, address, city/state and notes; quotes, items, amounts, projects, stages, tasks and charges.
  • Public quote page: when your client opens the link we record the view date; when they approve or decline, we record the name they type, an optional note, date/time and IP address as evidence of acceptance.
  • Obrix subscription: payment is handled by Stripe (card or boleto). Obrix never receives or stores full card details; we keep only Stripe customer and subscription IDs, plan, status and dates.
  • Charges via Asaas (optional): if your company connects its own Asaas account, we store its API key encrypted (AES-256-GCM) and send Asaas the client and charge details needed to issue Pix or boletos.
  • Technical data: IP address and browser/device identification for sign-in sessions, essential cookies and server access and error logs.
  • Usage statistics (only with your consent): on the marketing site, legal pages, sign-in/sign-up screens and web dashboard (not in the apps or on the public quote page), Google Analytics collects aggregated browsing data such as pages visited, traffic source, device type and approximate region, plus usage events without personal data (such as sign-up completed, plan selected, subscription started and confirmed, and contact message sent).
  • Contact form: name, email, phone (optional) and the message you send, used only to reply to you.

We do not collect location, address book contacts, camera, microphone, health data or advertising identifiers.

3. iPhone and Android apps

  • Photos: the app accesses your photo library only when you pick a company logo; only the chosen image is uploaded.
  • Biometrics (Face ID, Touch ID or fingerprint): when you turn on biometric sign-in, verification happens entirely on your device's operating system. Obrix never receives, sees or stores biometric data; the device only unlocks the session kept in secure storage (Keychain/Keystore). Your password is not stored on the device.
  • Sharing: when you send a quote or charge through WhatsApp or the system share sheet, you are the one sending it, through the app you choose.
  • The apps contain no third-party advertising, cross-app tracking or analytics SDKs.

4. Why we use data and legal bases

  • Providing the service (account, building and sending quotes, recording approvals, tracking projects and charges): performance of a contract (LGPD art. 7, V; GDPR art. 6(1)(b)).
  • Service emails (email verification, password reset, invitations, quotes you send to your clients): performance of a contract.
  • Billing the subscription and meeting tax and regulatory obligations: contract and legal obligation (LGPD art. 7, II and V; GDPR art. 6(1)(b) and (c)).
  • Security, fraud and abuse prevention, support and product improvement using aggregated data: legitimate interests (LGPD art. 7, IX; GDPR art. 6(1)(f)).
  • Usage statistics with analytics cookies (Google Analytics): consent (LGPD art. 7, I; GDPR art. 6(1)(a)), which you can withdraw at any time under "Cookie preferences".
  • Keeping access logs for the period required by Brazil's Internet Civil Framework (Law 12,965/2014, art. 15): legal obligation.

We do not use data for targeted advertising, we do not sell data and we do not make automated decisions with legal effects on you.

5. Who we share data with

We use service providers (sub-processors) that process data only to deliver the service to Obrix, under contract and with security safeguards:

  • Neon: PostgreSQL database (servers in the United States).
  • Cloudflare: network, attack protection and site delivery (global network).
  • Cloud server (VPS) provider where the application runs.
  • Resend: transactional email delivery (United States).
  • Google (Google Analytics): usage statistics for the website and web dashboard, only with your consent (United States).
  • Stripe: Obrix subscription payments.
  • Asaas: Pix and boleto charges, only if your company connects its own account.
  • Apple and Google: app distribution and, if you enable it, on-device biometrics (processed locally).

We may also share data when required by law or a competent authority, to protect rights, in a merger or acquisition (with prior notice), or with your consent.

6. International transfers

Some providers are located outside Brazil, mainly in the United States. For these transfers we rely on the safeguards provided by the LGPD (art. 33) and the GDPR, such as standard contractual clauses and the providers' security commitments.

7. How long we keep data

  • Account, company and content data: while the account exists. When you delete the account, we erase it from the production database immediately.
  • Database backups: automatically overwritten within 30 days.
  • Access logs: 6 months (Brazilian Internet Civil Framework).
  • Subscription invoices and payment records: for the period required by tax law (generally up to 5 years), kept at Stripe.

8. Your rights

Under the LGPD (art. 18) you may: confirm whether we process your data; access it; correct incomplete or outdated data; request anonymization, blocking or deletion of unnecessary data; portability; learn who we share it with; withdraw consent; and object to processing based on legitimate interests.

If you are in the European Economic Area or the United Kingdom, you have the equivalent GDPR rights (access, rectification, erasure, restriction, portability and objection) and may complain to your local data protection authority.

California residents (CCPA/CPRA): you may know what data we collect and request deletion and correction, with no discrimination for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising.

To exercise any right, write to [email protected] from your account email. We reply within 15 days. You may also complain to Brazil's National Data Protection Authority (ANPD).

If you are a client of a business that uses Obrix (for example, you received a quote), please contact that business first, as it controls your data; we will help it handle your request.

9. How to delete your account

  • In the app: More › Delete account.
  • On the web dashboard: Settings › Your account › Delete account.
  • By email: write to [email protected] from your account email.

If you are the only owner of a company, it is deleted too, including clients, quotes, projects, charges, catalog, logo, Asaas connection and subscription (cancelled immediately). If the company has another owner, you just leave it. More details at https://useobrix.app/excluir-conta.

10. Security

We use encrypted connections (HTTPS/TLS), hashed passwords, encrypted integration keys, digitally signed public quote links and per-company data isolation. No system is 100% secure; if a relevant incident occurs we will notify you and the authorities as required by law.

11. Cookies

Essential cookies: the session cookie (to keep you signed in) and the language cookie. In the apps and on the public quote page we use only these.

Analytics cookies (optional): on the public website, sign-in/sign-up screens and web dashboard we use Google Analytics 4, which sets its own cookies (such as _ga) to produce usage statistics: how many people visit, which pages, where they come from and which steps they complete (sign-up, plan selection, subscription). It only loads after you click "Accept" on the cookie notice (Google Consent Mode v2); if you decline or make no choice, nothing is sent to Google. Google signals and ad personalization are always off, Google Analytics 4 does not store IP addresses, we strip parameters such as email and tokens from URLs and we never send your name, email or phone. Legal basis: consent.

When an Obrix subscription is paid, our server may report the purchase (plan, amount, currency and invoice number) to Google Analytics through the Measurement Protocol, linked only to the anonymous _ga cookie identifier, and only if you had accepted analytics cookies when subscribing.

You can change your choice at any time through the "Cookie preferences" link in the footer of the website, sign-in screens and dashboard; when you decline, we delete the _ga cookies. You can also block or delete cookies in your browser settings or install the Google Analytics opt-out browser add-on (https://tools.google.com/dlpage/gaoptout). We do not use advertising cookies.

12. Children

Obrix is a professional tool intended for people aged 18 or over. We do not knowingly collect data from children or teenagers.

13. Changes to this Policy

We may update this Policy. Material changes will be announced by email or in Obrix before they take effect. The date at the top shows the current version.

14. Contact

CodexaFlow (Vinicius Alves Velasco LTDA), CNPJ 65.845.312/0001-41, Cuiabá – MT, Brazil. Privacy and DPO: [email protected]. Support: [email protected].

Data controller: CodexaFlow (Vinicius Alves Velasco LTDA), CNPJ 65.845.312/0001-41, Cuiabá – MT, Brazil.