Phronix never collects your card number, CVV, PIN, expiry date, banking credentials, OTPs, or transaction history. Only the name of the card product you own is stored — never any sensitive financial data.
Phronix is a mobile application that helps Sri Lankan consumers identify the best credit or debit card to use at any merchant, based on active bank card offers and promotions.
This Privacy Policy explains what personal data Phronix collects, how it is used, how long it is kept, and what rights you have over it. We are committed to handling your data responsibly and in compliance with the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA). This policy is governed primarily by the Sri Lanka PDPA. Where a user accesses Phronix from within the European Economic Area (EEA), or where the EU General Data Protection Regulation (GDPR) otherwise applies to the processing of their data, Phronix additionally complies with GDPR requirements. The data subject rights described in Section 8 reflect both PDPA and GDPR protections; users in the EEA may rely on the GDPR equivalents of those rights.
Before creating your account you will be presented with a summary of this Privacy Policy and asked to confirm that you have read and accept it. Most processing described in this policy is carried out on the basis of contract performance rather than consent, so there is no ongoing consent obligation for standard features. For any optional processing activity (such as future marketing notification categories), a separate consent prompt will be shown and you may decline without affecting your use of the core service.
If you do not accept this policy, do not proceed with account creation. If you have created an account and wish to withdraw, you may delete your account as described in Section 7.1.
| Term | Meaning |
|---|---|
| Phronix, we, us, our | The Phronix mobile application and its individual developer, Athiththan (operating as Phronix — not a registered company), based in Sri Lanka |
| User, you | Any person who downloads and uses the Phronix app |
| Personal data | Any information that can identify you directly or indirectly |
| Processing | Any operation on personal data (collection, storage, use, deletion) |
| Firebase | Google’s mobile development platform, used for authentication, database, and notifications |
| Card product | The name of a card type (e.g. “HNB Visa Signature Credit Card”) — not the card itself |
We collect only the data necessary to provide the service. The table below is a complete list.
| Category | Data | How it is collected |
|---|---|---|
| Account | Email address | Google Sign-In at registration |
| Account | Display name | Google Sign-In (optional; shown as greeting in app) |
| Account | Firebase User ID | Auto-generated by Firebase on first sign-in |
| Card profile | Card product names you own | You enter these manually in the app |
| Preferences | Saved offers, app theme, notification settings, currency | Your in-app actions and settings |
| Notifications | FCM device token | Auto-generated by Firebase Cloud Messaging |
| Analytics | App events (e.g., offer views, searches, screen navigation); device model, OS version, app version, country/region; a per-installation identifier generated by Firebase (Firebase Instance ID). On Android, the Google Advertising ID may also be collected unless you have disabled it in device settings. | Firebase Analytics SDK (automatic events and custom events) |
We do not collect precise location data in the current version. If location is introduced in a future update, this policy will be updated and you will be asked for explicit permission beforehand.
Google Play Data Safety declaration
In accordance with Google Play Store requirements, Phronix maintains a Data Safety declaration in its Play Store listing. The Data Safety section accurately reflects the practices described in this policy. In the event of any inconsistency between the Data Safety declaration and this policy, this policy takes precedence. The following data types are declared as collected in the Data Safety form: email address, user IDs (Firebase UID), name (display name), app interactions (analytics events), and device or other IDs (Firebase Instance ID, FCM token). All collected data is required to provide the service, except analytics which are optional. Account data can be deleted by the user through the in-app deletion flow described in Section 7.1.
Apple App Store privacy details
In accordance with Apple App Store requirements, Phronix maintains App Privacy details (“privacy nutrition label”) on its App Store product page. Those details accurately reflect the practices described in this policy. In the event of any inconsistency between the App Privacy details and this policy, this policy takes precedence. The declared data categories mirror those listed above: contact info (email address), identifiers (Firebase UID, FCM token, Firebase Instance ID), and usage data (analytics events). None of this data is used for third-party advertising or linked to your identity for advertising purposes. Account data can be deleted by the user through the in-app deletion flow described in Section 7.1.
Phronix is a card offer discovery tool. No current version of the app requests, accepts, or stores any of the following data types. If a future version were to require a new data category not listed in Section 3, this policy will be updated before that feature is released and you will be asked to review and accept the change.
| Data type | Collected? |
|---|---|
| Full card number (PAN) | Never |
| CVV / CVC security code | Never |
| Card PIN | Never |
| Card expiry date | Never |
| Internet banking credentials | Never |
| One-time passwords (OTPs) | Never |
| Transaction history | Never |
| Bank account numbers | Never |
| Biometric data | Never |
| Contacts, SMS, or call logs | Never |
The only card-related data stored is the name of the card product — equivalent to writing “I own a Visa Signature card” in a notebook. No card credentials are involved.
Phronix processes personal data only where a lawful ground exists under Section 5 of the Sri Lanka Personal Data Protection Act No. 9 of 2022. The table below sets out the applicable basis for each processing activity.
| Processing activity | Data involved | Lawful basis |
|---|---|---|
| Creating and maintaining your account; authenticating you on sign-in | Email address, Firebase UID, display name | Performance of the service contract — this processing is necessary to provide the app you have signed up to use (PDPA s.5(1)(b)) |
| Synchronising your card list, saved offers, and preferences across devices | Card product names, saved offers, preferences | Performance of the service contract |
| Delivering push notifications for offers you have saved or followed | FCM device token | Performance of the service contract; you may withdraw by disabling notifications at any time |
| Improving the product through usage analytics | Pseudonymised event data, Firebase Instance ID | Legitimate interests in improving and maintaining the service (PDPA s.5(1)(f)); you may opt out at any time as described in Section 8 |
| Responding to data subject rights requests and legal obligations | Any personal data held | Compliance with legal obligations under the PDPA (PDPA s.5(1)(c)) |
We do not rely on consent as the lawful basis for account creation or core service delivery. Consent will be sought separately, clearly identified and easy to withdraw, only where an optional feature requires it.
Your email and User ID are used to maintain your account and sync your card list, saved offers, and preferences across your devices. Your card product names are used exclusively to power the recommendation engine — identifying which of your cards has the best active offer at a given merchant.
All authentication is handled by Google Sign-In. Phronix does not send emails to you and has no access to your Google account password.
Your FCM device token is used to send push notifications for offer expiry reminders and alerts on offers you have saved. You can disable notifications at any time in your device settings (Settings → Apps → Phronix → Notifications) or in the Phronix Preferences screen.
Firebase Analytics collects usage events and device-level information to help us understand how the app is used and where it can be improved. Firebase assigns a per-installation identifier (Firebase Instance ID) to each device, which persists across sessions. This identifier is not linked to your name, email address, or card data within Phronix systems, but it does enable session-level analysis across app launches.
On Android, Firebase Analytics may also collect the Google Advertising ID (GAID) unless you have reset or disabled it in your device settings under Settings → Privacy → Ads.
This data is processed on Google’s servers and governed by Google’s Privacy Policy. You may opt out of analytics data collection at any time; see Section 8 for instructions.
We do not use analytics data to serve advertisements, build individual profiles, or make decisions that affect you.
Phronix does not sell, rent, trade, or otherwise share your personal data with any third party for commercial purposes, advertising, or profiling.
Note: Firebase services are operated by Google LLC. Google processes Phronix user data as a data processor acting on our instructions under the Firebase Terms of Service and Google’s Data Processing Addendum. Google’s own use of data derived from Firebase services is governed by Google’s Privacy Policy, which is separate from this document and outside Phronix’s control. We have selected Firebase services with data processing terms that are consistent with our privacy commitments.
Phronix does not use your data for any automated decision-making process that produces legal or significant effects on you. The recommendation engine ranks card offers for your convenience; it does not make financial decisions on your behalf.
Phronix uses the following Google Firebase services, all governed by Google’s Privacy Policy.
| Service | Purpose | Data involved |
|---|---|---|
| Firebase Authentication | Account creation and sign-in | Email, UID |
| Cloud Firestore | Cloud sync of card list, saved offers, preferences | Card names, saved offers, UID |
| Firebase Cloud Messaging | Push notifications | FCM device token |
| Firebase Analytics | Usage statistics and product improvement | Firebase Instance ID, device info, event data |
| Google Sign-In | Authentication via Google account | Email, display name |
Your personal data is stored and processed on Google Cloud infrastructure, primarily in the United States. The United States does not have an adequacy determination under the Sri Lanka PDPA. This transfer is made on the basis of appropriate safeguards, specifically the Standard Contractual Clauses incorporated into Google’s Data Processing Addendum, which commits Google to GDPR-equivalent protections for all data transferred under those clauses. Details of Google’s transfer mechanisms are available at https://cloud.google.com/terms/data-processing-addendum.
No third-party advertising, tracking, or analytics SDKs other than the Firebase services listed above are included in the current version of the app. Phronix does not include social media pixels, third-party crash reporters, or advertising networks. If any additional SDK is introduced in a future update, this policy will be updated before release.
| Data | Retained until |
|---|---|
| Account data (email, UID, display name) | Account is deleted |
| Card product selections | Account is deleted |
| Saved offers | Account is deleted, or you remove them |
| FCM token | Account is deleted or token is refreshed by the device |
| Analytics event data | Per Google’s Firebase Analytics retention settings |
You can delete your account from Profile → Delete account in the app, or by emailing us at athiththan.kathir@gmail.com. We will action your request promptly and will remove your account and all directly associated personal data — including email address, display name, Firebase UID, card product list, saved offers, and FCM token — from our active database systems within 30 calendar days. Full step-by-step instructions are on our Account Deletion page.
Encrypted system backups managed by Google Cloud may retain copies of deleted data for a further period before automated rotation removes them. This retention is governed by Google Cloud’s backup practices and the data is inaccessible in production during this period. We have no mechanism to accelerate deletion from Google’s infrastructure-level backups, but those backups are overwritten in the ordinary course of Google’s operations.
After the applicable retention periods, we will hold no copy of your personal data in any system under our control.
Note: deleting your Phronix account does not affect your Google account. Manage your Google data separately at myaccount.google.com.
Accounts with no recorded activity (sign-in, card list update, saved offer interaction) for 24 consecutive months are considered inactive.
Before any inactive account is deleted, we will send:
If you do not sign in within the 30-day notice period, the account and all associated personal data will be deleted. To prevent deletion, simply open the app and sign in before the date stated in the notice. If you no longer have access to your registered email address and miss the notice, contact us at athiththan.kathir@gmail.com before deletion to discuss recovery options.
Under the Sri Lanka PDPA (and GDPR where applicable), you have the following rights.
You may request a full copy of the personal data we hold about you at any time. We will respond within 30 calendar days.
You can update your display name directly from the Profile screen in the app. For corrections to other data, contact us.
You can delete your account and all associated data from Profile → Delete account, or by contacting us. Data is removed from active systems within 30 calendar days as described in Section 7.1.
You may request an export of your data (card list, saved offers, account information) in a structured, machine-readable format (JSON). Contact us to make this request.
You may ask us to restrict the active processing of your personal data in the following circumstances:
During a restriction, we will retain your data but will not actively process it beyond storage, except with your consent or for legal purposes. To request a restriction, contact us at athiththan.kathir@gmail.com.
Where any processing is based on your consent, you have the right to withdraw that consent at any time by using the relevant setting in the app (for example, disabling analytics in the Preferences screen) or by contacting us at athiththan.kathir@gmail.com. Withdrawal of consent does not affect the lawfulness of any processing carried out before withdrawal. Withdrawing consent for an optional feature does not affect your access to the core Phronix service.
If you believe that Phronix is processing your personal data in a manner that does not comply with the Sri Lanka Personal Data Protection Act No. 9 of 2022, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka. Contact details and complaint procedures for the Authority are available through the Sri Lanka government’s official portal. We encourage you to contact us first at athiththan.kathir@gmail.com so that we can address your concern directly, but this does not affect your right to approach the Authority at any time.
For users in the European Economic Area: you also have the right to lodge a complaint with the data protection supervisory authority in your member state.
You may object to processing of your personal data where that processing is based on legitimate interests (see Section 5.0). In practice, this currently applies to Firebase Analytics.
To limit Firebase Analytics data collection on Android:
Deleting the Advertising ID prevents Firebase Analytics from associating events with a consistent advertising identifier. Note that the Firebase Instance ID (a per-installation identifier distinct from the Advertising ID) is still generated by the Firebase SDK itself.
To request full suppression of your analytics data, contact us at athiththan.kathir@gmail.com with the subject line “Analytics opt-out.” We will implement the Firebase Analytics opt-out flag for your installation where technically feasible.
For objections to any other processing activity based on legitimate interests, contact us at athiththan.kathir@gmail.com. We will consider your objection and respond within 30 calendar days.
Submit any request to athiththan.kathir@gmail.com. We will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days. For complex or high-volume requests, we may extend this period by a further 30 days and will notify you of the extension before the initial deadline expires. No fee is charged for reasonable requests.
Security measures: All data transmitted between the Phronix app and Firebase servers is encrypted in transit using TLS. Data stored in Cloud Firestore is encrypted at rest using AES-256 by Google’s infrastructure. Firebase security rules restrict each user’s data to their own authenticated account — no user can access another user’s card list or preferences. Access to the Firebase project console is protected by multi-factor authentication. We do not store card numbers, banking credentials, or other high-sensitivity financial data, which significantly reduces the impact of any breach affecting Phronix data.
Breach detection and response: In the event of a personal data breach, we will:
If you discover or suspect a security vulnerability affecting Phronix, please report it to athiththan.kathir@gmail.com.
Phronix is intended exclusively for users aged 18 and above. Credit and debit card offers — the subject matter of the app — are financial products that require legal capacity to contract, which under Sri Lanka law requires a minimum age of 18.
Age restriction implementation: During account creation, users are presented with the minimum age requirement and must proceed through Google Sign-In, which requires a Google account (Google accounts require users to be at least 13 years old). Phronix does not implement automated age verification beyond this step and relies on the user’s declaration of eligibility. Users found to be under 18 will have their accounts terminated.
Minors discovered after registration: If we become aware — through a report or other means — that a user is under 18, we will suspend and delete their account and all associated personal data as soon as practicable, and in any event within 30 calendar days.
If you believe a minor has created an account, please notify us immediately at athiththan.kathir@gmail.com.
COPPA notice: Phronix is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we discover that we have inadvertently collected data from a child under 13, we will delete it promptly. Phronix is not enrolled in Google Play’s Designed for Families programme.
We may update this Privacy Policy as the app evolves. When we make material changes, we will:
Push notification delivery is best-effort and subject to device settings and connectivity. We will also display a prominent in-app banner on the next app launch after a material change to ensure all active users are informed regardless of notification delivery status.
For changes that introduce new processing activities or materially alter your rights, we will additionally require you to review and accept the updated policy before continuing to use the app. For minor administrative updates (correcting typographical errors, updating contact details, clarifying existing practices without changing their effect), continued use of the app after the notice period constitutes acceptance. You may always delete your account if you do not accept a policy change.