Phronix never collects your card number, CVV, PIN, expiry date, banking credentials, OTPs, or transaction history. Only the name of the card product you own is stored — never any sensitive financial data.

1. Introduction

Phronix is a mobile application that helps Sri Lankan consumers identify the best credit or debit card to use at any merchant, based on active bank card offers and promotions.

This Privacy Policy explains what personal data Phronix collects, how it is used, how long it is kept, and what rights you have over it. We are committed to handling your data responsibly and in compliance with the Sri Lanka Personal Data Protection Act No. 9 of 2022 (PDPA). This policy is governed primarily by the Sri Lanka PDPA. Where a user accesses Phronix from within the European Economic Area (EEA), or where the EU General Data Protection Regulation (GDPR) otherwise applies to the processing of their data, Phronix additionally complies with GDPR requirements. The data subject rights described in Section 8 reflect both PDPA and GDPR protections; users in the EEA may rely on the GDPR equivalents of those rights.

Before creating your account you will be presented with a summary of this Privacy Policy and asked to confirm that you have read and accept it. Most processing described in this policy is carried out on the basis of contract performance rather than consent, so there is no ongoing consent obligation for standard features. For any optional processing activity (such as future marketing notification categories), a separate consent prompt will be shown and you may decline without affecting your use of the core service.

If you do not accept this policy, do not proceed with account creation. If you have created an account and wish to withdraw, you may delete your account as described in Section 7.1.


2. Definitions

Term Meaning
Phronix, we, us, our The Phronix mobile application and its individual developer, Athiththan (operating as Phronix — not a registered company), based in Sri Lanka
User, you Any person who downloads and uses the Phronix app
Personal data Any information that can identify you directly or indirectly
Processing Any operation on personal data (collection, storage, use, deletion)
Firebase Google’s mobile development platform, used for authentication, database, and notifications
Card product The name of a card type (e.g. “HNB Visa Signature Credit Card”) — not the card itself

3. Data We Collect

We collect only the data necessary to provide the service. The table below is a complete list.

Category Data How it is collected
Account Email address Google Sign-In at registration
Account Display name Google Sign-In (optional; shown as greeting in app)
Account Firebase User ID Auto-generated by Firebase on first sign-in
Card profile Card product names you own You enter these manually in the app
Preferences Saved offers, app theme, notification settings, currency Your in-app actions and settings
Notifications FCM device token Auto-generated by Firebase Cloud Messaging
Analytics App events (e.g., offer views, searches, screen navigation); device model, OS version, app version, country/region; a per-installation identifier generated by Firebase (Firebase Instance ID). On Android, the Google Advertising ID may also be collected unless you have disabled it in device settings. Firebase Analytics SDK (automatic events and custom events)

We do not collect precise location data in the current version. If location is introduced in a future update, this policy will be updated and you will be asked for explicit permission beforehand.

Google Play Data Safety declaration

In accordance with Google Play Store requirements, Phronix maintains a Data Safety declaration in its Play Store listing. The Data Safety section accurately reflects the practices described in this policy. In the event of any inconsistency between the Data Safety declaration and this policy, this policy takes precedence. The following data types are declared as collected in the Data Safety form: email address, user IDs (Firebase UID), name (display name), app interactions (analytics events), and device or other IDs (Firebase Instance ID, FCM token). All collected data is required to provide the service, except analytics which are optional. Account data can be deleted by the user through the in-app deletion flow described in Section 7.1.

Apple App Store privacy details

In accordance with Apple App Store requirements, Phronix maintains App Privacy details (“privacy nutrition label”) on its App Store product page. Those details accurately reflect the practices described in this policy. In the event of any inconsistency between the App Privacy details and this policy, this policy takes precedence. The declared data categories mirror those listed above: contact info (email address), identifiers (Firebase UID, FCM token, Firebase Instance ID), and usage data (analytics events). None of this data is used for third-party advertising or linked to your identity for advertising purposes. Account data can be deleted by the user through the in-app deletion flow described in Section 7.1.


4. Data We Never Collect

Phronix is a card offer discovery tool. No current version of the app requests, accepts, or stores any of the following data types. If a future version were to require a new data category not listed in Section 3, this policy will be updated before that feature is released and you will be asked to review and accept the change.

Data type Collected?
Full card number (PAN) Never
CVV / CVC security code Never
Card PIN Never
Card expiry date Never
Internet banking credentials Never
One-time passwords (OTPs) Never
Transaction history Never
Bank account numbers Never
Biometric data Never
Contacts, SMS, or call logs Never

The only card-related data stored is the name of the card product — equivalent to writing “I own a Visa Signature card” in a notebook. No card credentials are involved.


5. How We Use Your Data

5.0 Lawful basis for processing

Phronix processes personal data only where a lawful ground exists under Section 5 of the Sri Lanka Personal Data Protection Act No. 9 of 2022. The table below sets out the applicable basis for each processing activity.

Processing activity Data involved Lawful basis
Creating and maintaining your account; authenticating you on sign-in Email address, Firebase UID, display name Performance of the service contract — this processing is necessary to provide the app you have signed up to use (PDPA s.5(1)(b))
Synchronising your card list, saved offers, and preferences across devices Card product names, saved offers, preferences Performance of the service contract
Delivering push notifications for offers you have saved or followed FCM device token Performance of the service contract; you may withdraw by disabling notifications at any time
Improving the product through usage analytics Pseudonymised event data, Firebase Instance ID Legitimate interests in improving and maintaining the service (PDPA s.5(1)(f)); you may opt out at any time as described in Section 8
Responding to data subject rights requests and legal obligations Any personal data held Compliance with legal obligations under the PDPA (PDPA s.5(1)(c))

We do not rely on consent as the lawful basis for account creation or core service delivery. Consent will be sought separately, clearly identified and easy to withdraw, only where an optional feature requires it.

5.1 Providing the service

Your email and User ID are used to maintain your account and sync your card list, saved offers, and preferences across your devices. Your card product names are used exclusively to power the recommendation engine — identifying which of your cards has the best active offer at a given merchant.

All authentication is handled by Google Sign-In. Phronix does not send emails to you and has no access to your Google account password.

5.2 Notifications

Your FCM device token is used to send push notifications for offer expiry reminders and alerts on offers you have saved. You can disable notifications at any time in your device settings (Settings → Apps → Phronix → Notifications) or in the Phronix Preferences screen.

5.3 Product improvement

Firebase Analytics collects usage events and device-level information to help us understand how the app is used and where it can be improved. Firebase assigns a per-installation identifier (Firebase Instance ID) to each device, which persists across sessions. This identifier is not linked to your name, email address, or card data within Phronix systems, but it does enable session-level analysis across app launches.

On Android, Firebase Analytics may also collect the Google Advertising ID (GAID) unless you have reset or disabled it in your device settings under Settings → Privacy → Ads.

This data is processed on Google’s servers and governed by Google’s Privacy Policy. You may opt out of analytics data collection at any time; see Section 8 for instructions.

We do not use analytics data to serve advertisements, build individual profiles, or make decisions that affect you.

5.4 No data selling

Phronix does not sell, rent, trade, or otherwise share your personal data with any third party for commercial purposes, advertising, or profiling.

Note: Firebase services are operated by Google LLC. Google processes Phronix user data as a data processor acting on our instructions under the Firebase Terms of Service and Google’s Data Processing Addendum. Google’s own use of data derived from Firebase services is governed by Google’s Privacy Policy, which is separate from this document and outside Phronix’s control. We have selected Firebase services with data processing terms that are consistent with our privacy commitments.

5.5 No automated decision-making

Phronix does not use your data for any automated decision-making process that produces legal or significant effects on you. The recommendation engine ranks card offers for your convenience; it does not make financial decisions on your behalf.


6. Third-Party Services

Phronix uses the following Google Firebase services, all governed by Google’s Privacy Policy.

Service Purpose Data involved
Firebase Authentication Account creation and sign-in Email, UID
Cloud Firestore Cloud sync of card list, saved offers, preferences Card names, saved offers, UID
Firebase Cloud Messaging Push notifications FCM device token
Firebase Analytics Usage statistics and product improvement Firebase Instance ID, device info, event data
Google Sign-In Authentication via Google account Email, display name

Your personal data is stored and processed on Google Cloud infrastructure, primarily in the United States. The United States does not have an adequacy determination under the Sri Lanka PDPA. This transfer is made on the basis of appropriate safeguards, specifically the Standard Contractual Clauses incorporated into Google’s Data Processing Addendum, which commits Google to GDPR-equivalent protections for all data transferred under those clauses. Details of Google’s transfer mechanisms are available at https://cloud.google.com/terms/data-processing-addendum.

No third-party advertising, tracking, or analytics SDKs other than the Firebase services listed above are included in the current version of the app. Phronix does not include social media pixels, third-party crash reporters, or advertising networks. If any additional SDK is introduced in a future update, this policy will be updated before release.


7. Data Retention

Data Retained until
Account data (email, UID, display name) Account is deleted
Card product selections Account is deleted
Saved offers Account is deleted, or you remove them
FCM token Account is deleted or token is refreshed by the device
Analytics event data Per Google’s Firebase Analytics retention settings

7.1 Account deletion

You can delete your account from Profile → Delete account in the app, or by emailing us at athiththan.kathir@gmail.com. We will action your request promptly and will remove your account and all directly associated personal data — including email address, display name, Firebase UID, card product list, saved offers, and FCM token — from our active database systems within 30 calendar days. Full step-by-step instructions are on our Account Deletion page.

Encrypted system backups managed by Google Cloud may retain copies of deleted data for a further period before automated rotation removes them. This retention is governed by Google Cloud’s backup practices and the data is inaccessible in production during this period. We have no mechanism to accelerate deletion from Google’s infrastructure-level backups, but those backups are overwritten in the ordinary course of Google’s operations.

After the applicable retention periods, we will hold no copy of your personal data in any system under our control.

Note: deleting your Phronix account does not affect your Google account. Manage your Google data separately at myaccount.google.com.

7.2 Inactive accounts

Accounts with no recorded activity (sign-in, card list update, saved offer interaction) for 24 consecutive months are considered inactive.

Before any inactive account is deleted, we will send:

If you do not sign in within the 30-day notice period, the account and all associated personal data will be deleted. To prevent deletion, simply open the app and sign in before the date stated in the notice. If you no longer have access to your registered email address and miss the notice, contact us at athiththan.kathir@gmail.com before deletion to discuss recovery options.


8. Your Rights

Under the Sri Lanka PDPA (and GDPR where applicable), you have the following rights.

8.1 Right to access

You may request a full copy of the personal data we hold about you at any time. We will respond within 30 calendar days.

8.2 Right to correction

You can update your display name directly from the Profile screen in the app. For corrections to other data, contact us.

8.3 Right to deletion (right to be forgotten)

You can delete your account and all associated data from Profile → Delete account, or by contacting us. Data is removed from active systems within 30 calendar days as described in Section 7.1.

8.4 Right to data portability

You may request an export of your data (card list, saved offers, account information) in a structured, machine-readable format (JSON). Contact us to make this request.

8.5 Right to restriction of processing

You may ask us to restrict the active processing of your personal data in the following circumstances:

During a restriction, we will retain your data but will not actively process it beyond storage, except with your consent or for legal purposes. To request a restriction, contact us at athiththan.kathir@gmail.com.

Where any processing is based on your consent, you have the right to withdraw that consent at any time by using the relevant setting in the app (for example, disabling analytics in the Preferences screen) or by contacting us at athiththan.kathir@gmail.com. Withdrawal of consent does not affect the lawfulness of any processing carried out before withdrawal. Withdrawing consent for an optional feature does not affect your access to the core Phronix service.

8.7 Right to lodge a complaint with the Data Protection Authority

If you believe that Phronix is processing your personal data in a manner that does not comply with the Sri Lanka Personal Data Protection Act No. 9 of 2022, you have the right to lodge a complaint with the Data Protection Authority of Sri Lanka. Contact details and complaint procedures for the Authority are available through the Sri Lanka government’s official portal. We encourage you to contact us first at athiththan.kathir@gmail.com so that we can address your concern directly, but this does not affect your right to approach the Authority at any time.

For users in the European Economic Area: you also have the right to lodge a complaint with the data protection supervisory authority in your member state.

8.8 Right to object

You may object to processing of your personal data where that processing is based on legitimate interests (see Section 5.0). In practice, this currently applies to Firebase Analytics.

To limit Firebase Analytics data collection on Android:

Deleting the Advertising ID prevents Firebase Analytics from associating events with a consistent advertising identifier. Note that the Firebase Instance ID (a per-installation identifier distinct from the Advertising ID) is still generated by the Firebase SDK itself.

To request full suppression of your analytics data, contact us at athiththan.kathir@gmail.com with the subject line “Analytics opt-out.” We will implement the Firebase Analytics opt-out flag for your installation where technically feasible.

For objections to any other processing activity based on legitimate interests, contact us at athiththan.kathir@gmail.com. We will consider your objection and respond within 30 calendar days.

8.9 How to exercise your rights

Submit any request to athiththan.kathir@gmail.com. We will acknowledge your request within 5 business days and provide a substantive response within 30 calendar days. For complex or high-volume requests, we may extend this period by a further 30 days and will notify you of the extension before the initial deadline expires. No fee is charged for reasonable requests.


9. Security and Data Breach Notification

Security measures: All data transmitted between the Phronix app and Firebase servers is encrypted in transit using TLS. Data stored in Cloud Firestore is encrypted at rest using AES-256 by Google’s infrastructure. Firebase security rules restrict each user’s data to their own authenticated account — no user can access another user’s card list or preferences. Access to the Firebase project console is protected by multi-factor authentication. We do not store card numbers, banking credentials, or other high-sensitivity financial data, which significantly reduces the impact of any breach affecting Phronix data.

Breach detection and response: In the event of a personal data breach, we will:

  1. Assess the nature, scope, and likely impact of the breach without undue delay.
  2. Notify the Data Protection Authority of Sri Lanka within the timeframe prescribed by PDPA regulations (expected to align with the 72-hour standard under GDPR).
  3. Notify affected users directly — by email and in-app notification — where the breach is likely to result in a high risk to their rights and freedoms. The notification will describe: what data was affected, the likely consequences, what steps we have taken, and what users can do to protect themselves.
  4. Maintain a written record of all breaches, including those that do not require external notification.

If you discover or suspect a security vulnerability affecting Phronix, please report it to athiththan.kathir@gmail.com.


10. Children and Minimum Age Requirement

Phronix is intended exclusively for users aged 18 and above. Credit and debit card offers — the subject matter of the app — are financial products that require legal capacity to contract, which under Sri Lanka law requires a minimum age of 18.

Age restriction implementation: During account creation, users are presented with the minimum age requirement and must proceed through Google Sign-In, which requires a Google account (Google accounts require users to be at least 13 years old). Phronix does not implement automated age verification beyond this step and relies on the user’s declaration of eligibility. Users found to be under 18 will have their accounts terminated.

Minors discovered after registration: If we become aware — through a report or other means — that a user is under 18, we will suspend and delete their account and all associated personal data as soon as practicable, and in any event within 30 calendar days.

If you believe a minor has created an account, please notify us immediately at athiththan.kathir@gmail.com.

COPPA notice: Phronix is not directed at children under 13. We do not knowingly collect personal data from children under 13. If we discover that we have inadvertently collected data from a child under 13, we will delete it promptly. Phronix is not enrolled in Google Play’s Designed for Families programme.


11. Changes to This Policy

We may update this Privacy Policy as the app evolves. When we make material changes, we will:

Push notification delivery is best-effort and subject to device settings and connectivity. We will also display a prominent in-app banner on the next app launch after a material change to ensure all active users are informed regardless of notification delivery status.

For changes that introduce new processing activities or materially alter your rights, we will additionally require you to review and accept the updated policy before continuing to use the app. For minor administrative updates (correcting typographical errors, updating contact details, clarifying existing practices without changing their effect), continued use of the app after the notice period constitutes acceptance. You may always delete your account if you do not accept a policy change.


12. Contact

Phronix — Privacy Enquiries
Data Controller: Athiththan (individual developer, operating as Phronix — not a registered company)
Email: athiththan.kathir@gmail.com
Country: Sri Lanka

Phronix is operated by an individual developer. No Data Protection Officer has been formally appointed; all privacy enquiries and data subject rights requests are handled directly by the developer. We respond to all privacy-related requests within 30 calendar days of receipt.
Financial disclaimer: Phronix provides card offer and promotion information for convenience only. Users should verify final eligibility, terms, and availability with the relevant bank or merchant before making a purchase. Phronix is not affiliated with, endorsed by, or partnered with any bank or financial institution listed in the app.