We believe you have the right to know exactly how BinRo handles your data — in plain language.
Plain-language summary: BinRo is a QR code safety and payment-fraud detection app. We collect data to analyse QR codes for fraud, power community safety features, and keep your account secure. We do not sell your personal data. We do not store your card numbers or UPI credentials. In-app purchases on Android are processed by Google Play Billing; on iOS by Apple In-App Purchase. Optional website donations are processed by Razorpay. In all cases, BinRo never receives or stores your actual payment credentials.
BinRo is a mobile application (Android and iOS) and web platform designed to help users scan, analyse, generate, and manage QR codes with a focus on fraud prevention in the Indian digital payment ecosystem — including UPI, BharatQR, and 80+ payment apps.
BinRo is operated as a private software project under the laws of India, supported by the Kerala Startup Mission. Our registered contact address is Kerala, India.
This Privacy Policy applies to:
By using any BinRo service, you agree to the collection and use of information as described in this policy. If you do not agree, please discontinue use of BinRo immediately.
We collect only the data necessary to operate BinRo's services. Below is a complete breakdown of every category of data we collect, why we collect it, and the legal basis under India's Digital Personal Data Protection Act, 2023 (DPDPA).
Please see Section 4 (Payments & Transactions) for the full breakdown. In summary:
Camera privacy: All camera frames are processed entirely on your device using on-device QR decoding. We do not upload your camera feed or individual frames to our servers. Images are only transmitted to our servers if you explicitly choose to upload a photo from your gallery to scan for a QR code.
We use your data for the following purposes. The legal basis for each use is noted in brackets, referencing India's Digital Personal Data Protection Act, 2023.
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Authenticate your account and maintain secure sessions | Account & identity data, device data | Contract |
| Analyse QR codes for safety and fraud in real time | QR scan data, device data | Contract |
| Sync scan history, favourites, and generated codes across devices | QR scan data, account data | Contract |
| Verify in-app purchases and unlock paid features | Transaction ID, receipt token | Contract |
| Send push notifications about QR safety alerts, friend activity, and app updates | Push token, account data | Consent |
| Build and improve our fraud detection models using aggregated, anonymised patterns | Anonymised scan & behavioural data | Consent |
| Power community trust scores from aggregated user reports | Community reports, scan velocity | Contract |
| Show relevant in-app advertising to keep BinRo free | Aggregated, non-PII usage data | Consent |
| Debug crashes and improve app stability | Crash logs, device data | Legitimate interest |
| Detect and prevent abuse, fraud, and spam | Behavioural data, device data, IP | Legitimate interest |
| Comply with Indian law and respond to lawful government requests | Account data, scan data (as required) | Legal obligation |
BinRo offers optional in-app purchases (such as premium features or support contributions) processed exclusively through the official billing systems of your device's app store. Here is exactly how it works:
BinRo never handles your payment credentials. We do not have access to your card number, CVV, expiry date, UPI ID, bank account number, net banking credentials, or Apple ID password. All payment processing is performed entirely by Google Play Billing (Android) and Apple In-App Purchase (iOS).
On Android, purchases are processed by Google Play using your Google account's saved payment method. Google's Google Payments Privacy Notice governs that transaction.
On iOS, purchases are processed by Apple using your Apple ID's payment method. Apple's Apple Privacy Policy governs that transaction.
After a successful payment, the app store sends BinRo only the following limited information to verify your purchase:
This purchase information is linked to your BinRo account solely to activate the features you paid for. It is not used for advertising profiling or shared with third parties beyond what is necessary to verify the transaction.
If you make a voluntary contribution via the BinRo website, payment is processed by Razorpay Software Private Limited, a PCI-DSS compliant payment gateway licensed by the Reserve Bank of India. Razorpay's Privacy Policy governs the data they process. BinRo receives only a transaction reference ID and the amount contributed — no card details or bank information.
BinRo never collects, stores, or transmits: credit/debit card numbers, UPI IDs or VPAs belonging to you as a payer, net banking credentials, bank account numbers, IFSC codes, CVV/CVC codes, ATM PINs, OTPs related to payments, or Apple ID / Google account passwords.
Note: When you scan a payment QR code, the payee's UPI ID or merchant VPA embedded in that QR code may be processed by our fraud-detection engine. This is limited to the payee's public merchant identifier — not your own payment credentials. See Section 5 for details.
BinRo specialises in scanning and analysing payment QR codes, including UPI QR codes, BharatQR, and QR codes from 80+ Indian payment apps. Here is how we handle this sensitive data:
A typical UPI QR code encodes publicly visible merchant information such as:
This information is publicly embedded in the QR code and is required for the payment to work. BinRo analyses this data to detect fraudulent or cloned merchant QR codes.
BinRo parses QR code formats across 80+ Indian payment applications including PhonePe, Google Pay, Paytm, BHIM, Amazon Pay, and others. This parsing is performed on-device. The decoded content may be sent to our servers for safety analysis as described above.
BinRo is not a payment app. We do not hold, transfer, or process funds. We are a security verification tool. If you have payment-related issues, contact your payment provider directly.
BinRo relies on the following third-party services to deliver its core functionality. Each service processes certain data and is governed by its own privacy policy:
| Service | Provider | Purpose | Data Shared |
|---|---|---|---|
| Firebase Authentication | Google LLC | User account creation, login, session management | Email, Google ID, auth tokens |
| Firebase Firestore | Google LLC | Primary database for scan history, QR data, user profiles, community reports | Account data, scan data, community data |
| Firebase Realtime Database | Google LLC | Real-time features such as live scan counts and trust scores | Anonymised aggregated scan/trust data |
| Firebase Storage | Google LLC | Profile photo storage and uploaded images for scanning | Profile photos, uploaded scan images |
| Firebase Cloud Messaging (FCM) | Google LLC | Delivering push notifications to your device | Push token, notification content |
| Google Safe Browsing API | Google LLC | Checking URLs decoded from QR codes against Google's threat intelligence database | URLs extracted from scanned QR codes |
| OpenAI API | OpenAI, L.L.C. | AI-powered QR code analysis and safety explanations | QR code content (no personal identifiers) |
| Razorpay | Razorpay Software Pvt. Ltd. | Website donation processing | Transaction amount; payment credentials handled by Razorpay only |
| Google Play Billing | Google LLC | Android in-app purchase processing | Transaction ID, product ID, receipt token |
| Apple In-App Purchase | Apple Inc. | iOS in-app purchase processing | Transaction ID, product ID, receipt token |
| Expo Push Notifications | Expo (by Shopify Inc.) | Cross-platform push notification delivery | Push token, notification payload |
Firebase (Google Cloud) is compliant with GDPR, SOC 2 Type II, ISO 27001, and ISO 27701. All Firebase data processing occurs under Google's Firebase Privacy and Security documentation.
We are not responsible for the independent data practices of these third-party providers. We select providers that meet high security and compliance standards, but we encourage you to review their individual privacy policies.
BinRo maintains a continuously updated threat intelligence database derived from community scan data and reports. This database is the engine that powers our real-time QR code safety scores.
All pattern analysis uses anonymised and aggregated data only. We do not build databases that link specific QR code content to identifiable individuals.
We may share your data only in the following circumstances:
We share data with the third-party services listed in Section 6 solely to deliver BinRo's functionality. These providers are contractually restricted from using your data for their own commercial purposes.
Anonymised URL, domain, and QR threat patterns (never linked to your identity) may be shared with threat intelligence networks to broaden fraud protection for the wider ecosystem.
Only aggregated, non-personally-identifiable usage data (such as general app category usage, device type, and approximate region) may be shared with advertising partners to serve relevant in-app ads. See Section 14 for your opt-out options.
We may disclose data when required by:
In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity under equivalent privacy protections. You will be notified of any such transfer via email or in-app notice.
We never sell your personal data. We do not sell your name, email address, phone number, specific QR scan content, payment credentials, UPI information, or any directly personally identifiable information to any third party for commercial purposes — ever.
Despite our best efforts, no system is completely immune to security incidents. If a breach occurs that affects your personal data, here is what you can expect from us:
Under India's Digital Personal Data Protection Act, 2023 (DPDPA) and applicable international frameworks, you have the following rights regarding your personal data:
| Right | What It Means | How to Exercise It |
|---|---|---|
| Access | Request a full copy of all personal data we hold about you | Email us at ahmedsameerbinan2@gmail.com |
| Correction | Update your name, email, or profile photo | Via Account Settings in the app, or by emailing us |
| Erasure / Deletion | Permanently delete your account and personal data (within 30 days) | Account Settings → Delete Account, or email us |
| Portability | Receive your personal data in a structured, machine-readable format (JSON) | Email us at ahmedsameerbinan2@gmail.com |
| Withdraw Consent | Opt out of personalised advertising or AI training use of your data | Email us at ahmedsameerbinan2@gmail.com |
| Object / Restrict | Object to or restrict certain processing of your data | Email us and we will assess your request |
| Lodge a Complaint | Complain to the Data Protection Board of India or your local data protection authority | Via the Board's official channel once established under DPDPA 2023 |
| Nominate | Nominate another person to exercise your data rights in the event of your death or incapacity | Email us at ahmedsameerbinan2@gmail.com |
We will respond to all verifiable rights requests within 30 days. We may need to verify your identity before processing requests. We do not charge a fee for reasonable requests.
Note: Some rights are limited where data has been fully anonymised and incorporated into community or AI datasets — anonymised data cannot be attributed to a specific individual and is therefore outside the scope of data subject rights.
The BinRo mobile app does not use browser cookies. Instead, we use:
The BinRo website may use the following types of cookies:
You can control cookies through your browser settings. Blocking essential cookies may affect website functionality.
BinRo's core safety features are and will remain completely free. In-app advertising helps us sustain the project without charging users.
To opt out of personalised advertising:
BinRo operates under Indian law. We comply with lawful government and law enforcement requests for user data, including those made under:
Our process for responding to government requests:
BinRo is not intended for users under 13 years of age (or under 18 where applicable local law requires parental consent for data processing of minors).
BinRo's primary user base is in India. Our backend infrastructure runs on Google Firebase, which stores and processes data in Google Cloud data centres. Firebase data for India-based users is processed within Google's infrastructure, which may include servers located outside India.
Google Cloud and Firebase comply with applicable cross-border data transfer requirements, including standard contractual clauses where required. By using BinRo, you consent to the transfer of your data to Google's global infrastructure as necessary to provide the service.
Calls to the OpenAI API (for AI-powered analysis) involve data transfer to OpenAI's servers in the United States. Only QR code content (no personal identifiers) is included in these requests. OpenAI complies with applicable data transfer frameworks.
We may update this Privacy Policy from time to time. When we make material changes, we will:
Continued use of BinRo after accepting the updated policy constitutes your agreement to the revised terms. If you do not agree to any changes, you should discontinue use of BinRo and request deletion of your account.
We recommend bookmarking this page and reviewing it periodically. The effective date at the top of this page reflects the most recent revision.
For any privacy questions, data access or deletion requests, or to exercise any of your rights described in this policy, please reach out to us:
📧 Email: ahmedsameerbinan2@gmail.com
🌐 Website: https://binan-maker.github.io/binro
📍 Address: Kerala, India
We aim to respond to all privacy-related enquiries within 5 business days. For urgent matters involving children's data or potential security incidents, please include "URGENT" in your subject line.