1. Introduction
This Privacy Policy explains how Fred Intelligence Limited ("Fred," "we," "us," or "our"), the developer and operator of the Swadhin Bangla AI Security mobile application (the "App"), website, customer portal, and related services (collectively, the "Services"), collects, accesses, uses, stores, shares, and protects personal and device-related information.
Fred Intelligence Limited is established in Bangladesh, with its registered office at Plot Kha-56, Amena Tower, Level 4, Shahjadpur, Gulshan, Dhaka-1212, Bangladesh.
This Policy applies when you:
- visit fredbd.com;
- download, install, activate, or use the App;
- create or manage an account or subscription;
- submit a file, application, link, or security event for analysis;
- contact our support team; or
- otherwise interact with the Services.
Please read this Policy before using the Services. Where consent is required, we will ask for it through an appropriate notice or permission request. You may decline an optional permission, although the related feature may then be unavailable.
2. Who Is Responsible for Your Information
For the purposes of applicable data-protection law, the organisation responsible for the processing described in this Policy is:
Fred Intelligence Limited
Developer and operator of Swadhin Bangla AI Security
Plot Kha-56, Amena Tower, Level 4
Shahjadpur, Gulshan, Dhaka-1212, Bangladesh
Website: https://www.fredbd.com/
Privacy and support email: support@fredbd.com
Telephone: +880 1977-031444
3. Scope
This Policy covers information processed through the App, fredbd.com, our licence or subscription services, security-analysis infrastructure, and customer-support channels.
This Policy does not cover:
- information processed by a third-party service under its own privacy policy;
- third-party websites reached through external links; or
- employee and job-applicant information, which is governed by separate internal notices.
4. Information We Collect or Access
The information we process depends on the features you use, the permissions you grant, and whether analysis occurs locally on your device or through our cloud services.
4.1 Account, licence, and contact information
We may collect:
- your name;
- email address;
- mobile telephone number;
- account identifier;
- encrypted authentication information;
- subscription or licence status;
- purchase and transaction reference information;
- customer type and, for business customers, company name and job title; and
- communications, feedback, and support requests you send to us.
We do not store your full payment-card details when payment is processed by an authorised payment provider. The payment provider processes that information under its own privacy policy.
4.2 Device and application information
For security, compatibility, licensing, diagnostics, and fraud prevention, the App may process:
- device manufacturer and model;
- operating-system and security-patch versions;
- App version, language, and configuration;
- network and internet-protocol address information;
- device or installation identifiers, including resettable or App-scoped identifiers where available;
- installed-application names, package names, versions, installation sources, certificates, requested permissions, and related security metadata;
- device security posture, such as whether relevant protection settings are enabled;
- crash reports, performance data, error logs, and diagnostic information; and
- licence activation and service-use events.
The App does not use an inventory of installed applications for advertising or unrelated profiling.
4.3 Files, APKs, and malware-analysis information
When you use malware protection, download protection, fake-app detection, or a security scan, the App may access or generate:
- file names, paths, sizes, types, and cryptographic hashes;
- APK package metadata, signing-certificate information, permissions, and code characteristics;
- detected indicators, risk scores, scan results, and quarantine or remediation status;
- the source from which an application or file was obtained, where available; and
- a suspicious file, APK, or limited technical sample when cloud analysis is required and permitted.
Where practicable, analysis is performed on the device or by transmitting a cryptographic hash or limited metadata instead of the entire file. If a suspicious sample must be uploaded for deeper analysis, the App will use the sample only for security analysis, threat detection, model improvement, and protection of users. Users should not intentionally submit files containing personal, confidential, or third-party information unless necessary for security analysis and lawfully permitted.
4.4 Web, phishing, and link-protection information
When you use web protection, phishing protection, DNS/VPN-based protection, or Check-a-Link, the App may process:
- URLs, domain names, host names, IP addresses, and redirect information;
- reputation-query results and threat classifications;
- time, source category, and outcome of a security check; and
- limited network metadata required to identify and block malicious destinations.
We use this information to determine whether a link or destination is malicious, fraudulent, deceptive, or otherwise unsafe. We do not use security-related browsing data to build advertising profiles.
If the App provides protection through a local VPN interface, that interface is used to inspect or route security-relevant network requests for the stated protection function. We do not claim to provide anonymity unless a separate feature expressly says so.
4.5 Scam, SMS-link, notification, and call-protection information
If you enable a scam-protection feature, the App may analyse links, sender information, telephone-number reputation, or security-relevant text that you submit or make available through a permission you grant. Depending on the implemented feature, this may include user-selected text, shared content, or security-relevant notification data.
The App does not collect message or call content for advertising. It does not send messages or initiate calls without an action by you. Any access to SMS, call logs, notifications, contacts, or similar sensitive information will be limited to the disclosed security purpose, subject to an in-app explanation, and requested only when required for an active feature.
4.6 Financial-fraud and fake financial-app protection
Swadhin Bangla AI Security may identify suspicious or fake applications that imitate bKash, Nagad, Rocket, Upay, banking, telecommunications, or other trusted services. This protection may use package metadata, signing information, installation source, file reputation, and other technical indicators.
The App does not inspect or process users' financial transactions inside bKash, Nagad, Rocket, Upay, or online-banking applications. We do not request or collect mobile-financial-service PINs, banking passwords, card PINs, one-time passwords (OTPs), transaction authorisation codes, or account balances.
4.7 Data-leak and breach-check information
If you choose to use a data-leak or breach-check feature, we may process the email address, telephone number, or other identifier you submit to check whether it appears in known breach or exposure records. Where supported, we use privacy-preserving techniques such as hashing, partial queries, or limited disclosure. Results are provided for security awareness and do not prove that a particular person committed or suffered fraud.
4.8 Website and cookie information
When you visit fredbd.com, our systems may automatically receive:
- IP address;
- browser and device type;
- operating system and language;
- referring and exit pages;
- pages viewed and actions taken;
- date and time of access; and
- cookie or similar technology identifiers, where used.
We use necessary technologies to operate and secure the website. We will request consent before using optional analytics or advertising cookies where required by law. Details of the cookies actually deployed should be described in a separate Cookie Policy or consent panel available on the website.
4.9 Customer service and communications
If you contact us, we may collect your contact details, the content of your request, related account or licence information, diagnostic materials you choose to provide, and records of our response. We will notify you before recording a telephone or video support session where required.
5. Device Permissions and Sensitive Access
The App may request Android permissions or special access only when needed for a feature you use. Depending on the released version, this may include access necessary to:
- discover and assess installed applications;
- select or scan files and APKs;
- monitor newly downloaded files;
- display security warnings or notifications;
- operate phishing or DNS/VPN-based protection;
- receive security-relevant notification information;
- run protection in the background; or
- support another clearly described security function.
Before requesting sensitive access that may not be obvious, we will provide a prominent in-app explanation describing what information is accessed, why it is needed, whether it is transmitted off the device, and how you can disable the feature.
Where a narrower Android API or system picker can provide the feature, we seek to use it instead of broader access. You can review or withdraw permissions through your device settings. Withdrawing a permission does not affect earlier lawful processing, but the corresponding feature may stop working.
6. How We Use Information
We process information to:
- provide, activate, authenticate, maintain, and support the Services;
- scan files, APKs, applications, devices, links, domains, and security events;
- detect malware, fake applications, phishing, scams, unsafe links, and other threats;
- display warnings and recommend or perform user-approved remediation;
- operate cloud reputation, threat-intelligence, and security-analysis services;
- improve signatures, detection rules, models, and protection quality;
- manage accounts, subscriptions, licences, payments, renewals, and entitlements;
- troubleshoot faults and improve stability and performance;
- prevent misuse, fraudulent activation, attacks, and unauthorised access;
- provide customer support and respond to requests;
- maintain audit, security, and compliance records;
- comply with applicable legal obligations and lawful government or court requests; and
- send service messages and, with any required consent, product or marketing communications.
We do not sell personal or sensitive user data. We do not use information obtained through sensitive device permissions for unrelated advertising or data-broker activities.
7. Artificial Intelligence and Automated Analysis
The Services may use artificial intelligence, machine learning, statistical models, signatures, heuristics, and automated rules to classify potentially malicious applications, files, URLs, permissions, behaviours, or security events.
These technologies may generate threat classifications, risk scores, explanations, or recommended actions. Automated security analysis can produce false positives or false negatives and should not be treated as a guarantee that a file, application, link, or device is safe or malicious.
We do not use the App's security classifications to make legal, employment, credit, insurance, or similarly significant decisions about an individual. Where appropriate, users may report an incorrect detection or request human review through our support channel.
8. Legal Grounds for Processing
Depending on the circumstances and applicable law, we process information on one or more of the following grounds:
- your consent;
- performance of a contract or steps requested before entering into a contract;
- compliance with a legal obligation;
- protection of vital or security-related interests; and
- our legitimate interests in providing, securing, improving, and preventing misuse of the Services, where those interests are not overridden by your rights.
Where we rely on consent, you may withdraw it at any time. Where we rely on legitimate interests, you may have a right to object, subject to applicable law.
9. When We Share Information
We may share information only as reasonably necessary with:
- Cloud, hosting, storage, and infrastructure providers that operate systems supporting the Services;
- Threat-intelligence, reputation, and malware-analysis providers used to evaluate suspicious files, hashes, applications, links, domains, or indicators;
- Payment and subscription providers that process purchases, renewals, and payment confirmations;
- Analytics, diagnostics, and customer-support providers used to maintain and improve the Services, subject to appropriate restrictions;
- Professional advisers, such as auditors, lawyers, insurers, and security consultants;
- Government authorities, regulators, courts, or law-enforcement bodies when disclosure is required or permitted by applicable law or necessary to protect rights and safety; and
- A successor organisation in connection with a merger, acquisition, financing, restructuring, or transfer of all or part of our business, subject to appropriate confidentiality and notice requirements.
Service providers may process information only for authorised purposes and under applicable contractual, confidentiality, and security obligations. We remain responsible for accurately identifying all third-party software development kits and processors in our Google Play Data Safety disclosures and other applicable notices.
We may share aggregated or de-identified information that cannot reasonably identify an individual.
10. International Data Transfers
Some service providers or security-analysis systems may process information outside Bangladesh. Where personal information is transferred internationally, we will use measures required by applicable law, which may include contractual protections, security controls, transfer assessments, consent where required, and limitation of the information transferred.
We will not represent that information remains exclusively in Bangladesh unless the relevant service has been technically and contractually configured to ensure local processing.
11. Data Security
We use reasonable administrative, technical, and organisational safeguards appropriate to the nature and risk of the information processed. These may include:
- encryption in transit using current transport-security protocols;
- encryption at rest where appropriate;
- access controls and least-privilege permissions;
- authentication, logging, monitoring, and audit controls;
- secure software-development and vulnerability-management practices;
- separation of production, testing, and administrative environments;
- malware-sample handling controls;
- backup, recovery, and incident-response procedures; and
- contractual and security reviews of relevant service providers.
No method of transmission or storage is completely secure. Users should protect their device, credentials, recovery information, and account access and should promptly install security updates.
If a personal-data breach occurs, we will investigate, contain, document, and provide notifications to affected individuals or authorities where required by applicable law.
12. Retention and Deletion
We retain information only for as long as reasonably necessary for the purpose for which it was collected, including to provide the Services, maintain security, resolve disputes, enforce agreements, and satisfy legal, tax, accounting, and compliance obligations.
Retention depends on the type of information:
- account and licence information is generally retained while the account or licence remains active and for a limited period afterward;
- payment and transaction records may be retained for the period required by financial, tax, and legal obligations;
- routine diagnostic and security-event logs are retained for a limited operational period unless needed to investigate an incident;
- malware hashes, indicators, signatures, de-identified detection data, and technical threat intelligence may be retained longer where necessary to protect users and cannot reasonably identify an individual;
- suspicious samples are retained only as long as needed for security research, detection, validation, legal compliance, or dispute resolution, subject to access restrictions; and
- support records are retained for service quality, security, and dispute-resolution purposes for a limited period.
When information is no longer required, we delete it, anonymise it, or securely isolate it until deletion from active systems and backups under our retention cycle. Legal holds, fraud investigations, security incidents, or statutory obligations may require longer retention.
13. Your Rights and Choices
Subject to applicable law and relevant exceptions, you may request to:
- know whether we process your personal information;
- access or receive a copy of personal information we hold about you;
- correct inaccurate or incomplete information;
- withdraw consent;
- object to or request restriction of certain processing;
- request deletion of information;
- obtain information about relevant recipients or categories of recipients;
- request review of a disputed automated security classification; or
- lodge a complaint with the competent authority.
You may also:
- change App permissions through Android settings;
- disable optional security features;
- opt out of non-essential marketing communications using the unsubscribe method provided; and
- uninstall the App, although uninstalling does not automatically delete account or server-side records.
To exercise a privacy right, email support@fredbd.com. We may need to verify your identity and request before disclosing, correcting, or deleting information. We will respond within the period required by applicable law.
Account deletion
If the App permits account creation, you may request account deletion from the account settings or through the deletion method identified on the App's Google Play listing and website. Upon a valid deletion request, we will delete or de-identify information associated with the account unless retention is required for security, fraud prevention, transaction records, dispute resolution, or another legal obligation. Merely disabling or freezing an account is not treated as completion of a valid deletion request.
14. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from a child under 13 without legally valid authorisation. The App is not intended to be used to monitor a child secretly or without lawful authority.
If you believe a child has provided personal information inappropriately, contact us at support@fredbd.com. We will investigate and delete the information where required. A higher age threshold or parental-consent requirement may apply in some jurisdictions.
15. Third-Party Services and Links
The Services may contain links to or integrate with third-party services. Their processing is governed by their own privacy policies. We are not responsible for an independent third party's practices, but we seek to assess providers that process information on our behalf and to limit their use through contractual and technical controls.
16. Changes to This Policy
We may update this Policy to reflect changes in the App, our processing activities, legal requirements, or security practices. We will post the updated Policy on fredbd.com and revise the effective or last-updated date.
If a change materially affects how we process personal or sensitive information, we will provide additional notice or request consent where required. Previous versions may be made available upon request.
17. Applicable Law
We process personal information in accordance with laws applicable to our operations, which may include Bangladesh's Personal Data Protection Ordinance, 2025, the Cyber Security Act, 2026, and other applicable consumer, electronic-transaction, telecommunications, and data-protection requirements.
References to these laws do not limit any rights that cannot lawfully be waived. If this Policy conflicts with a mandatory legal requirement, that requirement will apply to the extent of the conflict.
18. Contact Us
For privacy questions, complaints, data requests, or concerns about Swadhin Bangla AI Security, contact:
Privacy Officer
Fred Intelligence Limited
Developer and operator of Swadhin Bangla AI Security
Plot Kha-56, Amena Tower, Level 4
Shahjadpur, Gulshan, Dhaka-1212, Bangladesh
Email: support@fredbd.com
Telephone: +880 1977-031444
Website: https://www.fredbd.com/