Privacy Policy

Crossed · Last updated 2026-07-30

Who we are

Crossed is a social memory map. Two people pair with a short code and, only after both agree, the app reveals where their past paths may have crossed, based on the memories each person chooses to add. Crossed also has an optional group version, a Crossed Circle, which is described in its own section below.

This policy explains what data Crossed collects, how it is used, and how you can delete it. If you have any questions, contact us at edomis@edomis.io.

Data we collect

Account data (only if you sign in): your email address, an optional display name and profile photo, and which sign-in method you used (email, Google, or Apple).

Profile details you choose to add (optional): you can fill in a profile card that may include your date of birth or age, gender, city and country, profession, and phone number. These are off by default; a field is shared with the other person only if you have switched its sharing on, and it is then sent when you pair with them, before the Cross is revealed. If you set a profile photo, it is uploaded to Google Firebase Cloud Storage and shown to the person you cross with.

Messages: if you send messages to someone you have crossed with, those messages are stored in Google Cloud Firestore so both of you can see the conversation.

Location data (only with your permission): when you grant location access, Crossed reads your device location while you are using the app to build your private Trace Vault. Before anything is stored, each coordinate is coarsened on your device onto a grid cell of at least 3 km², and what is kept is an approximate place: a city, area and country name, that coarse cell in place of your real coordinate, and when the reading was taken (a timestamp plus a month-and-year label). Crossed does not collect location in the background.

Turning a reading into a place name — the one moment a coordinate leaves your device: to find out which city a reading belongs to, Crossed passes the location reading to your device's own operating-system geocoding service (provided by Google on Android and by Apple on iOS) and keeps the city, district and country it returns. That lookup happens before the reading is coarsened onto the storage grid. The reading is already approximate — Crossed only ever asks Android for approximate location, and at low accuracy — but it is finer than what is stored, and that platform service sees it under its own terms. The exact coordinate is never sent to Crossed's own servers, is never stored by Crossed, and is never shown to another person. The same lookup runs for points in a location file you import that do not already carry a place name.

Location history you import (optional, and only when you start it): on the Import screen you can add past places from a Google location export (a Google Takeout / Timeline JSON file). You begin this yourself, tick a consent box, and choose the file with your device's own file picker. Crossed reads the file on your device and keeps only the same approximate places described above; the export file itself is never uploaded. Crossed has no standing access to your Google account and does not connect to Google Photos, Google Calendar, or any other service to pull your history — an import happens only when you pick a file.

Photos: this version of Crossed does not scan your photo library and requests no photo or media-library permission. The only image Crossed handles is a profile photo you deliberately choose: you pick one file with your device's own system picker, and that single image is uploaded to Firebase Cloud Storage so the person you cross with can see your avatar.

Crossed Circles (only if you join one): when you create or join a Circle, the name on your profile, your initials, and your profile photo if you have one are stored in that Circle's shared record, where every other member of the Circle can see them. See the Crossed Circles section below for the full picture.

Safety data (blocking and reporting): if you block someone, we store a record naming you as the blocker and them as the blocked person, so the block can be enforced on our servers and not just hidden on your phone. If you report someone, we store your account identifier, the account identifier of the person you reported, the reason you picked, and the time.

Purchase data (only if you buy something): Crossed offers an optional subscription and one-time unlocks through Google Play. Google Play processes the payment — Crossed never sees or stores your card, bank, or billing address details. What we store is the outcome of the purchase: your current plan (free, Plus, or Founder), when a subscription period ends, how many one-time Cross credits you have left, how many AI reports you have generated this month, and a purchase record consisting of a one-way hash of the Google Play purchase token, the product identifier, and your account identifier.

Saved Crosses: your saved Crosses are synced to your account so they follow you across devices, and are cached on your device for offline viewing.

Crossed does not use your precise location to track your live position for anyone else, and it never shows your raw location history to the person you pair with.

How we use your data

To build your private Trace Vault from the locations you allow, so the app can look for possible past overlaps with another person.

To provide the core feature: pairing with another person and, after mutual consent and within the scope you both choose, generating a Cross Map of where your paths may have overlapped.

To run a Crossed Circle when you choose to join one: to show the other members who is in the Circle, and — once everybody has consented — to work out which cities two or more of you passed through.

To sync your Trace Vault and profile to your account so they are available across sessions and devices when you are signed in.

To let you message a person you have crossed with, we store your conversation in Cloud Firestore so both people can read it.

To keep people safe: to enforce a block you have made (and one made against you) across messaging, notifications, new Crosses and Circles, and to review the reports people file.

To sell and honour optional paid features: we verify every Google Play purchase with Google before unlocking anything (we never trust the device's own claim), and we act on Google's renewal, cancellation, expiry, and refund notifications so your plan stays correct.

To write an AI Deep Report, but only when you ask for one: a short, factual summary of that single Cross is sent to Anthropic's Claude API, which writes the report text and returns it. Exactly what is sent is listed under 'Service providers we use'.

To send you notifications about your Crosses and new messages, when you have allowed them.

To keep the app stable, we use Sentry (a crash- and error-reporting service) to receive crash reports and error diagnostics. These reports are privacy-hardened: they contain no account identifiers, no location, and no message or conversation content, and personal details in error data are scrubbed before sending.

To understand whether features work, we keep anonymous, aggregate counts of app events (for example, how many Crosses were revealed). These counts are daily totals per event, are not linked to you, and contain no location data. Crossed uses no advertising trackers.

We do not use your data for advertising, and we do not sell your data.

Consent and control

Location collection only happens after you grant permission. You can revoke it at any time in your device settings or in the app.

Before each Cross, you choose the scope you share (time range, level of detail, and sources). A Cross Map is only revealed when both people consent — there is no one-sided reveal, and approximate locations are used first.

A Crossed Circle works the same way, with everybody's consent instead of one other person's: the Circle is only computed once every member has agreed, and a member who joins can always leave the reveal unconsented.

Permissions we request

Crossed only requests permissions needed for features you choose to use, always asks before using them, and keeps working (with reduced functionality) if you decline. You can change any permission later in your device settings.

Location (while using the app): used to add the approximate places you visit to your private Trace Vault, which powers Cross discovery. Crossed asks only for approximate location, coordinates are coarsened on your device before storage, and your precise, real-time location is never collected or shown to anyone. Crossed does not request background-location access.

Camera: used only to scan a pairing QR code when you start a Cross in person. No photos or video are recorded.

Photos and media: this version of Crossed requests no photo or media-library permission at all and never scans your gallery. Choosing a profile photo goes through your device's own system file picker, which hands the app only the one file you select.

Notifications: with your permission, Crossed can send you notifications about your Crosses and new messages. You can turn them off at any time in your device settings. Crossed does not request contacts or microphone permissions.

Data obtained through these permissions is used only to provide the features above, is stored under your own account, and is never sold or shared with third parties for their own purposes.

Crossed Circles (group Crosses)

A Crossed Circle is the group version of a Cross. Somebody starts a Circle and shares a short join code; up to twelve people in total can be in it, so you and up to eleven others. It is invite-only — Crossed never surfaces nearby people, strangers, or anyone who does not have the code.

What the other members see about you: when you create or join a Circle, Crossed stores the name on your profile, your initials, and your profile photo if you have set one, inside that Circle's shared record. Every other member of that Circle can read them. This is the one place in Crossed where your details go to a group rather than to a single person, so only join a Circle whose members you are happy to be named to.

Nothing is revealed until everybody agrees. The Circle is only computed once every member has consented, and nobody can join a Circle after it has been revealed.

What the result contains: a list of cities that two or more members' paths passed through, and for each city, which of those members they were, plus a rough period. It shows no coordinates, no addresses, no exact dates, and never anybody's location history. As everywhere else in Crossed, a crossing is a possible, approximate overlap and never proof that people met.

Blocking applies inside Circles too. Somebody you have blocked, or who has blocked you, cannot join a Circle you are in, and a Circle containing such a pair is not computed.

If you delete your account, you are removed from every Circle you belonged to and your name and photo go with you; the Circle's computed result is deleted as well, so your name is not left inside it, and the remaining members can recompute without you.

Safety: blocking and reporting

You can block another person from their profile card or from a chat. A block is enforced on our servers, not merely hidden on your device: once it exists, the blocked person cannot message you or send you notifications, no new Cross is computed between you, and neither of you can join a Circle the other is in. The record stores who blocked whom, nothing else. You can undo a block, which deletes that record.

You can also report someone for harassment, spam, or inappropriate behaviour. A report stores your account identifier, the account identifier of the person you reported, the reason you chose, and the time. Reports cannot be read from the app by anyone, including you: they go to a moderation queue that we review.

Reports are deliberately kept even when an account is deleted — both the reports you filed and the reports filed about you. A report belongs to the safety queue rather than to your profile: deleting it would erase a safety signal about somebody else, and it would let a person clear the reports against them simply by deleting their account. Reports contain no location, no message content, and no payment detail.

Purchases and subscriptions

Crossed is free to download and use. Optional paid extras (a Crossed Plus subscription, one-time Cross unlocks, and a one-time Founder plan) are sold through Google Play, which handles the entire payment. Crossed never receives your payment method or billing details.

Every purchase is checked server-side against Google's Play Developer API before anything is unlocked, so your entitlement reflects Google's record rather than what the app on your device claims. We store the hashed purchase token described above for two reasons: so the same purchase cannot be granted twice, and so that when Google notifies us that a subscription has renewed, expired, been cancelled, or been refunded, we can apply that to the right account. Those notifications identify a purchase, not a person, and we never use them to learn anything else about you.

Google Play may retain its own record of the transaction under Google's terms. To manage or cancel a subscription, or to ask for a refund, use your Google Play account. See our Refund Policy and our Terms of Service for the details.

Cookies and local storage

Crossed does not use advertising or third-party tracking cookies, and contains no advertising SDKs.

On your device, the app stores data locally (device storage, or your browser's local storage on the web) so it works smoothly and remembers your preferences — for example your saved Crosses, your profile name and photo, your language and sound settings, and, if you choose it, your email address for faster sign-in. Your password is never stored.

When you sign in, Firebase Authentication keeps a secure session token on your device so you stay signed in between visits. You can end it at any time by signing out.

The hosted versions of these policy pages set no marketing or analytics cookies.

Clearing the app's data (Settings, Danger Zone) or uninstalling the app removes locally stored data.

Where your data is stored

Crossed uses Google Firebase as its backend: Firebase Authentication (sign-in), Cloud Firestore (your synced data), Firebase Cloud Storage (your profile photo), Cloud Functions (server-side Cross computation), and Firebase Hosting (the public versions of these pages).

Firestore data and our server functions run in Google's European region (europe-west3).

Crash and error diagnostics are processed by Sentry (sentry.io) on our behalf, in its EU region. We send Sentry no account identifiers, no location, and no message content.

Three of the providers listed below — Anthropic, Resend, and Expo's push service — are based in the United States, so the limited data described for each of them is transferred there when you use the feature it belongs to.

Service providers we use

These companies process data on our behalf, only for the purpose listed. None of them is allowed to use your data for their own purposes, and none of them is an advertiser.

Google Firebase — authentication, database, file storage, server functions, and hosting. This is where your account, profile, Trace Vault, Crosses, Circles, and messages live.

Google Play — processes and verifies purchases and subscriptions, and notifies us of renewals, cancellations, and refunds. Google Play receives your payment details; we do not.

Anthropic (Claude API) — used only at the moment you generate an AI Deep Report for one Cross. What is sent: the other person's first name only, the overlap score for that Cross, up to fifteen possible crossings (each as a city and country, an approximate date label such as a month and year, a likelihood word, and an approximate distance in kilometres), the closest moment (city and approximate date), and the names and cities of any shared places. Symmetrically, when the person you crossed with generates their own Deep Report, your first name is the name that is sent. What is never sent: either person's surname, email address, account identifier, phone number, or photo, any exact coordinate or street address, and any of your messages. Anthropic processes that text to write the report and returns it to us; the finished report is then stored under your own account and is deleted when you delete your account.

Resend — delivers one transactional email: when a friend you invited joins Crossed and your paths turn out to overlap, we email you about it. Resend receives your email address and that message. The email does not name the other person. If you would rather not receive it, email edomis@edomis.io and we will switch it off for your account.

Expo push notification service — delivers push notifications to your device, passing them on to Google's Firebase Cloud Messaging. To send one, Crossed hands Expo your device's push token together with the notification itself. Please note that for a chat notification this includes the sender's first name and the first 140 characters of the message, and for a 'liked your crossing' notification it includes the other person's name and the city of that crossing, because that is what is shown on your lock screen. The notification also carries the account identifier of the person who triggered it, so the app can open the right screen when you tap it. Turning notifications off in your device settings stops this.

Sentry — crash and error reporting, with no account identifiers, no location, and no message content attached.

We do not sell your data, we do not share it with advertisers, and Crossed contains no advertising or third-party ad trackers.

Sharing

Two different things are shared at two different moments, and it matters which is which. Your profile card — your name, your photo, and only those card fields you have switched on, such as your city, age, gender, profession, or phone number — is exchanged with the other person the moment you pair, so that each of you can see who you are about to cross with. That happens before either of you consents. What mutual consent gates is the Cross itself: your Cross Map, your shared places and your closest moment are computed and revealed only after both of you have approved, and never one-sidedly. Messages you send are shared with that same person.

If you join a Crossed Circle, your profile name, initials, and photo, and the part of the Circle result that names you, are visible to the other members of that Circle — up to eleven other people — as described in the Crossed Circles section.

A report you file is shared with nobody except us, for moderation.

Apart from that, your data is shared only with the service providers listed above, and only for the purposes described there.

Retention

We keep your account data and your synced Trace Vault until you delete them. Data stored locally on your device remains until you remove it or uninstall the app.

Three things survive account deletion. The full, itemised list of what is removed is on our account deletion page at https://crossed-app-a8d84.web.app/delete-account.html

A purchase record. If you ever bought something, we keep a record that the purchase was processed: a one-way hash of the Google Play purchase token, the product identifier, your former account identifier, and the time. We keep it so a purchase cannot be replayed or granted twice, and as a transaction record for accounting and fraud prevention. It holds no name, email address, location, message, or payment detail.

Moderation reports. Both the reports you filed and the reports other people filed about you are kept, for the safety reasons explained in the 'Safety: blocking and reporting' section above.

A block another person placed on you. That record belongs to their account, not yours, and removing it would undo a safety choice they made. Blocks that you created are deleted with your account.

Anonymous daily event counters (for example, how many Crosses were revealed on a given day) are aggregate totals with no account identifier in them, so there is nothing in them to delete.

One thing that is not ours to delete automatically: a Deep Report that the person you crossed with generated is a document in their archive, not yours. Deleting your account removes your entry from their saved Crosses, but a Deep Report they had already generated is their own saved copy and can still carry the name and photo you shared with them at the time, and its text can mention your first name. It is removed when that person deletes their own Crossed account. If you want it removed sooner, email edomis@edomis.io from the address on your Crossed account and we will delete it for you.

Your rights and how to delete your data

If you are signed in: open Settings, then Danger Zone, then Delete Profile & Account. This deletes your Crossed account and its data across our servers, and clears the app's local data on your device. The full list of what is removed, and of the few things that are kept, is at https://crossed-app-a8d84.web.app/delete-account.html

If you are not signed in: open Settings, then Danger Zone, then Delete All Data on This Device, to remove everything stored locally.

You can also remove individual places from your Trace Vault, clear the whole Trace Vault, and delete individual saved Crosses at any time, and turn location collection off in your device settings.

You may also request access to, correction of, or deletion of your data by emailing edomis@edomis.io. Please write from the email address associated with your Crossed account so we can verify the request.

Children

Crossed is not directed to children under 13, and we do not knowingly collect data from them.

Security

We rely on Google Firebase's security and use per-user access rules so that you can only access your own data. No method of storage or transmission is perfectly secure, but we take reasonable measures to protect your information.

Changes to this policy

We may update this policy as the app evolves. The 'Last updated' date at the top reflects the latest version.

Contact

Questions about this policy or your data? Contact edomis@edomis.io.

Questions? Contact edomis@edomis.io.