crosd

Privacy Policy

Effective date: 6 August 2026

The short version

Your photos never leave your phone. What we read from them is the location and time metadata — where a picture was taken and when, never what is in it. To compare you with someone, those places and times are sent to our server in the EU, where the matching runs. Each of you gets back only the places you were both in; neither of you ever sees the rest of the other person's map.

What we collect

What we never collect

Comparisons and consent

Nothing is compared until the other person explicitly accepts. Each side learns only the places and times you were both in, at the precision that side chose — from 25 metres within the same half hour, up to about a kilometre within the same day, and wider than that only for places you visited while travelling. Declining an invite shares nothing further.

Deletion

Settings → Data → Delete my trace removes your trace from the device and deletes your visits and every comparison half we hold from our servers. Deleting your account additionally removes your identifier, so no future comparison can name you, and detaches any feedback you left. You can also email us for deletion.

Data processors

Google Firebase — authentication, database and matching service (EU multi-region eur3, functions in europe-west3) and Crashlytics for crash reporting; Apple App Store and RevenueCat (subscriptions). Each processes data only as needed to provide the service.

Children

crosd is not directed at children under 13 and we do not knowingly collect their data.

Changes

We will post any changes to this policy on this page and update the effective date. The 6 August 2026 revision corrects an earlier description of how matching works: it said only irreversible place-time hashes were exchanged and that your trace stayed on your device. Matching moved to our server before launch, and the text above now describes what the app actually does.

Contact

Questions or requests: tahtaciburak@gmail.com