Crossd
Privacy PolicyTerms of Service

Crossd Privacy Policy

Effective 28 June 2026. Version 1.0.

Crossd is operated by Hillway Holdings Limited ("we", "us"), Sheffield, United Kingdom. We take your privacy seriously, because the data this app handles, where you have been and who you have crossed, is among the most sensitive there is. This policy explains, in plain English, what we collect, how we use it, and the control you have.

Our privacy promise

What we collect

  1. Account details. Your name and email address, or, if you use Apple or Google, the identifier they give us (Sign in with Apple may give us a private relay email rather than your real one).
  2. Location history. Places and times built on your device from the photos and Google Timeline data you choose to import, and, if you turn it on in future, from background location. This is stored on your device, protected by iOS file encryption.
  3. Derived match tokens. If and when you enable cloud matching, your device uploads only one-way salted hashes of a coarse place-and-time, never your actual coordinates and never place names. These let the server find overlaps between consenting friends without holding a readable history.
  4. Friends and reactions. Who you have connected with, and the canned reactions (such as a wave) you send. We do not host private messages or photos.
  5. Basic diagnostics. Limited technical information needed to run and fix the app.

How we use it

Our lawful bases under UK GDPR are your consent and the performance of our contract with you. You can withdraw consent at any time.

What leaves your device

Your raw location history does not leave your device unless you choose to share it. When cloud matching is enabled, only the hashed tokens above are uploaded. Place names and exact coordinates are resolved and shown on your device.

Sharing

We only reveal a crossing to a friend when both of you have an active, mutual agreement to compare. We do not sell, rent, broker, or share your location with advertisers or third parties for their own purposes.

Face ID and Touch ID

If you turn on the app lock, your face or fingerprint is checked by Apple on your device. We never receive, see, or store your biometric data.

Keeping and deleting your data

You can delete all of your data from inside the app at any time, and you can sign out or close your account. When you delete your data it is removed from your device, and any uploaded match tokens are deleted from the server.

Your rights

Under UK GDPR you can ask to access, correct, erase, or receive a copy of your personal data, object to or restrict processing, and withdraw consent. To exercise these, contact privacy@crossd.app. You can also complain to the Information Commissioner's Office (ico.org.uk).

Security

We encrypt your data at rest, store account credentials in the device Keychain, and use hashed tokens so the server never holds a readable location history.

Age

Crossd is for people aged 13 and over. If you are under 18, please make sure a parent or guardian is happy for you to use a location app, and only connect with people you actually know. We do not knowingly collect data from children under 13, and we will delete any such account we find.

Changes

If we make a material change to this policy we will update the version and ask you to agree again.

Contact

Hillway Holdings Limited, Sheffield, United Kingdom. privacy@crossd.app.