The plain-language promise
Crossed does not reveal who tapped first or either person’s exact tap time. Released mutual Crossings use a shared 30-minute display bucket.
The current Android app contains no advertising, session-replay, or behavioral-analytics SDK. It does not request access to contacts, location, camera, microphone, photos, or broad device storage.
Crossed is not “zero knowledge” or end-to-end encrypted. Its backend briefly needs server receipt times to decide whether two taps met.
What Crossed handles
Your account
Crossed creates a pseudonymous Firebase account. No email address, phone number, display name, or partner approval is required for signup. The app records a consent-version identifier and the time you confirmed that you are at least 18. Before you continue, the same screen explains that mutual Crossings stay in the calendar for 30 days. This is self-attestation, not identity or age verification.
The account also stores the locale and IANA timezone supplied by Android. These support language, calendar, daily-boundary, and release behavior; Crossed does not request GPS or Android location permission.
Your connection and invitations
Crossed stores one active connection at a time, invitation status, and the information needed to stop a blocked pair from reconnecting. The inviter’s Android timezone at invitation creation becomes the connection’s fixed timezone for daily boundaries and the 21:00 release schedule. An invitation contains a random secret in the link fragment; the server stores a one-way digest rather than the raw secret. Anyone who receives a valid bearer link could still be the first eligible person to claim it, so share it carefully.
A connection between two pseudonymous accounts can still reveal an intimate relationship or sexual orientation. Crossed treats pairing information as highly sensitive even when the accounts contain no names or relationship labels.
Crosses and released Crossings
For matching, the backend processes account and connection identifiers, server receipt times, a request identifier, the daily count/cooldown state, and short-lived waiting pair state. The other person cannot directly read these records. A released Crossing contains a coarse shared time bucket and release state, not either original tap time.
Notifications, recovery, and device state
If you opt into notifications, Crossed uses Firebase Cloud Messaging device information and your privacy choice for lock-screen visibility. Passkey recovery stores public-key credential material; the biometric or device PIN stays with your device or credential provider. A separately stored, one-use recovery code is available as a fallback.
Local Android data
The app keeps consent, connection/widget state, notification choices, cooldown/count cache, and limited recovery or deletion markers in app-private storage. Android backup and device-to-device transfer are disabled for this app data. Crossed does not claim that every local value is separately cryptographically encrypted.
Support correspondence
The public support mailbox is not configured in this beta. When it is added, the final notice will cover the correspondence and its reviewed retention rule.
Why the data is used
- To create one private two-person connection and validate one-use invitations.
- To enforce the 20-minute matching window, the eligibility cooldown, and a boundary of 12 admitted Cross submissions per connection day.
- To release mutual Crossings later without exposing who tapped first or an exact time.
- To keep up to 30 days of released calendar history and a cumulative released total for the current connection.
- To deliver optional neutral notifications and honor both people’s independent Live Crossings choices.
- To provide recovery, export, end-connection, block, and account-deletion controls.
- To prevent abuse, replay, unauthorized database access, and repeated invitation claims.
When a mutual match completes, the server replaces the two original tap times with one shared cooldown anchor. The caller-visible daily number is a private submission count, not proof that every submission was eligible or became a match.
Private Cross activity is not used as marketing telemetry. The website’s invitation fallback does not inspect or send the invitation fragment to analytics or the Play Install Referrer.
Selected application-enforced retention boundaries
“Stops being matchable” is immediate product behavior. Physical deletion by a database time-to-live process is asynchronous and may occur later.
This table covers records whose timing is enforced by current application logic. Provider backups, platform security logs, and hosting logs follow separately verified production schedules.
| Record | Retention rule in the current build |
|---|---|
| Unmatched raw matching state | Stops being matchable after 20 minutes; queued for asynchronous TTL deletion. |
| Per-account tap-ingress guard | 2 hours. |
| Opaque processed-request receipt | 48 hours. It uses a one-way owner hash and excludes the raw account ID, pair ID, and tap time. |
| Caller-only daily submission counter | 48 hours, and removed when the connection ends. |
| Unclaimed invitation | 24 hours; a used claim receipt lasts 24 hours after claim. |
| Released coarse Crossing | 30 days from release. |
| Current connection’s cumulative total | For the life of that connection. It resets when the connection ends. |
| Notification device record | Up to 60 idle days, and removed when the connection ends or the account is deleted. |
| Account, consent, locale, and timezone | While the account is active; the dormant-account retention boundary is still being defined. Removed by account deletion. |
| Connection membership and Live choices | For the life of the connection; removed when it ends. |
| Pending Live delivery fields | Only after a mutual match until the notice is sent, canceled, or fails; the randomized due time is normally 25–45 minutes after matching and is then removed. The first-of-day reservation clears shortly after that connection day closes. |
| Block record | Until either involved account is deleted. The current product has no unblock control. |
| Active passkey public key and recovery-code digest | For the account’s life, or until replaced or reset. |
| Short-lived recovery records | Passkey challenges: 5 minutes; unconfirmed code digest: 10 minutes; retry receipts and request bindings: 15 minutes; recovery rate-limit enforcement window: 15 minutes; rate-limit record: 30 minutes. |
| Identifiable operational or security logs | The engineering plan uses a 14–30 day range; the exact production schedule remains a publication gate. |
| Support correspondence | No public support mailbox is configured in this beta. |
| Deletion job | Until cleanup and Firebase account deletion finish; the completion tombstone lasts 24 hours. |
Provider backup deletion timing is being verified for the public notice. This beta copy does not imply an instant provider-backup erasure schedule.
Providers and processing regions
Crossed currently uses Google/Firebase services for pseudonymous authentication, server functions, the database, push messaging, app installations, and Play Integrity/App Check. Your chosen credential provider may store or sync passkeys under its own terms.
For the SEA-first deployment, relationship data and server functions are configured in Singapore. Firebase Authentication includes processing in US data centers, and notification-delivery metadata is visible to Google. Crossed therefore does not claim that all data stays in Singapore.
No marketing pixel or behavioral analytics provider is enabled in the current app or this website.
Your controls
- Export: download a filtered in-app JSON view of selected retained account and activity data. It excludes the other person’s activity, unmatched raw taps, unreleased Crossings, notification tokens, and authentication verifier material. It is not a complete authenticated access-request response.
- End connection: disconnect both people immediately. Each person keeps only their own already released Crossing copies until their original 30-day expiry.
- Block: end the connection and prevent those two accounts from reconnecting. The other person is not told that a block occurred.
- Delete account: disconnect both people and sweep your account, credentials, invitations, blocks, devices, active data, and your archived history. The other person keeps only their own previously released copies until expiry.
Sensitive export and deletion actions require recent passkey or recovery-code verification. See the account deletion page for the in-app steps and the public deletion-request option.
Security boundaries
The release configuration disables cleartext network traffic, the database rejects direct client reads and writes, and backend calls require authentication plus App Check where configured. Invitation secrets remain bearer credentials; a forwarded valid link may be claimed by its first eligible recipient.
No system can promise absolute security. Crossed avoids broad claims such as “military-grade,” “zero knowledge,” or “we cannot see tap times.” The narrower controls above are the promises this build can support.
Privacy contact
Questions or privacy requests can be sent to crossedlabs@gmail.com.