Skip to content
Crossways

Legal · Last updated 18 September 2026

Crossways Privacy Policy

For the short, readable version of the same ground, see What you share. For the location permission on its own, see why we ask for background location.

The short version

Crossways tells you when a friend is in the same city as you. To do that it needs to know which city you are in, including when the app is closed.

Crossways keeps a record of which cities you have been in, for as long as your account exists. Not thirty days — all of it, from the day you sign up until the day you delete your account. That is deliberate: it is what lets the app show you where you have been. If you would rather it did not, the app is not for you, and deleting your account deletes the record.

We do not sell your data. There are no advertising SDKs in the app. We do not share your location with anyone except the friends you have accepted — with one mechanical exception, the push notification, which is described below because it is the kind of thing a privacy policy should not leave out.

What we store

Your phone number

You sign in with your phone number. It is stored, and so is a SHA-256 hash of it, which is how friends find you (see below). Sign-in itself is handled by Clerk, which stores the number as well and sends the verification codes.

Which city you are in, and which cities you have been in

When your phone notices you have arrived somewhere new, it sends your position to our server. The server works out which city that is and throws the position away before the request finishes. What it keeps is the city, the coordinates of the city's centre — not yours — and the times you arrived and were last seen there.

Your exact position is never written to a database, an application log, or an error report. It exists on our servers only for the fraction of a second it takes to answer the question “which city is this?”, and only in memory.

The app also tells the server whether you are at home, as a yes or no. Your home address is never sent and we could not store it if we wanted to — there is no column for it. The phone decides the question and sends the answer.

Your contacts, when you scan them

If you use the contact scan to find friends, the app does not upload your contacts. It converts each phone number to a standard format, hashes it, and sends the hashes. We compare them against hashes of our own users' numbers and tell the app which ones matched. The uploaded list is not stored.

Be clear about what that is and is not. It is not anonymity. There are few enough possible phone numbers that anyone holding the hashes and some computing time could work out the numbers behind them. What it does is reduce the damage if a request log ever leaked, and it means we do not keep a copy of your address book. It does not make your contacts secret from us during the scan.

Your friends and your matches

Who you are connected to, who asked whom, and who blocked whom. Every time you and a friend are in the same city at the same time, that is recorded: the two of you, the city, and when it started and ended. This is the history the app shows you, and it is kept for as long as your account exists.

Your phone, and your settings

An identifier the app generates for your install, your notification token if you allow notifications, whether you are on iOS or Android, and when the app last checked in. Plus your display name, your match radius, your time zone, and whether you have sharing paused.

Two internal records

A security log. Actions taken on your account — signing in, registering a phone, a presence being written, a friend request — with a time and, where a city is relevant, the city. It records that something happened and never contains a coordinate. It is append-only and tamper-evident by design, which matters for what happens when you delete your account; see Deletion.

Product analytics. Counts of things happening in the app so we can tell whether it works — a permission granted, a notification opened, a presence written. These carry a city at most, never a coordinate, never a phone number, and never a contact hash.

What we never store

  • Your exact location. Not in the database, not in logs, not in error reports.
  • Your home address, or any other place you mark as home.
  • Your contact list.
  • Anyone's location history other than as a list of cities and times.

Who else can see any of this

Your friends — the ones you accepted — see that you are in a city when you are both in it, and see your shared history together. Nobody else using Crossways can see you. There is no directory, no profile pages, and no feed.

The services that run the app. They process your data on our instructions and for no purpose of their own:

  • Clerk — sign-in. Holds your phone number.
  • Neon — the database. Holds everything described above.
  • Vercel — runs the API. Its request logs are scrubbed of phone numbers, contact hashes and coordinates before anything is written.
  • Sentry — crash and error reports, with the same scrubbing applied twice: once to the message, and once over the whole report before it is sent.
  • Expo, Apple and Google — push notifications. A Crossways notification reads “Chris Alvarez is in Dallas too”, and that text has to pass through Expo's push service and then Apple's or Google's to reach your phone. So those companies handle a friend's name and a city on its way to you, the same way they handle the text of every other notification you receive. Turning off notifications for Crossways stops it.

City lookup happens entirely on our own database, from a public list of world cities. No mapping or geocoding company is involved and none of them ever sees where you are.

Where your data is. The database is hosted in the United States — Amazon's Ohio region. If you use Crossways from outside the United States, your information is stored there.

Beyond that: we do not sell your data, we do not share it for advertising, and the app contains no advertising or tracking SDKs.

We will disclose data if we are legally required to, and we will tell you unless we are forbidden from telling you.

Retention and deletion

Everything is kept for as long as your account exists. There is no expiry, no rolling window, and nothing that ages out. Your presence history and your match history go back to the day you signed up.

Deleting your account deletes it. Settings has a delete option that asks you to type a confirmation. When you confirm, your account and everything attached to it — your number, your friends, your presence rows, your match history — are deleted outright, not marked as deleted. Your sign-in identity at Clerk is deleted with it. This happens immediately, and in any event within 24 hours.

Our database provider keeps backups, and they take longer to age out. Deletion removes your data from the live database straight away. Neon, which runs that database, keeps encrypted backups for up to 30 days and can restore the database to any point in the previous 24 hours. So for a short period after you delete your account, your data still exists inside those backups, and it disappears as they expire rather than at the moment you press the button. We do not use backups to bring deleted accounts back. This is how every hosted database works and we would rather say so than let “deleted” carry more weight than it can hold.

One exception, and it is worth reading. The security log described above cannot be deleted row by row, because a log that can be selectively erased is not a security log. Instead, when you delete your account, every entry naming you has your identity replaced with a random value that points back to nothing, and anything identifying in it is cleared. What remains is a record that certain kinds of action happened at certain times, attached to nobody. We cannot get from those rows back to you, and neither can anyone who takes the database as it stands. The same backup window applies here as above: a copy of the database restored from a point before your deletion would still have the original entries in it, because the replacement had not happened yet.

Your controls

  • Pause sharing. Stops your location being reported at all, while your account stays. Nobody is told you paused, and the app never shows the difference between a paused friend and one who is simply not nearby.
  • Mute a friend to stop notifications about them, or block them to end the connection.
  • Set your match radius, which decides how close counts as the same place. If you and a friend set different radii, the tighter one wins.
  • Revoke location permission at any time in your phone's settings. The app will tell you what stopped working and will not work around it.
  • Delete your account, as above.

Depending on where you live you may have further rights — to a copy of your data, to correction, or to deletion. Write to the address below and we will answer.

Age

Crossways is for adults. You must be 18 or older to use it. It is not directed at children, and we do not knowingly keep an account belonging to anyone under 18 — if we learn of one, we delete it and everything attached to it.

We do not verify anyone's age. Signing up means you are telling us you are 18, and that is the whole of the check.

Changes

If what the app does with your data changes, this page changes before the build that does it is released — not after. The date at the top is when it was last revised.

Who we are, and how to reach us

Crossways is operated by AidStation Pro, LLC, which is the company responsible for the data described on this page.

AidStation Pro, LLC
509 Williams Avenue
Cleburne, TX 76033
United States
info@aidstation.pro