Almost Crossed is designed to help two people discover places where their lives may have crossed before they knew each other. The app is built around local processing, temporary encrypted exchange, and no account requirement.
This Privacy Policy explains what information Almost Crossed processes, what may leave your device, how analytics and attribution are used, and the choices you have.
Who We Are
Almost Crossed is provided by the Almost Crossed team.
Contact: almostappsup@gmail.com
Summary
- No account is required to use the app.
- We do not sell your personal information.
- We do not show third-party ads inside the app.
- Your photo library is scanned locally on your device.
- Your photos and videos are not uploaded by Almost Crossed.
- When you use a reveal or relay sync option, the app may send temporary encrypted payloads so another device can receive them.
- We use limited analytics to understand whether the app works correctly and to improve reliability and core product flows.
- We use attribution and measurement tools to understand whether app install and acquisition campaigns are working.
- If you choose to send rating feedback, the feedback text and limited app/device context are sent to our support inbox.
- Purchases are processed by Apple. We use RevenueCat to validate purchases and restore Full Access, and our access-verification service checks purchases before enabling shared access.
- If tracking permission is required by iOS, we ask for permission through Apple's App Tracking Transparency prompt before accessing the device advertising identifier for tracking.
- You can reset local app data from the app settings.
Information Processed On Your Device
Almost Crossed may process the following information locally on your device:
- Local profile information, such as the display name and optional avatar you choose.
- Photo and video metadata from your photo library, including dates, times, and location metadata when available.
- Private memory tokens generated from that metadata.
- Approximate places, dates, and match results shown inside the app.
- QR codes used to start a private reveal session.
- Nearby-device discovery information when you use Bluetooth or local-network reveal.
- Local app settings, scan progress, and saved reveal results.
- App usage and diagnostics events, such as screens viewed, buttons tapped, permission outcomes, scan progress counts, reveal flow status, error codes, app version, device type, operating system, and performance timing. Almost Crossed uses this information to create a private memory trail, compare it with another person's memory trail, and show possible shared crossings.
Photo Library
If you grant photo library access, Almost Crossed reads photo and video metadata on your device. This can include creation dates and embedded location metadata. Almost Crossed does not upload your photos or videos to our server.
The app turns photo and video metadata into approximate private tokens. These tokens are used to compare possible overlaps with another device.
Camera
Almost Crossed may ask for camera access so you can scan a QR code from another device and start a private reveal session.
Bluetooth And Local Network
Almost Crossed may use Bluetooth and local-network discovery to find nearby phones and exchange encrypted reveal data directly between devices when available.
Relay Server
If direct nearby sync is unavailable or you choose QR relay sync, Almost Crossed may use our relay server to pass encrypted reveal data between the two devices.
The relay server may receive:
- A temporary session code and session-specific authorization credentials.
- Message identifiers, encrypted payload sizes, and integrity hashes.
- Encrypted payloads created by the app.
- Payload type, sender role, creation time, expiration time, and delivery status.
- Standard technical request information that servers may receive, such as IP address, timestamps, headers, and diagnostic logs. The relay server stores encrypted payloads only temporarily. Relay sessions expire automatically, normally within 30 minutes of creation. Expired payloads are removed by periodic cleanup, which runs at least once per minute. Payloads may be removed earlier after the receiving phone acknowledges delivery, when both phones complete the session, or when a participant deletes the session.
The relay server is not designed to receive or store your raw photos, videos, full photo library, or full location history.
What Is Shared With The Other Person
During a reveal, the app first compares protected clues using private set intersection, a cryptographic process for finding clues both phones share. Detailed crossing information is exchanged only for shared matches. Both participants need compatible versions of the app.
The other person may receive:
- Your chosen display name.
- Your optional avatar if you added one.
- Approximate shared place information for matching crossings.
- Approximate date or time information for matching crossings.
- Match confidence and related reveal details.
- A public installation key and a signed proof of Full Access when a purchaser shares access for that reveal. This proof identifies the receiving installation and reveal, not the purchaser's Apple account or payment details. Non-matching private places are not intentionally revealed to the other person.
Notifications
Almost Crossed may use local notifications to tell you when a local scan or reveal action is complete. Current app notifications are intended for app functionality, not advertising.
Rating Feedback
If you choose a rating of three stars or fewer in the in-app feedback prompt and submit it, Almost Crossed sends the following information to our relay service and email delivery provider, Resend, so it can reach our support inbox:
- The star rating and feedback text you enter.
- The app version, platform, operating system version, prompt trigger, submission time, and a random submission identifier.
- Standard technical request information that servers may receive, such as IP address, timestamps, headers, and diagnostic logs. Rating feedback is used to respond to product issues and improve the app. Do not include sensitive personal information in the feedback field. App Store ratings and reviews are separately processed by Apple under Apple's terms and privacy policy.
Purchases And RevenueCat
Almost Crossed offers an optional one-time Full Access purchase. Apple App Store processes the payment. Almost Crossed does not receive or store your full payment card details.
We use RevenueCat to validate the purchase, determine whether Full Access is active, and restore access on supported devices. RevenueCat may process:
- An anonymous app customer identifier generated for this installation.
- Store, product, transaction, entitlement, and purchase-status information.
- App version, platform, device, network, and related technical information.
- Apple receipts and signed transaction information required to validate the purchase. Purchase data is used for app functionality, customer support, fraud prevention, and purchase analytics. It does not intentionally include your raw photos, videos, private memory trail, crossing locations, or encrypted reveal payload contents.
Purchase Verification And Shared Access
When a Full Access purchaser enables access for a partner, the app sends an Apple-signed transaction and the purchaser installation's public key to our access-verification service over an encrypted connection. The service checks Apple's signature, the app and product identifiers, the transaction environment, and current ownership and entitlement information in RevenueCat. This may involve processing transaction identifiers, purchase status and revocation information, verification results, and ordinary request information such as IP address and time. The service does not need your Apple account password or payment card details.
The service returns a signed access certificate tied to that installation's public key. The purchaser's phone uses a device-only private key to create a grant for the specific partner installation and reveal. The partner receives the certificate and grant inside the encrypted exchange, but not the Apple transaction or receipt. Initial certificate issuance and refresh require an internet connection. A valid cached certificate can be used for offline sharing.
Certificates last up to 30 days and the app attempts to refresh them when fewer than seven days remain. A refund or revoked purchase can therefore take up to the remaining certificate lifetime to prevent further offline grants. Previously unlocked saved reveal results are not automatically relocked when a certificate expires. The access-verification service processes transaction proofs in memory and does not intentionally retain a separate receipt database or log receipt bodies. Apple and RevenueCat maintain their own purchase records.
Analytics And Attribution
Almost Crossed uses limited analytics to monitor app reliability, understand whether important flows work, diagnose errors, and improve the product.
Analytics may include:
- App opens and screen views.
- Button taps and selected app actions.
- Permission request and permission result status.
- Photo scan progress counts, such as assets scanned, geotagged assets found, token counts, selected scan range, and scan duration.
- Reveal flow status, such as selected transport, QR creation or scan status, reveal success or failure, and crossing counts.
- Error codes or short error messages.
- App version, platform, device type, operating system version, and timing information.
- A local app profile identifier after you create a local profile.
- Purchase-flow events, such as viewing the Full Access screen, starting, completing, failing, or restoring a purchase, the product identifier, and the displayed localized price. Almost Crossed uses analytics and attribution service providers including Firebase Analytics, Amplitude, AppsFlyer, TikTok Business, and Meta App Events when configured. These providers process the corresponding app and campaign measurement events for us.
Almost Crossed may also use attribution data to measure the performance of app install campaigns and understand which campaigns led to app installs or app activity. This may include device identifiers, advertising identifiers, install information, campaign information, app events, device information, IP address, and related technical data.
When required by iOS, Almost Crossed asks for permission using Apple's App Tracking Transparency prompt before accessing the device advertising identifier or using data for tracking across other companies' apps and websites. If you deny tracking permission, attribution and measurement may still occur in a limited way using data that does not require tracking permission.
Analytics and attribution do not intentionally include your raw photos, videos, full photo library, full location history, encrypted relay payload contents, QR session secrets, or the full content of your private memory trail.
We do not sell analytics or attribution data. We do not show third-party ads inside Almost Crossed.
Data Retention
Local trail data remains on your device until you delete it, reset the app data, or uninstall the app. Device-only Keychain items may survive an uninstall on the same device; cached access certificates are accepted only while valid and expire within 30 days. Deleting the app does not delete purchase records held by Apple or RevenueCat.
Relay sessions normally expire within 30 minutes of creation, and expired payloads are removed during the next cleanup cycle, within approximately one further minute. A service restart may end a temporary session earlier.
Server logs, support feedback emails, analytics events, and attribution events may be retained for security, debugging, abuse prevention, service reliability, customer support, product-quality analysis, and campaign measurement.
Apple and RevenueCat may retain purchase records as required to operate their services, comply with law, prevent fraud, and support purchase restoration.
Your Choices
You can:
- Deny or revoke photo library, camera, Bluetooth, local network, notification, and tracking permissions in iOS Settings.
- Delete your memory trail in the app.
- Delete revealed crossings in the app.
- Reset local app data in the app settings.
- Restore Full Access from the app settings if you previously purchased it with the same supported store account.
- Delete the app from your device. Because Almost Crossed does not require an account, most data control happens directly on your device.
Advertising
Almost Crossed does not show third-party ads inside the app. Almost Crossed may use attribution and measurement tools to understand whether our own app install or acquisition campaigns are working.
Children
Almost Crossed is not directed to children under 13. If you believe a child has provided personal information to us, contact us so we can review and respond.
Security
Almost Crossed uses authenticated encryption for reveal payloads, private set intersection for comparing clues, and temporary relay storage. On iOS, the app applies file protection to local trail data, excludes its Documents and Application Support folders from device backups, and stores the private access-signing key and cached purchase certificate in device-only Keychain storage. No method of transmission or storage is completely secure, but we design the app to minimize the personal information sent off device.
International Processing
If you use the relay server, encrypted payloads and technical request information may be processed in the country or region where our hosting provider operates the relay service.
Analytics, attribution, purchase-validation, and app-store service providers may process data in the United States and other countries where they operate.
Changes To This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will update the "Last updated" date and provide the updated policy where users can access it.
Contact
For privacy or support questions, contact:
