Privacy policy
Last updated August 15, 2026
WeCrossed is built so that we, the people who run it, know as little about you as possible. This page explains what that means in practice, including your rights under the EU/UK GDPR and the California CCPA.
1. Who we are
WeCrossed is operated by Ticketbuddy VOF (Van Meerstraetenlaan 8, 3120 Tremelo, Belgium, VAT BE 0787.298.025), the data controller for the data described on this page. Reach us at contact@wecrossed.app for any privacy question or request.
2. What we don't collect
- No GPS or precise location. WeCrossed detects that two phones were physically near each other over Bluetooth. It never records or transmits coordinates.
- No plaintext profile, message, or match content. Everything your device sends leaves already encrypted, so our servers only ever hold ciphertext.
- No contacts, browsing history, or data from other apps.
3. On-device safety checks and encryption
A few things WeCrossed does happen entirely on your device, so they never touch our servers at all:
- Nudity screening. Every photo you add to your own profile is checked by a local image classifier before it's saved. A flagged photo is discarded and never added. The same check runs on photos you receive from a match, but there it only blurs the photo behind a tap to reveal, since it's your device making that call on content we never see.
- Selfie verification. To earn a "verified" badge, you take a live selfie, with a blink check to rule out a static photo, and a local model compares it against your own profile photos. The resulting face data is stored in your device's secure storage and is never uploaded.
Neither of these ever sends a photo, face embedding, or scan result to us or to any third party.
Two kinds of encryption handshake also happen before your data goes anywhere:
- Encounters. When two phones physically cross paths, they run a key exchange directly over Bluetooth to agree on a shared secret for that encounter. It's generated fresh each time and never leaves your device unencrypted.
- Friends. Adding a friend by QR code or link encodes a cryptographic fingerprint of their key, not the key itself. Your phone fetches the actual key afterward and checks it against that fingerprint, so our server can't substitute a different one.
4. What we collect
To make matching and messaging work at all, our server (the "relay") temporarily stores:
- Encrypted profile bundles and messages, addressed only by random tokens generated on your device, never by your name, email, or a persistent account ID.
- If push notifications are enabled, a push token so your phone can be woken up to check for a match. Push notifications are on by default and can be turned off at any time. The token is tied to your device, not to your identity.
Every one of these records carries an automatic expiration and is deleted on schedule. Nothing is kept indefinitely "just in case."
Separately, our server briefly uses your IP address to rate-limit requests and block abuse, the same way most servers do. It's not logged against your profile or stored long-term, and it's not something we use to work out where you are.
5. Bluetooth and notifications
Bluetooth permission
WeCrossed asks for Bluetooth access to detect nearby encounters. iOS may also request location or "always allow" Bluetooth permission as part of how background Bluetooth works on that platform. This is a platform requirement for background scanning, not something WeCrossed uses to read or store where you are.
Push notifications
Push notifications are delivered via Apple's or Google's service using a device token. They're optional, on by default, and can be turned off in the app at any time. Nothing else about matching or messaging depends on them.
Plain notifications
Plain notifications are a separate permission from push notifications, and they're optional too. They're split into types like new encounters, matches, and chat messages.
- Android: each type has its own toggle in system settings, except the persistent one required to keep background detection running as a foreground service. Turning that one off stops detection.
- iOS: per-type toggles are planned but not yet built.
7. Friends carrying or vouching for your profile
WeCrossed has three optional, off-by-default toggles that let people you trust help you find matches:
- Let friends carry my profile. A confirmed friend's phone can advertise your profile alongside their own when they cross paths with someone, so you can get a match without being there.
- Let friends introduce me to their crossings. A confirmed friend can vouch for your profile to someone they've crossed paths with.
- Let crossings introduce me to their friends. Someone you've crossed paths with can vouch for your profile to one of their own confirmed friends.
All three are off until you turn them on, and you can turn any of them off again at any time. Your profile is only ever carried or vouched for as the same encrypted bundle described above. Whoever's carrying or vouching for it can't read it.
8. Legal basis for processing
- Consent. Detecting encounters, building a profile, sending push notifications, and friend beaconing/vouching all require you to actively turn the relevant feature on in the app.
- Legitimate interest. Rate limiting and abuse prevention on our server, scoped to the minimum needed to keep the service running.
9. Data location
Our infrastructure runs on Cloudflare. Requests are handled at whichever location is nearest you, but nothing is stored there. The data itself stays in the EU: the database uses an EU jurisdiction setting, and encrypted profile bundles are held in Cloudflare's Western Europe (WEUR) region.
10. Your choices
- Pausing beaconing in the app stops all encounter detection immediately.
- Ignoring a match is silent. The other person is never told, and nothing about the interaction is retained beyond what expires normally.
- You can delete your profile and data from within the app at any time.
11. Your rights
Most of what a typical data request asks us to produce, correct, or delete does not exist on our servers in the first place. Profile and message content leaves your device already encrypted, so we hold ciphertext, not personal data we can read. Where we do hold something, like an encrypted profile bundle or a push token, it's addressed by a random token rather than your name or email, and it expires automatically.
EU/UK residents (GDPR)
Under GDPR and UK GDPR, you have the right to:
- Access the data we hold about you.
- Correct inaccurate data.
- Erase your data. See deleting your account for exactly what that removes immediately and what briefly persists.
- Restrict or object to processing.
- Data portability. In practice this just means your own device already has your data in a usable form, since we never hold a readable copy to export on your behalf.
- Withdraw consent at any time, without affecting past processing.
California residents (CCPA)
We don't sell or share your personal information, as those terms are defined by the CCPA, so there's nothing to opt out of. You still have the right to:
- Know what personal information we collect, and why. See section 4 above.
- Delete your data. See deleting your account.
- Correct inaccurate data.
- Not be discriminated against for exercising any of these rights.
Most of these you can exercise directly in the app. For anything else, email contact@wecrossed.app and we'll respond within the timeframe GDPR or the CCPA requires.
12. Children
WeCrossed is not directed at, and may not be used by, anyone under the age of 18.
13. Complaints
If you believe we've mishandled your data, you can lodge a complaint with your local data protection authority. We'd also appreciate the chance to make it right first at contact@wecrossed.app.
14. Changes to this policy
If this policy changes in a way that matters, we'll update the date above and, where appropriate, notify you in the app.
15. Contact
Questions about this policy? Reach us at contact@wecrossed.app.