Privacy Policy
Crosspace is a client-only app. It connects to cloud storage accounts that you already own, and moves your files directly between your device and those accounts. Crosspace runs no file server and stores none of your files. This policy explains the narrow set of information that does get handled, and by whom.
Crosspace has no account and no sign-in. You do not register, and there is nothing to log in to. The only accounts involved are the cloud storage accounts you choose to connect, which stay yours.
What stays on your device
- Cloud account credentials. OAuth tokens for Google Drive, Dropbox and Box, and the access keys you paste for S3-compatible buckets, are held in the iOS Keychain on your device. They are never transmitted to us, because there is no "us" to transmit them to — Crosspace has no server that receives them.
- Your files. Uploads and downloads go directly between your device and the cloud provider you chose. File contents never pass through infrastructure we operate.
- Your library index. The list of what lives where is a local database on your device.
- Vault files. A
.cpvaultfile is encrypted on your device with a passphrase only you know, and saved wherever you choose to put it. We cannot read one, and we do not receive one.
What is collected, and by whom
- Purchases (Apple and RevenueCat). Apple processes the payment; we never see your payment details. RevenueCat records which Crosspace Plus product was purchased and whether it is active, against an app-generated identifier, so the app knows to unlock Plus. See RevenueCat's privacy policy and Apple's privacy policy.
- Your cloud providers. When you connect an account, that provider sees the requests Crosspace makes on your behalf, under their own privacy policy. Crosspace requests the narrowest access each provider offers for the job.
There is no analytics SDK, no advertising SDK, no tracking identifier, and no tracking across apps or websites. Nothing is sold or shared with data brokers.
Permissions the app asks for
The app asks for these only when you use the feature that needs them.
- Photo library — only to read the photos and videos you pick for upload, or that Photo Backup is set to copy into your own cloud accounts.
- Camera — requested by the system media picker so you can choose photos and videos to upload. Crosspace never opens the camera itself.
- Local network — only for LAN Host, which is off unless you start it. It serves your library to another device on the same Wi-Fi and reaches nothing outside your network.
- Face ID — only to unlock the app, handled entirely by iOS. Your biometric data never reaches Crosspace.
Retention and deletion
Because the data lives on your device and in your own cloud accounts, deleting the app removes the local database and the stored credentials. Disconnecting a cloud account in Crosspace removes its stored token from your device. Files already uploaded stay in your cloud accounts until you delete them there.
There is no Crosspace account, so there is nothing held about you for us to delete and no request you need to send us. A purchase belongs to your Apple Account and is not affected by deleting the app; you can restore it later.
Children
Crosspace is not directed at children under 13, and we do not knowingly collect information from them.
Changes
If this policy changes, the updated version is posted here with a new date.
Contact
Questions about this policy: 123supportforapp@gmail.com