CrashMeet is a social meetup app that puts live events on a map so you and the people you choose can show up together. Because the app is about being somewhere with other people, it handles genuinely sensitive information — your precise location, your photos, and your contacts. This policy explains exactly what we collect, why, who can see it, and how to get rid of it.
CrashMeet (the "app") is operated by CRASHMEET, LLC ("CrashMeet," "we," "us"), a Utah limited liability company. This policy applies to the CrashMeet mobile apps for iOS and Android and to crashmeet.app.
The short version. We collect what the app needs to work and nothing for advertising. We do not sell your personal information. We do not share it with third parties for advertising or cross-app tracking. We do not use third-party ad networks. Your live location is only shared when you deliberately turn on sharing, only with the people you pick, and only for as long as that share lasts. Your phone's address book never leaves your device in readable form — only irreversible hashes do. You can delete your account, and everything tied to it, from inside the app.
Contents
- Information we collect
- Location — how sharing actually works
- Contacts and finding friends
- Photos, videos, camera, and microphone
- How we use information
- Who can see what
- How we share information
- How long we keep information
- Your choices and controls
- Deleting your data and your account
- Your legal privacy rights
- Security
- Children
- Where your data is stored
- Changes to this policy
- Contact us
1Information we collect
Information you give us
- Phone number. CrashMeet accounts are created with your phone number, verified by a one-time SMS code. This is our only sign-in method — we do not ask for a password or an email address.
- Profile information. Display name, username/handle, profile photo, bio, a general location you type in (such as a city), a social link, and interests you select. All of it is optional except a display name.
- Content you create. Events you host, RSVPs and "crashes," messages in event chats and direct messages, comments, photos and videos you post, group memberships, and the groups you create.
- Choices and settings. Notification preferences, presence and sharing preferences, per-person and per-group sharing settings, per-event sharing overrides, place labels you create, pinned highlights, and the accounts you block.
Information we collect automatically
- Location. Approximate and precise location, as described in Section 2.
- Motion and device sensors. Accelerometer and motion-activity readings. We use these for two things: to decide when it's worth waking up location (a phone sitting still doesn't need GPS, which saves your battery), and to drive the visual "speed trail" effect on live shares. Motion data is processed on your device and is not stored as a history of your movement.
- Device and technical information. App version and build number, device platform and model, operating-system version, language, time zone, and a push-notification token used to deliver notifications to your device.
- Diagnostics. Crash reports and error logs (via Firebase Crashlytics), including stack traces and device state at the time of a crash.
- Product analytics. Aggregate usage events (via Google Analytics for Firebase) such as app opens, screens viewed, an event being created, joining an event, and tapping an outbound ticket link. We use these to understand which features people actually use — not to build an advertising profile.
Information we derive
- Activity and momentum signals. Server-side counts of how many people have joined an event and when it was last active, used to show which events are "live."
- Co-presence. When you and another CrashMeet user are at the same place at the same time and both of you were sharing location, we may record that you were there together, which is what turns a photo into a verified shared memory.
- Suggested places. Places you frequently return to may be surfaced back to you as a suggestion (for example, labeling somewhere as "Home"). These suggestions are private to you.
Information from other sources
- Public event listings. We ingest publicly available event data (venue, date, lineup, price, ticket link) from ticketing and event providers, and headlines from public news sources, to populate the map and the in-app news digest. This is information about events, not about you.
2Location — how sharing actually works
Location is the most sensitive thing CrashMeet touches, so it gets its own section. There are two entirely separate uses, and the difference matters.
a. Finding things near you (private to you)
While you have the app open, we use your device location to show nearby events, sort them by distance, center the map, search for venues, and pick the right local news metro. This use is private to you — it is not shown to anyone else, and we do not retain a history of it.
b. Sharing your location with people (only when you turn it on)
CrashMeet has several deliberate sharing features — Pulse, Route Share, Blast, and Convoy. Each one is off until you turn it on. When you do:
- You choose the audience. Specific people, specific groups, or your family circle. Sharing is never a public broadcast to all users.
- It is time-limited. Every share has an expiry and ends on its own. You can stop it at any moment, and stopping takes effect immediately.
- You choose the precision. Some shares can be set to an approximate area rather than an exact point.
- Revoking works retroactively where we say it does. If you turn off sharing for a specific person, we stop showing them your live position, and we remove them from the audience of the share in progress.
c. Background location
An active share has to keep working when your phone is in your pocket or you're driving — otherwise the feature is useless. So while a share you started is running, CrashMeet may collect location in the background, and on Android runs a visible foreground-service notification while it does. We do not collect background location when you have no active share. There is no always-on tracking.
d. Trails and kept rides
While a live share is running, the recent path it draws on the map is ephemeral — it is not saved as a permanent record. If, at the end of a ride, you choose to keep it, that route is saved to your account as a Trail so you can look back at it. Kept Trails are yours; the audience that can see one is controlled by your per-person sharing settings, which you can change later.
e. Location attached to content
Photos and videos you post may carry the place and time they were taken so they can appear on the Moments map, on your profile, and to the audience you selected for that post. The composer tells you when a post will be visible on the map, and you can change a post's audience afterward.
f. Turning it off
You can revoke location permission entirely in your device's system settings (iOS: Settings → Privacy & Security → Location Services → CrashMeet; Android: Settings → Apps → CrashMeet → Permissions → Location). The app continues to work — you'll just lose distance sorting, nearby discovery, and any location-sharing feature.
3Contacts and finding friends
If you grant contacts permission, CrashMeet helps you find people from your address book who are already on the app. How that works technically matters, so here it is plainly:
- Your contacts are read on your device.
- Each phone number is normalized and converted into a one-way SHA-256 hash on your device.
- Only those hashes are sent to us, and only to be matched against registered users. The matching runs on our server against an index that no app or user can read — so the lookup can answer "this contact is on CrashMeet" without ever exposing anyone's number.
- Your contacts' names, numbers, emails, and any other address-book details are never uploaded to our servers. We do not build a shadow profile of people who aren't CrashMeet users.
One limit worth being straight about: a phone number is a short, predictable string, so a hash of one is not as private as a hash of a password. That is exactly why the matching index is kept unreadable rather than published or exposed to the app.
The same matching path backs the app's "search by phone number" box: you can type a number you already have and see whether it belongs to a CrashMeet account. It answers yes or no and shows that account's public profile — it never turns an account into a phone number, and it never reveals a number you didn't already have.
Granting contacts access is optional; you can decline it, revoke it later in system settings, and still use the app by searching for people by name or handle.
4Photos, videos, camera, and microphone
- Camera is used when you take a photo or record a video in the app. Microphone is used only while recording video with sound. Neither is ever accessed in the background, and we never record audio or video without you starting it.
- Photo library access is used to let you pick existing photos to post. We only receive the specific items you select.
- Media you post is uploaded to our cloud storage (Google Firebase Storage) and shown to the audience you chose for it. Photos and videos you never post are not uploaded.
5How we use information
| Purpose | What we use |
|---|---|
| Create and secure your account | Phone number, verification code, device info |
| Show nearby and relevant events | Location, general location you typed, interests |
| Let you share your location with chosen people | Precise location, motion, sharing settings |
| Connect you with people you know | Hashed phone numbers, handle, friend requests |
| Deliver messages, invites, and notifications | Content you send, push token, notification preferences |
| Build shared memories and profiles | Photos, videos, place and time, co-presence |
| Keep the app safe and enforce our rules | Reports, blocks, message content when reported, account activity |
| Fix crashes and improve the product | Diagnostics, aggregate analytics, app version |
| Comply with law and respond to legal requests | Whatever a valid legal obligation requires |
We do not use your information for behavioral advertising, and we do not sell it. We do not use automated decision-making that has legal consequences for you.
6Who can see what
Most privacy questions about CrashMeet are really visibility questions, so here is the model:
- Public to other users of the app: your display name, handle, profile photo, bio, and the earned badges on your profile. Assume anyone on CrashMeet can see these, and that anyone can find your profile by searching your name or handle.
- Visible to an audience you choose: your posts, photos, videos, and kept trails. Audiences are things like specific friends, a group, or your family circle. You can change a post's audience after publishing.
- Visible only while you're sharing, only to that share's audience: your live location.
- Visible to people in the same event or group: that you joined, and anything you say in that chat. Chat messages are not end-to-end encrypted — hosts, other participants, and CrashMeet can see them.
- Private to you: your contacts, your notification and sharing settings, your private place labels, and the location we use just to find things near you.
- Your phone number is never displayed to other users, and we never publish a directory of numbers. It is stored apart from your public profile, where only you can read it.
- But someone who already knows your number can find your profile with it. Like most messaging apps, CrashMeet lets a person check whether a number they already have belongs to an account — through contact sync or by searching a number directly. That returns your public profile (name, handle, photo); it never reveals a number to anyone who didn't already have it. If you'd rather not be findable this way, tell us at kvjensen99@gmail.com and we'll remove you from the matching index.
- Incognito: events marked incognito are hidden from feeds and profiles outside incognito mode, by design.
One honest caveat: anything you share with another person can be screenshotted, saved, or repeated by them. Choosing a narrow audience limits what CrashMeet shows; it can't control what a person does with what they saw.
8How long we keep information
| Data | Retention |
|---|---|
| Account and profile | Until you delete your account |
| Posts, photos, videos, trails you kept | Until you delete them, or you delete your account |
| Live location while sharing | Deleted when the share expires or you stop it; not retained afterward unless you explicitly keep the ride as a Trail |
| Location used to find things near you | Not retained |
| Raw contacts | Never uploaded; hashes are kept while your account exists |
| Messages | Until deleted by a participant or with the conversation or event |
| Reports and safety records | Kept as long as we need them to enforce our rules and keep removed users out — including after the accounts involved are deleted |
| Expired live shares, invites, and pings | Deleted automatically after expiry |
| Crash reports and analytics | Per Firebase's retention settings, generally up to 14 months, in aggregate or pseudonymous form |
| Records we must keep by law | As long as the legal obligation requires |
Deleted data may persist briefly in encrypted backups before being overwritten in the ordinary course of operations.
9Your choices and controls
- Location: grant, downgrade to approximate, or revoke in system settings; start and stop each share in the app.
- Contacts: decline or revoke in system settings.
- Camera, microphone, photos: decline or revoke in system settings.
- Notifications: turn off categories (direct messages, event chat, invites, social) in the app, or all notifications in system settings.
- Audience: change who can see your posts and trails at any time, per person, per group, or per post.
- Blocking: block another account to cut off contact in both directions.
- Message requests: a direct message from someone you're not connected to arrives as a request. They don't get a conversation with you unless you reply — you can leave a request unanswered, or block or report the sender from it.
- Transparency: Location Access History (Me tab → menu) shows you who actually viewed your Route Share.
- Analytics: on iOS, turning off "Allow Apps to Request to Track" and "Share iPhone Analytics" limits what diagnostics reach us. We do not request tracking permission because we do not track you across other companies' apps or websites.
10Deleting your data and your account
You can delete individual posts, photos, trails, and messages in the app at any time.
To delete your whole account, open the Me tab → menu → Leave CrashMeet in the CrashMeet app. This is immediate and cannot be undone. It removes:
- your account and sign-in credential;
- your profile, settings, and hashed contact data;
- events you created, and their chats and photos;
- your photos and videos;
- your friendships, friend requests, and group memberships;
- your direct-message conversations;
- your live shares, route shares, pings, and kept trails;
- your RSVPs and your presence in other events' attendee lists.
Three honest limits. First, messages you posted in a conversation or event that belongs to someone else may remain visible to the other participants after your account is gone, because deleting your account does not delete their conversation. Second, aggregate and pseudonymous analytics and crash records that are no longer linked to you are not deleted. Third, reports and related safety records are retained even after the accounts involved are deleted — deleting an account is not a way to erase a pattern of abuse.
If you can't reach the in-app control — for example, you've lost access to your phone number — email kvjensen99@gmail.com from an address we can verify against your account and we will delete it for you. We'll respond within 30 days.
11Your legal privacy rights
Depending on where you live, you may have rights to know what personal information we hold, access or receive a copy of it, correct it, delete it, limit our use of sensitive information, and not be discriminated against for exercising these rights.
California (CCPA/CPRA)
In the past 12 months we have collected the categories described in Section 1, including identifiers, geolocation data, audio and visual information, and internet activity, for the purposes in Section 5. Precise geolocation is treated as sensitive personal information; we use it only to provide the features you asked for and never to infer characteristics about you. We have not sold personal information, and we have not shared it for cross-context behavioral advertising. Because we don't, there is no "Do Not Sell or Share My Personal Information" link to offer. You may designate an authorized agent to make a request on your behalf.
Utah, Colorado, Connecticut, Virginia, Texas, and other US state laws
Residents of states with comprehensive privacy laws — including the Utah Consumer Privacy Act, where CrashMeet is based — have the rights listed above and may appeal a denied request by replying to our decision. We do not process personal data for targeted advertising, sell personal data, or profile you in a way that produces legal effects.
EEA, UK, and Switzerland (GDPR)
CrashMeet is offered from the United States and is not directed at the EEA, UK, or Switzerland. If you use it from there, our legal bases are: contract (running your account and the app's core features), consent (location, contacts, camera, microphone, photos, notifications — withdrawable at any time in system settings), legitimate interests (security, abuse prevention, fixing crashes, improving the product), and legal obligation. You also have the rights to data portability, to object, to restrict processing, and to lodge a complaint with your supervisory authority.
Making a request
Email kvjensen99@gmail.com with the subject line "Privacy Request." We will verify that the request comes from you or your authorized agent, and respond within 45 days (extendable once by another 45 days where the law allows), or within 30 days for deletion requests.
12Security
We protect your information with encryption in transit (TLS) and at rest, phone-based authentication with one-time codes, and server-enforced access rules that decide per request who is allowed to read or write each piece of data. Sensitive derived values — such as activity counts and co-presence — are written only by our servers, never by the app, so they can't be forged from a device.
No system is perfectly secure. Please use a device passcode, keep the app updated, and tell us right away if you think someone else has access to your account.
13Children
CrashMeet is not intended for anyone under 13, and we do not knowingly collect personal information from children under 13. If we learn that we have, we will delete the account and its data promptly. If you believe a child under 13 is using CrashMeet, email kvjensen99@gmail.com.
Because the app involves meeting people in person and sharing location, parents and guardians of teenage users should review the sharing controls in Section 9 together with them.
14Where your data is stored
CrashMeet runs on Google Cloud infrastructure, with our primary database hosted in Google's us-west3 (Salt Lake City, Utah) region. Files, notifications, and diagnostics may be processed in other Google Cloud regions in the United States. If you use CrashMeet from outside the United States, your information is transferred to and processed in the United States, where privacy laws may differ from those where you live. Where required, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses for those transfers.
15Changes to this policy
We'll update this policy as the app changes. When we do, we'll revise the "Last updated" date at the top. If a change materially affects how we handle your information, we'll give you notice in the app or by notification before it takes effect, and where the law requires it, ask for your consent. Continuing to use CrashMeet after a change takes effect means you accept the updated policy.
CrashMeet is currently in private beta and features described here may change.
16Contact us
Questions, privacy requests, or concerns about this policy:
CRASHMEET, LLC
Utah, United States
kvjensen99@gmail.com
See also our Terms of Service.
This policy is governed by the laws of the State of Utah, without regard to its conflict-of-laws rules.