Privacy Policy

Privacy Policy

Last updated 14 May 2026

CrossMeet respects and is committed to protecting user privacy. This policy explains how we collect, use, and safeguard your data.

0. Data Controllers

CrossMeet is operated by two independent legal entities. Each acts as the data controller for users in its respective region:

Your region Data controller Applicable law
China mainland [CN_COMPANY_NAME] (Unified Social Credit Code [USCC], registered in [CN_CITY], address [CN_REGISTERED_ADDRESS]) Personal Information Protection Law (PIPL), Data Security Law, Cybersecurity Law of the People's Republic of China
Outside China mainland (including Hong Kong, international) [HK_COMPANY_NAME] (BRN [BRN], CR [CR], registered in Hong Kong SAR, address [HK_REGISTERED_ADDRESS]) Hong Kong Personal Data (Privacy) Ordinance, EU GDPR, UK-GDPR, California CCPA / CPRA

The two entities are compliance-independent, settlement-independent, and invoice-independent. User data is segregated by region and never flows between the two entities.


1. Data we collect

1.1 Account information

  • Email address, username (provided at registration)
  • Encrypted password hash (irreversible bcrypt)
  • Registration time, last login time, login IP (for fraud prevention)

1.2 Payment information

  • Payments are processed by Stripe / Alipay / WeChat Pay / PayPal / Wire Transfer. We do not store credit card or bank card numbers. We retain only: transaction ID, amount, currency, timestamp, subscription status, and receiving entity.
  • Invoice data (company name, tax ID) — saved only when explicitly submitted by customers requesting an invoice.

1.3 Device information (license binding)

  • Device hardware fingerprint (HWID): an irreversible hash derived from CPU + motherboard + MAC. Contains no personally identifying information.
  • Device activation time, last heartbeat time, device name (user-customizable)

1.4 Usage logs

  • Crash reports (automatic): only stack traces uploaded on crash (no user input content)
  • Error logs: stored locally at %APPDATA%/CrossMeet/logs.db. Not uploaded by default. Only attached if you submit feedback.

1.5 What we do NOT collect (important)

  • ASR audio content is NOT uploaded to our servers. Cloud ASR (e.g., OpenAI Whisper, Aliyun) uses your own API key — audio goes directly to that cloud service, never through CrossMeet servers
  • Translation content and conversation history are NOT uploaded. Stored locally at %APPDATA%/CrossMeet/crossmeet.db
  • ❌ We do NOT collect microphone, screen, or filesystem listing data

2. Data storage & security

Storage is segregated by data controller:

Data controller Storage location Cross-border transfer
[CN_COMPANY_NAME] (China mainland users) Aliyun East China nodes (within China mainland) None — data does not leave China mainland
[HK_COMPANY_NAME] (international users) AWS Hong Kong / North America Only under GDPR / UK-GDPR Standard Contractual Clauses (SCCs) where applicable

Technical controls (identical across both entities):

  • Transport encryption: HTTPS (TLS 1.3)
  • Storage encryption: at-rest AES-256 database encryption
  • Environment isolation: dev / staging / prod strictly separated
  • Access control: role-based least-privilege (RBAC); audit logs record every data access

3. Data retention

  • Account data: retained while account exists; permanently deleted within 30 days of voluntary account closure
  • Device records: retained while license is valid; cleared 90 days after expiry
  • Email send logs: 90 days
  • Crash reports: aggregated stats kept; raw data cleared after 6 months
  • Payment records: retained per local tax law (10 years for China, 7 years for Hong Kong), then destroyed

4. Cookies

  • Session cookie (required): keeps you logged in, expires when browser closes
  • CSRF token: prevents cross-site request forgery
  • No third-party tracking cookies (no Google Analytics, no Facebook Pixel)

5. Third-party services

Service Purpose Data shared Used by entity
Stripe International payments Credit card data (never touches our servers) [HK_COMPANY_NAME]
PayPal International payments Payment information [HK_COMPANY_NAME]
Alipay / WeChat Pay China mainland payments Order ID + amount only [CN_COMPANY_NAME]
Resend Email delivery (registration, password reset) Email address + email content Both entities
Cloudflare CDN + DDoS protection Visitor IP (aggregated) Both entities

Cloud ASR / TTS / LLM (OpenAI, Aliyun, Claude, etc.) used inside the desktop app run with your own API keys — they never touch our servers and are outside the scope of this privacy policy.

6. Your rights

Under China PIPL, EU GDPR, UK-GDPR, and California CCPA / CPRA, you have the right to:

  • Access: request all data we hold about you
  • Rectification: correct inaccurate personal information
  • Erasure / Right to be Forgotten: request complete deletion of your account and related data
  • Data Portability: download your account data as JSON / CSV
  • Restriction of Processing: pause processing of certain data categories
  • Object: object to automated processing based on legitimate interest
  • Withdraw Consent: withdraw any previously given consent at any time

To exercise these rights, contact the data controller responsible for your region:

We respond within 30 calendar days (GDPR / CCPA compliant).

7. Policy changes

If we make material changes, we will email all registered users and post a notice on the site at least 7 days in advance. The effective date is reflected in the last_updated frontmatter field.

8. Contact

Get started

Ready to make every conversation feel native?

NO CREDIT CARD CANCEL ANYTIME LOCAL-FIRST
~100ms
End-to-end latency
30+
Languages
4
ASR engines
WIN 10/11
Native platform