Privacy Policy
Last updated: September 2026
CroxYou is a professional networking service that helps members meet relevant professionals in person. This policy explains exactly what personal data the service processes, why, and what control you have over it.
1. Who is responsible for your data
The controller of the personal data described in this policy is Diego Ofano, established in Luxembourg, operator of the CroxYou app and of https://croxyou.com.
For any privacy question or to exercise your rights, contact privacy@croxyou.com.
2. Data you provide when creating an account
- · Account and authentication data: your email address and, depending on the method you choose, the identifier and basic profile details returned by Google, LinkedIn or Apple sign-in. If you register with email and password, the password is stored only in hashed form by our authentication provider and is never visible to us.
- · The sign-in method used and the date your account was created.
3. Professional profile information
Members build a professional profile. Depending on what you enter, this may include:
- · First and last name, headline, short biography, job title, professional function, seniority, company and website or LinkedIn URL.
- · Industry, areas of expertise, professional interests, languages, education, work experience, certifications, what you can offer and what you are looking for.
- · City and country, nationality where you choose to provide it.
- · A profile photo, if you add one.
Profile information is visible to other signed-in CroxYou members, and parts of it may appear on public profile or shared pages when you deliberately share such a link.
4. CV / resume uploads (optional)
Uploading a CV is entirely optional and is not required to use CroxYou. If you choose to upload one, the file is stored in a private storage bucket that only you and the service backend can access. With your consent, the document is processed once by an automated language model in order to propose structured profile fields (such as experience, education, skills and seniority). Nothing is applied to your profile without your review: you decide which suggested fields to accept. The original file remains private, is never shared with other members and is deleted when you delete your account.
5. Meeting, matching, travel and event data
- · Meeting goals, meeting intent, availability slots and whether you are open to meet.
- · Trips you add: destination city and travel dates, as you enter them yourself. CroxYou does not track your location continuously and never displays your precise device location to other members.
- · Events you view, mark as attending ("I'm going"), create or are invited to, and your availability around those events.
- · Connections, introductions, meeting requests, meeting details and post-meeting feedback.
- · Matching signals derived from the above, used to recommend relevant people and events.
Device location is optional. It is used only when you actively choose a feature such as “Use my location” to set your current city. When you do, your device coordinates are sent once to our server and to our geocoding provider (Photon / Komoot) solely to determine the corresponding city, and are not stored against your account. In the rare case where the provider returns no coordinates for the matched city, the coordinates you submitted may be saved on that shared city record itself (a city’s own location, not yours) so the city can be placed on a map; such a record is not linked to you as a location history. There is no background or continuous location tracking, your precise coordinates are never shown to other members, and the app remains fully usable without granting location permission. You can always search for and select your city manually instead.
Approximate location from your connection: if you have not chosen a city, when you sign in to the app we may estimate an approximate city or metropolitan area (for example “Luxembourg” or “Milan”) from the city and country that our hosting provider derives from your IP address. We store only the resulting city or metropolitan area and a note that it was estimated. We do not store your IP address, coordinates or the underlying location data, and no separate geolocation provider is used. The estimate is used to suggest relevant nearby members and events, never replaces a city you have chosen, and you can change or remove it at any time in your profile.
Privacy settings in the app let you hide your trips and your event attendance from other members.
6. Messages
Messages you exchange with connected members are stored so the conversation can be delivered and displayed. They are not used for advertising. Staff access is limited to what is strictly necessary to investigate a report of abuse or a technical fault. An “I’d like to meet” interest, and any short note you attach to it, is stored and shown to the person you send it to; messaging only becomes possible once both sides have accepted.
7. Community discussions
CroxYou includes a professional Community. If you take part, we process the discussions you post (subject and body), the topic you choose, your replies, the discussions you follow and the replies you mark as helpful, together with the time each was created or edited.
Community content is visible to all signed-in CroxYou members, not only to your connections. Treat anything you post there as shared with the whole membership.
8. Anonymous posting
You may choose to post a discussion anonymously. Anonymous means your name and profile are hidden from other members: the app does not return your identity for that post to anyone except you. It does not mean the post is anonymous to us. Your account remains recorded against the post internally so that the conduct rules can be enforced, abuse investigated and legal obligations met. Replies cannot be posted anonymously.
9. Reports, blocks and content screening
- · Reports: when you report a discussion, a reply, a member or an event, we store who reported it, what was reported, the reason you selected, any details you add, and the status of the report. Your identity as reporter is never shown to the person reported.
- · Blocks: when you block another member, we store the pair and the time. Blocking works in both directions and is not disclosed to the other person; blocked members simply no longer see each other's content or receive each other's requests.
- · Automated screening: Community subjects, discussion bodies and reply bodies are checked automatically against a list of prohibited content categories before they are stored. Content that matches is refused and never published. The check runs on the text itself and does not profile you or produce a score attached to your account.
10. Technical and security data
To keep the service running and secure we process: a last-activity timestamp (used for basic product metrics such as active members), moderation and abuse reports, an audit log of administrative and event-moderation actions, and rate-limiting and error information generated when you use the service. CroxYou does not run advertising trackers, does not build advertising profiles and does not sell personal data.
11. Purposes and legal bases (GDPR)
- · Performance of a contract (Art. 6(1)(b) GDPR): creating and operating your account, and processing the profile information, meeting goals, trips, event attendance, connections, introductions, meetings, messages, invitations and Community participation needed to provide the professional networking, matching, meeting and discussion functionality you request. This applies whether a profile field is technically optional or not: the basis is providing the service, not consent.
- · Legitimate interests (Art. 6(1)(f) GDPR): keeping the service secure, preventing abuse and fraud, screening Community content automatically before it is published, handling reports and blocks, moderating content, maintaining security audit logs, rate limiting and measuring basic aggregate product usage (such as active-member counts). Our interest is operating a safe, reliable networking service; we balance this against your rights and do not use this basis for advertising or profiling for third parties.
- · Consent (Art. 6(1)(a) GDPR): only where a feature is genuinely optional and separate from the core service (enabling push notifications on your device, and uploading a CV for automated profile extraction). You may withdraw consent at any time (via device or in-app notification settings, or by deleting the CV), without affecting the lawfulness of processing already carried out.
- · Legal obligation (Art. 6(1)(c) GDPR): where we must retain or disclose information to comply with applicable law.
12. Who your data is shared with
Other members see the profile information, trips and event attendance you choose to make visible, the messages you send them, and the Community discussions and replies you post (without your name where you posted anonymously). Beyond that, data is shared only with service providers acting on our instructions:
- · Lovable Cloud / Supabase: application hosting, database, authentication and file storage.
- · Google, LinkedIn and Apple: only if you choose to sign in with one of those identity providers.
- · Expo push notification service and the Apple / Google push infrastructure: delivery of push notifications to your device.
- · Lovable AI Gateway: automated processing of an uploaded CV to suggest profile fields.
- · Lovable email delivery: transactional emails such as sign-in links and service notices.
- · OpenStreetMap / Nominatim and Photon (Komoot): city and venue lookup when you search for a place. Only the search text is sent; no account identifier is included.
We may also disclose data where legally required, or to protect the rights and safety of members.
13. International transfers
Some of the providers above may process data outside the European Economic Area. Where that happens, transfers rely on the safeguards permitted by Chapter V GDPR, in particular the European Commission's Standard Contractual Clauses or an adequacy decision.
14. Retention and deletion
Your profile and related data are kept for as long as your account exists. When you delete your account, the account and its data are removed as described below. Messages within a conversation are removed together with the connection they belong to. Administrative and event-moderation audit records may be retained for a limited period for security and abuse prevention, with identifying references to the deleted account removed or replaced so the remaining entries cannot be attributed to you. Routine encrypted backups may still contain data for a short period until they age out in the normal cycle.
15. Deleting your account
You can permanently delete your CroxYou account from within the app, under You → Settings → Delete Account. Deletion runs immediately and is irreversible. It removes your authentication account (so you can no longer sign in), your profile, CV files and generated share images, connections and the messages inside them, meetings and meeting feedback, introductions and “I’d like to meet” interests including any notes attached, event attendance, availability and event reports, trips and travel plans, open-to-meet information, notifications, notification preferences, blocks you set, registered push devices, any linked LinkedIn identity, and the invitations you sent.
Your Community data is removed with the account: your discussions, your replies, your helpful marks, the discussions you follow and the reports you filed. Because a discussion cannot exist without its author, the replies other members wrote underneath your discussions are removed together with the discussion. Your replies under other members’ discussions are removed while those discussions remain. Anonymous posts are removed in the same way as any other post.
Events and shared records that other members rely on are retained without your personal identifiers, and invitations addressed to you by someone else are kept for that sender with the link to your account removed. The service confirms deletion only once the authentication account has actually been removed and that removal verified. Full details are on the Delete your account page.
16. Your rights
Under the GDPR you have the right to access your data, to rectification, to erasure, to restriction of processing, to object to processing based on legitimate interests, and to data portability. Where processing is based on consent, you may withdraw that consent at any time. To exercise these rights, contact privacy@croxyou.com.
You also have the right to lodge a complaint with a supervisory authority. In Luxembourg this is the Commission nationale pour la protection des données (CNPD), 15 Boulevard du Jazz, L-4370 Belvaux, www.cnpd.lu.
17. Children
CroxYou is a professional networking service intended for working professionals. It is not directed at children, and accounts may only be created by persons aged 18 or over. If we learn that an account belongs to a minor, it will be removed.
18. Security
Access to member data is restricted at database level by row-level security rules, uploaded files are stored in private buckets, privileged credentials are held only on the server and are never exposed to the app, and sensitive operations are authenticated and rate-limited. No online service can be guaranteed to be completely secure, but we work to protect your data with appropriate technical and organisational measures.
19. Changes to this policy
We may update this policy as the service evolves. The date at the top of this page always reflects the current version, and material changes will be communicated in the app.
20. Contact
Diego Ofano, established in Luxembourg, privacy@croxyou.com.