Privacy Policy
Effective Date: June 15, 2026
At Across, we value your privacy and are committed to protecting it with a simple and secure approach.
What Data We Collect
Across collects minimal data, and the following information is collected without linking it to you personally:
- Identifiers
- Usage Data (information about how you use the app, not your event or task data)
- Diagnostics
The collected data is processed through Google Analytics and Firebase services to help improve the app experience.
How Your Data is Handled
- Apple Calendar & Reminders: Across does not operate its own servers for your Apple data. All events and tasks are securely stored in your personal iCloud account, managed by Apple.
- No Access to Apple ID: Across never knows or accesses your Apple ID.
- Permission-Based Access: Across accesses your Calendar and Reminders only with your explicit permission.
- Google Calendar: If you connect your Google account, your calendar data is accessed via the official Google Calendar API and used only within the app. Across uses a backend server solely to enable real-time synchronization (registering Google Calendar watch channels and delivering silent push notifications). This server does not store your calendar events, contacts, or your Google refresh token. Across’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Google Data We Access
When you connect your Google account, Across accesses the following only with your explicit consent:
- Your Google account email address
- Google Calendar lists (names, colors, IDs)
- Calendar events (titles, start and end times, time zones, locations, descriptions, and attendee information when applicable)
- Incremental sync metadata such as sync tokens
- Google Contacts and other contacts (names, email addresses, and avatars), including addresses you have previously interacted with, used only for attendee suggestions when creating or editing events
How Your Google Data Is Used
- Google Calendar data is used only to display, create, update, or delete calendar events as requested by you.
- Google Contacts information is used exclusively for attendee auto-completion when adding participants to your events, and is processed only on your device.
- Across does not use your Google data for advertising and does not share it with third parties.
- All access to your Google data occurs through Google’s secure OAuth 2.0 authorization flow and only with your explicit consent.
Google Synchronization Server
Across uses a backend server for the sole purpose of real-time synchronization with Google Calendar, such as registering watch channels and delivering silent push notifications when your calendar changes. The server stores only the minimum information required for this purpose:
- Your Google account email address
- Device identifiers and push notification tokens (for delivering sync notifications)
- Google Calendar watch channel metadata (channel IDs, resource IDs, and expiration timestamps)
The server never stores the following:
- Google refresh token: Across does not store your refresh token, the long-lived Google credential, on its server at any time.
- Access tokens: When synchronization is needed, the app sends a short-lived access token to the server, which uses it only temporarily in memory and never saves it.
- Calendar event contents: Titles, descriptions, locations, notes, reminders, and attachments are never stored on the server. They remain within your Google account and on your device.
- Google Contacts: Contact data is processed only on your device and is never uploaded to or stored on the server.
All communication between your device, the Across server, and Google APIs occurs over encrypted HTTPS connections.
Real-Time Synchronization and Notifications
To keep your calendars up to date, the app itself registers and renews Google Calendar watch channels using credentials you have already authorized on your device, and sends a short-lived access token to the server only when needed. The server uses the watch channel metadata and your push notification token only to deliver a silent notification to your device when a change is detected. The app then fetches the updated data directly from Google.
Because Across never stores your Google refresh token, the long-lived credential, on its server, the server cannot access your Google account on its own. Even in the unlikely event of a server-side incident, your Google account remains protected, as the server holds no credential that could be used to reach your Google data. This design keeps your Google account access entirely under your control on your device.
Across’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Retention for Google User Data
Across retains only the minimum Google user data required to support real-time synchronization. Across does not store Google Calendar event contents or Google Contacts data at any time, and never stores your Google refresh token.
The only data retained on the server is:
- Your Google account email address
- Device identifiers and push notification tokens
- Google Calendar watch channel metadata
Data Deletion for Google User Data
You can delete all Google-related data at any time.
- Device Sign Out: When you sign out on a single device, only that device’s information (device identifier and push notification token) is removed from the server. Other devices connected to the same Google account continue to operate normally.
- All Devices Signed Out: When all devices associated with your Google account are signed out, the server removes all remaining account-related data, including your email address, all device records, and watch channel metadata.
- Google Account Revocation: You may also revoke Across’s access from your Google Account settings at any time. Once revoked, Across can no longer access your Google data, and the related server-stored synchronization data is removed.
Permissions Requested
Across requests access to certain features solely for providing core app functionalities:
- Calendar: To display and create events (Apple Calendar and, when connected, Google Calendar).
- Reminders: To display and create tasks.
- Contacts: To display and suggest attendee information for events, including your Google Contacts and other contacts you have previously interacted with. Contact data is processed only on your device and is never sent to the Across server.
- Location: To display weather information and attach a location when creating events.
These permissions are used only for the purposes described above and are neither used for any other purposes nor stored separately.
Your Privacy, by Design
Your Apple data is securely stored in your iCloud account, encrypted and managed by Apple.
If you connect your Google account, your calendar and contact data remain within your Google account and on your device, and are accessed securely through official Google APIs. The Across server is used only for real-time synchronization and never stores your event contents, contacts, or Google refresh token.
Contact
If you have any questions about this Privacy Policy, please contact us at: support@daymore.com
Company: DayMore Corp.
Person in Charge: JeongMin Kang