Crosspoint X
NetSpect
Last Updated: September 14, 2026
Crosspoint X ("Company," "we," "us," "our") operates the NetSpect mobile application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the App. Please read it carefully — if you do not agree with our policies and practices, do not use the App.
We request "Always" location permission so check-in can work even when the App isn't open, but we do not continuously track or stream your location. Your location is read when you arrive at a court for a run you joined, and again opportunistically while that run is under way — when the App is already awake — so that the time you spent there is measured rather than assumed. It is not read between runs, and we do not build a movement history. We use geofencing instead: your device monitors a small, specific boundary around a court only when you have an active match there, and notifies the App only when you cross that boundary — we do not receive or store a continuous trail of your movements. We verify your reported arrival server-side before releasing your reserved credit. Location data is never sold or shared with third parties, and is used only for check-in verification and showing matches near you.
You can use NetSpect two ways, and they collect different things.
Anonymous sign-in: an authentication ID generated by Firebase, plus the display name you type. No email, no password, no real name.
Sign in with Apple: the same authentication ID, plus what Apple hands us the first time you authorise — your email address and your name. If you chose Apple's "Hide My Email", what we receive and store is the private relay alias, not your real address, and we record which of the two it is so we know never to treat the alias as a contactable address. Apple sends these once, at first authorisation only.
Either way we also store: your group membership, the runs you joined, your check-in records, your chat messages, and a push notification token for each device you sign in on.
When you delete your account, an Apple sign-in is revoked as part of the deletion, not left connected.
For each device you sign in on, we store a push notification token so we can tell you a run has been called. A token identifies a device, not a person, and it changes when you reinstall the App.
We do not collect your device model, OS version, advertising identifier, IP-based location, or browsing behaviour, and there is no analytics or crash-reporting SDK in the App. If you contact us about a problem, we may ask you for your device and OS version — that is you telling us, not us collecting it.
Your data is stored and processed through Firestore, Firebase Authentication (anonymous sign-in and Sign in with Apple), Firebase Cloud Functions, and Firebase Cloud Messaging for push notifications. We do not use Firebase Analytics, Firebase Crashlytics, or any Google Analytics products.
The first time you open NetSpect after installing it, the App checks your clipboard one time for a NetSpect invite link. This is how an invite survives the trip through the App Store: you tap a link, the website puts the invite code on your clipboard, you install the App, and the App picks the code up so you land in the run you were invited to instead of on a blank screen.
It asks iOS what KIND of thing is on the clipboard before reading anything, so a clipboard holding a photo or a password is never read at all. It happens once, ever, on first launch — never again, and never in the background. If it does read a link, iOS shows you its own paste notification. Nothing from your clipboard is sent anywhere unless it is a NetSpect invite link.
The courts map shows how busy each court has been. That figure counts distinct people who checked in, never who they were, and any court with fewer than three distinct people in the period is reported as having no activity at all rather than as a small number — so a quiet court can never identify the one or two people who were there.
The App also shows you the names of people you have previously played with, and shows your name to them on the same basis. Your name and check-in status are visible to members of your own group. Your location coordinates are never shown to anyone.
To find out why check-ins fail for real people in real places, the App records on your own user record: whether you granted location permission, a count of check-in failures, and when the last one happened. That is the whole of it. There is no analytics SDK, no crash reporter, no advertising identifier and no third-party tracking in this App.
Running the App: keeping your account, your group membership, the runs you call or join, invite links, and the messages you send to your group.
Check-in: detecting that you arrived at the court for a run you joined, verifying it server-side against that court's real coordinates so it cannot be faked from a phone, and measuring how long you stayed.
Telling you things: push notifications when your group calls a run, and when you are counted in at a court.
Weather: showing the forecast at the court you picked for an outdoor run, looked up by the court's location, not yours.
Showing the group what happened: attendance on a run, the people you have played with, and how busy a court has been in aggregate.
Keeping it working and lawful: fixing check-in failures, resolving disputes, enforcing our Terms, and responding to legal requests.
We do not use your information to advertise to you, and we do not sell it.
While you have an account, check-in records and credit history are held so the credit system can function — we don't retain a continuous location history, only confirmation that a check-in occurred. If you delete your account, this is a real, permanent deletion, not a deactivation: your profile, group membership, credit history, and pickup-game attendance records are permanently deleted, and your account cannot be recovered. Some records shared with other users — chat messages you sent, or the outcome of a completed match — aren't retroactively altered, since doing so would change other members' own record of a shared event, not just yours.
We do not share your data with advertisers, data brokers, social media platforms, or other third-party services. We share data with three companies, all of them to make the App work rather than to market to you:
Google LLC (Firebase) — storage, authentication, cloud functions and push delivery. Your account, groups, runs, check-ins and messages live here.
Apple Inc. — if you use Sign in with Apple, Apple authenticates you and tells us your email and name. If you chose Hide My Email, Apple also relays mail to you without giving us your real address. Apple delivers our push notifications to your device. Apple also supplies the weather forecast shown for outdoor runs (Apple Weather): the App sends Apple the court's coordinates and the game's time window, never your own location and nothing that identifies you.
Microsoft Corporation (GitHub) — encrypted backups of our source code. No user data is on GitHub, only the code that runs the App. We may disclose information if required by law (e.g. court order, subpoena).
NetSpect is intended for users age 13 and older. By creating an account, you confirm that you are at least 13 years old. We do not knowingly allow anyone under 13 to use the App.
You can request a copy of your personal data and how it's used. You can delete your account at any time from Settings → Delete Account — see Data Retention above for exactly what is and isn't removed. You can disable location permissions at any time in your device settings; this will prevent check-ins from working, meaning a reserved credit for a match you accept won't be released back to you. If you're a California resident, you have CCPA rights to know what's collected, know whether it's sold (it isn't), and delete it — contact us at pointxcross@gmail.com to exercise these rights.
Location data is transmitted encrypted (HTTPS/TLS). Firestore is protected by Google's enterprise-grade security. We verify location data server-side to prevent client-side manipulation. We store the least that makes the App work: a display name always, and an email address only if you signed in with Apple and chose to share one — see "Account & User Data" above for exactly what that means. We do not collect phone numbers, postal addresses, payment details, contacts, photos, or your device's advertising identifier. We cannot guarantee 100% security against unauthorized access — no security system is impenetrable, and use of the App is at your own risk.
We may update this Privacy Policy from time to time. When we make material changes, we'll notify you within the App and update the "Last Updated" date above. Continued use of the App after changes means you accept the new policy.
Questions about this policy, your data, or your privacy rights:
Email: pointxcross@gmail.com
Mailing Address: Crosspoint X 131 Continental Dr, Suite 305 Newark, DE 19713, US
Email: pointxcross@gmail.com
Mailing Address:
Crosspoint X
131 Continental Dr, Suite 305
Newark, DE 19713, US
This Privacy Policy is effective as of September 13, 2026.