In July 2021 The Pillar, a Catholic newsletter, reported that the general secretary of the US Conference of Catholic Bishops had used Grindr and gone to gay bars between 2018 and 2020. It bought "commercially available" app data from a vendor and matched one phone's identifier to him, because that phone was used from his office and his home. He resigned when he learned the report was coming. Grindr called it "an unethical, homophobic witch hunt" and said it did not believe it was the source.
In March 2023 The Washington Post named a buyer of this kind of data. Catholic Laity and Clergy for Renewal, a group in Denver, had spent at least $4 million on data from dating and hookup apps, most of it about Grindr users, paid for with donations from philanthropists. It bought from data brokers, matched the locations to the addresses of parishes, workplaces and seminaries, and gave what it found to bishops around the country. The Post's reporter said the priest outed in 2021 was, they believed, found through this data, and that some priests were approached without being told where the information came from.
Norway's data protection authority had fined Grindr NOK 65 million in 2021 for passing users' location, and the fact that they used the app at all, to advertising partners without valid consent. In October 2025 the Borgarting Court of Appeal upheld the fine and ruled that "data about the use of the app is special category personal data". In the US, where laws against this exist in only a few states, the same kind of data was sold as "commercially available". After the 2021 report, Senator Ron Wyden said brokers and advertising companies had assured the public the information was anonymous, and that "individuals can be tracked and identified".
What it shows
This is re-identification of de-identified data: a phone that sleeps at a rectory and spends its days at a parish office identifies its owner. Device data is personally identifiable information in some jurisdictions and not in others. Deletion is not a finality: a company can de-identify your data instead of deleting it, and companies decide for themselves whether they feel the de-identification is sufficient, when it often isn't. This case is proof that people can be re-identified, and that people are looking for that data and buying it. Here the buyer was a religious group, and what it found went to the priests' own bishops.
For your own record
When you ask a company to delete your data, ask it to say in its reply whether it will anonymise or de-identify any of it instead, and keep that reply. Ask who it has shared your data with, advertising partners and brokers included, and ask it to stop. More on why "de-identified" has worn thin in De-identified does not mean what it used to.