Case study · 2023 to 2026 · filed 1 October 2026

You report a match. Someone else's staff reads it.

Dating apps send reports, with the messages and photos in them, to outside moderators and software. The firm that moderated Grindr now belongs to an AI company whose contract makes de-identified client data its own.

In November 2023 the Bureau of Investigative Journalism published interviews with more than 40 people who moderate dating apps for Bumble, Grindr and Match Group. Moderators read the reports people send, from harassment to child sexual abuse material, and decide who gets banned. Grindr, the investigation found, relies on an outsourcing firm, PartnerHero, for much of its moderation, and many of those moderators are recruited in Honduras. Grindr said it had "worked in collaboration with PartnerHero over the course of our relationship to consistently improve processes, training, and support." Global Dating Insights also describes PartnerHero as Grindr's moderation contractor.

A report is evidence. It carries the messages, the photos and the profile that led to it. Bumble's own privacy policy names one of the systems these pass through: Cinder, a moderation platform that processes "user-generated data, such as reports, messages, and media".

In October 2024 Crescendo, a company selling AI customer service, acquired PartnerHero. Crescendo publishes the agreement it signs with its clients. Section 5.3 lets it "create and/or derive from Customer Data de-identified, anonymized and/or aggregated data" and says that data belongs to Crescendo, during the contract and after it ends. Its data processing agreement keeps the identifiable data to the job it was hired for. What is de-identified from that data becomes Crescendo's.

Grindr's own privacy policy draws the same line. It says Grindr "and our partners also scan, analyze, and collect information from the videos, images, audio, messages, and other content" people upload, for purposes "that do not identify you but may be associated with your profile".

What it shows

A report on a dating app travels along a chain: the app, the firm or the software that reads it, and the company that owns that firm. Each can promise not to identify you and still keep what you wrote. Chat text with the name taken off still carries the way you write and when you write, and writing style can point back to a person. 63% of the dating app policies we read let the company keep and use data once it is called de-identified, and a quarter let it share that data or use it for any purpose the law allows.

For your own record

Ask the app whether reports and messages go to an outside firm or software, and which. If you reported someone, ask for a copy of what your report holds and what was decided. When you ask for your data to be deleted, ask the app to say whether any of it will be de-identified and kept instead, by the app or by the companies working for it, and keep the reply.

More case studies

Grindr A Catholic group bought app data to find priests who used Grindr Phone data with no names on it, showing which devices used Grindr and where they went, was on sale through brokers. A Catholic group in Denver bought it, matched phones to parishes and seminaries, and passed what it found to bishops.
Ashley Madison Ashley Madison charged people to be deleted, and kept the rest The affair site charged a fee for a full delete and kept deactivated accounts indefinitely. Then it was breached, and 36 million accounts were exposed.
Tinder She asked Tinder for her data and got 800 pages A journalist used her right of access in 2017. The file listed her likes, her photos, the men she was interested in, and when and where every conversation with a match happened.