What you hand a dating app
A dating or matrimony app asks for more than an email and a password. It gets your photos, often a selfie to prove you're real, and a profile written in your own words about what you want. It gets your location, sometimes to the street. On a matrimony site it usually gets your religion, your family, and on some sites your caste or sect, because the service is built on them. Then come the messages, which you typed for one person.
The law treats a lot of this as special. Religion, sexuality, health, and a face scan used to recognise you are special category data under UK and EU law, the kind with the strictest rules. Using a dating app at all can count. Norway's data protection authority fined Grindr for passing on the fact that people used the app, and the Borgarting Court of Appeal upheld the fine, treating that fact as information about a person's sexuality.
Where it has already gone
Shared with other companies
In 2018 Grindr admitted sending users' HIV status, and the date of their last test, to two analytics companies, alongside their GPS location, phone ID and email. In September 2026 it paid £26 million to settle the UK group claim over that sharing, without admitting liability. In 2020 the Norwegian Consumer Council tested ten popular apps and found them sending data to at least 135 advertising and profiling companies. OkCupid was among them, sending answers about sexuality, drug use and political views to an analytics company. In 2024 Mozilla gave 22 of the dating apps it reviewed its privacy warning label.
Handed to an AI company
In March 2026 the US Federal Trade Commission said OkCupid gave nearly three million user photos, with location and other information, to an outside company, with no limits on how they could be used. OkCupid's founders had invested in it. The company was Clarifai, and it used the photos to train a tool that estimates a person's age, sex and race from their face. It has since deleted the photos and the models trained on them.
Sold through the advertising trade
An app doesn't have to sell your location for it to be sold. Apps show adverts, and ad auctions pass along where the phone is. In 2021 a Catholic newsletter bought app location data with no names in it, matched one phone to a senior priest by where it spent its nights and working days, and reported that it showed Grindr use and visits to gay bars. He resigned. In 2023 the Washington Post reported that a Catholic group in Colorado had spent at least $4 million on dating and hookup app data to track priests, most of it from Grindr. In January 2025 hackers took location data from the broker Gravy Analytics that came from thousands of apps, Tinder and Grindr among them, and researchers used it to map Tinder users across the United Kingdom.
The app itself can give your location away too. In 2023 researchers at KU Leuven found that six of fifteen major dating apps let a stranger work out a user's exact position from the distance the app showed or filtered by, including on apps that hid the number. The same kind of flaw has turned up again and again since 2014, on Tinder, Grindr, Bumble and others, and each time someone outside the company found it.
Scraped
In 2016 two researchers published nearly 70,000 OkCupid profiles, with usernames and answers to personal questions. In 2017 someone pulled 40,000 Tinder profile photos and posted them as a free face dataset for AI experiments, along with the tool that collected them.
Leaked, then used for extortion
When Ashley Madison was breached in 2015, 36 million people's profiles were exposed, with dates of birth, relationship status and sexual preferences. Extortion demands followed within weeks, and in 2020 a new wave of personalised extortion emails was built from the same data, five years on. In 2025 nearly 1.5 million images from five niche dating apps, including explicit photos sent in private messages, sat in open cloud storage for anyone to find.
Were you talking to a person?
Fake profiles are as old as the apps. According to the FTC, Ashley Madison used fake profiles of women to message 19 million Americans into paying. It alleged in 2019 that at some points more than half the messages Match.com users received came from accounts Match had already flagged as fraudulent. Human Rights Watch documented security forces in Egypt, Iraq and Jordan setting up fake profiles on Grindr and Facebook to draw people out, then using their photos and chats to prosecute them. The FBI counted $929 million lost to romance fraud in the US in 2025, and notes that scammers now write with AI chat tools.
AI can now run the whole conversation. In September 2026 Anthropic reported a studio that had built more than 20 dating apps, advertised as fully human, where about three in four profiles were AI personas. Over two weeks in April 2026 those personas talked with at least 25,000 people and sent about 2.36 million messages. Some users told them about serious illness.
A match who went quiet may never have been a person. A stranger can now hold a long conversation with you for almost nothing, and in it you write about yourself, in your own voice.
How your writing gives you away
Identifying someone by how they write is called stylometry, and it's older than the internet. In 1963 two statisticians settled who wrote twelve disputed Federalist Papers by counting small words like "upon", "an" and "of", which people use at steady rates whatever they're writing about. The method looks for habits that don't depend on the subject: capital letters or none, one space after a full stop or two, favourite or favorite, "tbh", the emoji you reach for, how long your sentences run.