Issue 03 · Dating and matrimony · 23 September 2026

What dating apps keep, and how the way you write can name you

A dating or matrimony profile holds your face, your faith, who you're drawn to and years of private messages. Some of that has already been shared, sold, scraped, handed to an AI company and leaked. Taking your name off doesn't hide you, because AI can now work out who wrote a text from the way it's written. Here's what these apps hold, where it has gone, and what to ask for.

What you hand a dating app

A dating or matrimony app asks for more than an email and a password. It gets your photos, often a selfie to prove you're real, and a profile written in your own words about what you want. It gets your location, sometimes to the street. On a matrimony site it usually gets your religion, your family, and on some sites your caste or sect, because the service is built on them. Then come the messages, which you typed for one person.

The law treats a lot of this as special. Religion, sexuality, health, and a face scan used to recognise you are special category data under UK and EU law, the kind with the strictest rules. Using a dating app at all can count. Norway's data protection authority fined Grindr for passing on the fact that people used the app, and the Borgarting Court of Appeal upheld the fine, treating that fact as information about a person's sexuality.

Where it has already gone

Shared with other companies

In 2018 Grindr admitted sending users' HIV status, and the date of their last test, to two analytics companies, alongside their GPS location, phone ID and email. In September 2026 it paid £26 million to settle the UK group claim over that sharing, without admitting liability. In 2020 the Norwegian Consumer Council tested ten popular apps and found them sending data to at least 135 advertising and profiling companies. OkCupid was among them, sending answers about sexuality, drug use and political views to an analytics company. In 2024 Mozilla gave 22 of the dating apps it reviewed its privacy warning label.

Handed to an AI company

In March 2026 the US Federal Trade Commission said OkCupid gave nearly three million user photos, with location and other information, to an outside company, with no limits on how they could be used. OkCupid's founders had invested in it. The company was Clarifai, and it used the photos to train a tool that estimates a person's age, sex and race from their face. It has since deleted the photos and the models trained on them.

Sold through the advertising trade

An app doesn't have to sell your location for it to be sold. Apps show adverts, and ad auctions pass along where the phone is. In 2021 a Catholic newsletter bought app location data with no names in it, matched one phone to a senior priest by where it spent its nights and working days, and reported that it showed Grindr use and visits to gay bars. He resigned. In 2023 the Washington Post reported that a Catholic group in Colorado had spent at least $4 million on dating and hookup app data to track priests, most of it from Grindr. In January 2025 hackers took location data from the broker Gravy Analytics that came from thousands of apps, Tinder and Grindr among them, and researchers used it to map Tinder users across the United Kingdom.

The app itself can give your location away too. In 2023 researchers at KU Leuven found that six of fifteen major dating apps let a stranger work out a user's exact position from the distance the app showed or filtered by, including on apps that hid the number. The same kind of flaw has turned up again and again since 2014, on Tinder, Grindr, Bumble and others, and each time someone outside the company found it.

Scraped

In 2016 two researchers published nearly 70,000 OkCupid profiles, with usernames and answers to personal questions. In 2017 someone pulled 40,000 Tinder profile photos and posted them as a free face dataset for AI experiments, along with the tool that collected them.

Leaked, then used for extortion

When Ashley Madison was breached in 2015, 36 million people's profiles were exposed, with dates of birth, relationship status and sexual preferences. Extortion demands followed within weeks, and in 2020 a new wave of personalised extortion emails was built from the same data, five years on. In 2025 nearly 1.5 million images from five niche dating apps, including explicit photos sent in private messages, sat in open cloud storage for anyone to find.

Were you talking to a person?

Fake profiles are as old as the apps. According to the FTC, Ashley Madison used fake profiles of women to message 19 million Americans into paying. It alleged in 2019 that at some points more than half the messages Match.com users received came from accounts Match had already flagged as fraudulent. Human Rights Watch documented security forces in Egypt, Iraq and Jordan setting up fake profiles on Grindr and Facebook to draw people out, then using their photos and chats to prosecute them. The FBI counted $929 million lost to romance fraud in the US in 2025, and notes that scammers now write with AI chat tools.

AI can now run the whole conversation. In September 2026 Anthropic reported a studio that had built more than 20 dating apps, advertised as fully human, where about three in four profiles were AI personas. Over two weeks in April 2026 those personas talked with at least 25,000 people and sent about 2.36 million messages. Some users told them about serious illness.

A match who went quiet may never have been a person. A stranger can now hold a long conversation with you for almost nothing, and in it you write about yourself, in your own voice.

How your writing gives you away

Identifying someone by how they write is called stylometry, and it's older than the internet. In 1963 two statisticians settled who wrote twelve disputed Federalist Papers by counting small words like "upon", "an" and "of", which people use at steady rates whatever they're writing about. The method looks for habits that don't depend on the subject: capital letters or none, one space after a full stop or two, favourite or favorite, "tbh", the emoji you reach for, how long your sentences run.

How your writing gives you away

The de-identified file
Profile 48213 honestly just after someone to go to gigs with. favourite thing is a sunday roast, least favourite is small talk tbh 🙃 dont mind a long walk if theres a pub at the end x
Profile 90377 Looking for someone who doesn't take life too seriously 😂 I'm a nurse, so my schedule is all over the place lol. Favorite color is green, if that helps!
Public posts, under real names
Sam Okafor went to see the new exhibition today. colours were unreal tbh 🙃 cant believe its free... will defo go back
Jess Marlowe just finished my first half marathon lol 😂 legs are dead, dont talk to me tbh
Dan Reyes Finally finished painting the spare room and I'm honestly pretty proud of how the color turned out given that I had never done anything like this before 😂 Next up, the kitchen, which I've been putting off since we moved in last spring.

A dating app's file, with the names taken off.
Two profiles. No name, no photo.

This is what a set of profiles looks like once it has been de-identified to be shared, sold or studied. The name, the photos and the email address are gone. What people wrote about themselves is still there, in their own words.

1 / 5

Step through it.

Private messages have already been read this way in court. In two British murder cases, a linguist compared text messages sent from the victims' phones with the messages the victims and the accused normally wrote, using habits like writing "im" for "I am", and "me" for "my". Both men were convicted.

In 2012 a team matched anonymous blog posts to their authors among 100,000 bloggers by style alone, and from a single post it picked the right one about 7.5 percent of the time. A random guess would be right once in 100,000 tries.

Language models have made it cheap. In 2024 an off-the-shelf language model, told only to compare writing style, picked the author of short blog posts of about 79 tokens, roughly sixty words or dating-profile length, from ten candidates with a weighted F1 score of 84 percent. It beat systems built for the job. In 2023 researchers at ETH Zurich found models could read ordinary posts and work out a writer's location, age and relationship status at about a hundredth of what the same work cost people. In 2026 a pipeline that reads raw text, pulls out anything that points to identity and checks candidates matched pseudonymous accounts to real people at up to 68 percent recall at 90 percent precision, where the best older method managed close to none. It uses what people say as well as how they say it, which is also what a profile gives away.

A 2025 study found that language models still struggle to imitate how ordinary people write in blogs and forums, so a casual style is also the hardest one to fake.

What this means for a copy that has already gone out

Dating data will be matched back to people this way. Dating apps have shared, sold and handed over profile and message data. Taking the name off first leaves the words in place, and they are long passages about yourself in your own voice. Bought app data has already been used to identify named people. Language models now pick out who wrote a text from its style and what it says, at a cost anyone can afford. A copy that went out years ago under the promise that it couldn't identify anyone is still wherever it went.

We wrote about the promise itself, and why it rested on re-identification being expensive, in De-identified does not mean what it used to.

If you still use the app

You don't have to leave to limit what an app does with you. You can object to the uses that aren't needed to run the service: selling or sharing your data, targeted advertising, profiling, and training AI on your photos and messages. Ask them to confirm the objection and to tell you who they've shared your data with, including anything passed on with your name removed. If the app shows or filters by distance, look for the setting that hides it.

Before you leave

Deleting the app from your phone deletes nothing on their side. Send a deletion request before you close the account, from the email address the account uses, since that's how they'll find your records and confirm the request is yours. Ask for everything: the profile, the photos, the verification selfie, the messages, and whatever they've inferred about you. Ask them to pass the deletion on to every company that received a copy, including copies with your name taken off, and to tell you in writing what they're keeping and why.

Some of it will stay. Copies already sent out won't come back on their own, and a company can keep some records for legal reasons. Their written answer is still worth having. If your data turns up somewhere later, you'll have their own dated account of what they held and what they said they did with it.

We keep that record for you. You add the company, and we work out what it likely holds and write the request, ready to send. You send it from your own inbox, their reply lands in yours, and we keep the list and the dates. Start your record →

More from the blog

ISSUE No. 02

Post 16 Jun 2026

De-identified does not mean what it used to

Every privacy policy lets a company pass on what it holds once your name is off it. The law allowed that because putting a name back took an expert, days and money. It now takes an AI model and a few seconds, and years of messages and profiles went out under the old assumption.

ISSUE No. 01

Post 16 Jun 2026

You proved you were real. Where did the proof go?

To open an account, watch a video, or start a job, you hand your face and your ID to a company you never chose. Here is what they keep, why 'we delete it' is a claim you can't check, and what a regulator found when it looked.

The Fine Print Dating & Matrimony: how the industry handles your data