THE INDUSTRY FILES

Dating & Matrimony

A dating app's file runs past your profile: it records behaviour you never typed, pooled under one blanket permission that often covers a whole affiliate group. Leaving rarely means gone; safety holds keep a minimum long after the account is closed.

TRACKING PRIORITY HIGH

Orientation, messages, and location, pooled and kept. Keeping the record is worth it.

IF IT LEAKS SEVERE
EXPECT IT KEPT INDEFINITELY

Safety holds keep a minimum long after you close the account, and one owner often pools it across several apps.

IDENTITY DEMANDED LIVENESS OR ID

Liveness checks are common; some apps also ask for a government ID.

Industry profile reviewed 23 August 2026. Also machine-readable via the free API.

IF IT LEAKS

What leaks here is who you want, what you believe, and what you said in private. People have been outed and extorted with exactly this, and changing a password undoes none of it.

What repeats in the policies

WHAT THE FILE SAYS

It records things you never typed

On a mainstream app it is drawn from who you look for and who you message. On a faith or matrimony service the fields are on the form: religion, community, sometimes caste. On an app built for one community, being in the database is itself the disclosure, and a European regulator has held exactly that, ruling that membership alone reveals sexual orientation whatever your profile says.

WHAT YOU HAND OVER

One profile, one blanket permission

Who you want, what you believe, your private messages, your face, your live location, and the card that pays for it. The most sensitive fields all ride on a single yes.

WHEN YOU LEAVE

Leaving rarely means gone

How long your data stays after closing is their claim: a few months, two years, or as long as they judge necessary. One company often owns several apps and pools the data across them, so quitting one doesn't clear the shared picture.

WHILE YOU'RE THERE

They don't sell. They share.

Many apps say they don't sell your data and share it anyway with ad networks and partners: under their own definition, sharing is not selling.

What a company here typically holds

Worked out from the industry, not from any one company. What you actually handed over is yours to record.

Contact InfoAccount ProfileMessagesLocation Identity Documents maybeBrowsing & Activity maybePurchases maybeFinancial maybePhotos & Biometrics maybe

What this can reveal about you

Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.

Sexual orientation HIGHLY LIKELY

Norway's data protection authority held in 2021 that the fact of using one dating app strongly indicates membership of a sexual minority.

Who matters to you HIGHLY LIKELY

Who you match and message maps your intimate life.

Religion and community LIKELY

Faith and community are profile fields on matrimony services.

Health LIKELY

Some apps take health and disability as optional fields.

What lawfully stays after you leave

Two kinds of hold. LAW SETS IT: a statute makes them keep it. THEY SET IT: a ground the company grants itself.

safety and abuse records AS LONG AS THE BAN HOLDS THEY SET IT

To enforce bans and stop blocked or abusive users coming back.

identity and age-check records AS LONG AS THEY CHOOSE THEY SET IT

To prove they checked your age or identity and to block known fraud, sometimes held by a separate verification company.

online-safety and child-protection reports 1 YEAR FOR CONTENT, 5 FOR THE REPORT REFERENCE LAW SETS IT

A legal duty to preserve child-safety reports, which overrides an erasure request for that data.

records tied to a live or potential dispute THE LIMITATION PERIOD OF THE CLAIM THEY SET IT

They can keep records to defend a live or possible legal claim.

tax and accounting records ABOUT 6 YEARS LAW SETS IT

Tax and company law makes them keep billing and payment records.

Who wants this data

Location data from dating apps has been bought and tied to real people: one app's trail was used years later to publicly out a named person. Your chats and profile increasingly feed the company's own AI, and opt-outs only work going forward.

SOLD OR SHARED HIGHLY LIKELY

Location trails from these apps have been bought and tied to named people.

AI TRAINING HIGH

Chats and profiles increasingly feed the company's own AI; opt-outs only work going forward.

Even anonymised, this can still be you

Anonymised is their word. A dating file holds your location, your messages, your face, and who you talk to; four location points single out 95% of people (de Montjoye et al., 2013), and in 2021 commercially sold, name-stripped app location data was used to publicly identify a named person.

Name, date of birth, postcode TYPICAL

Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).

Location traces TYPICAL

Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).

Payment patterns SOMETIMES

Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).

How you write TYPICAL

Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).

Face and voice TYPICAL

A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.

Browsing fingerprint SOMETIMES

Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).

Who you know TYPICAL

The shape of who a person connects with re-identifies accounts across networks with no other data (Narayanan and Shmatikov, 2009).

THE STUDIES Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·De-anonymizing Social Networks (IEEE Symposium on Security and Privacy, 2009)·Administrative fine against Grindr LLC (decision of 13 December 2021) (Datatilsynet, the Norwegian Data Protection Authority, 2021)

The wording that does the work

Clauses that recur across this industry, and what each one actually permits.

“to provide and improve our services”

The catch-all purpose. Analytics, profiling, personalisation, and increasingly AI training can all ride under it. When they want to do something new with your data, this sentence usually already covers it.

THE MOVE An objection draws the line: use your data to run the service, not to improve, target, or train on it.

“we do not sell your personal information”

Often technically true, and still misleading. It usually means no cash changes hands. Data can still flow to ad networks, analytics firms, and partners: on their definition, sharing is not selling.

THE MOVE Flip the do-not-sell switch where one exists. The written objection on top of it goes on your record.

“service providers, partners, and affiliates”

How data leaves the building with no name attached. Recipients are listed by what they do, never who they are. You cannot send a request to a company you cannot name, which is the point.

THE MOVE An access request can ask for the recipients by name, not just the categories. UK and EU law put that choice with you. The reply, or the silence, goes on your record.

“aggregated or de-identified information”

Stripping the name does not strip the pattern, and the pattern often still points at you. Policies grant themselves free, indefinite use of this data because in their telling it is no longer about you.

THE MOVE If a deletion comes back as 'anonymised', keep the reply. It is their claim, not a fact you can check.

“retained as long as necessary, or as required by law”

They can keep it for: legal duties, tax rules, fraud prevention, possible lawsuits, their own business reasons. None of them carries a firm end date. Deletion becomes a negotiation, not an event.

THE MOVE Which reasons apply to you, and how long each runs, is a request of its own. Their reply goes on your record.

“you grant us a licence to use your content”

A contract term, not a data setting, so a privacy request cannot undo it. The careful version ends with your account. The broad version can be passed on, never expires, and survives deletion.

THE MOVE Whether the licence ends with the account is written in their terms, not yours. Closing the account goes on your record.

“we implement a safety retention window following account closure”

Your data outlives your deletion for a safety reason the company defines and judges itself. A closure commonly means a few months; a ban a year or more, with no independent review of the ban.

THE MOVE Which window applies to you, and what it covers, is theirs to answer. Their reply goes on your record.

“we share data with our affiliates, and they share data with us”

Pooling across every brand the group owns, including apps you never joined, for safety screening, marketing, and whatever the group builds next.

THE MOVE A request aimed at the group, not just the app, reaches the shared pool. Every brand's copy is covered.

“if you choose to provide this data, you consent to us using it”

One yes covers the most dangerous data you have: orientation, faith, or health entered as profile fields becomes blanket permission, not a separate choice per use.

THE MOVE Consent can be withdrawn in writing. Withdrawing it forces them to find another reason or stop.

From the Dispatch

Their own policy is the one that binds them. Pin it down with a request, and keep the reply. Start your record →