Dating & Matrimony
A dating app records more than you type into your profile, and one permission at sign-up covers all of it, often across every app the company owns. Closing the account rarely clears the file, because safety holds keep part of it long afterwards.
The read at a glance
One file holds your orientation, your messages and your location.
A leak exposes who you want, what you believe, and what you said in private, and people have been outed and extorted with exactly that.
Safety holds keep a minimum long after you close the account, and one owner often pools it across several apps.
Liveness checks are common; some apps also ask for a government ID.
Industry profile reviewed 23 August 2026. Also machine-readable via the free API.
If it leaks
What leaks here is who you want, what you believe, and what you said in private. People have been outed and extorted with exactly this, and changing a password undoes none of it.
What repeats in the policies
It records things you never typed
On a mainstream app it comes from who you search for and who you message. A faith or matrimony service asks outright: religion, community, sometimes caste. On an app built for one community, being in the database is itself the disclosure, and a European regulator has ruled that membership alone reveals sexual orientation whatever the profile says.
One profile, one blanket permission
The file holds who you want, what you believe, your private messages, your face, your live location and the card that pays for it. Agreeing once at sign-up covers all of it.
Leaving rarely means gone
How long your data stays after closing is their claim: a few months, two years, or as long as they judge necessary. One company often owns several apps and pools the data across them, so quitting one doesn't clear the shared picture.
A promise not to sell leaves out sharing
Many apps promise they never sell your data, then share it with ad networks and partners. Their own definition of selling does not cover sharing, so the data goes either way.
What a company here typically holds
Worked out from the industry, not from any one company. What you actually handed over is yours to record.
What this can reveal about you
Built only from what this kind of service actually collects. A dimension that the data does not support is not listed.
Sexual orientation Highly likely
Norway's data protection authority held in 2021 that the fact of using one dating app strongly indicates membership of a sexual minority.
Who matters to you Highly likely
Who you match and message maps your intimate life.
Religion and community Likely
Faith and community are profile fields on matrimony services.
Health Likely
Some apps take health and disability as optional fields.
What lawfully stays after you leave
Two kinds of hold. Law sets it: a statute makes them keep it. They set it: a ground the company grants itself.
Safety and abuse records They set it as long as the ban holds
To enforce bans and stop blocked or abusive users coming back.
Identity and age-check records They set it as long as they choose
To prove they checked your age or identity and to block known fraud, sometimes held by a separate verification company.
Online-safety and child-protection reports Law sets it 1 year for content, 5 for the report reference
A legal duty to preserve child-safety reports, which overrides an erasure request for that data.
Records tied to a live or potential dispute They set it the limitation period of the claim
They can keep records to defend a live or possible legal claim.
Tax and accounting records Law sets it about 6 years
Tax and company law makes them keep billing and payment records.
Who wants this data
Location data from dating apps has been bought and tied to real people: one app's trail was used years later to publicly out a named person. Your chats and profile increasingly feed the company's own AI, and opt-outs only work going forward.
Sold or shared Highly likely
Location trails from these apps have been bought and tied to named people.
AI training High
Chats and profiles increasingly feed the company's own AI; opt-outs only work going forward.
Even anonymised, this can still be you
A dating file holds your location, your messages, your face, and who you talk to; four location points single out 95% of people (de Montjoye et al., 2013), and in 2021 commercially sold, name-stripped app location data was used to publicly identify a named person.
Name, date of birth, postcode Typical
Fifteen demographic attributes re-identify 99.98% of Americans in a released dataset (Rocher, Hendrickx and de Montjoye, Nature Communications, 2019); date of birth, postcode, and sex alone did it for most people in the first study of the problem (Sweeney, 2000).
Location traces Typical
Four time-and-place points single out 95% of people in mobility data (de Montjoye et al., Scientific Reports, 2013).
Payment patterns Sometimes
Four card transactions identify 90% of people in payment data (de Montjoye et al., Science, 2015).
How you write Typical
Language models infer where a person lives, their income, and their sex from their writing alone, at near-human accuracy and at scale (Staab et al., ICLR 2024).
Face and voice Typical
A face, voice, or fingerprint template identifies a person directly; there is nothing left to anonymise, and it cannot be reissued like a password.
Browsing fingerprint Sometimes
Browser and device fingerprints were unique for 84% of visitors in the first large study (Eckersley, 2010), and sparse histories of what people viewed re-identified them against public reviews (Narayanan and Shmatikov, 2008).
Who you know Typical
The shape of who a person connects with re-identifies accounts across networks with no other data (Narayanan and Shmatikov, 2009).
The studies Estimating the success of re-identifications in incomplete datasets using generative models (Nature Communications 10, 3069, 2019)·Simple Demographics Often Identify People Uniquely (Carnegie Mellon University, Data Privacy Working Paper 3, 2000)·Unique in the Crowd: The privacy bounds of human mobility (Scientific Reports 3, 1376, 2013)·Unique in the shopping mall: On the reidentifiability of credit card metadata (Science 347 (6221), 2015)·Beyond Memorization: Violating Privacy via Inference with Large Language Models (ICLR 2024, 2024)·How Unique Is Your Web Browser? (Privacy Enhancing Technologies Symposium (PETS 2010), 2010)·Robust De-anonymization of Large Sparse Datasets (IEEE Symposium on Security and Privacy, 2008)·De-anonymizing Social Networks (IEEE Symposium on Security and Privacy, 2009)·Administrative fine against Grindr LLC (decision of 13 December 2021) (Datatilsynet, the Norwegian Data Protection Authority, 2021)
The wording that does the work
Clauses that recur across this industry, and what each one actually permits.
“to provide and improve our services”
The catch-all purpose. Analytics, profiling, personalisation and AI training all fit under it. When they want to do something new with your data, this sentence usually already allows it.
The move An objection tells them to use your data to run the service and nothing more.
“we do not sell your personal information”
Usually this means no cash changes hands. Your data can still go to ad networks, analytics firms and partners, because they count that as sharing rather than selling.
The move Use the do-not-sell switch where there is one, and put an objection in writing as well.
“service providers, partners, and affiliates”
This is how your data leaves with no name attached. Recipients are described by what they do rather than named, and you cannot send a request to a company you cannot name.
The move An access request can ask for recipients by name rather than by category, and UK and EU law put that choice with you.
“aggregated or de-identified information”
Taking your name off does not take away the pattern, and the pattern often still points at you. Policies give themselves free use of this data with no end date, on the basis that it is no longer about you.
The move If a deletion comes back as 'anonymised', keep the reply. It usually means de-identified, and it is their claim, not a fact you can check.
“retained as long as necessary, or as required by law”
They can keep it for legal duties, tax rules, fraud prevention, possible lawsuits and their own business reasons. None of those has a firm end date, so deletion turns into something you have to argue for.
The move Which reasons apply to you, and how long each runs, is a request of its own.
“you grant us a licence to use your content”
This is a contract term rather than a data setting, so a privacy request cannot undo it. A careful version ends when your account does. A broad one can be passed on, never expires and survives deletion.
The move Their terms say whether the licence ends when the account does. Close the account and log the date here.
“we implement a safety retention window following account closure”
Your data outlives your deletion for a safety reason the company defines and judges itself. A closure commonly means a few months; a ban a year or more, with no independent review of the ban.
The move Which window applies to you, and what it covers, is theirs to answer.
“we share data with our affiliates, and they share data with us”
Pooling across every brand the group owns, including apps you never joined, for safety screening, marketing, and whatever the group builds next.
The move The app answers for itself, and the wider group takes a request of its own.
“if you choose to provide this data, you consent to us using it”
One yes covers the most dangerous data you have: orientation, faith, or health entered as profile fields becomes blanket permission, not a separate choice per use.
The move Consent can be withdrawn in writing. Withdrawing it forces them to find another reason or stop.
“fully deleted and/or anonymised”
Keeping the record with the name taken off. Which of the two happens, and by what method, is never said, and a profile this detailed can still point back to you without the name on it.
The move Ask which one applies to your data, and by what method.
From the blog
Post 23 Sept 2026
What dating apps keep, and how the way you write can name you
A dating or matrimony profile holds your face, your faith, who you're drawn to and years of private messages. Some of that has already been shared, sold, scraped, handed to an AI company and leaked. Taking your name off doesn't hide you, because AI can now work out who wrote a text from the way it's written. Here's what these apps hold, where it has gone, and what to ask for.
Their own policy is the one that binds them. Pin it down with a request, and keep the reply.