Dating Apps. The Most Intimate Data in the Least Trustworthy Hands

What you hand over when you’re looking for love

Journalist Judith Duportail decided to check what Tinder knew about her. She filed a data-access request under European law. A few weeks later, she got a response.

800 pages.

Everything was in there. Every click. Every swipe left and right. Every message — including the ones she’d already deleted. Her exact location every time she opened the app. How many times she’d opened the chat with each person. How many seconds she’d looked at each profile. Information pulled from her Facebook — political views, likes, interests. Data about her phone.

800 pages of one person’s intimate history, from someone who was simply looking for a relationship.

This was 2017. Since then, apps have started collecting more.

Dating apps are a special case among digital services. Not because they’re technically more complex. Because the data they collect is the most personal there is. Sexual preferences. Religious beliefs. Political convictions. HIV status. Information about children. Financial standing. Appearance. Loneliness.

A person looking for a partner opens up as much as possible. That’s natural. It’s necessary for the goal at hand. But it’s exactly what makes them vulnerable.

Let’s break down how this works across four different worlds. And why, despite all their differences — the substance is the same everywhere.


What everyone collects. No exceptions.

Before talking about regional differences, it’s important to understand what unites every dating app, regardless of country or platform.

The Mozilla Foundation conducted a study of dating apps in 2024. The conclusion was blunt: they’d gotten even worse for privacy than they were in 2021. In 2024, the stakes went up — and data protection hasn’t kept pace.

Here’s the standard set of data a typical dating app collects.

Profile data. Name, age, gender, sexual orientation, photos, self-description, partner preferences. Everything you voluntarily entered — and plenty you entered because the app simply won’t work without it.

Behavioral data. Who you liked. Who you didn’t. How long you looked at each profile. Which photos held your gaze. Who you started messaging. Who replied. Who didn’t. How fast you replied. What time of day you were active.

Communications. The content of your messages — even the ones you “deleted.” Most services retain messages on their servers regardless of whether you deleted them on your end.

Location. Where you were each time you opened the app. Precise enough to identify home, work, and regular routes.

Technical data. Phone model. OS version. IP address. The device’s advertising identifier. Through it, data from the dating app can be linked to your behavior in other apps.

Inferred data. 64% of apps explicitly state in their privacy policies that they generate “inferences” from your data. This means the algorithm guesses things about you that you never said. Income level. Education. Political views. A psychological profile.

And that’s just what apps officially admit to. A HAR file from a live session shows considerably more.


Europe. There’s a law. Enforcement is another question.

Europe has the strictest personal-data protection laws in the world. The GDPR. Maximum fines. Data-subject rights. Mandatory consent.

You’d think this is exactly where dating-app users should be most protected.

Reality is more complicated.

The Grindr case. The most telling precedent.

Grindr is the largest dating app in the LGBTQ+ community. Operates worldwide. Its European headquarters is in the US. But users in Europe fall under GDPR protection.

From when the GDPR took effect in 2018 until April 2020, Grindr shared its users’ data with advertising partners without an adequate legal basis. The data included GPS location, IP address, advertising identifier, age, gender — and, most critically: the very fact that a user was on Grindr at all.

That last point is critical. Being on Grindr reveals sexual orientation. That’s a special category of data under GDPR Article 9. Maximum protection. Processing without explicit consent is prohibited.

Norway’s regulator, Datatilsynet, imposed a fine of 65 million Norwegian kroner — about €6.5 million — in December 2021. Grindr fought the decision for four years. In October 2025, the Borgarting Court of Appeal finally upheld the fine. The ruling took effect.

What exactly was violated. The consent Grindr used as its legal basis wasn’t freely given. If a user clicked “Cancel” instead of “Accept” the first time they opened the app, they couldn’t register. This is bundled consent. GDPR explicitly prohibits it under Article 7(4).

Tinder and the Irish regulator.

Tinder is owned by Match Group. Its European headquarters is in Ireland. That makes Ireland’s DPC the competent regulator for European users.

In February 2020, Ireland’s DPC opened an investigation into Tinder. The focus — GDPR compliance regarding how data-access requests were handled and data-retention policies.

In January 2024, the DPC issued a preliminary decision: Tinder violates the GDPR. The procedure isn’t yet complete.

In parallel — in the US, a class-action lawsuit was filed against Match Group in February 2024. It alleges their apps are deliberately designed to “coerce subscriptions and keep users hooked forever.” In September 2025, the parties agreed to a $60.5 million settlement.

What this means for a European user.

The GDPR provides real tools. The right to access data — Article 15. The right to erasure — Article 17. The right to object to processing — Article 21.

Judith Duportail used Article 15 and received 800 pages. You can do the same. Any dating app operating in the EU must respond within 30 days.

But tools only work when people use them. Most don’t — because they don’t know these tools exist.


America. A market with no federal law.

The US is home to most of the largest dating apps. Tinder, Bumble, Hinge, OkCupid, Grindr — all American companies. All collecting enormous volumes of data. And all operating under a fundamentally different legal landscape than Europe.

The US has no federal personal-data protection law on the level of the GDPR. The American Privacy Rights Act — a bill that’s been discussed for years — still hadn’t passed as of 2026.

This means the rules of the game are set state by state. California has the CCPA. Texas has the Texas Data Privacy and Security Act. Other states vary widely, or have nothing at all.

What this means in practice.

An American company handling American users’ data in most states isn’t required to obtain consent before collecting it. Isn’t required to disclose exactly what it collects. Isn’t required to delete data on request — unless the user is in California or another state with a privacy law.

Apps make maximum use of this space.

Tinder collects data on your messages — including deleted ones. Reserves the right to share data with law enforcement “when required by law.” Reserves the right to share data with third parties for advertising. Its privacy policy states “we don’t sell personal data” — but immediately follows with a list of who it “shares” data with. The distinction between “sell” and “share” is legal, not factual.

Bumble collects user data including “sensitive information” — and explicitly states in its policy that it may share it with partners to “improve services.”

OkCupid asks questions that directly reveal political views, religious beliefs, and attitudes toward drugs and sex. All of this becomes part of the profile — and potentially part of the data shared with third parties.

American data and law enforcement.

In the US, apps regularly receive requests from law enforcement agencies. And regularly respond to them.

Match Group — Tinder’s parent company — discloses the number of government requests in its reports. In a single year, the company received hundreds of requests from American authorities for user data.

This isn’t necessarily bad — law enforcement uses this data, among other things, to investigate real crimes. But most users don’t know that their dating conversations could end up in a case that has nothing to do with them at all.


Russia. The state as a data recipient.

The Russian dating-app market is its own story.

Before 2022–2023, it resembled the European and American markets. Tinder led. Badoo was popular. International platforms operated freely.

Then the situation changed fundamentally.

Badoo stopped operating in Russia in April 2022 in response to the invasion of Ukraine. Tinder exited the Russian market entirely on June 30, 2023. According to Statista, Tinder’s audience in Russia shrank from 26% in 2022 to 1% by the end of 2024.

Domestic platforms now dominate the market that opened up. VK Dating — a product of Russia’s largest social network. Mamba — 70 million profiles, one of the oldest Russian dating apps. Twinby, Tabor, LovePlanet.

The mechanism of state access.

Russia operates a system called the “register of information dissemination organizers” — run by Roskomnadzor. Any platform collecting data on Russian users is required to: store the data on servers in Russia, provide the FSB and law enforcement with access to user data on request, and notify Roskomnadzor of any changes to how the service operates.

Mamba was added to this register back in 2014. Badoo — in 2017. Tinder — in 2019.

What this means in practice. A Russian user of a dating app that’s on the register has their data accessible to state agencies without a court order. Messages. Location. Sexual preferences — if listed.

This isn’t a hypothetical threat. It’s a direct consequence of legislation that’s actively enforced.

The particular vulnerability of LGBTQ+ users.

In 2023, Russia passed a law banning “propaganda of non-traditional sexual relations” for any audience — not just minors, as had been the case before. A law banning gender-affirming medical procedures was passed at the same time.

For LGBTQ+ users of dating apps in Russia, this creates a direct risk. The data they enter in their profiles — sexual orientation, preferences — could potentially be used as grounds for persecution. Especially if that data is stored on servers in Russia with state access.

This is precisely why Grindr received a record fine in Norway — for sharing sexual-orientation data with advertisers without consent. In the Russian context, the same type of data creates a risk of a different order entirely — not advertising, but criminal.

VK Dating and ecosystem integration.

VK Dating isn’t a standalone app. It’s a feature within the VKontakte ecosystem. And VKontakte is a social network required, under Russian law, to store data in Russia and hand it over to state agencies.

A VK Dating user is using a dating feature inside a platform that has no ability to refuse a state request. This is an architecturally built-in absence of privacy — not an accident, but a design feature.


China. Privacy in a different sense.

China’s dating-app market is the largest by user count. More than 82 million active users. More than 270 apps. A market worth nearly $13 billion.

The market leaders are Momo and Tantan. Momo acquired Tantan in 2018; both platforms now belong to Hello Group Inc. Soul is backed by Tencent. This is a significant detail: China’s largest tech companies have a presence in the dating ecosystem.

A different concept of privacy.

In China, the very concept of data privacy is structured differently than in Europe or the US.

In Europe, privacy is an individual’s right to protection from corporations and the state.

China passed its Personal Information Protection Law (PIPL) in 2021. Structurally, it resembles the GDPR. But its application differs substantially. The state is simultaneously the privacy regulator and the largest recipient of data. The law limits what companies can do with data among themselves. It doesn’t limit the state’s access to that data.

What this means for a user.

Tantan is legally required to store Chinese users’ data within China. State agencies have access to this data on request.

Tantan has been pulled from Chinese app stores multiple times — in 2019, because of regulators’ objections to “immoral content.” This shows the state actively monitors not just the technical aspects of how apps operate, but their content too.

Identity verification.

Unlike most Western apps, Chinese dating platforms require verification of a real name and, in some cases, an identity-document number.

This is the exact opposite of the anonymity Western apps offer. Every Momo or Tantan user is verified. The state knows who is dating whom.

Security at the code level.

During its growth phase, Tantan had a serious vulnerability — data was transmitted unencrypted. A security researcher found that, over open WiFi, it was possible to intercept users’ phone numbers, passwords, location coordinates, and chat history. This isn’t state surveillance — it’s technical negligence. But the effect is the same: the data is accessible to anyone who knows how to get it.

Banned in India.

Tantan was banned in India in 2020, along with more than 200 other Chinese apps — on national-security grounds. The official reason: the apps “stealthily transmit users’ data to servers outside India.” In 2025, the app returned under the brand “TanTan — Asian Dating App.” What happened to the data in the meantime was never publicly explained.


What unites all four worlds

For all their differences — in laws, culture, risks — there are three things that work the same way everywhere.

First — data is collected to the maximum extent possible.

None of the apps reviewed applies the principle of data minimization — collecting only what’s necessary for the service to function. All of them collect substantially more. Because data is money. Advertising, sale to brokers, use to improve algorithms — all of it gets monetized.

Second — consent is a formality.

In Europe — a lengthy privacy policy and an “Accept” button. In the US — by default, everything’s permitted unless explicitly prohibited. In Russia — state access is built into the legislation. In China — identity verification is mandatory, and the state stands above the law.

Nowhere does the user get a genuine choice about what actually happens to their data after they click the button.

Third — the data outlives the relationship.

You found a partner. Deleted the app. Data about you — messages, preferences, location, psychographic profile — stays on the company’s servers. On advertising brokers’ servers. In databases the company sold or shared.

The relationship might end. The data doesn’t.


A special risk. When data lands somewhere it shouldn’t.

There’s a scenario common to every region — one almost never discussed.

Dating apps collect data on people in vulnerable situations. People hiding their orientation from family. People who are married and looking on the side. People who are HIV-positive and disclosed it in their profile. People going through a divorce and seeking support. People physically located in a country where their sexual identity is criminalized.

In 10 countries around the world, same-sex relationships are punishable by death. A user who opens Grindr in an airport in one of these countries has their location recorded. The data goes out to advertising partners. If a partner has access to that data within that jurisdiction, the user is at risk.

This isn’t paranoia. It’s a documented risk cited in research on digital security for the LGBTQ+ community.

Data that’s harmless in one context is lethal in another.


What to do. Specifically.

Giving up dating apps entirely is possible, but not required. Understanding what happens to your data is essential.

Request your data

Under GDPR Article 15, any app operating in the EU is required to hand over all the data it holds on you. Request it through the form in the app’s settings, or by emailing support. Response deadline — 30 days.

This is what Judith Duportail did. 800 pages. You can do it too. It’s free. No lawyer needed.

Minimize what you disclose

If an app asks for political views, religion, alcohol and drug use — these are optional fields in most cases. The less you disclose, the less data sits in a profile that could potentially leak.

Using your real name isn’t always required. Photos with location metadata are always a risk. Strip the geotags from photos before uploading.

Check the app’s permissions

A dating app needs the camera for photos. Possibly location, for nearby search. Access to your contacts — not needed. Background microphone access — not needed.

iOS: Settings → Privacy → check every item. Android: Settings → Apps → select the app → Permissions.

Delete your account properly

“Delete profile” and “delete account” are different actions. A deleted profile can be restored. A deleted account — with a data-deletion request — gives you the right under GDPR Article 17 to demand the data be destroyed.

After deleting your account, send a separate request for the deletion of all data. Note the date you sent it. If there’s no response within 30 days, or the data isn’t deleted, that’s a violation of GDPR Article 12(3). Grounds for a complaint to the regulator.

Use a separate email

The email you use for a dating app shouldn’t be the same one you use everywhere else. This limits the ability to link data from the app with data from other sources.

If you’re in a higher-risk situation

If you’re in a country or situation where your sexual orientation or personal life could create legal or physical risk, consider using a VPN before opening the app. Use apps with end-to-end encrypted messaging. Check the privacy policy for where data is stored and who it’s shared with.


One last thing. About intimacy in the digital age.

Looking for a partner is one of the most human needs there is. Apps that make this easier genuinely help billions of people.

But there’s a huge gap between what you’re looking for and what you’re giving up in the process — one most people never notice.

You’re looking for love. Or closeness. Or just good company.

The algorithm builds your psychographic profile. An advertising broker buys it. An insurance company analyzes it. The state — depending on the country — has access to it.

Data about who you’re drawn to, at what time of day, how long you look at photos, what words you use in conversation — all of it exists somewhere on a server. Right now. And ten years from now.

Regardless of whether you found what you were looking for.

Knowing this shouldn’t stop you from using these apps. It should change how you use them.

Being deliberate means understanding the price. Not refusing to pay it. But knowing exactly what you’re paying.

← All journal entries