All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Grindr users trusted a dating app with some of the most sensitive information a person can share. Now the company is paying £26 million to settle allegations that some of that information was shared with third parties.[1]
The LGBTQ+ dating app has agreed to settle a UK lawsuit brought on behalf of roughly 12,000 users who accused the company of improperly sharing personal information, including HIV status and testing information.
Grindr disputes the allegations, and the settlement includes no finding or admission of liability.
The privacy concerns go back years
Dating apps know a lot more about you than who you swipe on
How to give dating apps less information
What Grindr users accused the company of sharing
London law firm Austen Hays filed the claim in the High Court of England and Wales in 2024.
The lawsuit alleged that Grindr violated UK data protection laws by handling users' sensitive information before 2020.
At the center of the case was data that could include users' HIV status and the date they were last tested. The claim also raised concerns about other information, including the use of medications such as PrEP.
Around 12,000 people ultimately joined the action.
Grindr has agreed to pay £26 million to settle it, split into two £13 million payments due by the end of December 2026 and March 2027.
If the settlement were divided evenly among 12,000 claimants, that would work out to roughly £2,167 per person, although actual payments may differ.
Grindr said the settlement concerns "historical data practices before 2020" and stressed that it does not admit liability.
"While Grindr disputes the allegations, it recognizes and acknowledges the distress and loss of trust expressed by some of its U.K. users regarding that pre-2020 period," the company said in a regulatory filing.
The privacy concerns go back years
This isn't the first time Grindr's handling of user information has come under scrutiny.
In 2018, researchers at Norwegian nonprofit SINTEF found that Grindr was transmitting users' HIV status and last HIV test dates to Localytics and Apptimize, two third-party services used for app analytics and optimization.
Those companies were not advertisers, and Grindr said it shared the information to test and improve its service. But users reportedly weren't told their HIV information was being sent to them.
Amid the backlash, Grindr said it would stop sharing HIV-status information with those third-party vendors.
Grindr later faced separate regulatory action over its advertising practices. Norway's Data Protection Authority fined the company 65 million Norwegian kroner after finding that Grindr disclosed personal information to third parties for behavioral advertising without valid consent.
The UK's Information Commissioner's Office also reprimanded Grindr in 2022 after finding that the company failed to provide UK users with effective, transparent information about how their personal and special-category data was processed.
Grindr says it has overhauled its privacy program since 2020.
Dating apps know a lot more about you than who you swipe on
That's what makes this case bigger than Grindr.
Dating apps can contain an extraordinary amount of personal information.
Depending on the app and what you choose to provide, your profile and activity could reveal your sexual orientation, approximate or precise location, relationship preferences, photos, age, interests ,and health information.
Some of those details might not seem particularly dangerous on their own. Put them together, however, and they can create a remarkably intimate picture of your life.
Location data can show where you spend your time. Profile information can reveal your sexuality or relationships. Health information can disclose medical details you might not have told friends, family members, or employers.
And unlike a password, you can't simply change your HIV status, sexual orientation, or history if that information gets exposed.
How to give dating apps less information
You don't necessarily have to delete every dating app on your phone. But it's worth treating them differently from apps that don't handle such intimate information.
Start by limiting your profile to information other users actually need to see. If a health, workplace, or location field is optional, consider whether the benefit of filling it out outweighs the privacy risk.
Review the app's privacy and advertising controls. Disable personalized advertising and unnecessary tracking where possible, and check your phone's permissions to see whether the app has access to your precise location, contacts, photos, or other information it doesn't need.
You can also limit location access while you're using the app rather than allowing constant background access.
Most importantly, don't assume that information is private simply because you entered it into a private account.