What we found
OkCupid: FOkCupid promised to protect your personal data.
Norwegian Consumer Council "Out of Control" report (January 2020): OkCupid shared GPS location, sexual orientation, drug use, and political views with at least 135 third-party companies including Google, Facebook, and data brokers. Data transmitted included answers to intimate questions like "Have you ever used drugs?" tagged with device ID and GPS coordinates. The Norwegian Data Protection Authority received formal GDPR complaints. Data was shared in ways that enabled individual identification — your sexual orientation, your GPS coordinates, your device ID, all bundled together.
Grindr: FGrindr's owner sold it to a Chinese gaming company.
Chinese gaming company Kunlun Tech acquired Grindr in 2016-2018. CFIUS (Committee on Foreign Investment in the United States) ordered Kunlun to divest in 2019, determining that Chinese ownership of a database containing the sexual orientation, HIV status, location data, and private messages of millions of Americans posed a national security risk. Intelligence officials feared the data could be used for blackmail of military and government personnel. Kunlun sold Grindr in 2020 for $608 million.
eHarmony: FeHarmony called their password storage secure.
The 2012 breach exposed 1.5 million passwords hashed with unsalted SHA-1 in case-insensitive form. Trustwave cracked 80% within 72 hours using basic dictionary attacks. No salting, case normalisation — elementary errors well below industry standard for 2012.
Bumble: DBumble asks for your politics, your religion, whether you drink, smoke, exercise, want kids.
Bumble prompts users to share political leaning, religious beliefs, zodiac sign, education, drinking habits, smoking habits, exercise frequency, pet preferences, and desire for children. This data — classified as "special category" under GDPR requiring explicit consent — is used for matching algorithms but also shared with analytics partners. Combined with location data, it creates a detailed profile of users' most sensitive beliefs and lifestyle choices, tied to their real identity and precise location.
Tinder: DFrench journalist Judith Duportail asked Tinder for her data under European privacy law.
French journalist Judith Duportail filed a GDPR Subject Access Request and received 800 pages of data Tinder had collected on her. The data included: every conversation she'd had, the ages and genders of men she swiped on, how often she logged in, where she logged in from, which friends she had on Facebook, her interests, how many Facebook photos she had, when and where every conversation happened, and a secret internal "desirability score." Guardian investigation, September 2017.
Hinge: DHinge says it's "designed to be deleted." It launched that slogan the same year its parent company went public on the stock market.
Match Group 2023 10-K SEC filing: "Our financial performance depends on successfully retaining existing users and attracting new users." Match Group revenue: $3.2 billion (2023). Hinge launched "designed to be deleted" in 2019 — the same year Match Group completed its IPO. Hinge revenue grew from ~$197M (2021) to ~$400M (2023). Match Group's stock price drops when user counts decline. Every person who deletes Hinge is a lost subscriber worth $200-480/year.
Match.com: DThe FTC sued Match.com for using fake love to sell subscriptions.
FTC sued Match Group (September 2019): Match.com sent "You caught his eye" and "Someone's interested in you!" emails using messages from accounts Match knew were likely fraudulent. Between June 2016 and May 2018, approximately 25-30% of new Match.com accounts were fraudulent. Match still used their messages to lure free users into buying subscriptions at $203-480/year. FTC: "We believe Match.com conned people into paying for subscriptions via messages the company knew were from scammers." Internal data showed users who received these messages purchased subscriptions at higher rates.