Independent guide · No sign-up · Updated today18+FIRUEN
TREFFIKONETake the test
No affiliate links in this section

What dating apps collect

Location, photos, messages — and what happens when you delete the account.

Short answer

Dating apps collect three layers of data: what you entered yourself, what is gathered automatically on every login, and what is inferred from your behaviour. Under EU law the first layer belongs to a special category — data on sex life and orientation is protected more strictly than ordinary data, its processing is prohibited by default, and it is permitted by explicit consent. The Norwegian supervisory authority fined one service 65 million kroner, treating even the bare fact that a person uses it as special category data.

Art. 9Sex life and orientation are a special categoryGDPR
65 M NOKFine for passing such data to advertisersDatatilsynet, Norway
10 yearsTinder keeps transactional datapolicies.tinder.com
1 monthDeadline for answering your requestGDPR, Art. 12(3)

What is always collected, even if you never filled in a profile

This layer does not depend on how careful you are; it is collected by the fact of using the service.

Account data: your email address, your phone number if it was confirmed, the date you registered.

Technical data: IP address, device model, operating system version, language, time zone. Separately, the device’s advertising identifier — the Advertising ID by which different apps from the same owner recognise you.

Behavioural data: when you logged in and for how long, whose profiles you looked at, who you wrote to, who you skipped, how quickly you replied. This is the largest layer and the most underrated: a profile says what you decided to say about yourself, behaviour says what you did not intend to.

Location, if you allowed it. On apps that show distance, the precision can be such that with enough persistence a home address can be worked out.

An important consequence: deleting the text of your profile and your photographs does not delete this layer. It is attached to the account, not to the content of the profile.

Why the law treats this data more strictly than usual

This is not a formality but the thing that changes the controller’s obligations and the extent of your rights.

Article 9 of the GDPR treats data on sex life and sexual orientation as special categories, whose processing is prohibited as a general rule. The prohibition is lifted, among other ways, by the data subject’s explicit consent — which is why such services ask for consent separately and in more detail than usual.

The Finnish Data Protection Ombudsman (tietosuojavaltuutettu) confirms the same list and the same principle of prohibition.

Two concrete obligations follow from the special status. Large-scale processing of such data requires a data protection impact assessment. And if such processing forms the core activity, appointing a data protection officer is mandatory.

In practice this is visible in the documents. The Finnish Treffit24, in its description of data processing, explicitly lists data on sexual behaviour and orientation among the sensitive information it handles, if a user chooses to state it. Tinder acknowledges in its privacy policy that some data is treated as sensitive in certain countries, and names consent as the basis for processing.

The wordings are honest — and they also mean that this data really is there.

Who this data goes on to

The most underrated part of the subject: people worry about what other users will see, while the volume passed to third parties is usually greater.

The Norwegian Consumer Council — a state body — published a technical study and a formal complaint in 2020 based on measurements of app traffic. Its conclusions are stated plainly.

On those measurements, Tinder passed special category data to the third-party providers LeanPlum and AppsFlyer, and the device advertising identifier to Salesforce and Krux. OkCupid passed sensitive personal data to Braze and the advertising identifier to Kochava. Both apps passed the advertising identifier to Facebook and interacted with Google DoubleClick.

The report separately describes a case where, through advertising mediation, data — IP address, advertising identifier, location, age and gender — spread out to a whole range of advertising platforms.

The mechanics matter more here than the particular names, because partners change and the scheme does not. An app embeds third-party libraries for analytics and advertising, and those libraries receive data directly, without a separate conversation with you. Formally you gave consent on installation; in practice nobody reads the list of recipients.

Checking this yourself is hard, but one action is available to everyone: in the privacy policy, find the section on passing data to third parties and see whether the recipients are named individually or described as “partners and service providers”.

The Norwegian case: why this is not theory

The one major European supervisory case specifically about dating, and the reasoning matters more than the sum.

The supervisory authority Datatilsynet fined Grindr LLC 65 million Norwegian kroner — around 6.5 million euros — for passing user data to advertising third parties. The infringement period was July 2018 to April 2020.

The authority’s key conclusion reads like this: data revealing that a person is a user of this service strongly indicates that they belong to a sexual minority, and data on sexual orientation belongs to a special category and deserves special protection.

In other words, what came under protection was not the text of a profile or the photographs but the bare fact of having an account.

The decision held: in September 2023 it was confirmed by the Privacy Appeals Board, and in 2025 the court of appeal left the fine standing, holding that the consents were invalid and that special category data had been passed to advertising partners.

For a user one simple thought follows. If the bare fact of using a service is protected data, then a leak of a user list — without a single message or photograph — is already a serious incident.

What remains after you delete your account

This is where the gap between expectation and practice is widest.

Tinder describes its safety period explicitly: profile data is deleted with a delay of three months after an account is closed, and a year after a ban. Correspondence with support is kept for six years. Transactional data is kept for ten years, under tax and accounting requirements.

Treffit24 warns that deleting a profile cannot be undone and the data cannot be restored. The retention period in its data protection document is tied to the time you are a customer, plus until the end of the third year after that.

Note the difference between “hide” and “delete”. A hidden profile stays with the controller and is usually deleted automatically only months later. If the aim is to remove data, hiding is not enough.

Separately, about what has already gone to third parties. Deleting an account with the controller does not automatically delete copies held by advertising partners. Here the provision that helps is the one requiring a controller who made data public to take reasonable steps to inform other controllers of your demand that links and copies be erased — but it has to be invoked through a separate request.

The practical conclusion: deleting an account should be accompanied by a written data deletion request. They are different actions with different consequences.

Your rights and the exact deadlines

The deadlines are specific, and knowing them changes the tone of a correspondence with a controller by itself.

The right of access lets you obtain confirmation of whether your data is being processed, and to receive a copy of it together with information on the purposes, the recipients and the retention periods.

The right to erasure applies, among other cases, where the data is no longer needed for the purposes it was collected for, or where you have withdrawn the consent the processing rested on. For dating the second ground works almost always, because consent is the ground.

The deadline for a reply: without undue delay and in any case within one month of receiving the request. It can be extended by at most two months where the request is complex or where there are many requests, but the extension has to be notified within the first month, with reasons.

If the controller refuses to act on the request, it has to state the reasons for the refusal without delay and at the latest within a month, and explain the possibility of lodging a complaint with a supervisory authority and of going to court.

A separate provision covers anyone whose data has spread: if the controller made the data public, it has to take reasonable steps, including technical measures, to inform other controllers of your demand that links, copies and replications be erased.

How to file a request and where to complain in Finland

The order is strict, and breaking the sequence is the most common reason a case comes back with nothing.

The controller itself first, without exception. The Finnish Data Protection Ombudsman puts it plainly: contact the ombudsman only if the controller refused on grounds you consider insufficient, and as a rule cases where the controller was never contacted are not handled.

A request is best filed in writing and in free form, but with four things in it: who you are, what exactly you are asking for — access or erasure — on what basis, and where to send the answer. Keep a copy and the date of sending: the month runs from that date.

If there is no answer, or the answer does not satisfy you, the next step is a notification to the ombudsman. The form is submitted through the Turvalomake secure service, and it can be filed anonymously by leaving the contact fields empty.

On timescales, honestly, so that there are no illusions. Since the beginning of 2024 the ombudsman’s office has had a duty, within three months of a case being opened, either to issue a decision or to tell you its estimate of when it will decide; if that does not happen, it can be complained about to the administrative court. But the target for actually handling a case is one year.

So the mechanism works, but it is not quick. That is exactly why the first step — a well-drafted written request to the controller — is worth doing carefully: in most cases that is where the matter ends.

What happens when this kind of data leaks

A dating service leak differs from an online shop leak not in volume but in what becomes known.

The most telling case happened in 2015 with Ashley Madison, a platform for people already in relationships. In August of that year the data of around 36 million accounts was published.

What exactly was published was examined by the Canadian and Australian regulators, and it looked like this. Profile data: user name, postcode, marital status, gender, height, weight, body type, ethnicity, date of birth. Account data: the email addresses given at registration, security questions with answers, and hashed passwords. And payment data: the payers’ real names, billing addresses and the last four digits of cards.

Note that last category. Anonymity of a profile does not protect you from payment data: a person may have stated nothing in their profile, but by paying for a subscription left a real name and address.

The consequences of such leaks stretch out over years and consist mostly not of accounts being broken into but of blackmail: addresses from a leak are used for years in mass threatening mailings. That is why an email saying “I know you were on such-and-such a site” sometimes contains real data — it was taken not from your device but from an old leak.

The practical conclusion. Whether your email address has appeared in known leaks can be checked free of charge on specialist services. A separate email address for dating, and paying through an app store instead of entering a card directly, reduce what there is to leak in the first place.

What you can do yourself right now

A short list of actions that reduce the volume collected, not only the feeling of control.

Reset or restrict the advertising identifier in your phone settings. This is the single most effective action: it is what links you across apps.

Check the app’s permissions. Location set to “always” is almost never necessary — “while using” is enough, and often you can do without it entirely.

Get a separate email address used only for dating. It cuts the link to your other accounts and makes leaving easier.

Do not sign in through social networks. Signing in that way is convenient and creates a permanent exchange of data between two services.

Read one section of the privacy policy — the one on passing data to third parties. If the recipients are not named individually, you do not know who your data goes to, and you will not be able to find out.

And before deleting your account, export your data if the service allows it. After deletion there will be nothing left to request it from.

The three layers of data and what can be done about them

LayerWhat it includesCan it be limited
What you enteredProfile, photographs, preferences, messagesYes, entirely in your hands
AccountEmail, phone, date of registrationPartly: a separate email, no social sign-in
TechnicalIP, device, advertising identifierPartly: reset the advertising ID in settings
LocationCoordinates, distance to othersYes: “while using” permission, or refusal
BehaviouralWho you viewed, who you wrote to, how fastNo: collected by the fact of using the service
Passed onwardAnalytics and advertising partnersIndirectly: reset the ID, refuse personalisation

Categories based on the services’ privacy policies and the Forbrukerrådet study, 2020.

Frequently asked

What do dating apps collect about a user?

Three layers: what you entered (profile, photographs, messages), account and technical data (email, IP, device, advertising identifier), and behavioural data (when you logged in, whose profiles you viewed, who you wrote to, how quickly you replied). The last layer is collected by the fact of using the service and is not deleted along with your profile text.

Why is data from dating sites protected more strictly?

Article 9 of the GDPR treats data on sex life and orientation as special categories, whose processing is prohibited as a general rule and permitted, among other ways, by explicit consent. Obligations follow for the controller: an impact assessment for large-scale processing, and appointing a data protection officer if this is the core activity.

Do dating apps pass data to third parties?

On the Norwegian Consumer Council’s 2020 study, yes. Tinder passed special category data to LeanPlum and AppsFlyer, OkCupid to Braze, and both passed the advertising identifier to Facebook and interacted with Google DoubleClick. The partners change, the scheme does not: embedded analytics and advertising libraries receive data directly.

What does the Norwegian Grindr fine mean for an ordinary user?

That what is protected is not only the content of a profile but the bare fact of having an account. Datatilsynet fined the service 65 million kroner, holding that data showing a person uses it strongly indicates membership of a sexual minority. The decision was confirmed by the appeals board in 2023 and by the court of appeal in 2025.

What remains after an account is deleted?

More than people expect. Tinder deletes profile data with a delay of three months after an account is closed and a year after a ban, keeps correspondence with support for six years, and transactional data for ten years. Hiding a profile is not deletion. Deleting an account should be accompanied by a separate written data deletion request.

How long does an answer to a deletion request take?

One month from receipt of the request. It can be extended by at most two months where the request is complex or where there are many requests, but the extension, with reasons, has to be notified within the first month. If refused, the reasons and your right to complain and to go to court have to be explained within the same period.

What becomes known when a dating service leaks?

More than people think. In the 2015 Ashley Madison leak the data of around 36 million accounts was published: profile details, email addresses, security questions, hashed passwords and — crucially — the payers’ real names, billing addresses and the last four digits of cards. Anonymity of a profile does not protect you from payment data.

Where do I complain in Finland if a controller does not answer?

To the Data Protection Ombudsman, but you must contact the controller itself first — as a rule cases without that are not handled. The form is submitted through the Turvalomake secure service and can be anonymous. Since 2024 the office has had to issue a decision or state an estimate within three months, but the target handling time is a year.

Can an app be used without consenting to advertising?

Usually yes: consent to processing for advertising purposes has to be asked for separately from the consent needed for the service to work. Check the privacy settings inside the app and your phone’s system settings. Resetting the advertising identifier is the single most effective action: it is what links you across apps.

What does blocking tracking in phone settings achieve?

It restricts the app’s access to the advertising identifier, which breaks the link between your activity across different apps. It does not switch off collection by the service itself — it still knows everything you do inside it. But the volume that goes to advertising partners is reduced.

Is a service obliged to say who it passes my data to?

Yes. Under the right of access, a controller has to state not only what it holds but who it has passed it to. If the answer describes the recipients as “partners and service providers” with no names, that is grounds for a follow-up letter: a generalisation is not an answer to a request about categories of recipients.

What is an advertising identifier and why does it matter?

It is a number assigned to your device by which different apps recognise the same person. It contains no name in itself, but it links your behaviour in a dating app to your behaviour in every other one. It can be reset or restricted in your phone settings — the single most effective action for privacy.

Does data collection differ between Finnish and international services?

The legal framework is the same: the GDPR applies identically. The difference is in disclosure practice. The Finnish Treffit24 explicitly lists data on sexual behaviour and orientation among the sensitive information it processes. International apps usually use more general wording, and the list of recipients is more often described by category than by name.

Sources

3069 words

Back to home