Privacy check
How easily you can be identified
The tool runs through twelve points about what a dating service knows about you and what your profile shows beyond the photos: how you signed in, which accounts are connected, how precise your location is, your employer, your username, your email address. Each point you tick produces its own fix. At the end it assembles a ready data request that shows what the service actually holds. Nothing is sent to a server.
Tick the points that are true of your own account. Each one ticked produces its own fix. Nothing is sent to a server.
No clear linking data came up. Go through the settings once even so — they revert to defaults on app updates surprisingly often.
Nothing is ticked.
Choose the language by who answers: a Finnish service deals in Finnish, an international one in English. Send the request to the address given in the privacy policy.
The time to answer is one month from when the request arrives. If no answer comes, or it is incomplete, the matter can be reported to the Data Protection Ombudsman’s office.
The tool does not see your account and does not contact the service. It asks, you answer, and the request is assembled in your browser.
What this check looks at, and what it does not
This tool looks at the account and the service: which login you used, which accounts are connected, how precise the location setting is, what the profile says beyond the photos, and what the service holds about you.
It does not look at photos. They have a checklist of their own, with fifteen points and two separate scales, and it asks what can be worked out from an individual picture. The line is deliberate: two tools answering one question would compete with each other and neither would answer it properly.
Nor does it run a reverse image search. That belongs on the photo side too, and the reason we do not run one through this site is set out there.
And it does not assess the service as a whole. That takes reading a privacy policy, and it is done separately on the page what dating apps collect.
Identification comes from two facts, not one
A single fact on a profile rarely gives anything away. The first name Anna says nothing. A city says nothing. An occupation says nothing.
Two facts together often say everything. A first name and an employer are usually enough for one search. A username and a city are enough for another. Identification is not the leak of one fact but the joining of two, which is why the list is made up of joining facts in particular.
The strongest joiners are the ones that are the same everywhere: an email address, a phone number and a username. They work as keys. An address links you to every leaked database in which the same address appears, and a number is searched straight in messaging apps, where a real name and photo may sit.
A connected account is a case of its own. Once Instagram or the like is attached to a profile, the profile no longer says only what you wrote in it — it says the feed, the followers and often the name.
Location is the only one of these that works with no text at all. When distance is given in metres, three readings from different points are enough to locate the starting one. An approximate location at city level removes this entirely.
A data request is the only way to see what a service holds
A privacy policy says what a service intends to collect. The answer to a data request says what it has collected. These are not the same thing, and the difference shows only in the second.
Article 15 of the regulation gives the right to a copy of the data concerning you, and with it the purposes of processing, the categories of data, the recipients, the retention period and the source of the data where it was not collected from you. That last point is often the most interesting: it reveals what was bought about you elsewhere.
The time to answer is one month from when the request arrives. It is worth writing the deadline into the request itself: a named deadline starts running, an unnamed one does not.
Send the request to the address given in the privacy policy, not to the support chat. Policies often carry a separate address for the data protection officer, and that is the right recipient.
If no answer comes, or it is incomplete, the matter can be reported to the Data Protection Ombudsman’s office. You normally go there after writing to the service first.
Deleting an account and deleting data are different things
Deleting an account in an app usually means the profile is no longer visible to others. It does not mean the data has been deleted.
The retention period after deletion is written into the privacy policy, and it ranges from months to years by service. The same policy sets out what must be kept under a legal obligation — accounting records, for instance, survive whatever you ask for.
Erasure is requested under Article 17, and the request is worth pairing with two further questions: what is retained and on what basis, and whether the erasure request has been passed on to those the data was disclosed to. It is the second question that exposes the ad networks.
The whole procedure, step by step, is worked through on the page how to delete your data from a dating app. This tool hands you the request ready-made; that page tells you what to read in the reply.
What the tool does not do
It does not see your account. It signs in nowhere, asks for no credentials and contacts no service. It asks, you answer, and the result forms in your browser.
It does not send the request for you. The request must go from your own email address, because the service has to be able to establish that it is you asking.
It does not know a particular service’s settings menu. Setting names change on updates, and a stale instruction would send you hunting for an item that no longer exists.
And it deletes nothing. It shows what links the profile to you and hands you the request that finds out the rest. The remainder is done in the service’s settings and by email.
What each fact links to
| Fact on the profile | What it links to |
|---|---|
| Email address | Every leak in which the same address appears |
| Phone number | Messaging apps carrying a name and a photo |
| Username | Search results from other services |
| Connected account | A feed, followers and often a name |
| Employer | A name on the employer’s own website |
| Precise location | A home, from three readings taken at different points |
One row alone is rarely enough to identify someone. Two rows together usually are.
Frequently asked
How does this differ from the photo check?
This looks at the account and the service: the login, connected accounts, location precision, the profile text and what the service holds. The photo check looks at what can be worked out from an individual picture. The line is kept because two tools answering one question would compete with each other.
What does a data request actually give you?
A copy of the data held about you, and with it the purposes of processing, the categories of data, the recipients, the retention period and the source where the data was not collected from you. That last point is often the most interesting: it reveals what was acquired about you elsewhere.
How long is the wait for an answer?
One month from when the request arrives. Write the deadline into the request. If no answer comes, or it is incomplete, the matter can be reported to the Data Protection Ombudsman’s office — normally after writing to the service first.
Is my data deleted when I delete the account?
Not necessarily. Deleting an account usually means the profile is not visible to others. The retention period after deletion is stated in the privacy policy and ranges from months to years. Actual erasure is requested separately under Article 17.
Why does location precision matter?
Because it works with no text at all. When distance is given in metres, three readings from different points are enough to locate the starting one. A location given at city level removes this entirely and barely affects using the service.
Will you send the request for me?
No. The request has to go from your own email address so that the service can establish who is asking. The tool assembles the text in your browser, and the sending is left to you.
Sources
- Tietosuoja.fi: the right of access — Article 15, time to answer
- Tietosuoja.fi: notification to the Data Protection Ombudsman
- GDPR — Articles 15, 17 and 12(3)
- Forbrukerrådet: Out of Control — measurements of data transmission, 2020
- Datatilsynet: the fine against Grindr
1328 words