Grindr is sharing the HIV status and “last tested” date of users with two other firms, according to an analysis by an outside research firm verified by BuzzFeed
A data analysis conducted by an outside research firm, and independently verified by BuzzFeed News … Tweets: @azeen , @azeen , and @caseynewton Tweets: Azeen Ghorayshi / @azeen : and HIV/AIDS advocates aren't happy about this either: “That is an extremely, extremely egregious breach of basic standards that we wouldn't expect from a company that likes to brand itself as a supporter of the queer community.” http://www.buzzfeed.com/... Azeen Ghorayshi / @azeen : NEW from me: Grindr is sharing their users' HIV status info (tied to email and GPS data) with two third-party companies, a data analysis shows —> http://www.buzzfeed.com/... Casey Newton / @caseynewton : Unfortunately, Grindr being owned by a Chinese company means that users can expect even less privacy over time http://twitter.com/...
Context & Ripple Effects
A BuzzFeed-verified analysis by an outside research firm found Grindr transmitting users' HIV status and 'last tested' dates to two third-party companies, with the health fields tied to identifying data like email addresses and GPS location. The finding landed on a company that brands itself as a supporter of the queer community, and HIV/AIDS advocates quoted in the coverage called it an egregious breach of basic standards.
The report opened a multi-year arc rather than a one-day story: Grindr's security chief pushed back within a day, insisting the company was unfairly singled out and had already cut the HIV-status sharing (Grindr's own security chief), yet later reporting showed the underlying data practices kept generating consequences — from location data flowing through ad networks to UK users suing over HIV-status sharing years after the promised fix.
First-order effects
- Users' most sensitive health attribute — HIV status and testing date — was being transmitted alongside email and GPS identifiers to two outside firms, exposing them to disclosure or commercial reuse they never meaningfully consented to.
- Grindr was forced into damage control immediately: its security chief Bryce Case publicly argued the company had been unfairly singled out and stated it had already stopped sharing HIV status with its third-party vendors.
Second-order effects
- The ad-tech vendors in Grindr's supply chain became the liability vector — the same pipeline later surfaced when millions of users' location data were collected from a digital ad network and sold since at least 2017 (location data sold via an ad network), showing the problem extended beyond the HIV field itself.
- Data-handling failures compounded ownership scrutiny: Beijing Kunlun's decision to give engineers in China access to user data prompted US officials to require a sale of Grindr (forced divestiture over data access), tying privacy practice directly to the company's corporate control.
Third-order effects
- The pattern — sensitive data shared, then partially curtailed, then litigated years later — culminated in UK users suing Grindr over alleged HIV-status sharing with ad companies like Localytics from 2018 to 2020 (UK class action over HIV-status sharing), establishing that vendor-sharing decisions create legal exposure that outlasts any single policy change.
- If the pattern holds, dating apps treating health and sexual-orientation data as ordinary ad-targeting inputs face a structural reckoning: regulators, courts, and national-security reviewers converging on the same conclusion that intimate-category data cannot sit in standard programmatic pipelines.
The trend: Dating apps are learning that monetizing intimate user data through third-party pipelines converts directly into regulatory, litigation, and ownership-level risk.