Report: some apps using Facebook's SDK, like Grindr and Bible+, send user info to Facebook, including location, where users click, and how long the app is used
Facebook provided developers with tools to build Facebook-compatible apps like Tinder, Grindr and Pregnancy+.
Context & Ripple Effects
This report lands three months after a European website was found exposing the exact locations of Grindr's 3.6M+ active users through its private API — but where that leak was unauthorized, this one runs through an official channel: Facebook's own developer tools, which it supplied so apps like Tinder, Grindr and Pregnancy+ could be built Facebook-compatible.
The pattern it documents didn't stop with the SDK. Two years later, researchers documented how Grindr, OkCupid, Tinder and period-tracking apps like Clue and MyDays were sharing intimate user data with data brokers, suggesting the SDK flow was one strand of a broader app-data economy.
First-order effects
- Facebook is receiving location, click behavior, and session-duration data from apps embedding its SDK — meaning users of Grindr and Bible+ are feeding Facebook usage profiles without a direct Facebook login or interaction.
- The named app makers now own a disclosure problem: their integration choices, not just their own servers, are routing sensitive signals to a third party.
Second-order effects
- Every developer shipping a third-party SDK faces the same audit question — what telemetry does the library fire by default — pushing SDK providers toward opt-in data terms as the price of distribution.
- For sensitive-category apps in particular, the finding hands privacy regulators and platform gatekeepers a concrete mechanism to target, since the data path is contractual rather than a breach.
Third-order effects
- If the pattern holds, app-store and regulatory pressure converges on SDK governance: the embedded-analytics layer becomes the choke point where consent, minimization, and audit requirements get enforced, rather than individual app privacy policies.
- The recurring Grindr disclosures — API exposure, then broker sharing, then SDK telemetry — point toward intimate-data apps being treated as a distinct risk class under future privacy rules.
The trend: Mobile data leakage is shifting from isolated breaches to systemic flows through official developer infrastructure, making the SDK itself the next battleground for privacy enforcement.