Breaking
Cyber CrimeConfirmed

Grindr's £26M Settlement and the Stakes for User Trust

Grindr agrees to pay £26m to settle U.K. claims over pre-2020 data sharing, without admitting liability.

··6 hours ago·4 min read
a pink and purple phone sitting on top of a purple and pink background
Photo by Jakub Żerdzicki on Unsplash

Grindr has agreed to pay £26 million to resolve a U.K. class action over claims that it shared users' HIV status and other sensitive data with third parties before 2020. The settlement, disclosed in a U.S. Securities and Exchange Commission filing, closes a legal chapter that dates back to revelations from 2018 — but it also raises questions about how dating apps handle the most sensitive data they hold.

Legal Claims and Settlement Terms

The lawsuit was filed in April 2024 in the U.K., accusing Grindr of violating British privacy laws by sharing users' personal information for commercial purposes, including advertising. The legal action was brought on behalf of more than 10,000 clients. According to the SEC filing dated September 2, 2026, the California-based company said it settled the suit related to its historical data practices before 2020, a period when it was managed by Kunlun, a Chinese gaming company.

Grindr's ownership changed in May 2020, when Kunlun sold the platform to an investor group called San Vicente Acquisition LLC. The settlement agreement covers the period before that sale. The company has agreed to pay £13 million to the counterparties by December 31, 2026, and a further £13 million by March 31, 2027.

No Admission of Liability

The SEC filing emphasizes that the settlement includes no findings or admission of liability. Grindr disputes the allegations but, in the company's own words, "recognizes and acknowledges the distress and loss of trust expressed by some of its U.K. users regarding that pre-2020 period." The quote appears in the filing, attributed to Grindr.

This is a common pattern in high-profile privacy settlements: companies pay substantial sums while explicitly denying wrongdoing. But for Grindr, the statement goes further than a typical denial. It acknowledges user distress, a concession that may reflect the sensitivity of the underlying data.

The 2018 Revelations

The origins of the case trace back to April 2018, when a Norwegian non-profit research group called SINTEF uncovered that Grindr was sharing users' HIV status and last tested date with two companies, Apptimize and Localytics, which had been enlisted to optimize the app. The discovery was reported at the time and quickly drew criticism, given the sensitivity of HIV-related information and the potential for discrimination or stigma if such data were exposed or misused.

Shortly after the findings were made public, Grindr announced it would stop the data-sharing practice. In a statement at the time, the company insisted: "Grindr has never sold, nor will we ever sell, personal user information – especially information regarding HIV status or last test date – to third parties or advertisers. No advertisers have ever had access to HIV status or last test date, unless they viewed it in your public profile. The HIV status and last test date information was used by Apptimize and Localytics only to provide services to Grindr."

Regulatory Consequences

The U.K. settlement is not the only legal trouble Grindr has faced over its data practices. In January 2021, Norway's data protection authority fined Grindr £8.6 million (later reduced to £5.5 million) for violating the General Data Protection Regulation (GDPR). The Norwegian regulator found that Grindr had shared personal data such as location, sexual orientation, and mental health details with advertisers. Grindr challenged the decision, but Norway's court of appeal upheld the fine in the fall of 2025.

Company's Response and Current Stance

Grindr has said that it has revamped its privacy program since 2020 and emphasized that the platform "remains a safe space for users," committing to transparency, user control, and responsible data practices. The company has not commented beyond the statements in the SEC filing and its earlier defense.

For users, the settlement is a reminder that even a company that says it never sells data may still share it with partners — and that such sharing can have significant consequences when the data is health-related. The case also shows that privacy regulators and courts are willing to hold companies accountable for practices that occurred years ago.

Why It Matters

This settlement could serve as a cautionary tale for other tech companies, particularly those that collect sensitive health or personal data. It demonstrates that historical data-handling practices can come back to haunt a company long after the practices have changed. For users of dating apps and other platforms, it suggests that vigilance is still important: even if a company promises not to sell data, the ways it shares data with third parties may not always be clear. The onus is on companies to be transparent about their data practices, and on users to stay informed about how their information is used.

#grindr#privacy#data-sharing#hiv-status#uk-settlement#gdpr

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories