Grindr, the dating platform that bills itself as the world’s largest LGBTQ+ app, has agreed to pay £26 million to settle a class action lawsuit centred on allegations that it shared deeply personal user information, including HIV status, ethnicity, and sexual orientation, with third-party companies for commercial gain. The settlement, reached on September 2, 2026, marks one of the most significant privacy payouts involving a dating app in British legal history.
What the Lawsuit Actually Claimed
The legal action, brought by law firm Austen Hayes, was first filed in London’s High Court back in 2024. The firm alleged that Grindr had breached UK privacy laws by passing sensitive user data to outside parties without adequate consent or transparency. The nature of that data is what made the case particularly alarming: not just email addresses or browsing habits, but the kind of health and identity information that, if exposed, can carry real-world consequences for the people it belongs to.

HIV status. Ethnicity. Sexual orientation. These are categories that, in the wrong hands, can expose individuals to discrimination, stigma, or worse. For an app whose users often rely on it precisely because it offers a degree of anonymity and community safety, the allegations cut especially deep.
As the case gained momentum, the lawsuit was served in the United States as well. Austen Hayes confirmed it had signed up more than 11,000 claimants, giving the action considerable weight. You can read the full breakdown of the settlement as reported by the BBC.
How the Payment Breaks Down
According to a filing Grindr submitted to the US Securities and Exchange Commission, the company will split the settlement into two equal tranches. The first £13 million payment is due by December 31 of this year. The second £13 million follows by March 31, 2027. The total comes to £26 million, though Grindr has been careful to note the settlement carries no admission of liability on its part.
In a statement included in the SEC filing, the company said it “disputes the allegations” but acknowledged and recognised the “distress and loss of trust expressed by some of its UK users” relating to that period. That language is telling. It threads a legal needle, stopping short of any concession while nodding to the very real emotional impact felt by thousands of people who trusted the platform with information they would never share casually.
The Kunlun Connection: Why 2020 Is the Dividing Line
Grindr is keen to draw a clear boundary around the timeline. The company points out that the practices in question are “historical” and predate 2020, when the app was owned by Chinese technology firm Kunlun. Kunlun acquired Grindr in 2016 and sold it in 2020 following pressure from US national security regulators who raised concerns about a Chinese company holding such sensitive data on American citizens.
The current Grindr has attempted to distance itself from those earlier decisions, essentially arguing that a different company made these choices under different ownership. Whether that distinction satisfies the 11,000-plus claimants is another matter entirely.
Why Ownership History Matters in Data Privacy
This ownership argument is worth pausing on, because it surfaces a structural problem in how personal data is treated when companies are bought and sold. When you sign up for an app and accept its privacy policy, you are entering an agreement with a specific entity at a specific moment. But that entity can change hands, and the data you handed over travels with the business. Your HIV status, shared under one ownership regime, does not reset when the company is acquired. It persists.
That gap between user expectation and corporate reality is precisely what regulators and courts are now being asked to address.
The Wider Stakes for App Privacy
It would be easy to read this story as a cautionary tale specific to one app in one niche. It is not. Dozens of health, fitness, and lifestyle apps routinely collect sensitive personal information, from menstrual cycle data to mental health check-ins to sexual behaviour. Many of them, at various points, have shared that data with advertising networks, analytics firms, or other third parties under terms buried in privacy policies that few users read in full.
The Grindr case is significant because it demonstrates that litigation on this front, in UK courts particularly, can produce real financial consequences. Class actions involving data privacy have historically been difficult to pursue, partly because proving individual harm is complex. But a £26 million settlement involving more than 11,000 people signals that the legal landscape is shifting.
UK privacy law, shaped by the UK GDPR following Brexit, grants individuals meaningful rights over their personal data. The Grindr case suggests those rights have teeth, and that law firms are increasingly willing to organise large groups of claimants to test them in court.
What This Means If You Use Dating Apps
For everyday users, the practical takeaway is uncomfortable but necessary. Most people sign up for apps in a hurry, tap “agree” on the terms without reading them, and assume the data they share stays within the walls of that service. The Grindr saga is a reminder that this assumption is often wrong, and that the information you share on a platform designed for intimacy can end up treated as a commercial asset.
Checking privacy settings, understanding what data an app collects, and occasionally auditing which services have access to your information is no longer the behaviour of the paranoid. It is basic digital hygiene.
A Settlement, Not an Ending
Grindr will make its payments, claimants will receive their share, and the case will formally close. But the questions it surfaces will not go away. Who actually controls the data you share on your phone? What happens to it when a company changes hands? And when the harm is not a leaked credit card number but something as personal as your health status or sexual identity, what is the appropriate remedy?
Those are questions that courts, regulators, and the companies building these platforms will be wrestling with for years. A £26 million settlement is a significant sum. Whether it is enough to prompt genuine, lasting change in how apps handle the most sensitive corners of their users’ lives is a very different question.
So here is one worth sitting with: when did you last actually read the privacy policy of an app that knows the most personal things about you?


