Grindr is paying £26 million to settle claims it shared users’ HIV status with third-party analytics firms. The company’s privacy policy said it wouldn’t. The company did it anyway. Turns out that’s just how tech works now.
The settlement doesn’t require Grindr to admit wrongdoing—because admitting wrongdoing costs extra. Instead, it’s a fine that rounds to “the cost of doing business while treating user data like a clearance bin at a going-out-of-business sale.” The data went to Amplitude and Mixpanel, who presumably needed to know exactly which users were vulnerable in order to serve them better ads.
Why do tech companies keep doing this? Because the math is simple. Share sensitive data, hope nobody notices, negotiate a settlement that’s smaller than quarterly marketing spend, move on to the next privacy violation. The cycle is so predictable that Grindr probably has it on a spreadsheet labeled “Q4 Expenses.”
The UK’s Information Commissioner’s Office called it a breach of privacy law. Grindr’s legal team called it a “learning opportunity.” Both are correct. Grindr learned that sharing intimate health data generates headlines but not consequences. The rest of the industry is taking notes.
This is now the industry standard: privacy policies are press releases, user consent is theater, and settlements are just licensing fees for the next violation. Grindr didn’t break the rules—it just proved which rules actually have teeth. Spoiler: not many.