Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million
The LGBTQ+ dating app Grindr has agreed to pay £26 million ($35.2 million) to resolve a UK lawsuit alleging that it provided advertisers with sensitive user data, including individuals’ HIV status.
The company will pay the fines in two lump sums, with one payment due by the end of December and the other slated for the end of March, according to a regulatory filing with the Securities and Exchange Commission (SEC) signed on September 4.
The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.
The incidents occurred in a period before early 2020 when Grindr was owned and run by a Chinese company, Kuntun.
A spokesperson for Grindr declined to comment, pointing to the company’s statement in the regulatory filing, which says the settlement “includes no findings or admission of liability.”
“While Grindr disputes the allegations, it recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period,” according to the filing.
Since new ownership took over in 2020, Grindr has “overhauled its privacy program with a keen focus on the unique needs of its community,” the filing said. “Grindr is and remains a safe space for users, committed to transparency, user control, and responsible data practices.”
In May 2024, Grindr’s then chief privacy officer, Kelly Peterson Miranda told Recorded Future News that the lawsuit’s assertions were untrue.
“In the lawsuit they allege that we sold health information — HIV last-tested date — and used it for advertising purposes, which categorically I can say no, that never happened,” she said. “We have never used users’ health-related information for any type of advertising purposes as purported in the lawsuit.”
The information was shared with two service providers, she said, to facilitate development of a new feature that allowed users to include HIV status in a special field in their profile.
“It was never a breach, it was never shared unknowingly,” she said at the time. “It was shared in encrypted manners for the purposes of actually rolling out and monitoring the feature.”
There were reportedly 12,000 class members in the lawsuit.
Suzanne Smalley
is a reporter covering digital privacy, surveillance technologies and cybersecurity policy for The Record. She was previously a cybersecurity reporter at CyberScoop. Earlier in her career Suzanne covered the Boston Police Department for the Boston Globe and two presidential campaign cycles for Newsweek. She lives in Washington with her husband and three children.



