Okcupid spilled 3 million dating profiles and the ftc just nailed it

The photos you swiped on, the exact spot where you flirted, the age and height you typed in—OkCupid quietly shipped all of it to an unnamed third-party company for years while promising users the opposite. Yesterday the Federal Trade Commission slammed the dating platform and parent Match Group Americas with a settlement that bans future lies about privacy and exposes a cover-up that started in 2014.

The promise that melted under heat

OkCupid’s own policy pledged that personal data would be shared only with “service providers, business partners, or affiliates” and always with a user opt-out. The FTC’s complaint, filed in federal court, says the recipient was none of those things and that users were never given the choice. For at least two stretches between 2017 and 2020 the outside company received location stamps, nearly three million photographs and demographic dossiers that were supposed to stay locked inside the app’s walled garden.

Investigators found no contractual limits on how the data could be reused, no encryption requirements, no deletion schedule—nothing. When reporters started asking questions in 2020, OkCupid told the public the third party “never had access to user data.” The FTC calls that statement false and part of a broader effort to obstruct the probe.

What the settlement actually changes

What the settlement actually changes

The proposed order—open for public comment before it becomes final—goes beyond the usual wrist-slap. It forces Match Group and Humor Rainbow (OkCupid’s legal entity) to document every future transfer of photos, geolocation or demographic data and to spell out in plain language why it is collected. Any claim that users can control sharing through in-app toggles must be provable; if California or Illinois privacy laws give residents extra rights, the companies must honor them in every state.

No fine is listed yet, but the FTC retains the hammer: each new violation could trigger civil penalties of up to $50,120 per affected user per day.

The bigger dating empire watching its back

The bigger dating empire watching its back

Match Group owns Tinder, Hinge, Match.com, Meetic, PlentyOfFish and a dozen other properties that together process the romantic hopes of roughly 100 million people every month. The commission’s director of consumer protection, Christopher Mufarrige, warned the entire portfolio: “We will enforce the privacy promises you make—even if we have to haul you into court to get the documents.”

Translation: the regulator just fired a tracer bullet across the whole online-dating sector. Competitors that still rely on vague “affiliate” language or bury data-sharing details in labyrinthian policies know they’re next.

Users, meanwhile, can do little retroactively. The exposed data has already been duplicated, indexed, possibly sold. The only immediate remedy is to delete the app and revoke every permission you once granted—camera, microphone, precise location, contacts. Few bother, and Match is counting on that inertia.

Bottom line

OkCupid built its brand on math-driven matchmaking and left-leaning inclusivity; it ends this chapter as a cautionary tale of corporate gaslighting. The FTC’s move won’t claw back the selfies or the coordinates that slipped out, but it sharpens the teeth of privacy law for every dating app still playing fast and loose with desire converted into data. Swipe accordingly.