privacy

What Happens to Your Photos When You Delete a Dating App

OkCupid secretly gave 3 million user photos to a facial recognition firm. Here's how long dating apps keep your images—and what 'delete' really means.

On March 30, 2026, the Federal Trade Commission settled an enforcement action against OkCupid and its parent company Match Group over a data-sharing arrangement that had existed — undisclosed to users — for more than a decade.

OkCupid had shared nearly three million user photos with Clarifai, a facial recognition and computer vision company, along with location data and demographic information. No formal agreement governed the transfer. No restrictions were placed on how Clarifai could use the data. Users were never notified and had no opportunity to opt out.

The photos were used to train Clarifai’s facial recognition AI. Clarifai’s founder had contacted OkCupid’s co-founder directly to request the dataset, and it was transferred based on a personal connection between the companies’ leadership — a data pipeline built on relationships rather than legal process, privacy review, or user consent.

The FTC settlement required Clarifai to delete the photos and any models trained on them, and banned Match Group from misrepresenting its data practices for 20 years. No financial penalty was assessed because the FTC lacks authority to issue fines for this category of privacy violation.


Why This Case Matters Beyond OkCupid

The OkCupid-Clarifai arrangement isn’t an isolated incident. It’s the clearest documented example of something that privacy researchers have long warned about: the gap between what dating apps tell users about their data and what actually happens to it internally and through informal partnerships.

Dating apps accumulate some of the most sensitive personal data in any consumer category. Photos are obvious — but the full picture includes your location at the time you open the app, your demographic details, your stated preferences and dealbreakers, the messages you send, the profiles you linger on, and, on some platforms, your behavioral patterns across sessions. That data profile is detailed and intimate in ways that few consumer products match.

When that profile is transferred to a third party that trains computer vision models on human faces, the implications extend far beyond OkCupid’s terms of service. Facial recognition models trained on dating app photos could theoretically be used to identify users in contexts entirely separate from dating — a concern the FTC action explicitly raised in framing this as a consumer protection issue, not merely a contractual compliance question.


What Happens When You Delete Your Tinder Account

Tinder is owned by Match Group — the same parent company as OkCupid, Hinge, Match.com, and more than 40 other dating platforms globally. Its data retention practices after account deletion are the most detailed of any platform in the category, in part because they’ve been subject to public scrutiny and regulatory review.

Per Tinder’s privacy policy, when you delete your account:

Your profile is immediately deactivated. Other users stop seeing you. Your matches and messages are removed from the active interface.

Tinder retains your data for three months. The company describes this as a safety window — time to investigate harmful or unlawful conduct that may be reported after an account is deleted. During this period, your data remains on Tinder’s servers in a form that can be retrieved and investigated.

An additional retention window for legal purposes. Beyond the initial three months, Tinder keeps profile data for one year “in anticipation of potential litigation, for the establishment, exercise or defense of legal claims.” This is standard legal hold language, but it means the timeline from account deletion to genuine data erasure is not three months — it’s closer to fifteen months.

What’s actually deleted. Tinder states that photos, profile text, and messages are deleted at the end of the retention window. What remains may include transaction records, customer service interactions, and account-level identifiers for fraud prevention purposes, retained under separate time frames.

The photo specifically: the three-month minimum retention, then twelve additional months, means a photo you uploaded and then deleted your account over could remain on Match Group’s servers for more than a year. That’s the timeline if everything goes according to the privacy policy. Third-party sharing that occurred before deletion — of the type the OkCupid case revealed was possible — operates on a different timeline entirely.


The Match Group Data Ecosystem

Understanding how dating app data moves requires understanding that Tinder, OkCupid, Hinge, Match.com, and dozens of other platforms are not independent companies with independent data systems. They’re properties under a single parent corporation.

Match Group’s privacy policy states that the company may share information among its brands, though it frames this as enabling account safety and integrity functions rather than advertising. The practical implication is that data you provide to Hinge and data you provided to OkCupid years earlier may exist within the same corporate data infrastructure, potentially linked.

This isn’t unique to Match Group — platform consolidation has been a defining pattern in consumer tech for a decade, and it creates the same data accumulation risk across media, fitness, finance, and entertainment. But dating apps are a particularly sharp example because the data involved is both intimate and extensive, users often don’t think of these as “the same company,” and the history of how the data has been used doesn’t match the minimizing framing companies offer in their privacy policies.


Photo Verification Data: A Special Case

Many dating apps now require photo verification — you take a real-time selfie that’s compared against your profile photos to confirm you’re a real person.

The data generated by photo verification is different from the data generated by your profile photos. It includes a biometric comparison: the system takes facial measurements from your verification selfie and matches them against your profile photo mathematically. Whether or not the selfie and the measurement data are retained after verification completes is an important question that most dating apps’ privacy policies don’t answer clearly.

Tinder’s policy states that verification data is deleted upon account closure. But “upon account closure” is subject to the same retention windows described above — closure initiates a process, not an immediate erasure.

For apps that partner with third-party verification services (many do), the biometric data may pass through an external company’s systems, with retention and use governed by that company’s own terms, not the dating app’s.


Third-Party Data Sharing Is Broader Than You Think

Beyond the informal partnership that the OkCupid case revealed, dating apps share data through more routine channels that their privacy policies do disclose — in language designed to be technically accurate rather than easily understood.

Standard categories of sharing include:

  • Advertising partners. Most free-tier dating apps are ad-supported. Ad targeting requires sharing behavioral signals with advertising networks. The specific signals vary, but they generally include demographic attributes, location, and engagement patterns.
  • Analytics providers. App analytics tools (crash reporting, session tracking, A/B test infrastructure) receive behavioral data about how users navigate the app.
  • Service providers. Payment processors, customer support platforms, fraud detection services.
  • Law enforcement. Valid court orders and law enforcement requests compel disclosure. Dating apps have disclosed user data in criminal investigations, custody disputes, and civil litigation.

The OkCupid case was unusual because the sharing was undisclosed and lacked any formal agreement — but the broader practice of sharing data with third parties for purposes users didn’t specifically agree to is endemic to the advertising-funded consumer app model.


What You Can Do Before and After Using a Dating App

Before uploading photos:

Use photos that don’t exist elsewhere under your name. Profile photos that appear in a Google Image search connected to your identity make reverse image search trivially easy for other users. Consider cropping out recognizable background locations.

Check whether the app you’re using is owned by a larger parent company. If Match Group or any major platform operator owns the app, their data ecosystem applies, not just the individual app’s branding.

When deleting an account:

Submit a formal data deletion request under your applicable law (CCPA in California, GDPR in the EU, equivalent laws in other jurisdictions) rather than simply deleting the app. Account deletion and legal deletion requests invoke different processes — the latter is more likely to result in your data being purged from the company’s systems on a documented schedule.

Wait for written confirmation of deletion. Many jurisdictions require companies to confirm receipt of data deletion requests; a confirmation email is evidence that the request was logged.

For photos you consider particularly sensitive:

Consider whether you want them uploaded to any advertising-funded platform at all, regardless of the stated privacy policy. The OkCupid settlement is a reminder that stated policies and actual practices have diverged in ways that weren’t discovered until regulatory investigation, years after the data transfer occurred.


Where to Store Personal Photos You Want to Control

The OkCupid case is a concrete illustration of what “we don’t sell your data” actually means in practice for a company with informal partnerships built on personal relationships rather than legal review.

For photos you want stored somewhere with a simpler data model: no advertising business, no third-party AI training, no informal data-sharing arrangements, daftei stores personal photos and files without running an ad business and without training its own or third-party AI models on user content. Files are encrypted with TLS 1.3 in transit and AES-256 at rest. The company is GDPR and CCPA compliant, and account deletion results in permanent erasure after a 30-day grace window.

The contrast with what the OkCupid settlement revealed isn’t just a marketing point — it’s a structural one. A product with no advertising revenue has no incentive to share your photos with advertising-adjacent data partners, formally or informally.

Store your photos somewhere with a simpler data model

Your memories deserve better than an ad platform.

Try daftei free →
← All posts