9 Total
2 High severity
6 Medium severity
1 Low severity
Stay ahead of the changes
Track Bumble and get the diff the day its terms change.
Summary

This document establishes Bumble's practices for collecting, using, and sharing personal information from users of its dating application and websites. Bumble collects sensitive data categories including precise geolocation, biometric identifiers for verification purposes, photographs submitted for identity verification, device information, and message content, with authorization to share this information with third-party service providers, affiliated entities, and government bodies in response to legal process. Users located in California, the EU, and the UK are granted specific rights to access, correct, delete, and export their personal data, exercisable through the application settings or Bumble's support contact mechanism.

Analysis

This document is Bumble Group's global privacy policy, governing the collection, use, storage, and disclosure of personal information by Badoo Trading Limited and Bumble Trading LLC across the Bumble mobile application, desktop version, and associated websites, with GDPR cited as a primary legal framework and Bumble positioned as data controller. The policy states it collects a broad range of data categories including registration details, geolocation, device identifiers, biometric data (for profile and ID verification), purchase information, message content, photo metadata, and linked social media data, and the terms authorize use of this information for matching algorithms, moderation, service delivery, marketing, fraud prevention, and legal compliance. Notably, the policy discloses collection and processing of biometric data through profile and ID verification features, a category subject to heightened legal requirements in several US states (including Illinois BIPA and Texas CUBI) and under GDPR Article 9 as a special category; the policy also acknowledges use of automated decision-making including profiling, and discloses that user data may be transferred internationally outside the EEA under standard contractual clauses or other approved transfer mechanisms. The policy engages GDPR, UK GDPR, CCPA/CPRA for California residents, and potentially Illinois BIPA and other US state biometric privacy statutes, with enforcement exposure distributed across the ICO (UK), EU supervisory authorities, California Privacy Protection Agency, and US state attorneys general. Material compliance considerations include the lawfulness of biometric data processing under both GDPR and US state law, the adequacy of consent mechanisms for special category data, and the sufficiency of disclosed cross-border data transfer safeguards.

What this means for you

The policy establishes that Bumble collects and processes biometric identifiers, precise location data, message content, and device information, with terms authorizing disclosure to third-party service providers and affiliated entities. Users subject to CCPA/CPRA (California residents) and GDPR (EU and UK users) operate under supplemental data protection obligations, including rights to request access, correction, deletion, and export of personal data, and rights to object to automated decision-making and certain forms of profiling. These rights are exercisable through mechanisms specified in the policy document and Bumble's support infrastructure.

Institutional Analysis
Stay ahead of the changes

Institutional analysis available with Insight

Which mapped governance frameworks each document engages, tied to the specific provisions that engage them.

7 important changes detected

7 versions captured · Last updated: August 2026

What changed In an update detected on August 11, 2026, Bumble expanded its privacy policy to add a new section describing its Connection Quizzes feature. The updated policy discloses that Bumble collects quiz responses, email addresses (if provided), technical and usage information, and cookies from users who participate in Connection Quizzes. The policy states Bumble uses this information to generate results, operate the feature, enable sharing, send promotional communications where permitted by law, and protect service security. Quiz data is retained for up to 90 days unless a longer retention period is required for safety, legal, or compliance purposes.
Why this matters The updated policy discloses that if you choose to participate in Connection Quizzes, Bumble collects your quiz responses, optional email address, and technical usage information through cookies and similar technologies. The policy states this data is used to generate quiz results, operate the feature, enable sharing, send promotional communications where permitted by applicable law, and protect service security. Your quiz data will be retained for up to 90 days unless a longer retention period is required for safety, legal, or compliance purposes.
View full change record →
What changed Bumble removed a hyperlink from their privacy policy language describing identity verification procedures. The previous version linked the phrase 'Community Guidelines' to bumble.com/guidelines; the updated version removes this link and presents the text as plain language. This change does not alter what Bumble collects or verifies, only how the policy presents the reference to their guidelines.
Why this matters This change is a formatting modification with no material impact on consumer rights or data practices. The policy continues to state that Bumble will request phone numbers and may require photo or ID verification to enforce Community Guidelines. The removal of the hyperlink does not change what data Bumble collects, how it processes identity information, or what verification procedures apply to users.
View full change record →

June 14, 2026 low

Bumble revised its BeePitched feature description and data retention practices on June 14, 2026. The updated policy recharacterizes BeePitched from a tool for creating personalized content about others to a …

View change record →
May 30, 2026 medium

Bumble added disclosure language describing BeePitched, a new feature that allows users and non-users to create and share personalized 'Pitches' about others. The updated privacy policy now states that BeePitched …

View change record →
April 19, 2026 medium

Bumble removed a reference to UK servers from its privacy policy on April 19, 2026. The policy previously stated the company's network includes servers in the US, UK, and EU; …

View change record →
March 21, 2026 medium

Bumble removed the UK from its list of server locations in its privacy policy. The updated language now states the network includes servers in the US and the EU, whereas …

View change record →
March 19, 2026 low

Bumble updated its privacy policy on March 19, 2026 to specify that its network infrastructure includes servers located in the US, UK, and the EU, rather than the previous statement …

View change record →
Featured, High severity
Featured, Medium severity
Featured, Low severity
Stay ahead of the changes

Monitoring

Bumble has updated this document before. Monitor includes same-day alerts, structured change summaries, and monitoring for up to 20 platforms.

Stay ahead of the changes

Governance Intelligence

Need provision-level monitoring and regulatory mapping? Insight includes governance timelines, drift analysis, and full provision tracking.

Cross-platform context

See how other platforms handle Automated Profiling and Matching Algorithms and similar clauses.

Compare across platforms →

Mapped Governance Frameworks

BIPA
Illinois, USA
View official text ↗
CCPA/CPRA
California, USA
View official text ↗
Connecticut Data Privacy Act Amendments
US-CT
View official text ↗
CAN-SPAM
United States Federal
View official text ↗
FTC Act Section 5
United States Federal
View official text ↗
GDPR
European Union
View official text ↗
Indiana Consumer Data Protection Act
US-IN
View official text ↗
Kentucky Consumer Data Protection Act
US-KY
View official text ↗
UK GDPR
United Kingdom
View official text ↗
Universal Opt-Out Mechanism Expansion 2026
US
View official text ↗
VPPA
United States Federal
View official text ↗
Archival ProvenanceSource & Archival Record
Last Captured August 11, 2026 00:37 UTC
Capture Method Automated scheduled archival capture
Document ID CA-D-000226
Version ID CA-V-005676
SHA-256 d088ef1205f4f14366a80287639a8999c0aaae3743a4ad673eed8cdf4483de91
✓ Snapshot stored ✓ Text extracted ✓ Change verified ✓ Hash verified

Governance Monitoring

Monitor governance changes across the platforms you rely on.

Structured alerts for policy changes, governance events, and provision updates across 352+ platforms.

Start monitoring → Compare plans