Get the weekly research letter
Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.
The policy authorizes use of sensitive personal information, including special-category data, to power AI-driven features (branded 'gAI') for personalization, recommendations, behavior-based profile insights, personalized chat prompts, and compatibility-based profile recommendations.
This analysis describes what Grindr's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This provision establishes that sensitive personal information, including health data and other special-category fields, is processed by AI systems for personalization and recommendation purposes; the policy states consent is the legal basis for this processing where required, and users may withdraw consent via in-app Privacy Settings.
Under these terms, sensitive personal information provided through user profiles (including HIV status, vaccination status, and other special-category data) is processed by Grindr's AI systems to generate personalized recommendations, chat prompts, and profile insights; the policy states users may withdraw consent for certain AI-related uses of sensitive data through in-app Privacy Settings.
Cross-platform context
See how other platforms handle AI-Driven Personalization Using Sensitive Data and similar clauses.
Compare across platforms →Monitoring
Grindr has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Provide the Services with artificial intelligence-driven features ('gAI') and improve and develop such features, including by using your sensitive personal information, for personalization, recommendations, and other enhancements, and to support platform and user safety. Personalizing and customizing your experience on the Grindr Services by providing tailored content, recommendations, and insights through AI-powered features, such as reconnection reminders, behavior-based profile insights, personalized chat prompts or compatibility-based profile recommendations.Excerpt from Grindr's Privacy Policy
1. REGULATORY LANDSCAPE: This provision engages GDPR Article 9 (special-category data) and Article 22 (automated decision-making), as well as the EU AI Act for AI systems processing sensitive data. The policy explicitly states that Grindr does not use AI for decisions producing legal or similarly significant effects, which may limit Article 22 exposure, but processing of special-category data by AI systems for personalization still requires a valid Article 9(2) legal basis. The UK ICO and EU DPAs are relevant enforcement authorities. Brazil's LGPD and U.S. state AI transparency requirements in Colorado and Connecticut may also engage. 2. GOVERNANCE EXPOSURE: High. The use of health data and other special-category personal information as inputs to AI personalization systems creates documented Article 9 exposure. The adequacy of consent obtained through Ketch CMP for this specific processing purpose, including whether users understood that sensitive health fields would be used as AI training or inference inputs, warrants audit. 3. JURISDICTION FLAGS: EU/EEA and UK create primary exposure under GDPR Article 9 and emerging AI governance frameworks. Colorado and Connecticut have enacted AI transparency and automated decision-making laws that may engage. California CPRA imposes restrictions on automated decision-making involving sensitive personal information. 4. CONTRACT AND VENDOR IMPLICATIONS: If third-party AI vendors process sensitive data on Grindr's behalf, data processing agreements must address Article 9 compliance, data minimization, and purpose limitation. Vendor assessments should verify that AI processing of sensitive data is limited to the purposes disclosed in this policy. 5. COMPLIANCE CONSIDERATIONS: Legal teams should document a Data Protection Impact Assessment (DPIA) for AI systems processing special-category data, as this is likely required under GDPR Article 35 given the scale and sensitivity of data involved. Consent mechanism audits should verify that users provided explicit, informed consent for AI processing of sensitive fields specifically. The policy's object-to-processing mechanism should be tested to confirm it operates as described for AI-related processing.
Full institutional analysis
Regulatory citations, enforcement risk, and due diligence action items.
Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This provision establishes that sensitive personal information, including health data and other special-category fields, is processed by AI systems for personalization and recommendation purposes; the policy states consent is the legal basis for this processing where required, and users may withdraw consent via in-app Privacy Settings.
Under these terms, sensitive personal information provided through user profiles (including HIV status, vaccination status, and other special-category data) is processed by Grindr's AI systems to generate personalized recommendations, chat prompts, and profile insights; the policy states users may withdraw consent for certain AI-related uses of sensitive data through in-app Privacy Settings.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grindr.