Grindr · Grindr Privacy Policy · View original document ↗

Sensitive Data Collection and Processing

High severity High confidence Explicitdocumentlanguage Unique · 0 of 352 platforms
Get alerted the next time Grindr changes these terms. Get same-day alerts →
Share 𝕏 Share in Share 🔒 PDF
Recent governance activity Grindr recorded 3 documented changes in the last 30 days.
Get same-day alerts →
Monitor governance changes for Grindr Monitor emails you the same day this changes. The archive stays free.
Get same-day alerts →

Get the weekly research letter

Companies change their terms quietly. We read every version and catch what actually changed. One email a week on the changes that matter and what they mean. No account.

Document Record

What it is

The policy discloses that users may provide health information including HIV and vaccination status, racial or ethnic origin, and other sensitive data through their public profiles, and that this information is processed to provide the Services including AI-driven personalization features.

This analysis describes what Grindr's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology

ConductAtlas Analysis

Why it matters (compliance & governance perspective)

This provision establishes that Grindr processes GDPR Article 9 special-category data, including health data and racial or ethnic origin, as part of its core service delivery and AI personalization functions, requiring a valid Article 9 legal basis for each processing purpose.

Clause Stability Stable

0
Changes
4
Months Monitored
Jul 9, 2026
First Seen
Jul 9, 2026
Last Seen

Consumer impact (what this means for users)

The agreement authorizes collection and processing of health information (including HIV status) and racial or ethnic origin provided through user profiles, and states this information is used to provide the Services including AI-driven personalization; the policy notes that profile information is public-facing.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    Navigate to Settings within the Grindr app, tap Privacy Settings, and adjust consent preferences to withdraw consent for certain AI-related uses of sensitive data. For full data deletion, follow the profile deletion steps outlined in the app or submit a request at privacy@grindr.com.

Cross-platform context

See how other platforms handle Sensitive Data Collection and Processing and similar clauses.

Compare across platforms →

Monitoring

Grindr has changed this document before.

Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.

Get Monitor Or create a free account →
▸ View Original Clause Language DOCUMENT RECORD
"
You choose what personal information you provide as part of your public profile. For example, you may share or not share health information like HIV and vaccination status, or sensitive data like racial or ethnic origin, or photos and videos. Your profile is public, so you should not include information that you want to keep private. Note that some of the information you may choose to provide us (e.g., profile fields such as ethnicity, looking for and position) may be considered 'sensitive', 'special category' under applicable privacy laws. We use this information to provide the Services as described in this Policy.

Excerpt from Grindr's Privacy Policy

ConductAtlas Analysis

Institutional analysis (regulatory & governance intelligence)

1. REGULATORY LANDSCAPE: This provision directly engages GDPR Article 9 (processing of special-category personal data), which requires explicit consent or another enumerated condition for lawful processing of health data and racial or ethnic origin. Equivalent provisions exist under the UK GDPR, Brazil's LGPD, and U.S. state health data frameworks including the Washington My Health MY Data Act. Relevant enforcement authorities include EU member state DPAs, the UK ICO, and state attorneys general. The policy's use of consent as the stated legal basis for sensitive data processing in service improvement and AI personalization contexts may require evaluation for adequacy under Article 9(2)(a) given the conditional opt-out language. 2. GOVERNANCE EXPOSURE: High. The collection and processing of HIV status and vaccination status as explicit profile fields, combined with their stated use in AI-driven personalization ('gAI') and potential sharing with advertising and marketing partners, creates material exposure under Article 9 of the GDPR and equivalent frameworks. The inferability of sexual orientation from platform use further compounds special-category exposure regardless of explicit disclosure. 3. JURISDICTION FLAGS: EU/EEA, UK, and Brazil create heightened exposure given explicit special-category data frameworks. Washington state's My Health MY Data Act and Nevada's equivalent statute may apply to HIV status and vaccination data collected from residents of those states. California's CPRA creates additional obligations regarding sensitive personal information including health data and racial/ethnic origin. Illinois BIPA is engaged where biometric data is collected for age verification. 4. CONTRACT AND VENDOR IMPLICATIONS: Advertising and marketing partners receiving data associated with profiles containing or inferably linked to special-category attributes may require data processing agreements addressing Article 9 compliance, particularly regarding re-identification risk. Procurement teams should assess whether partner contracts include appropriate restrictions on further processing of sensitive data received from Grindr. 5. COMPLIANCE CONSIDERATIONS: Legal teams should audit whether consent obtained through the Ketch CMP satisfies Article 9(2)(a) explicit consent requirements for each stated processing purpose involving sensitive data, including AI personalization and service improvement. Data mapping should document all flows of special-category data to third-party advertising and service provider recipients. The post-opt-out processing carve-out should be assessed against the legal bases documented for each sensitive data processing purpose.

Full institutional analysis

Regulatory citations, enforcement risk, and due diligence action items.

Get same-day alerts when this changes → Get Analyst

Monitor: same-day alerts on the platforms you choose. Analyst: full institutional analysis.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data practices involving sensitive health information and may evaluate whether consent mechanisms for special-category data processing are adequate under Section 5 of the FTC Act.
    File a complaint →
  • State AG
    State attorneys general in California, Washington, and Nevada have enforcement authority over sensitive health data collection and processing under CPRA, the My Health MY Data Act, and Nevada's equivalent statute.
    File a complaint →

Provision details

Document information
Document
Grindr Privacy Policy
Entity
Grindr
Document last updated
May 5, 2026
Tracking information
First tracked
July 9, 2026
Last verified
July 9, 2026
Record ID
CA-P-015011
Document ID
CA-D-00270
Evidence Provenance
Source URL
Wayback Machine
Content hash (SHA-256)
d975ff63d08e3c4b736841b3b0bc5d768ca9e5f4b20e241c55c4c227fb46ef8c
Analysis generated
July 9, 2026 06:55 UTC
Methodology
Evidence
✓ Snapshot stored   ✓ Hash verified
Citation Record
Entity: Grindr
Document: Grindr Privacy Policy
Record ID: CA-P-015011
Captured: 2026-07-09 06:55:48 UTC
SHA-256: d975ff63d08e3c4b…
URL: https://conductatlas.com/platform/grindr/grindr-privacy-policy/provision/CA-P-015011/sensitive-data-collection-and-processing/
Accessed: July 23, 2026
Permanent archival reference. Stable identifier suitable for legal filings, compliance documentation, and research citation.
Classification
Severity
High
Categories

Other risks in this policy

Compliance Governance Intelligence

Need to monitor specific governance provisions?

Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.

Arbitration clauses AI governance Data rights Indemnification Retention policies
Get Compliance

Or start with Monitor →

Built from archived source documents, structured governance mappings, and historical version tracking.

Frequently Asked Questions

What does Grindr's Sensitive Data Collection and Processing clause do?

This provision establishes that Grindr processes GDPR Article 9 special-category data, including health data and racial or ethnic origin, as part of its core service delivery and AI personalization functions, requiring a valid Article 9 legal basis for each processing purpose.

How does this clause affect you?

The agreement authorizes collection and processing of health information (including HIV status) and racial or ethnic origin provided through user profiles, and states this information is used to provide the Services including AI-driven personalization; the policy notes that profile information is public-facing.

Is ConductAtlas affiliated with Grindr?

No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Grindr.