Okcupid leaks 3 million user photos to mystery third party, ftc says
Match Group’s dating app OkCupid handed over nearly three million user photographs—plus precise geolocation data—to an unnamed outside company while telling members the opposite, the U.S. Federal Trade Commission revealed Tuesday.
The deception, buried in a proposed settlement released yesterday, stretches back to 2014 and includes what regulators call overt obstruction: when reporters first caught wind of the leak in 2020, OkCupid publicly denied any relationship with the recipient and privately urged staff to stonewall investigators.
How the data pipeline worked
According to the complaint, OkCupid’s iOS and Android clients piped every newly uploaded photo, along with latitude–longitude pairs pulled from handset GPS chips, to a Silicon-Valley analytics outfit that was neither a service provider nor a corporate affiliate. No contract limited resale; no notice popped up inside the app; no opt-out switch ever appeared. The only hint lived inside an opaque clause that promised data might be shared with “business partners”—a category the FTC says the recipient never met.
Regulators peg the haul at 2.9 million unique user images and “continuous” location pings for an undisclosed subset, enough to reconstruct nightly bar crawls or morning gym routes. The third party, identified only as “Company A,” combined the feed with ad-tracking cookies, effectively deanonymizing faces behind device IDs.

Match group’s damage-control playbook implodes
Inside OkCupid’s Slack channels, product managers fretted over “optics” and “regulatory heat,” the FTC filing shows. Publicly, the company blog claimed “we do not share your personal data with third parties for marketing.” That post stayed live until investigators served a Civil Investigative Demand in 2021; Match Group then spent nine months fighting the order in federal court before losing.
The proposed deal forbids Match Group and subsidiary Humor Rainbow from misrepresenting any collection, use or sharing of photos, demographic tags or geocoordinates. It carries no financial penalty—typical for first-time FTC privacy settlements—but plants a legal tripwire: future violations can draw $50,210 per user per day under the agency’s newly minted penalty offense authority.
OkCupid, for its part, emailed users a terse “we updated our privacy FAQ” late Tuesday. The message never mentions the FTC or the photo leak.

Why this still matters in 2024
Match Group commands more than 45 dating brands—Tinder, Hinge, Match.com, PlentyOfFish, Meetic—reaching 750 million global accounts. Tuesday’s settlement applies company-wide, yet the conglomerate’s privacy policy still lets any app “share data with corporate family members” for vague “research and analytics.” Translation: the same data-slurping machine remains intact; only the branding changed.
Lovelorn consumers now face a stark asymmetry: your intimate selfies and late-night coordinates can become someone else’s machine-learning fodder overnight, and the only bulwark is a paragraph of legalese you scrolled past at signup. The FTC just proved that paragraph was a lie. Next time the penalty will be cash, not just a promise.
