Grindr has agreed to a UK settlement worth £26 million over data practices from before 2020. The company disclosed the deal in a Form 8-K filed with the SEC on 4 September. The settlement, the filing says, includes no findings or admission of liability, and the filing does not name a single third party.
How much is Grindr paying to settle the UK data-sharing claim?
Per Grindr’s Form 8-K, the company will pay £13.0 million by 31 December 2026, then £13.0 million by 31 March 2027. Together that is £26 million; the filing converts each instalment to about $17.6 million, and The Register reports the total as $35.1 million. The payment settles a High Court of England and Wales claim brought on behalf of UK Grindr users “from a period up to early 2020.” The 8-K states plainly that the settlement includes no findings or admission of liability.
No Names in the Filing
The claimants issued High Court proceedings in April 2024, according to the 8-K, and served them on Grindr in April 2025. Grindr says it “disputes the allegations” but “recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.” That is not an admission of wrongdoing, and the filing does not present it as one.
The filing frames the episode as history. It notes that Grindr changed owners six years ago and listed on the New York Stock Exchange two years later. Since 2020, Grindr says, it has “overhauled its privacy program.” None of that fills the gap in the filing. It names no law firm, no claimant count, and no company that received any data. For that, the record runs back to 2018.
The Route: How a Medical Field Reached Two SDKs
The 8-K does not explain how the data moved. Norwegian research organisation SINTEF ran the analysis for Swedish broadcaster SVT in 2018. It found that Grindr’s app sent users’ HIV status and “last tested date” to two companies, alongside GPS position, phone ID and email, BuzzFeed News reported. The recipients, Apptimize and Localytics, were companies BuzzFeed described as helping app makers optimize their apps. Other profile fields, such as tribe, sexuality, relationship status and ethnicity, went to advertising companies, sometimes in plain text, BuzzFeed reported; the HIV field went to the two app vendors. Neither is an ad network. Localytics is a mobile analytics and marketing-automation platform. Apptimize is an A/B-testing tool. Both are the kind of software development kit a product team wires directly into an app. The field-by-field question is the same one that came up here last week on the advertising side of the line, when OpenAI’s measurement pixel was found to ship four of nine fields unhashed.
“The HIV status is linked to all the other information. That’s the main issue,” SINTEF researcher Antoine Pultier said at the time. Grindr’s then-CTO, Scott Chen, pushed back on the word sold: “No Grindr user information is sold to third parties. We pay these software vendors to utilize their services.” Days later, Grindr’s head of security said the company had removed HIV-related data from Apptimize and was discussing removing it from Localytics too. The sources never explain why the field was sent. They only show it travelling with the rest of the profile data the app passed to both SDKs.
Law firm Austen Hays filed the underlying claim in April 2024. It calls Localytics and Apptimize “advertising companies” and alleges they may have passed data on to further, unnamed parties. It dates the disclosures mainly before 3 April 2018, and separately between 25 May 2018 and 7 April 2020. The second window opens on the day the GDPR began to apply. “Our clients have experienced significant distress over their highly sensitive and private information being shared without their consent,” said Chaya Hanoomanjee, the firm’s managing director. Press reports put the claimant group at roughly 12,000. Split equally and before legal costs, £26 million works out to about £2,167 each, arithmetic the filing never states.
Two Legal Tracks, Not One
Grindr also lost a separate Norwegian enforcement case. The two are easy to run together, and they should not be: they concern different conduct, ran through different systems, and reached different outcomes.
| Forum | What Was Alleged | Outcome | Date |
|---|---|---|---|
| High Court of England and Wales (Austen Hays claim) | Sharing profile data, including HIV status, with Localytics and Apptimize without consent | £26M settlement; no findings or admission of liability | Settled 2 September 2026 |
| Datatilsynet and Norwegian courts | Sharing GPS, IP address, age, gender and Grindr-user status with advertising partners without valid consent | NOK 65M fine upheld on appeal | Fined December 2021; appeal upheld 21 October 2025 |
Norway’s Borgarting Court of Appeal upheld the fine on 21 October 2025, after the Oslo District Court had already upheld it on 1 July 2024. The appeals court held that Grindr lacked valid consent to disclose personal data to advertising partners. It treated the fact of being a Grindr user as data about sexual orientation. That case concerns advertising partners; the UK claim names two companies whose products are app-side SDKs, even though the claim itself labels them advertising companies. Neither outcome resolves the other.
What Analytics Teams Should Check Before This Happens to Them
A mobile-analytics or A/B-testing SDK receives whatever a product team hands it: device and user identifiers, event names, and any user or event property attached to them. That is normal integration behaviour, not misconduct by the vendor. The safeguards belong upstream, in what a team decides to send.
- Audit every user property and event parameter before it ships. A field revealing health status, sexual orientation, religion, or similar special-category data should never travel as a plain property, hashed or not.
- Read the vendor’s data processing agreement for retention periods, sub-processor lists, and whether raw values are logged before any transformation happens.
- Limit what a feature-flagging or A/B tool receives to an identifier and a variant assignment, not the full user profile the app holds in memory.
- Gate anything sensitive behind consent before the SDK initializes, not after. A field removed from a live feed can still sit in a vendor’s collected history.
Australia’s exposure draft would make consent the price of a “trade” in personal information, and its consultation paper names ad pixel disclosures as one thing that definition may capture. A paid analytics SDK is a different transaction from a pixel feeding a programmatic buy; Grindr’s own line in 2018 was that it paid its vendors. The upstream discipline holds either way: decide what leaves the app before any vendor sees it, the same gate that GA4’s consent mode, covered here in June, now puts in front of the data GA4 shares with Google Ads.
