Privacy policies describe what a company says it collects and keeps. This guide compares Tinder, Bumble and Hily on photos, messages, location, face data and deletion, with what the Grindr case showed.

What these policies say at a glance

Tinder, Bumble and Hily each describe collecting substantial information connected to dating use, but their policies differ in detail. Tinder expressly lists photos, chats, search queries, approximate and permission-based precise location, and face geometry data for certain verification features. Bumble lists photographs, messages, geolocation and biometric information connected to verification. Hily warns users to treat posts and messages as potentially publicly accessible and lists tracking software that can collect device identifiers and approximate location. Account deletion does not necessarily mean immediate erasure of every record. This is general information, not legal advice.

What a privacy policy can — and cannot — tell you

A privacy policy is a company’s account of the data it collects, retains and processes under stated conditions. It can be useful for identifying the categories of information connected to an account, the consequences of enabling permissions, and the steps the company says are available for access or deletion.

It is not an independent audit of how effectively an app protects that information in practice. The available source material does not measure the security of Tinder, Bumble or Hily, nor does it compare their technical safeguards. A policy also cannot prevent a person who has already seen, copied or saved something from keeping it. Our online dating safety guide covers the other half of staying safe: who you talk to, not only what the app stores.

That final point is stated particularly plainly in Bumble’s policy. It says that, after someone removes information or deletes an account, copies may still be visible where they were previously shared, copied or stored by other people. Bumble says it cannot control that material.

When reading any dating-app policy, separate four questions that are often blurred together:

The distinction matters. Removing a profile from search or closing an account may change what other users can see, while records such as transaction data, consent records or customer-support correspondence may be retained for reasons described in the policy.

Policies also change. The Tinder Privacy Policy discussed here says it applies from April 4, 2026. The Hily Privacy Policy has an effective date of March 18, 2026. The Bumble Privacy Policy was read in October 2026. Before acting on a setting or submitting a deletion request, users should check the version currently presented to them.

Comparison: photos, messages, location and retention

TopicWhat the policies sayWhat it means for users
Photos and profile contentTinder lists photos, videos, audio and text as content. Bumble lists photographs and photo information. Hily warns that material posted or shared may be publicly viewable and accessible.A photo can be account data, profile content and something other users may copy or share. Deleting an account cannot necessarily retrieve copies held by others.
MessagesTinder lists chats with other members. Bumble lists messages. Hily says users should presume that anything posted, shared or messaged may be publicly viewable and accessible, including outside the app.Treat chat content as potentially lasting beyond the moment it is sent. Avoid sending identifying or sensitive information to people you do not trust.
LocationTinder lists approximate location and, with device permission, precise latitude and longitude. Bumble lists geolocation information. Hily lists software development kits that may collect approximate location when location services are enabled.Check location permissions and avoid putting precise location in a profile or message. A profile location and device-based location may be separate issues.
Face verificationTinder says certain verification features collect face geometry data, which may be biometric data in some jurisdictions. Bumble lists biometric information for verification and says it retains biometric scans until no longer needed.Verification can involve more than a visible selfie. Read the verification notice before starting, especially where a policy describes biometric or face-geometry processing.
Account closure and recordsTinder gives several specific retention periods. Bumble says it retains communications records for 6 years after deletion. Hily says freezing is not account deletion and keeps data during use until deletion, blocking or suspension.“Delete,” “deactivate,” “freeze” and “cancel a subscription” are not interchangeable actions. Confirm which one is being completed.

Tinder: broad content collection and defined retention periods

Tinder’s policy provides one of the more detailed lists in the available material. Its stated account data includes a phone number, email address and date of birth. Profile data includes gender, interests, preferences and approximate location. The policy says that some profile information may be sensitive in certain countries, giving examples including sexual orientation, sexual life, health and political beliefs. It says that a person who chooses to provide such information consents to its use.

Its content category is extensive: photos, videos, audio, text, search queries and chats with other members are all listed. The policy also lists purchase data, marketing, survey and research data, customer-support data, usage data, technical data, insights and inferences, and data obtained from third parties. The third-party category includes information from accounts such as Facebook, Google or Apple.

Location deserves closer attention because Tinder distinguishes approximate location from more precise device data. Its policy says it may collect precise latitude and longitude from a device only when the user gives permission. Removing that permission is therefore one of the practical controls the policy itself identifies.

Tinder also specifically addresses face data. It says that Photo Verification, Photo Check and ID + Photo Verification involve collection of face geometry data. The policy adds that this may be considered biometric data in some jurisdictions. A user deciding whether to complete one of those processes should not treat it as equivalent to simply uploading an ordinary profile image. If you want to know what the paid tiers add, read our Tinder review.

Tinder’s retention language is unusually specific. Closing an account removes the profile from view, but that is not the end of every retention period. The policy says that recreating an account with the same credentials within 90 days restores some data. It also says inactive accounts are closed automatically after two years.

The policy lists several retention periods that may apply after closure or in connection with particular records:

A woman at a kitchen table adjusting settings on her smartphone with a closed laptop beside her
Settings are worth reviewing before a profile fills up, not after.

For a user who wants a clean break, the 90-day restoration point is practical. Re-creating a Tinder account using the same credentials soon after closure may restore some information rather than starting with an entirely empty account history.

Tinder says users can review some data by logging in and can retrieve a copy through the process described in its policy. It also says some data can be deleted within the service, while account closure is available for the account as a whole. The policy describes opting out of some processing in account settings and withdrawing consent by changing settings or removing permissions for location, photos, contacts and push notifications.

Bumble: verification, biometrics and records after deletion

Bumble’s policy lists registration information such as name, email, date of birth, photographs, mobile number, sexual preference and social-media login data. It also lists linked social-media information, purchase information, geolocation information, device information, photo information, link information, messages, customer-support contact information, cookies and similar technology.

The policy also includes success stories, surveys and other contributions. That is a reminder that information supplied outside the main profile or chat screen can still become part of the information associated with use of a service.

Bumble says it requires every person using its app and sites to verify their account. Its policy lists profile verification and ID-verification information, including biometric information. It says that if a person verifies their profile, Bumble keeps biometric scans it receives so it can verify that person in the future and for record-keeping, until it no longer needs the scans. That is a stated retention standard rather than a fixed period. The policy does not provide a public number of days or years for Bumble’s own retention of those biometric scans in the material available here. Our Bumble review looks at the app itself.

The ID-verification process has a separate detail. Where a user also verifies an ID, Bumble says a selfie and ID are compared by a third-party partner, Veriff. According to Bumble’s policy, Veriff retains the selfie and ID picture for up to 72 hours.

That does not establish what happens with every other item connected to verification, but it does show why users should read the verification information before submitting a selfie or identity document. A visual profile photo, a biometric scan and an ID image may be handled under different descriptions.

For deletion, Bumble says it keeps records of communications with a user for 6 years after the account is deleted. The policy’s warning about previously shared or copied material should also shape expectations. Closing an account may stop future profile visibility, but it cannot reliably erase a screenshot, a saved message or content another person has stored elsewhere.

Hily: the policy’s warning about public visibility

Hily’s policy takes a notably direct approach to user-shared material. In section 1.2, it tells users to presume that everything they post, share or message on the app may be publicly viewable and accessible, both to Hily users and to people outside the app.

That is a strong warning, and it should affect the kind of information put into a profile or sent in private conversation. Hily says it does not recommend placing emails, URLs, phone numbers, full names, addresses, card details, national ID numbers or precise location in a profile. It also says not to send such information to people a user does not trust.

The policy separately warns against sharing sensitive personal information with other users. Its examples include religious denomination, sexual preferences, health details, political leanings and addictions. It points users to its tags feature for safer sharing.

Hily’s retention language also makes a distinction that users can easily miss. Its policy says data is stored during the term of use until account deletion, blocking or suspension. It expressly says temporary deactivation, described as “freezing” an account, does not qualify as account deletion.

That means a person seeking deletion should not assume that a temporary pause has the same effect. The policy also says cancelling a subscription is separate from deleting data. Subscription cancellation may be handled through Apple, Google or Hily, while data deletion is a different request or account action.

The policy’s tracking-technology section lists third-party software development kits. The Facebook Audience Network SDK entry lists device identifiers, including IP address, iOS advertising identifier and Android advertising ID, as well as approximate location when location services are enabled. An AppLovin SDK entry lists advertising identifiers, approximate geolocation, demographic information such as age or gender, interests and device details.

Those entries are a reason to review what is voluntarily placed in a profile and whether location services are enabled. They do not, by themselves, provide an independent measurement of Hily’s privacy or security practices.

A woman by a dark window with city lights behind her, reading something on her phone with a guarded expression
What you send in a private chat can outlast the conversation, whatever the app's policy says.

Hily’s policy lists a legal contact for questions and a support contact for rights requests. It also refers to Apple’s privacy process for deletion requests tied to Apple.

What the Grindr case showed about data sharing

The Grindr matter is relevant because it showed how a dating app’s data can be sensitive in context, particularly when advertising technology is involved. It should not be used to make unsupported claims about Tinder, Bumble or Hily.

On January 14, 2020, the Norwegian Consumer Council announced formal complaints to the Norwegian Data Protection Authority against Grindr and companies that received personal data through it: Twitter’s MoPub, AT&T’s AppNexus, OpenX, AdColony and Smaato. The complaints concerned alleged breaches of the GDPR.

The Norwegian Consumer Council’s release included a statement from noyb founder Max Schrems: “Every time you open an app like Grindr advertisement networks get your GPS location, device identifiers and even the fact that you use a gay dating app.”

The case later reached a confirmed outcome. On September 29, 2023, noyb said the Norwegian Privacy Appeals Board upheld the Norwegian Data Protection Authority’s fine against Grindr. The fine was NOK 65 million, described as approximately 5.8 million euros, and Grindr’s appeal failed. The Norwegian Consumer Council said the decision affirmed that Grindr’s practice of sharing sensitive personal data with third parties was illegal.

The narrow lesson is not that every dating app has the same data-sharing practices. The available sources do not support that claim. The lesson is that combinations of data can reveal more than a single field appears to reveal. GPS location, a device identifier and use of a particular dating app may be highly sensitive together.

No regulator fine against Tinder, Bumble or Hily was verified in the source material used here.

A practical privacy-settings checklist

Privacy controls are most useful before a profile becomes established and before sensitive content is sent. A user cannot fully control what another person does with a message or image after receiving it, but there are still meaningful ways to reduce unnecessary exposure. A fake profile is the other privacy risk, which our guide to spotting fake dating profiles explains.

Use this checklist when setting up or reviewing an account:

The safest practical habit is restraint with shared content. Hily’s warning is broad enough to be useful beyond one app: material that is private in tone may still be copied, stored or viewed beyond the intended recipient.

Deletion and data-access checklist

Deleting an account should be treated as a process rather than a single button press. The available policies describe different retention rules, and Hily draws an explicit line between subscription cancellation and deletion.

  1. Save information you may need before closing the account. Tinder says users can access and review some information by logging in and can retrieve a copy through the process described in its policy. If account data, conversations or transaction records matter to you, seek any available copy before closure.

  2. Remove optional profile information and content where the service allows it. Tinder says some data can be deleted in the service. Removing optional details before closure may reduce what remains publicly visible while the account is still active.

  3. Close the account rather than merely pausing it. Tinder says closure removes a profile from view. Hily says freezing does not amount to deletion. The exact label on a screen matters.

  4. Handle subscriptions separately. Hily says cancelling a subscription is separate from deleting data. Do not assume that ending payment arrangements removes account information, or that deleting an account necessarily addresses a subscription.

  5. Use the stated rights-request route where needed. Hily’s policy identifies support as the contact for rights requests and names a separate legal contact for questions. Tinder says users can retrieve a copy through its stated process and can close an account through the service.

  6. Understand that closure may begin, rather than end, a retention schedule. Tinder lists a three-month safety retention window after closure, along with longer periods for records such as transactions, traffic logs, consents and customer-care exchanges. Bumble says it retains communication records for 6 years after deletion.

  7. Avoid immediately recreating a Tinder account with the same credentials if you do not want some prior information restored. Tinder says doing so within 90 days restores some data.

Finally, account deletion cannot guarantee that shared material disappears from other people’s devices or records. Bumble says copies may remain viewable if other people previously shared, copied or stored them. That is why the privacy decision that often matters most happens before a photo, identity document, precise location or sensitive message is sent.

Frequently Asked Questions

What data does Tinder say it collects from users?+
Tinder's policy lists account data such as phone number, email address and date of birth; profile data including gender, interests, preferences and approximate location; and content such as photos, videos, audio, text, search queries and chats. It also lists purchase, usage, technical, customer-support, marketing, survey and research data, third-party data, insights and inferences. Precise latitude and longitude are collected only with device permission.
Does deleting a Tinder account erase all data immediately?+
Tinder says closing an account removes the profile from view, but it lists retention periods for some records. It describes a safety retention window of three months after account closure, transaction-data retention for tax and accounting, traffic-log retention, consent-record retention and customer-care exchange retention. It also says recreating an account with the same credentials within 90 days restores some data. The policy allows users to delete some data within the service.
What biometric information does Bumble say it uses for verification?+
Bumble lists profile verification and ID-verification information, including biometric information. It says every person using its app and sites must verify their account. If a person verifies a profile, Bumble says it keeps biometric scans it receives for future verification and record-keeping until they are no longer needed. For ID verification, Bumble says a selfie and ID are compared by Veriff, which retains the selfie and ID picture for up to 72 hours.
Can Hily messages and profile information be seen outside the app?+
Hily's policy tells users to presume that everything posted, shared or messaged on the app may be publicly viewable and accessible by Hily users and people outside the app. It advises against putting emails, URLs, phone numbers, full names, addresses, card details, national ID numbers or precise location in a profile, or sending them to people a user does not trust. It also warns against sharing sensitive personal information with other users.
What happened in the Grindr privacy case in Norway?+
The Norwegian Consumer Council filed complaints against Grindr and companies receiving personal data through it, alleging GDPR breaches. In 2023, noyb said the Norwegian Privacy Appeals Board upheld the Norwegian Data Protection Authority's fine against Grindr. The fine was NOK 65 million, described as approximately 5.8 million euros, and Grindr's appeal failed. The Norwegian Consumer Council said the decision affirmed that Grindr's sharing of sensitive personal data with third parties was illegal.