Remember that risqué photo you sent someone on a dating app that one time when you were feeling a little frisky? Unfortunately, the internet remembers it, too.
Last month, cybersecurity researchers revealed that over 1.5 million user photos, uploaded across five different dating apps, were publicly accessible via one mobile developer’s unsecured Google Cloud servers. The exposed content included photos that were uploaded to profiles as well as photos sent privately between users on the apps.
Today, I want to explain how this happened, and what you can do in the future to protect yourself.
As of April 2025, one of the only reliable ways of privately sharing our most sensitive bits and bytes is through an encrypted messaging platform like Signal.* However, most dating apps offer no such luxury. Whenever you type text, toggle settings, or upload and send multimedia on an app or website, there’s a good chance it’s either being sent via an unencrypted network, or stored on servers where others may be able to access it.
Of course, most of the time you want others to access it. If you upload a new profile photo to Hinge, you want Hinge to receive, store, and display your photo so that your future suitors can see it. When you send a photo to your match, you want them to see and engage with it.
But from the moment you press enter/send/submit/share/post, you enter into a pact of digital trust with many more third parties than you might expect. Virtually every platform you engage with on the internet automatically shares your uploaded content across their internal teams as well as potentially dozens of other vendors.
That photo you uploaded on Hinge may be accessible (based on their privacy policy) to third party vendors who provide “data hosting and maintenance, analytics, customer care, marketing, advertising, payment processing, legal support, and security operations.” Each of these entities has their own privacy policy and data security protocols that apply if and when they’re handling your content.
Other entities may eventually have access to your data as well, including law enforcement authorities and future platform owners in the event of an acquisition, merger, etc.1
*Please note, for the record, that even if you privately share a risqué photo with someone via a secure, encrypted channel, all they have to do is save or screenshot your photo for it to then potentially auto-upload to whatever cloud storage service they use and go right back to being as ripe for compromise as ever, subjected to whatever data practices and privacy policies their storage provider and its contracted vendors adhere to.
Dating Industry Fun Fact #1
I once spoke to a man who professionally buys dating & social media apps while at a dating conference in Los Angeles. He revealed that in his most recent business acquisition, the previous owner just sent him the passkeys to the dating app’s servers where all user photos, messages, and credit card information were directly visible to him, unencrypted, with no data safeguards in place.
And let’s not forget the “affiliates” your platform may partner with to deliver and improve services (and ads). These affiliates may have access (in the case of Hinge and other Match Group properties) to your:
Account Data
Profile Data
Content
Purchase Data
Marketing, Survey and Research Data
Third Party Data
Customer Support Data
Social Media Data
Usage Data
Technical Data
Geolocation Data
Face Geometry Data*
ID Data
*Dating Industry Fun Fact #2
From the moment you upload your very first photo, some dating platforms use your facial geometry to find people who share characteristics with you, based on research showing that ratings of facial attractiveness could be in part predicted by “similarity to the rater”.
By now, most of us are familiar with large scale data breaches, like when Equifax had an ‘oopsie’ and accidentally leaked 147 million Americans’ private records. These massive hacks and data leaks happen practically every year, and there’s not much we can personally do about it, other than set alerts, freeze our credit, and if lucky, maybe collect a whopping ~$12 remuneration from a class action lawsuit.
In the particular case of the 1.5 million user photos exposed in March, the culprit was not a malicious hacker, but something more painfully dumb, and frighteningly common: the API access keys to the Google Cloud storage buckets where the photos were stored had been accidentally left exposed in the raw code of the dating apps themselves!
Cybernews researchers explained, “If proper authentication is not set up or the credentials are simply left in the application code, attackers could read or delete data stored in the cloud, putting user data at risk.”2
Most modern websites store user data in “the cloud,” which is a fanciful way of saying that they either host their own private server (rare), or they pay another company to securely host the data. Amazon, Microsoft, and Google are responsible for nearly two thirds of all global cloud storage, so most of the time your data will ultimately reside on one of their cloud servers.
But when CyberNews researchers downloaded 156,000 iOS apps to analyze their security features, they discovered that fully half of these apps had left some of their storage buckets or API keys exposed and vulnerable.
Alas, in the case of the exposed dating app photos, the API keys that were hardcoded into the five compromised dating apps (all of which were made by the same developer) enabled researchers (and any other savvy digital snoopers) to gain access to the data.
Unfortunately for all of us unsuspecting users, there’s pretty much fuckall we could have done to protect ourselves here. The mistakes were out of our hands. In theory, we could have refrained from ever uploading them to the apps or sending them to other users within the apps, but that just feels like giving up entirely on using apps in the first place, right?
Given what we now know about how our photos might get stored and shared with third parties, at the very least, we should proceed with extreme caution before sending particularly risqué or compromising photos on the dating apps themselves. Further, we should only send sensitive content within secure, end-to-end encrypted apps, and ideally set it to disappear after being viewed.
For the sake of our lovers with fewer netsec scruples, we can also do them the service of not letting their lovingly-sent smut upload directly to our own personal cloud storage services like Google photos or Apple iCloud.
Oh yes.
Back in 2004 (over 20 years ago!), I took my first classes on computer networking and data security as a high school freshman. My teacher at the time was larger than life, taking an almost theatrical approach to personifying our personal data on its journey from the moment we click “send,” from our keystrokes, to the fiber optic cables of our local networks, to their routers and DHCP servers, to millions of servers, cables, towers, and satellites undergirding the open internet.
He showed us how anyone can just run a packet sniffer on an unsecured network to see, in plaintext, whatever people were sending over the network. He warned us about unsecured home networks and the perils and pitfalls of public wifi. He told us stories of sophisticated encryption and security protocols that could be completely undermined by something as simple as someone accidentally clicking a phishing link in an email, or plugging in a thumb drive they found on the ground, or leaving their phone or laptop unattended in a public space.
Honestly, it may not even matter. We’re rapidly approaching an era where AI agents may crack encryption and render all our global data security protocols obsolete. We already have AI that can automagically remove clothing from anyone in any photos, or simply conjure up deepfake photos and videos of anyone doing or saying anything, so honestly, it’s kind of a shitshow out there.
My best advice is to mentally, emotionally, and logistically prepare yourself for possible leaks, fuckery, and extortion. And if you’re going to take sultry selfies or film your own smut, at least make it high enough quality that if and when it leaks, you can shrug it off, blame the AI, and/or invite them to subscribe to your OnlyFans.
https://hinge.co/privacy#how-we-share-data
https://cybernews.com/security/apple-ios-apps-leak-sensitive-secrets/

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.