People are reasonably careful with their banking details and remarkably careless with their dating profiles. This is backwards. A leaked bank password is expensive and fixable. A leaked record of who you are attracted to, what you're afraid of, and what you said at two in the morning to someone you trusted is neither.
This isn't an argument for avoiding dating apps. It's an argument for understanding what you're handing over, because most people have never actually thought it through.
The obvious layer. Name, age, photographs, location, job, education. Ordinary profile material. On its own, roughly what you'd tell a stranger at a party.
The inferential layer. Who you swiped toward and away from, how long you looked at each profile, when you're active, how quickly you reply and to whom. You never typed any of this, but it's collected continuously and it's revealing in ways the obvious layer isn't. Patterns of attention describe preferences far more accurately than self-description does.
The disclosed layer. Your messages. Everything you wrote at length to someone you were starting to trust — including things you may never have said aloud to anyone. This is the crown jewels, and it's the part people forget is stored at all.
The inferred-identity layer. From the above, a system can derive sexual orientation, religious belief, political leaning, mental health struggles, relationship status, and health information. Under GDPR and similar frameworks, several of these are "special category" data requiring heightened protection. Most of it was never explicitly asked for. It was deduced.
Almost every privacy policy contains this sentence, and it's usually true in the narrow sense: the company is not putting a spreadsheet of users up for sale.
But data moves in ways that aren't "selling":
None of this is necessarily sinister. It's simply that "we don't sell your data" answers a much narrower question than the one you're actually asking, which is: who can see this, and what happens to it if things go wrong?
Most data breaches are an inconvenience. Breaches of intimate data are different in kind, because the harm isn't financial — it's exposure.
There have been well-documented cases of dating and affair-related services being breached, with real consequences for users: outing of people who were not out, damage to families and careers, and in some regions genuine physical danger. For anyone in a country where their orientation is criminalised, or in a controlling relationship, or in a profession with strict conduct expectations, this stops being abstract quickly.
Ask not "do I trust this company?" but "what happens to me if this company is breached, sold, or subpoenaed?" The second question is the one that predicts your actual risk.
There's a well-established framework — Privacy by Design, developed by Ann Cavoukian — that predates most of these apps. Its principles are unglamorous and rarely followed:
The implicit bargain of most free connection products is that your attention and your data pay for the service. For a photo-sharing app that's a defensible trade. For a product built on people telling the truth about their loneliness, it's a strange one — because the thing being monetised is the vulnerability that made the product worth using.
It's possible to build differently: to collect little, to make privacy the default rather than a setting, to let people reveal themselves one deliberate piece at a time to one specific person. That's the model The Garden is built on, and you can read exactly how it works in our privacy policy — written to be read, not to be survived.
no ads · no tracking · nothing sold