OkCupid handed nearly three million user photos to Clarifai, a facial recognition company, along with demographic information and location data. No user consent. No opt-out. No contractual restrictions on how the images could be used. The arrangement started in September 2014 when Clarifai’s founder requested the data directly, and OkCupid handed it over because its own founders were financial investors in Clarifai.
The Federal Trade Commission announced on March 30 that it settled the case against Match Group Americas and its subsidiary Humor Rainbow, Inc. (which operates OkCupid). The penalty for a decade of deception, active concealment from media, and obstruction of a federal investigation: zero dollars.
The settlement requires OkCupid to stop misrepresenting its privacy practices and submit compliance reports for 10 years. That is the entire enforcement action. No admission of wrongdoing. No monetary fine. An OkCupid spokesperson told reporters that the alleged conduct “does not reflect how OkCupid operates today.”
The timeline makes the settlement feel even worse. The data sharing happened in 2014. The New York Times exposed it in 2019. The FTC filed a petition demanding documents in May 2022. And in March 2026, twelve years after the violation and four years after the investigation began, the resolution is a promise to file paperwork. Match Group’s portfolio includes OkCupid, Tinder, Hinge, and dozens of other dating platforms that collectively hold some of the most intimate personal data on the internet. Selfies, sexual orientation, location history, conversation logs. All of it sitting behind privacy policies that, in OkCupid’s case, the company itself was violating.
What makes this a structural failure rather than a company-specific scandal is the enforcement mechanism. The FTC cannot impose civil penalties on first-time privacy violators under its current authority. That is not a bug. That is the design of US privacy law. A company can share your most intimate photos with an AI firm, lie about it for a decade, obstruct the federal investigation, and the maximum consequence is a consent decree that says “please don’t do it again.” The punishment for getting caught is supervision. Not cost.
This is the same pattern playing out across technology right now. A jury in another courtroom is deciding whether Instagram was deliberately designed to be addictive. Platform companies build their business on user trust, extract maximum value from personal data, and face regulatory consequences so light that the violation is effectively free. The FTC’s own enforcement tools are not built for the scale of the problem. When a company operating dozens of dating apps across hundreds of millions of users can settle a biometric data case for zero dollars, the message to every other platform is clear: the fine for violating your users’ privacy is less than the value of what you took.
What This Means for Everyday People
If you have ever used OkCupid, your photos may have been sent to a facial recognition company over a decade ago. There is no mechanism to find out whether your specific data was included in the transfer to Clarifai, and the settlement does not require notification to affected users.
More broadly, your dating app data, the photos, the preferences, the location history, is among the most sensitive information you produce online. The privacy policies protecting it are only as strong as the enforcement behind them. Right now, that enforcement amounts to a promise to file compliance reports. If that bothers you, the problem is not OkCupid. It is the absence of a federal privacy law with actual teeth.