The trade-off built into how these apps work
Location-based dating apps need your location to do the one thing they’re built for: show you people nearby. Your exact coordinates sit on the app’s servers, and the app has to translate that into something safe to show a stranger — usually a distance (“3 miles away”) instead of a map pin. How safe that translation actually is depends on how carefully each app engineers it.
In 2024, researchers from KU Leuven’s DistriNet research group tested that engineering across the 15 most-downloaded location-based dating apps on the Google Play Store, including Tinder, Bumble, Hinge, Badoo, Grindr, and happn. Their peer-reviewed paper, “Swipe Left for Identity Theft”, presented at USENIX Security 2024, found that six of the fifteen apps could be manipulated to reveal a user’s near-exact location, despite proven countermeasures — like the grid snapping Tinder uses — that are meant to prevent exactly this.
How “distance away” turns into an exact location
The technique is called trilateration: if you know your distance from three known points, you can calculate the one location consistent with all three. It’s the same math GPS uses, run in reverse against another person.
The researchers documented three versions of the attack, according to their paper:
- Exact distance trilateration, found on Grindr. Grindr rounds a user’s coordinates to three decimal places before they reach its servers, but the paper describes a way to recover distance with just one account by repeatedly manipulating a location-search parameter — accurate to at least a 111-by-111-meter area at the equator, including for users in countries like Egypt where Grindr always hides distance by default.
- Rounded distance trilateration, found on happn. The app shows a rounded distance, but its underlying data feed leaked a more precise distance rounded to the nearest value in a fixed set of steps (249, 499, 999, 1999 meters, and so on) — precise enough to reverse-engineer a tighter estimate.
- Oracle trilateration, found on Badoo, Bumble, Hinge, and Hily. These apps use exact distances internally to power their distance filters — the slider that searches for people within a certain range. By repeatedly adjusting a fake location and watching when a target enters or drops out of that range, the researchers could narrow down a location. For Hinge and Hily, this worked even when a user had turned off distance display in their profile — hiding distance in the interface did not close the underlying leak.
TechCrunch’s reporting on the study quoted lead researcher Karel Dhondt saying the technique used against Badoo, Bumble, Hinge, and Hily could narrow a person’s location down to about 2 meters — not exact GPS coordinates, but, in his words, “close enough to pinpoint the user.”
Tinder was not among the vulnerable apps. The researchers found it defends against trilateration with “grid snapping” — dividing the map into 1-by-1-mile cells and using the center of a cell, rather than a person’s true coordinates, for every distance calculation, which makes the math the attack relies on impossible to solve precisely.
What happened after the researchers reported it
The KU Leuven team followed responsible disclosure practice, contacting all 15 vendors before publishing, and according to their paper, nine of the twelve companies that acknowledged the report engaged substantially and deployed fixes. Vendors gave specifics to TechCrunch: Bumble’s vice president of global communications said the company was “made aware of these findings in early 2023 and swiftly resolved the issues outlined,” including at Badoo, which Bumble owns; a Hinge spokesperson said the company “immediately took action”; and Hily’s co-founder described building new geocoding algorithms with the researchers that have been running for over a year, as reported by TechCrunch.
That’s a good outcome, but it doesn’t mean location risk on dating apps is solved for good. The researchers’ own recommendations are aimed at the whole category: minimize what location data is collected, harden APIs so they don’t leak more than the interface shows, and default to sharing only an approximate location. In their university’s summary of the research, the team put it plainly: don’t put too much faith in an app’s setting for hiding your data from others, because everything you share is stored on the company’s servers and could be exposed later. Their advice: share only an estimated location where the app allows it, and set your phone to ask for location permission every time you open a dating app rather than granting it permanently.
Settings that actually limit who can find you
These won’t stop a determined, technically sophisticated attacker rebuilding the trilateration technique — no app setting can promise that. But they do control who sees you by default.
Tinder. Tinder’s help center documents this under Discovery Settings: distance, age, and who you see, with dealbreaker toggles so Tinder won’t show you people outside your range, and an option to turn Discovery off entirely so your profile stops appearing to anyone new while existing matches still work.
Bumble. The distance filter (profile → filters icon → Basic filters) caps how far away people can be to appear in your queue, though Bumble’s help center notes it only filters who you see — people outside your distance setting may still see you, unless you also use Incognito Mode. Incognito Mode, part of Bumble Premium and Premium+ subscriptions, hides your profile from everyone except people you’ve already liked, according to Bumble’s support page on the feature.
Hinge. Hinge’s help center describes no equivalent hide-your-profile feature; distance is one of the dating preferences every user can set, alongside gender, age range, ethnicity, relationship type, and religion, to control who’s shown to you.
For a person you specifically want to avoid — an ex, a coworker, a family member — Tinder’s Block Contacts and Hinge’s Block List offer a contacts-based block, syncing your phone contacts or letting you manually enter a name, email, or phone number, rather than relying on you spotting their profile yourself. Neither app notifies the person you’ve blocked. Both note the same limit: if the contact info you enter doesn’t match what that person used to sign up, blocking won’t work. It’s worth setting this up before you’re actively using the app, rather than waiting until you encounter them.
Linking other accounts widens what a stranger can find
Dating profiles that link Instagram or Spotify make verification easier for other users, but they also connect your dating identity to accounts that may carry your face, your friends, your routine, and your real name in ways your dating profile alone doesn’t. If someone is already trying to identify or locate you, a linked social account can hand them the rest of the picture your dating profile was designed to withhold. Our guide on locking down social media covers how to audit what a stranger can piece together from a profile.
Fake profiles and impersonation
If someone creates a profile pretending to be you — sometimes used to embarrass a target or lure their contacts into conversations — all three platforms have a reporting path for it. Hinge’s process asks you to submit a request under “Safety and Reporting” with the impersonating profile’s exact name, age, bio, and photos, plus screenshots, according to Hinge’s help center; you can also file on someone else’s behalf if authorized, such as a parent. Bumble’s safety features page describes Block and Report tools on any profile or conversation, alongside an automated system it calls Deception Detector, which it says is intended to flag fake and scam profiles. Tinder’s process routes reports through a form where you select “Someone is impersonating me,” attach a screenshot of the profile’s name, age, and bio, and describe the situation, according to Tinder’s support form.
Screenshot everything before you report — the profile, the bio text, any messages — since the profile may disappear once it’s actioned and you’ll want the record. Our guide to preserving evidence walks through how to document this in a way that holds up if you need it later.
Meeting up safely
None of this changes the baseline advice for a first meeting: video chat before meeting in person, choose a public place you pick rather than one they choose, and tell a friend where you’re going and when to expect to hear from you. If a match pushes to move off the app quickly, asks for money, or resists a video call, take that pattern seriously rather than explaining it away.
Where this connects to broader tracking risk
If you’re worried specifically about someone tracking your real-time location rather than your dating profile, see Is someone tracking my phone? and our overview of location sharing settings across the apps and accounts on your phone. Dating apps are one source of location exposure among many, and the fixes for the broader problem — permission audits, checking who has standing access to your location — apply here too.