Trending
    A person holding a smartphone displaying a dating app interface with data privacy and security warning icons.
    A person holding a smartphone displaying a dating app interface with data privacy and security warning icons.
    Regulatory Monitor

    Tea Is Back. Three Lawsuits, a Data Breach and an Apple Ban Later.

    ByDII Regulatory Monitor··6 min read

    Key Points

    • Tea exposed government IDs, selfie videos, private messages, and home addresses for over one million users during data breaches in July.
    • Three active class action lawsuits remain filed against Tea following the catastrophic data security breaches.
    • Apple has maintained its App Store ban on Tea for seven months, cutting the app off from 50% of the UK smartphone market.
    • Despite ongoing legal actions and security failures, Tea requires new users to submit selfie videos or photographs alongside government identification.

    Tea's website relaunch marks one of the most brazen comebacks in dating tech this year — and possibly the most ill-advised. The app that promised to make women safer in dating by collecting government IDs, selfies, and detailed relationship histories has returned after data breaches exposed precisely that information for over one million users. The company now asks users to trust it again with the same sensitive data it failed catastrophically to protect just months ago.

    The timing couldn't be worse. Three separate class action lawsuits remain active. Apple's App Store ban persists, cutting Tea off from roughly half the UK smartphone market. According to reporting by 404 Media, the July breaches didn't just leak usernames — they exposed selfie videos, government ID photographs, private messages, and home addresses. Some of that material ended up circulating on public forums, turning a safety tool into a doxing database.

    Person holding smartphone showing dating app interface with security concerns
    Person holding smartphone showing dating app interface with security concerns
    Tea's core business model is fundamentally compromised. The platform demands unprecedented personal data to verify users and prevent fake reviews, making it an irresistible target for bad actors.

    A honeypot by design

    The paradox at the heart of Tea's offering has always been apparent to anyone paying attention. Creating a women-only review platform for flagging dangerous men requires robust identity verification — otherwise, the system drowns in fake reviews, retaliation, and men reviewing themselves under false accounts. That verification infrastructure, however, creates exactly the kind of high-value data trove that motivated attackers dream about.

    Create a free account

    Unlock unlimited access and get the weekly briefing delivered to your inbox.

    No spam. No password. We'll send a one-time link to confirm your email.

    Tea's solution compounds the problem. According to statements from the company's head of trust and safety, Jessica Dees, new users must now submit either a selfie video or photograph alongside government-issued identification. This verification runs through a third-party provider, which the company frames as an enhanced security measure. But outsourcing doesn't eliminate risk — it distributes it.

    Users must now trust both Tea's infrastructure and its vendor's security posture, despite Tea having already demonstrated it cannot prevent unauthorised access to sensitive material. The broader dating industry has largely moved away from requiring government ID for basic access. Match Group properties offer optional ID verification through third parties like Garbo and Persona, but don't mandate it for platform use.

    Bumble introduced optional photo verification using selfies and pose-matching, avoiding document collection entirely. Grindr has resisted implementing mandatory verification, citing privacy concerns for LGBTQ+ users in hostile jurisdictions. Tea went the opposite direction. Its entire value proposition depends on collecting precisely the data most operators try to minimise holding.

    Digital security concept showing data protection and privacy concerns
    Digital security concept showing data protection and privacy concerns

    iOS exile and AI expansion

    The company's exclusion from Apple's App Store isn't merely symbolic. iOS accounts for approximately 50% of the UK smartphone market, according to Statcounter data, and skews heavily towards higher-income demographics — precisely Tea's target user base. Operating solely via web and Android limits growth, reduces discoverability, and eliminates Apple's App Store review process, which, whatever its flaws, provides a baseline security assessment.

    Apple's decision to maintain the ban suggests the platform identified issues severe enough to warrant ongoing exclusion despite potential pressure to reinstate a high-profile app. The company has not publicly detailed its reasoning, but removal following security incidents typically requires demonstrable remediation before reinstatement. Tea's continued absence from iOS seven months post-breach indicates either incomplete fixes or Apple's assessment that the fundamental architecture remains problematic.

    Rather than focusing entirely on rebuilding security credibility, Tea has introduced new AI features to its Android app. The additions include an AI dating coach and an upcoming tool called Red Flag Radar AI, which will analyse chat conversations. According to Dees, these features are 'designed to supplement community insight and can help inform a community member's point of view on something they might not be sure about'.

    For a company that hasn't yet demonstrated it can secure basic user information, adding systems that analyse private conversations seems premature at best, reckless at worst.

    The introduction of AI-powered chat analysis raises immediate questions about data processing, retention, and potential exposure. Training and running AI models typically requires substantial data throughput and storage. For a company that hasn't yet demonstrated it can secure basic user information, adding systems that analyse private conversations seems premature at best, reckless at worst.

    Regulatory compliance and legal documentation concept
    Regulatory compliance and legal documentation concept

    The compliance calculation

    For trust and safety teams across the dating industry, Tea's trajectory offers a cautionary case study. The EU Digital Services Act and UK Online Safety Act both impose obligations around user data protection, with the latter specifically addressing intimate image abuse. A platform that collects government IDs and facilitates reviews of individuals' relationship behaviour sits squarely in the regulatory crosshairs.

    Tea's data breaches predated full OSA enforcement, but similar failures going forward would likely trigger Ofcom action. The regulator has signalled it will treat dating platforms as high-risk services requiring enhanced protections. Operators holding sensitive personal data without demonstrable security infrastructure face potential fines up to 10% of qualifying worldwide revenue under the OSA, with criminal liability for senior management in cases of non-compliance.

    The company claims it has 'actively conducted penetration testing at the infrastructure level' and implemented expanded monitoring processes. Without independent security audits or third-party attestation, however, these assurances remain precisely that — assurances from a company whose previous security claims were contradicted by reality.

    Whether users will return depends on a calculation that may be impossible to make rationally. Tea offers a service that some women clearly value, judging by its brief App Store dominance. But that service requires trusting a platform that has already exposed users' most sensitive information. The dating industry has spent the past three years trying to rebuild trust after a series of self-inflicted wounds. Tea's relaunch suggests some operators still haven't grasped how fragile that trust remains, or how completely it can shatter.

    Key Takeaways

    • Mandatory identity verification creates a high-value target for attackers, making data minimisation and optional third-party verification a safer architectural choice for dating app operators.
    • Compliance teams must note that unaddressed data security failures under the UK Online Safety Act risk fines of up to 10% of qualifying worldwide revenue.

    Frequently Asked Questions

    D
    DII Regulatory Monitor

    Policy & Regulation Desk

    The DII Regulatory Monitor tracks legislation, enforcement action, safety rules and compliance across dating industry markets.

    More articles by DII Regulatory Monitor

    Comments

    Join the discussion

    Industry professionals share insights, challenge assumptions, and connect with peers. Sign in to add your voice.

    Your comment is reviewed before publishing. No spam, no self-promotion.

    More in Regulatory Monitor

    View all →
    Regulatory Monitor
    A smartphone displaying a secure user identity verification interface against a technical background.

    France's Age Verification Mandate: A Wake-Up Call for Dating Apps

    France has passed legislation requiring all social media users, not just minors, to verify their identity through regula…

    Wednesday 29th July · 1 min readRead →
    Regulatory Monitor
    A smartphone displaying a social media shopping interface alongside data security graphics and online trade icons.

    TikTok's Counterfeit Crisis: A Warning for Dating Apps on Trust and Regulation

    TikTok removed 143 million videos for counterfeit-related violations between January and June 2024 Over 530,000 videos a…

    Tuesday 6th January · 1 min readRead →
    Regulatory Monitor
    A smartphone user holding a device displaying a synthetic AI profile alongside analytical fraud detection graphics.

    AI Catfishing: The Trust Crisis Dating Apps Can't Ignore

    62% of 3,000 people tested failed to identify AI-generated dating profiles, despite 57% expressing confidence they could…

    Thursday 13th March · 1 min readRead →
    Regulatory Monitor
    A smartphone displaying the Tinder app resting beside a banking security token and a British pound banknote.

    Match Group Joins Stop Scams UK. Compliance or Real Fraud Fix?

    Romance and dating fraud cost UK victims £92 million in 2023, making it one of the costliest fraud categories nationally…

    Tuesday 6th May · 1 min readRead →