Introduction: "Can I get your number? WhatsApp would be easier"
Thursday, 10:40 p.m. Three days of messages, two fits of laughter, one shared playlist. The conversation is good, genuinely. And then comes the most ordinary sentence in the world: "Can I get your number? WhatsApp would be easier."
You hand it over. In twenty seconds, someone you have never met in person obtains: your mobile number, your WhatsApp profile picture, your status, your last-seen time, and — if your number is floating around in an old classified ad, a delivery form or a data breach — your surname. From there, a search engine query with your first name, your city and your job is often enough to turn up your employer, your neighbourhood, sometimes your building.

From a data point of view, dating apps are the most intimate place on the internet. You voluntarily declare what the GDPR calls sensitive data: sexual orientation, religious beliefs, sometimes health status. You add precise location data, photos of your face, and a complete picture of your daily rhythm (when you're awake, when you're alone, when you get home from work).
This guide won't tell you to run away from the apps. It offers a simple method: move forward in stages, giving away at each step only what is needed for the next one.
Who knows what, exactly
Three recipients, three different risks
People often conflate "the app is watching me" with "the person I'm chatting to can identify me." These are two distinct problems, with distinct countermeasures.
| Recipient | What they get | Main risk |
|---|---|---|
| The app's publisher | Profile, messages, photos, location, swipe history, payment data | Database breach, resale of derived data, retention after deletion |
| Advertising partners and analytics tools | Advertising ID, inferred interests, usage events | Cross-referencing with your other apps, sensitive ad profiling |
| The person on the other end | Photos, first name, age, job, approximate neighbourhood, habits, later your number | Full identification, harassment, image sharing |
The third one is the most underestimated. Most of the bad experiences people describe don't come from a spectacular hack: they come from an ordinary person who took a screenshot, ran a reverse image search and made three deductions.
What the law says
France's CNIL regularly points out that data relating to sex life and sexual orientation falls under Article 9 of the GDPR: processing it is prohibited in principle, barring explicit consent or a limited set of exceptions. In practice, that gives you concrete leverage:
- Right of access: you can ask the publisher for a copy of all your data. The results are often eye-opening — thousands of rows, years of messages, a history of your locations.
- Right to erasure: deleting your account must result in actual deletion, not mere deactivation. Some apps nevertheless keep data for long periods on anti-fraud grounds.
- Right to object to ad profiling, independently of deleting your account.
Remember: uninstalling the app deletes nothing. You have to delete the account from within the app or the website, then, a few weeks later, send an access request to check what's left.
Your profile: what identifies you without your realising it
Photos say more than the bio
A profile photo isn't just a face. It's:
- a background (a metro station, a shop sign, a church tower, the view from your balcony);
- a social context (a uniform, a badge, a club jersey, a company tote bag);
- and above all, a reusable visual fingerprint. Reverse image search engines now make it possible to find the same face elsewhere: a professional network, a public account, a sports club photo, a local newspaper article.
The most effective rule fits in one sentence: never use a photo on a dating app that has already been published elsewhere under your real identity. A unique photo, taken for the occasion, breaks the link between your handle and your real name. A small smartphone tabletop tripod is enough to take decent portraits yourself, without relying on a friend who will then post the whole set on their own feeds.
Other habits worth adopting:
- Crop out geographic landmarks (street numbers, bar names, signs).
- Avoid photos featuring your children, your colleagues or your car with its licence plate.
- Be wary of photos taken in front of your front door or in your stairwell: they are highly recognisable at city scale.
Metadata: almost a non-issue
Most large platforms strip EXIF data (including GPS coordinates) on upload. But as soon as you send a photo in a private message, by email or via a file transfer service, the metadata can travel with it. On both Android and iOS there are "remove location" options when sharing; get into the habit of using them.
The bio: the game of seven clues
First name + age + specific job + neighbourhood + sports club + dog breed = identity. Each of those items is harmless; together they are not. A simple principle: at most two identifying clues in a public profile. "Sound engineer in Lille" and "trail running on Sundays" are enough to start a conversation, without making you findable.
Settings: the best-spent half hour

Location
Many apps offer an "approximate location" mode or a minimum distance setting. Use them. On iOS, allow approximate location rather than precise; on Android, choose "while using the app" and turn off precise location.
A sensitive point: the "distance" feature makes it possible, by moving around and noting the displayed distances, to pinpoint a position by triangulation. It's a well-known technique, documented by several security researchers for years. If the app lets you hide distance, do it.
The advertising ID
On iOS, decline tracking when the "Allow to track your activity" prompt appears. On Android, delete the advertising ID in your Google settings. This doesn't stop the app from working, but it cuts off part of the cross-referencing between your love life and the rest of your digital life.
The account itself
- Create a dedicated email address for dating, separate from your main address and your work address.
- Don't sign in via a social network: it links two worlds you have every interest in keeping apart.
- Enable two-factor authentication where available, and use a unique password. A password manager makes this hygiene painless, and a physical security key protects your most critical accounts.
- Check your notification settings regularly: a lock screen that displays message previews exposes your private life to anyone walking past your phone. A privacy screen filter also limits over-the-shoulder reading on public transport.
The phone number: the real tipping point
This is the riskiest moment in the whole sequence, precisely because it's framed as a simple convenience.
Your mobile number is a near-permanent identifier. It isn't easily changed, it's tied to your contract, your bank, your online accounts, and it serves as a matching key in just about every commercial database. Giving it to a stranger means opening the front door to your digital identity.
The recommended stages
- Stay inside the app until you have met the person. It's less convenient, but blocking there is immediate and one-sided.
- If you want to move off the app, use an encrypted messenger with a username rather than your personal number. Signal lets you use a username without revealing your number; other messengers also work by handle.
- If an SMS channel is genuinely necessary — confirming a venue, warning about being late, cancelling at the last minute — a one-off message with a masked sender avoids handing over your personal line for a two-line note. That's exactly the use case where an anonymous SMS service makes sense: a piece of practical information delivered, no lasting identifier disclosed.
- A second line (a prepaid SIM or a second plan on a dual-SIM phone) remains the most comfortable solution for anyone who dates a lot. An entry-level dual-SIM phone does the job nicely, and you can abandon that number with no consequences the day it becomes a nuisance.
Warning sign: someone who pushes hard for your number, your surname or your address before any meeting isn't after convenience. They're after data.
The first date: physical safety and discretion

Privacy isn't only a matter of bytes. The classic recommendations remain the best ones:
- Public place, reasonable time, your own transport. Don't accept a lift home on a first date, and don't give out your address even "just for the GPS."
- Tell someone: place, time, first name, and an end-of-evening check-in message agreed in advance.
- Never leave your drink unattended. Drink-spiking test strips, sold in pharmacies and online, are not foolproof but cost little and provide reassurance. Public health bodies and prevention campaigns mainly stress the basic rule: sudden, unexplained dizziness or discomfort justifies alerting the venue's staff immediately.
- Don't share your live location with the person you're meeting. Share it instead with someone close to you, for a limited period.
- Avoid connecting to the venue's public wifi with sensitive accounts; your phone's hotspot is safer. A compact power bank saves you from having to rush home because your phone is at 4%.
When things go wrong
Image-based blackmail (sextortion)
The playbook is well established: a fast-moving conversation, a switch to video, encouragement to undress, recording, then a demand for money under threat of sending it to your contacts. The official platform cybermalveillance.gouv.fr and the PHAROS service (internet-signalement.gouv.fr) document exactly what to do.
The rules:
- Never pay. Payment only opens the door to a series of further demands.
- Keep the evidence: screenshots, usernames, account IDs, the bank details requested.
- Report to the platform, then to PHAROS, and file a complaint. The French Interior Ministry's website allows an online pre-complaint.
- 17 cyber and 3018 (online harassment, free of charge) offer immediate assistance.
Sharing images without consent
Sharing a sexual image without the person's consent is a criminal offence in France (Article 226-2-1 of the Penal Code), punishable by imprisonment and a fine — including when the image was taken with the person's consent. Platforms are obliged to promptly remove such reported content.
Harassment after cutting contact
Block on every channel, lock down your public accounts, and document every message in a dated file. If messages continue despite the blocks, moral harassment and identity theft are criminal offences. A paper notebook for keeping a log of events remains, however odd that may sound, a very useful item when you need to reconstruct a timeline for an investigator.
Parting ways: cleaning up behind you
People rarely think about the exit. Yet that's where the data stays.
Account closure checklist
- Delete the account from within the app (not just uninstall it).
- Check for the deletion confirmation email and keep it.
- Send a GDPR access request a month later to check what remains.
- If the subscription was paid, cancel it separately on the App Store or Google Play: deleting the account doesn't stop the billing.
- Remove the app from the list of services connected to your Google/Apple/Facebook account.
- Delete sensitive conversations in third-party messengers, on both sides where possible.
- Run a reverse image search on your old profile photos, to spot any reuse.
If you're refused or get no reply within a month, filing an online complaint with the CNIL is free and takes ten minutes. The CNIL noted in 2025 that complaint volumes had reached record levels: individual reports genuinely weigh on which investigations it chooses to pursue.
Recap: the staged-disclosure rule
| Stage | What you give | What you don't give yet |
|---|---|---|
| Public profile | First name, age, two interests, previously unpublished photos | Surname, employer, precise neighbourhood, social media |
| Conversation in the app | Tastes, availability, city | Number, main email address, intimate photos |
| Moving off the app | Handle on an encrypted messenger or a one-off masked message | Personal mobile number |
| First date | First name, real appearance, public venue | Address, route home, live location |
| After several dates | Number, surname, life context | Account access, passwords, identity documents |
Conclusion: trust is given, not pre-filled
Meeting someone requires showing yourself. That isn't at odds with protecting your privacy: it's a question of pacing. The apps, for their part, push for immediate disclosure, because their business model rests on the volume of information and the time you spend there. Nothing obliges you to follow that tempo.
The right question isn't "do I have something to hide?" but "what will this piece of information allow someone to do in six months, if the relationship goes sour or the database leaks?" A first name allows nothing. A mobile number allows a great deal. An address allows everything.
Keep to yourself what is irreversible, give generously what is revocable — and give the other person time to earn the rest.



