Coffee Meets Bagel
- Introductory paragraph is something about an incident, not info about the company.
- Random "Background" section for no apparent reason.
Common issues include not following the correct preload outline (incident, company, product), references that don't use <ref></ref> or Cite web, leftover "WIP" markers, or long quotes not wrapped in Quote. You can help by applying the relevant preload sections, converting raw URLs into proper citations, and removing editor notes.
| Basic information | |
|---|---|
| Founded | |
| Legal Structure | Private |
| Industry | Online dating |
| Also known as | |
| Official website | https://coffeemeetsbagel.com/ |
Coffee Meets Bagel's Google Play "Data safety" label tells users "No data shared with third parties" for both of its published app builds,[1][2] while the company's own privacy policy states that photo and video verification data is collected by "our third party vendor, Persona, an identity verification company", which "may collect, use, and store scans of your facial geometry."[3] Google's developer documentation defines the "sharing" the label denies as transferring user data to a third party, and excludes transfers to a "service provider" that processes the data on the developer's behalf.[4] Two proposed class actions filed in 2024 under the Illinois Biometric Information Privacy Act, Cajas v. Coffee Meets Bagel, No. 3:24-cv-00144 (N.D. Cal., filed January 8, 2024),[5] and Moller v. Coffee Meets Bagel, No. 1:24-cv-03015 (N.D. Ill., filed April 15, 2024),[6] alleged that CMB scanned users' selfies into facial-geometry templates and disclosed those templates to third-party service providers without the written notice and written release that Illinois law requires.[7][8][9] Both suits terminated within months: Cajas after the plaintiff filed a notice of voluntary dismissal on June 14, 2024,[5] and Moller on July 16, 2024.[6]
Consumer impact summary
[edit | edit source]
Background
[edit | edit source]Coffee Meets Bagel is a dating and social-networking service based in the United States. Google Play distributes it as two separate app builds under two corporate entities: the build with package identifier io.cmbus.app is published by "Coffee Meets Bagel Inc.",[2] and the build with package identifier com.coffeemeetsbagel is published by "COFFEE MEETS BAGEL PTE. LTD."[1]
During account setup, the app runs a photo and video verification step. CMB's privacy policy, last updated September 4, 2025, states that this data "is collected by our third party vendor, Persona, an identity verification company", and that "Persona may collect, use, and store scans of your facial geometry extracted from photos and videos you upload during the verification process."[3] Persona's own Processor Privacy Policy describes its role as a data processor:
Persona acts as a processor (or similar role under applicable law) on behalf of the customer controller who has contracted with us to provide the age assurance or identity verification services.[10]
Persona's policy also states that it may collect "a scan of your facial geometry based on the photos or video you provide" and that "Persona does not sell or share personal data with third parties."[10]
Incidents
[edit | edit source]This is a list of all consumer-protection incidents this company is involved in. Any incidents not mentioned here can be found in the Coffee Meets Bagel category.
Biometric data collection through Persona
[edit | edit source]CMB's privacy policy assigns collection of photo and video verification data to Persona and discloses that Persona may store "scans of your facial geometry."[3] A separate CMB Biometrics Policy, last updated September 4, 2025, defines "biometric information" as "a scan of your facial geometry extracted from photos and videos you upload during the identity verification process."[11] That policy states that CMB "will not permit Persona to disclose your biometric information to any party other than its vendors" absent consent or legal process, and sets a retention cap of "2 years from when you provided the biometric information."[11]

The same privacy policy states that CMB "does not sell personal information to third parties" but "does permit third parties to collect the personal information described above through our service and shares personal information with third parties for business purposes," and lists "Service providers and business partners" among the parties with which it shares.[3] This is a biometric-collection pattern the wiki documents at Walmart, Anker, Lockdown Browser, and the Friend app, in each case tied to the Illinois Biometric Information Privacy Act.
Google Play "Data safety" label
[edit | edit source]Google Play's "Data safety" section for the com.coffeemeetsbagel build states: "No data shared with third parties. The developer says this app doesn't share user data with other companies or organizations," while listing "Photos and videos" and "Personal info" among the data types the app collects.[1] The label for the io.cmbus.app build likewise declares "No data shared with third parties."[2] Both labels are set by the developer and can be edited at any time.

Google's Play Console documentation defines the term the label uses. It states that "'Sharing' refers to transferring user data collected from your app to a third party," and that "the following types of data transfers do not need to be disclosed as 'sharing': Service providers," meaning "an entity that processes user data on behalf of the developer and based on the developer's instructions."[4] Persona describes itself as exactly such a processor, acting "on behalf of the customer controller."[10] CMB's privacy policy, by contrast, discloses that Persona collects users' facial-geometry scans during verification.[3]
Illinois BIPA class actions
[edit | edit source]The Illinois Biometric Information Privacy Act, 740 ILCS 14/, defines a "biometric identifier" to include a "scan of hand or face geometry."[9] Under Section 15(b), no private entity may collect a person's biometric identifier unless it first "informs the subject ... in writing" that the identifier is being collected, informs them of the specific purpose and length of term, and "receives a written release."[9] Section 15(a) requires a written, publicly available retention and destruction schedule, and Section 15(d) bars disclosure of a biometric identifier without consent.[9] The statute creates a private right of action with liquidated damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless violation, plus attorneys' fees and costs.[9] Its current codified text reflects Public Act 103-769, effective August 2, 2024.[9]

In Cajas v. Coffee Meets Bagel, Inc., No. 3:24-cv-00144, filed January 8, 2024 in the U.S. District Court for the Northern District of California before Judge Vince Chhabria, an Illinois resident alleged that the app asks a new user to upload a selfie, then "scans the photograph to create a 'biometric template' of the user's face," and that CMB shared "thousands" of face templates belonging to Illinois residents with "third-party service providers" without authorization.[8] The plaintiff filed a notice of voluntary dismissal on June 14, 2024, and the case was terminated June 17, 2024.[5]
In Moller v. Coffee Meets Bagel, Inc., No. 1:24-cv-03015, filed April 15, 2024 in the U.S. District Court for the Northern District of Illinois before Judge Jorge L. Alonso, plaintiff Kayla Moller pleaded three BIPA counts: Section 15(a) for the absence of a public retention schedule, Section 15(b) for collection without written notice and a written release, and Section 15(d) for disclosure to third parties.[7][6] The complaint alleges:
Crucially, CMB scans the "selfie" photographs that users like Plaintiff provided and uploaded, creates a biometric template of the user's face, and compares the user's facial biometrics to the photographs which the user is posting in their online profile to verify the identity of all CMB users.[7]

Bloomberg Law reported that the complaint alleged CMB collected members' biometric information when they uploaded selfies during sign-up and "provided the information to a third-party identity-verification provider, Persona Identities Inc."[12] The complaint seeks statutory damages of $5,000 for each intentional or reckless violation, or alternatively $1,000 for each negligent violation, under 740 ILCS 14/20.[7] The case was terminated July 16, 2024.[6]
August 2023 data-deletion attack
[edit | edit source]In August 2023, Coffee Meets Bagel suffered a worldwide outage that the company later attributed to a destructive cyberattack. In an outage FAQ quoted by BleepingComputer, CMB said the outage "was the result of an outside actor who maliciously deleted company data and files" and that it had notified law enforcement.[13] The company said service was restored on September 3, 2023.[13]
Refund process
[edit | edit source]The cancellation window for the service is 14 days in EU, EEA, UK, and Switzerland, and 72 hours in the states of Arizona, California, Connecticut, Illinois, Iowa, Minnesota, New York, North Carolina, Ohio and Wisconsin, as outlined in sections 8 and 20 of the terms of service (TOS).[14] Customers in other states are not eligible for refund.[14] The process for cancellation regardless of region includes either going through the subscription provider (Apple) or mailing a signed notice to the company's mailing address.[14] California and Ohio users are given the option to open a ticket through an online portal.[14]
-
Portion of section 20 of Coffee Meets Bagel TOS, cancellation process
-
Portion of section 8 of Coffee Meets Bagel TOS, general cancellation policy
-
Portion of section 8 of Coffee Meets Bagel TOS, cancellation policy in EU and specific regions
Forced arbitration
[edit | edit source]Section 19 of Coffee Meets Bagel's Terms of Use states that the user, by accepting the terms of service, waives their right to litigation.[14] In particular, the terms of service prohibit customers' from participation in any kind of class action and limits claims to the customers' individual capacity. In addition, before any action the terms of service stipulate that a pre-demand notice be physically mailed to Coffee Meets Bagel offices that has to meet certain criteria.
-
Portion of section 19 of Coffee Meets Bagel TOS, class action waiver
-
Portion of section 19 of Coffee Meets Bagel TOS, pre-demand notice
See also
[edit | edit source]References
[edit | edit source]- ↑ 1.0 1.1 1.2 1.3 "Coffee Meets Bagel Dating App - Data safety". Google. Archived from the original on 16 Aug 2026. Retrieved 18 Aug 2026.
- ↑ 2.0 2.1 2.2 "Coffee Meets Bagel: Dating App - Data safety". Google. Archived from the original on 19 Aug 2026. Retrieved 16 Aug 2026.
- ↑ 3.0 3.1 3.2 3.3 3.4 3.5 "Privacy policy". Coffee Meets Bagel. 4 Sep 2025. Archived from the original on 19 Aug 2026. Retrieved 16 Aug 2026.
- ↑ 4.0 4.1 "Provide information for Google Play's Data safety section". Google. Archived from the original on 13 Aug 2026. Retrieved 16 Aug 2026.
- ↑ 5.0 5.1 5.2 "Cajas v. Coffee Meets Bagel, Inc. (3:24-cv-00144)". Court Listener. 8 Jan 2024. Archived from the original on 19 Aug 2026. Retrieved 19 Aug 2026.
- ↑ 6.0 6.1 6.2 6.3 "Moller v. Coffee Meets Bagel, Inc. (1:24-cv-03015)". Court Listener. 16 Jul 2024. Archived from the original on 19 Aug 2026. Retrieved 19 Aug 2026.
- ↑ 7.0 7.1 7.2 7.3 7.4 Foote, Mielke, Chavez & O'Neil, LLC; Audet & Partners, LLP (15 Apr 2024). "Class Action Complaint, Moller v. Coffee Meets Bagel, Inc" (PDF). TruthInAdvertising.org. Archived (PDF) from the original on 19 Jun 2025. Retrieved 16 Aug 2026.
{{cite web}}: CS1 maint: multiple names: authors list (link) - ↑ 8.0 8.1 Mehorter, Kelly (12 Jan 2024). "Coffee Meets Bagel Collects, Shares Illinois Users' Facial Geometries Without Consent, Class Action Alleges". ClassAction.org. Archived from the original on 21 Apr 2026. Retrieved 16 Aug 2026.
- ↑ 9.0 9.1 9.2 9.3 9.4 9.5 9.6 "Biometric Information Privacy Act, 740 ILCS 14/". Illinois General Assembly. Archived from the original on 19 Aug 2026. Retrieved 19 Aug 2026.
- ↑ 10.0 10.1 10.2 "Processor Privacy Policy". Persona. 9 Apr 2026. Archived from the original on 10 Aug 2026. Retrieved 16 Aug 2026.
- ↑ 11.0 11.1 "Biometrics Policy". Coffee Meets Bagel. 4 Sep 2026. Archived from the original on 19 Aug 2026. Retrieved 16 Aug 2026.
- ↑ Brown, Christopher (16 Apr 2026). "Coffee Meets Bagel Hit With Biometric Lawsuit Over User Selfies". Bloomberg Law. Archived from the original on 19 Aug 2026. Retrieved 19 Aug 2026.
- ↑ 13.0 13.1 Abrams, Lawrence (5 Sep 2023). "Coffee Meets Bagel says recent outage caused by destructive cyberattack". BleepingComputer. Archived from the original on 6 Sep 2023. Retrieved 16 Aug 2026.
- ↑ 14.0 14.1 14.2 14.3 14.4 "Coffee Meets Bagel Terms of service". Coffee Meets Bagel. 2 Mar 2026. Archived from the original on 19 Aug 2026. Retrieved 18 Aug 2026.