Jump to content

Coffee Meets Bagel biometric data collection

From Consumer Rights Wiki

The dating app Coffee Meets Bagel scans the selfies users upload during its photo verification step, and its third-party vendor Persona collects scans of their facial geometry from those photos and videos.[1] In 2024, two proposed class actions alleged that the company captured Illinois users' face templates and shared them with third-party service providers without the written notice and written release the Illinois Biometric Information Privacy Act requires.[2][3][4] Both suits ended within months of filing without a ruling on the merits: Cajas v. Coffee Meets Bagel was terminated June 17, 2024,[5] and Moller v. Coffee Meets Bagel was terminated July 16, 2024.[6]

Background

[edit | edit source]

Coffee Meets Bagel is an online dating service that ships two Google Play builds under two corporate entities: io.cmbus.app under "Coffee Meets Bagel Inc.," and com.coffeemeetsbagel under "COFFEE MEETS BAGEL PTE. LTD."[7][8] The app offers a photo and video verification feature that asks a user to upload a selfie so the service can confirm the person's identity. According to the company's privacy policy, this verification data is collected not by Coffee Meets Bagel directly but by an outside vendor. The policy states that the information is collected by "our third party vendor, Persona, an identity verification company."[1] Persona's own processor privacy policy states that Persona "acts as a processor (or similar role under applicable law) on behalf of the customer controller who has contracted with us to provide the age assurance or identity verification services."[9]

Biometric data collection

[edit | edit source]

Coffee Meets Bagel's privacy policy, last updated September 4, 2025, discloses that during identity verification, "Persona may collect, use, and store scans of your facial geometry extracted from photos and videos you upload during the verification process."[1] The company's separate Biometrics Policy defines the "biometric information" at issue as "a scan of your facial geometry extracted from photos and videos you upload during the identity verification process," and sets a retention cap of "2 years from when you provided the biometric information."[10] That policy also states that Coffee Meets Bagel "will not permit Persona to disclose your biometric information to any party other than its vendors" absent consent or legal process.[10] Persona's processor policy separately confirms that it collects "a scan of your facial geometry based on the photos or video you provide."[9]

The company's privacy policy states that Coffee Meets Bagel "does not sell personal information to third parties," but "does permit third parties to collect the personal information described above through our service and shares personal information with third parties for business purposes," and it lists "Service providers and business partners" among the parties with which it shares.[11]

Illinois BIPA class actions

[edit | edit source]

The Illinois Biometric Information Privacy Act defines a "biometric identifier" to include a "scan of hand or face geometry."[4] Under 740 ILCS 14/15(b), no private entity may collect or capture a person's biometric identifier unless it first informs the subject in writing and "receives a written release."[4] Under 740 ILCS 14/15(a), an entity in possession of biometric identifiers must maintain a written, publicly available retention and destruction schedule, and under 740 ILCS 14/15(d) an entity may not disclose or redisclose that data without consent.[4] The statute's private right of action, at 740 ILCS 14/20, provides liquidated damages of $1,000 for a negligent violation and $5,000 for an intentional or reckless violation.[4]

Cajas v. Coffee Meets Bagel

[edit | edit source]

Cajas v. Coffee Meets Bagel, Inc., No. 3:24-cv-00144, was filed January 8, 2024 in the United States District Court for the Northern District of California and assigned to Judge Vince Chhabria.[5] ClassAction.org, reporting on the filing, described the 12-page complaint: when a consumer sets up an account, the app asks them to upload a selfie, and "the app then scans the photograph to create a 'biometric template' of the user's face."[3] The complaint alleged that Coffee Meets Bagel had shared "thousands" of face templates belonging to Illinois residents with "third-party service providers" without authorization.[3] Plaintiff Anthony Cajas filed a notice of voluntary dismissal on June 14, 2024, and the docket was terminated June 17, 2024.[5]

Moller v. Coffee Meets Bagel

[edit | edit source]

Moller v. Coffee Meets Bagel, Inc., No. 1:24-cv-03015, was filed April 15, 2024 in the United States District Court for the Northern District of Illinois and assigned to Judge Jorge L. Alonso.[6] The complaint alleged that the company scans the selfies users upload, "creates a biometric template of the user's face," and compares the face to profile photographs to verify identity.[2] It pleaded three counts under BIPA: 740 ILCS 14/15(a) for the lack of a public retention and destruction schedule, 740 ILCS 14/15(b) for collection without written notice or a written release, and 740 ILCS 14/15(d) for disclosure to third-party service providers without consent.[2] The complaint sought statutory damages of $5,000.00 for each intentional or reckless violation under 740 ILCS 14/20, or $1,000.00 for each negligent violation.[2] Bloomberg Law, reporting the filing, wrote that Coffee Meets Bagel allegedly collected members' biometric information when they uploaded selfies during sign-up and "provided the information to a third-party identity-verification provider, Persona Identities Inc."[12] The docket was terminated July 16, 2024.[6]

Neither suit reached a ruling on the merits of the BIPA allegations. The current privacy policy still describes Persona collecting facial geometry during verification, so the underlying practice continues.[1]

Google Play "Data safety" label

[edit | edit source]

The Google Play "Data safety" section for the com.coffeemeetsbagel build declares "No data shared with third parties" and states that "the developer says this app doesn't share user data with other companies or organizations," while listing "Photos and videos" and "Personal info" among the data types the app collects.[8] The label for the io.cmbus.app build likewise declares "No data shared with third parties."[7] The same company's privacy policy discloses that its vendor Persona collects users' facial geometry during verification.[1]

Google's own developer documentation defines the term "Sharing" as "transferring user data collected from your app to a third party," and states that transfers to a "service provider ... that processes it on behalf of the developer" are among "the following types of data transfers [that] do not need to be disclosed as 'sharing'."[13] Persona describes itself as a processor acting on the customer's behalf,[9] and its processor policy states that "Persona does not sell or share personal data with third parties."[9]

See also

[edit | edit source]

References

[edit | edit source]
  1. 1.0 1.1 1.2 1.3 1.4 Coffee Meets Bagel, Inc. (2025-09-04). "Privacy policy". Coffee Meets Bagel. Retrieved 2026-08-16.
  2. 2.0 2.1 2.2 2.3 Foote, Mielke, Chavez & O'Neil, LLC; Audet & Partners, LLP (2024-04-15). "Class Action Complaint, Moller v. Coffee Meets Bagel, Inc" (PDF). TruthInAdvertising.org. Archived from the original (PDF) on 2026-08-16. Retrieved 2026-08-16.{{cite web}}: CS1 maint: multiple names: authors list (link)
  3. 3.0 3.1 3.2 Kelly Mehorter (2024-01-12). "Coffee Meets Bagel Collects, Shares Illinois Users' Facial Geometries Without Consent, Class Action Alleges". ClassAction.org. Retrieved 2026-08-16.
  4. 4.0 4.1 4.2 4.3 4.4 Illinois General Assembly. "Biometric Information Privacy Act, 740 ILCS 14/". Illinois Compiled Statutes. Retrieved 2026-08-16.
  5. 5.0 5.1 5.2 CourtListener. "Cajas v. Coffee Meets Bagel, Inc. (3:24-cv-00144)". CourtListener. Retrieved 2026-08-16.
  6. 6.0 6.1 6.2 CourtListener. "Moller v. Coffee Meets Bagel, Inc. (1:24-cv-03015)". CourtListener. Retrieved 2026-08-16.
  7. 7.0 7.1 Google Play (2026-08-16). "Coffee Meets Bagel: Dating App - Data safety". Google Play. Retrieved 2026-08-16. {{cite web}}: |author= has generic name (help)
  8. 8.0 8.1 Google Play (2026-08-16). "Coffee Meets Bagel Dating App - Data safety". Google Play. Retrieved 2026-08-16. {{cite web}}: |author= has generic name (help)
  9. 9.0 9.1 9.2 9.3 Persona Identities, Inc. (2026-04-09). "Processor Privacy Policy". Persona. Retrieved 2026-08-16.
  10. 10.0 10.1 Coffee Meets Bagel, Inc. (2025-09-04). "Biometrics Policy". Coffee Meets Bagel. Retrieved 2026-08-16.
  11. Coffee Meets Bagel, Inc. (2025-09-04). "Privacy policy". Coffee Meets Bagel. Retrieved 2026-08-16.
  12. "Coffee Meets Bagel Hit With Biometric Lawsuit Over User Selfies". Bloomberg Law. 2024-04-16. Retrieved 2026-08-16.
  13. Google. "Provide information for Google Play's Data safety section". Play Console Help. Retrieved 2026-08-16. {{cite web}}: |author= has generic name (help)