Two data analytics services, Apptimize and Localytics, were identified as third parties with access to the sensitive data.
The claim said a potentially unlimited number of third parties used it to customise advertisements to Grindr’s users.
It followed revelations in 2018 that Grindr had been sharing personal data, including the HIV status of its users, with the two data analytics providers.
Grindr defended the practice at the time as in line with industry standards – but it said it then stopped sharing HIV data with those companies.
It was fined £5.5m by Norway’s data protection watchdog and, later in 2022, reprimanded by the UK Information Commissioner’s Office for its data practices.
The company said in its filing on Friday that since 2020, it had “overhauled” its privacy practices to help meet the “unique needs of its community”.
“Grindr is and remains a safe space for users, committed to transparency, user control, and responsible data practices,” it said.