# The dating app that doxxed 72,000 women...

Source: https://www.youtube.com/watch?v=miTpJmMt7uo
Recap page: https://rapidrecap.app/video/miTpJmMt7uo
Generated: 2025-08-28T10:33:27.639+00:00

---
## Quick Overview

A data breach exposed over 72,000 selfies and driver's licenses from the dating app "Tea," with the data being uploaded to a public Firebase storage bucket and later leaked on 4chan, leading to the creation of a website that ranks users based on their appearance.

**Key Points:**
- The dating app "Tea" suffered a major data breach, exposing approximately 72,000 images, including 13,000 selfies and photo IDs submitted for age verification.
- This sensitive data was stored in a public Firebase storage bucket, making it accessible to anyone who found the link.
- The compromised data was leaked on 4chan, leading to the creation of a website that ranks "Tea" users based on their appearance, with some data even being used to create AI girlfriend chatbots.
- The breach occurred due to a legacy data storage system that was not properly secured, allowing unauthorized access.
- The app's privacy policy stated that selfies would be deleted after verification, but this was not followed.
- The founder of "Tea," Sean Cook, has a background in software engineering and previously worked on dating safety tools.

![Screenshot at 00:17: The video displays screenshots of the "Tea" app interface, showing user profiles and a "Background Check" feature that includes convictions and marital status, highlighting the type of personal information users shared.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-00-17.png)

**Context:** The "Tea" app was designed as a dating safety tool for women, allowing them to share information and gossip about men they've dated. To verify users are women, the app required them to upload a selfie with their ID. This video details a significant data breach that compromised this sensitive user information.

## Detailed Analysis

The dating app "Tea," which aimed to provide dating safety tools for women, experienced a massive data breach. The breach exposed over 72,000 images, including approximately 13,000 selfies and driver's licenses submitted by users for age and gender verification. This data was stored in an unsecured public Firebase storage bucket, allowing it to be easily accessed and downloaded. The breach was discovered on July 25, 2025, and the compromised data was subsequently leaked on 4chan. This led to the creation of a website that ranks "Tea" users based on their perceived attractiveness, and some of the leaked data was even used to create AI girlfriend chatbots. The app's privacy policy was misleading, as it claimed to delete user selfies after verification, which was not the case. The vulnerability stemmed from a legacy data storage system that lacked proper security measures. The founder, Sean Cook, has a background in software engineering and previously worked on similar safety-focused applications.

### Data Breach Details

- Exposure of 72,000+ images including selfies and IDs
- Data stored in unsecured public Firebase bucket
- Leaked on 4chan, leading to ranking website and AI chatbots

### App Functionality & Privacy Concerns

- Designed for women's dating safety
- Required selfie with ID for verification
- Misleading privacy policy regarding data deletion

### Security Vulnerability

- Legacy data storage system compromised
- Lack of proper security measures

### Founder's Background

- Sean Cook, software engineer with experience in dating safety tools

### Impact on Users

- Personal data leaked, leading to doxxing and appearance-based ranking

### Legal & Ethical Implications

- Potential violations of privacy laws, misuse of personal data

![Screenshot at 00:17: Screenshots of the "Tea" app interface, showing user profiles and a "Background Check" feature.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-00-17.png)
![Screenshot at 00:34: A collage of driver's licenses with faces blurred out, illustrating the type of personal identification data compromised.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-00-34.png)
![Screenshot at 00:41: A screenshot showing a directory of leaked image files, including selfies and IDs, with filenames visible.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-00-41.png)
![Screenshot at 01:45: A 4chan post detailing the "TEA APP DOXXES ALL" with a link to the leaked data.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-01-45.png)
![Screenshot at 02:26: A screenshot of the "Tea" app's official statement about the breach, highlighting the "NON-APOLOGY CORPO-SPEAK."](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-02-26.png)
![Screenshot at 02:52: A "Tea" app screen showing the selfie verification process with the text "Don't worry, we delete this after."](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-02-52.png)
![Screenshot at 03:12: A graphic illustrating the rising costs associated with AI development and cloud hosting, potentially relating to the misuse of leaked data.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-03-12.png)
![Screenshot at 03:33: A screenshot of the Hostinger website, showcasing various operating system templates for VPS hosting.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-03-33.png)
![Screenshot at 03:44: A Hostinger order summary showing a discount code being applied, indicating a promotional tie-in.](https://ss.rapidrecap.app/screens/miTpJmMt7uo/00-03-44.png)
