Dating apps

Age verification requirements for dating apps: USA

· 8 min read

Applies to
Dating apps distributed to US users through the Apple App Store or Google Play
In force
COPPA amendments since 22 April 2026; California's age signal operative 1 January 2027
What to do
Request the platform age signal and act on it; keep age-check data for age checking only, and delete it

On 27 June 2025 the Supreme Court upheld a Texas age verification law in a single line: House Bill 1181 "triggers, and survives, review under intermediate scrutiny because it only incidentally burdens the protected speech of adults." Free Speech Coalition v. Paxton says nothing about dating apps, and the Texas statute it upheld does not reach them. It is still the most consequential thing that has happened to age verification for a US dating product.

The reason is that in the United States the binding constraint on age verification has never been a regulator. It has been the First Amendment. Before Paxton, states writing age checks into law were drafting against an uncertain standard of review. After it, they have a workable one — and the laws that followed are not aimed at pornography. They are aimed at the app store, which is where every dating app lives.

Start with what does not apply

There is no federal statute requiring a dating app to verify the age of its users. There is no federal online safety regulator of the kind the UK has in Ofcom, and no horizontal duty of the kind the EU wrote into Article 28 of the Digital Services Act. Compliance is assembled from state law, one constitutional question, and a single federal privacy rule.

The state age verification laws that get the headlines do not catch dating apps either, and the reason is worth reading in the text. Texas HB 1181, the statute upheld in Paxton, applies to a commercial entity publishing or distributing material on a website or other platform "more than one-third of which is sexual material harmful to minors." That one-third threshold is replicated across the wave of state laws that followed it. A dating app with moderated profile photos does not cross it, and no amount of user-generated intimacy in private messages changes what fraction of the published material qualifies.

So the porn age verification wave misses dating apps almost entirely. What does not miss them is the thing built next.

The layer that will actually bind

Two statutes show the shape of it, and neither has the word "dating" in it.

Texas SB 2420, which by its own terms "takes effect January 1, 2026", puts age verification and parental consent duties on app stores and on the developers who distribute through them. Utah enacted a comparable App Store Accountability Act in its 2025 session. Several other states have since passed statutes on the same model.

California took the more interesting route. The Digital Age Assurance Act, chaptered in October 2025, does not ask the app to check anything. It requires the operating system provider to hold the age information and hand the developer an age bracket signal — "nonpersonally identifiable data derived from a user's birth date or age" indicating, at minimum, whether the user is under 13, at least 13 and under 16, at least 16 and under 18, or at least 18. The Act becomes operative on 1 January 2027. For applications already installed, a developer that has not requested a signal must request one before 1 July 2027.

Read that as a product requirement rather than a compliance one. The question a Californian regulator will ask a dating app is not what document it scanned. It is whether the app requested the signal and what it did with the answer. The identity work moves to Apple and Google; the obligation to act on the result stays with the developer.

Two cautions. These statutes are the most actively litigated in the field, and their effective dates have already moved more than once — check the current posture of any specific date before building a schedule on it. And the Paxton standard does not automatically carry over to them. The Court's reasoning was about material obscene to minors, not about age limits in general, so the constitutional question for an app store law is genuinely open in a way the question for a porn site law no longer is.

The federal rule, and the catch-22 it created

The one federal statute in play is the Children's Online Privacy Protection Rule, 16 CFR Part 312, which governs personal information collected from children under 13. The FTC's amended Rule was published on 22 April 2025, took effect that June, and reached its compliance date on 22 April 2026. Among the amendments: biometric identifiers are now personal information.

That amendment and age verification collide directly. Facial age estimation produces a face template. Running it on an unknown visitor to determine whether they are a child means processing a biometric identifier belonging to someone who may be a child, without the verifiable parental consent COPPA requires — and you cannot obtain the consent first, because you do not yet know you need it. The most privacy-preserving age check available was also the one most likely to create liability.

The FTC addressed this on 25 February 2026 with an enforcement policy statement promoting the adoption of age verification technology. The Commission said it will not bring a COPPA enforcement action against operators that collect, use and disclose personal information for the sole purpose of determining a user's age, on conditions: the service must be general audience or mixed audience rather than child-directed; the information must be used for nothing but the age determination; it must be reasonably secured; it must be deleted once the check concludes; and the operator must be complying with COPPA in every other respect.

This is enforcement discretion, not a rule change — the Rule still says what it said, and the statement can be withdrawn. But its conditions are a usable specification, and they happen to describe good engineering: single purpose, short retention, no secondary use. A dating app that stores age check artefacts in the same place it stores profile data has forfeited the discretion before anyone asks.

Where the states diverge, and where they do not

State legislatures have written statutes specifically about dating services. They chose not to make them about age.

New Jersey's Internet Dating Safety Act, N.J.S.A. 56:8-168 to 56:8-174, is a disclosure regime. A service that does not conduct criminal background screenings must say so, clearly and conspicuously, to its New Jersey members, in at least two of several prescribed placements.

Colorado's SB 24-011, signed 5 June 2024 and effective 7 August 2024, goes further and is the closest thing to a dating-specific age rule in the country. It requires an online dating service to maintain a safety policy, and that policy must explain the service's identity and age verification practices. The service must post the policy, submit its URL to the Attorney General's office, and file an annual report on member safety and compliance from 31 January 2026. A missing or non-compliant policy is a deceptive trade practice.

Note what Colorado does and does not do. It does not tell a dating app how to check age, or that it must. It requires the app to describe its practice, in public, to the state's chief law enforcement officer, annually. That is a different enforcement theory: not a technical mandate but a documented representation, which a consumer protection statute can then be used against if it turns out to be untrue. For a company operating in all fifty states, the practical effect is that the weakest link is a claim you made about your own age check rather than the check itself.

What this looks like in practice

  • Do not build for the porn statutes. The one-third threshold means they are not aimed at you, and designing to them wastes the effort.
  • Build to consume a platform age signal. California's brackets — under 13, 13–16, 16–18, 18+ — are the interface the industry is converging on, and requesting the signal is itself a legal duty there from 2027.
  • Keep age check data in a single-purpose store with automatic deletion. That is the condition of the FTC's enforcement discretion, and it is the difference between a check and a liability.
  • Treat any public statement about your age verification practice as enforceable. In Colorado it is filed with the Attorney General.
  • Track effective dates rather than memorising them. The app store statutes have moved repeatedly under active litigation.

The UK gave dating apps a regulator, and the EU gave them a duty. The US is giving them an API — written for app stores, enforced through privacy and consumer protection law, and arriving whether or not any statute ever says the word "dating."

ProofAge for Dating Apps — Stop Fake Profiles Before They Kill Trust

ProofAge helps dating platforms reduce fake profiles, speed up review, and verify real users — without the heavy friction of enterprise KYC.

See how it works