In August 2025, security flaws in the TeaOnHer app exposed sensitive account information, including email addresses, usernames, self-reported locations, driver’s license images, and verification selfies. The data was accessible through an improperly protected backend API, while some identity documents were stored at publicly accessible web addresses.
The technical flaws were later reported fixed, but the story did not end with the initial exposure. Apple removed TeaOnHer from the App Store in October 2025; the app and its services were later discontinued, and U.S. lawmakers expanded an investigation into the platform and a related service in February 2026.
For former users, the key issue is not whether the app can still be downloaded. It is whether information shared during identity verification could be misused later.
What Happened in the TeaOnHer Data Leak?
TeaOnHer was launched as a social app where men could post photos and information about women they said they had dated. It arrived during the rapid rise of Tea, a separate app marketed toward women.
On August 6, 2025, TechCrunch reported that TeaOnHer’s backend exposed private user information. Some API requests did not require authentication, allowing records to be returned without a password or account login.
The report said the exposed database contained about 53,000 users at that time. That number describes the app’s user count visible through the flaw; it should not be interpreted as proof that every record was downloaded or misused by an attacker.
TechCrunch also found an email address and plaintext password associated with the developer on the server. The credentials appeared related to an administrative panel, although the publication did not try to use them.
What Information Was Exposed?
The accessible records reportedly included:
- Usernames and display names
- Email addresses
- Self-reported ages and locations
- Driver’s licenses or other government-issued ID images
- Selfies submitted for identity verification
- Links connecting account records to identity documents
This combination is more sensitive than an email-address leak alone. An ID image can contain a person’s full name, date of birth, address, photograph, signature, and license number. Paired with an email address and location, that information can make phishing and identity-fraud attempts more convincing.
The exposure also affected the privacy of people discussed on the platform. Reporting and later congressional scrutiny raised separate questions about images and personal information posted about women and minors, including whether the subjects had consented.
Was the Security Problem Fixed?
In an August 13 technical follow-up, TechCrunch said the flaws it found appeared to have been resolved. The API documentation was taken down, the previous unauthenticated requests stopped working, and public access to uploaded identity documents was restricted.
TeaOnHer’s developer, Xavier Lampkin, later told Business Insider that API documentation had been exposed because of a configuration error and said the issue was fixed shortly after notification. He also claimed TechCrunch was the only party to access the data during that window.
That claim does not establish that no one else viewed or collected the information. TechCrunch reported that the developer would not say whether server logs could determine if other parties had accessed the documents.
The safest conclusion is that the public exposure was confirmed, the reported flaws were later restricted, and the extent of any third-party access remains uncertain.
Why Was TeaOnHer Removed From App Stores?
Apple removed TeaOnHer and Tea from the App Store in October 2025. According to Apple’s statement reported by TechCrunch, the apps failed to meet requirements related to content moderation and user privacy.
Apple also cited a high number of complaints and negative reviews, including complaints involving minors’ personal information.
TeaOnHer was still available on Google Play when Apple acted. However, a February 2026 congressional follow-up letter referred to Google’s later decision to remove TeaOnHer from Google Play. An official TeaOnHer social account subsequently announced that the app and its services had been discontinued.
TeaOnHer’s former users should not confuse the discontinued social app with unrelated websites or similarly named services that may currently appear in search results.
What Did Congress Investigate?
On February 12, 2026, the U.S. House Committee on Oversight and Government Reform expanded its investigation to include TeaOnHer and Trinity Social.
The committee requested records concerning digital-safety procedures, content involving women and minors, app-store removals, data preservation, and the reported migration of TeaOnHer users to Trinity Social.
The committee’s statements represent allegations and investigative concerns, not final court findings.
The development matters to former users because shutting down an app does not automatically answer what happened to stored accounts, uploaded identification documents, posts, or migrated data.
What Should Former TeaOnHer Users Do?
Former users should focus on the information they submitted and respond according to its sensitivity.
- Watch for targeted phishing. Treat unexpected messages about account verification, refunds, app migration, legal claims, or identity protection with caution. Open official websites directly instead of clicking links in unsolicited messages.
- Change reused passwords. The reporting did not say TeaOnHer users’ account passwords were exposed. Still, if you reused the same password on other services, replace it with a unique password and enable multifactor authentication, especially on email and financial accounts.
- Review credit reports and consider a freeze. The Federal Trade Commission explains that a credit freeze is free, does not affect a credit score, and can make it harder for an identity thief to open a new account. U.S. consumers must contact Equifax, Experian, and TransUnion separately to place freezes.
- Consider a fraud alert. A fraud alert tells businesses to take extra steps to verify someone’s identity before opening new credit. Contacting one of the three nationwide credit bureaus is enough to start a standard alert because that bureau must notify the other two.
- Use IdentityTheft.gov if misuse appears. If you find an unfamiliar account, transaction, or another sign of identity theft, report it at IdentityTheft.gov to receive a recovery plan.
- Preserve evidence. Keep screenshots, notices, suspicious emails, dates, and copies of reports. Do not publicly repost exposed IDs or images while documenting the incident.
Replacing a driver’s license is not automatically necessary in every exposure. Requirements and available safeguards vary by state, so affected users should consult their state motor-vehicle agency if a license number appears to be misused.
What This Incident Shows About Identity Verification
Identity checks can reduce fake accounts, but they also create a high-value collection of sensitive documents.
Apps that request government-issued IDs should minimize the data they retain, restrict access, protect storage, maintain useful access logs, and provide clear deletion and incident-response procedures.
Users cannot audit an app’s entire security program before signing up. They can still ask whether an ID is truly necessary, how long it will be stored, who can access it, and how its deletion works.
A new app’s popularity or high app-store ranking is not evidence that its privacy protections have been independently tested.