← Back to GRND filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Except as set forth below, there have been no material changes from the risk factors previously disclosed in “Item 1A. Risk Factors” in our Annual Report on Form 10-K for the year ended December 31, 2025. We have revised the risk factors set forth below to reflect additional products we have begun to offer, or expect to offer soon, in connection with our Woodwork telehealth service.
We may not be able to successfully implement our new product and services roadmap, which could adversely impact our business, financial conditions or results of operations.
We are continually evaluating the changing consumer, market, and competitive environment of the community we serve and seeking to improve our performance by implementing a comprehensive and competitive business strategy addressing the needs and wants of our user base. Our product strategy continued to advance in the first half of 2026 and we expect to continue to launch a number of new products and services to some, if not all, users. There is no guarantee that our investment in new products and services, new features, feature innovations, and other initiatives will succeed or generate revenue or other benefits for us. New or innovative products, services, and features may provide temporary increases in engagement that may ultimately fail to attract and retain users over time such that they may not produce the long-term benefits that we expect. We may also introduce new products, services, features, terms of service, or policies and seek to find new, effective ways to show our community new and existing products and services and alert them to events and opportunities to connect that our users do not like. If our new or enhanced brands, products and services, or product extensions fail to engage users or marketing partners, or if our business plans are unsuccessful, we may fail to attract or retain users or to generate sufficient revenue, operating margin, or other value to justify our investments, any of which may materially adversely affect our business.
Entering into new types or lines of business requires significant management attention, may disrupt our existing business, exposes us to new legal and regulatory requirements, and may fail to produce the benefits and synergies we anticipate. Furthermore, assumptions underlying expected financial results or consumer demand and receptivity may not be met or economic or consumer conditions may deteriorate. We also may be unable to engage with partners of choice or engage on terms favorable to us in order to implement our strategic initiatives. Any of our partners may not perform their obligations as expected or may breach or terminate their agreements with us. The failure of our partners to meet their obligations, comply with legal requirements, adequately deploy resources or to satisfactorily resolve disputes with us could have an adverse effect on our business, financial condition or results of operations. If these or other factors limit our ability to successfully execute our strategic initiatives, our business activities, financial condition or results of operations may be adversely affected.
In 2025 we also began offering new products to serve the health and wellness needs of our users and expect to continue to expand these offerings and available products in the future. Products and services in health and wellness, including any new products or services we may offer, may subject us to increased regulation and costly compliance efforts. For additional information on certain of the risks associated with our health and wellness services and products see “—Risks Related to Regulation and Litigation—Compounded drug products and dietary supplements offered through our platform are subject to extensive regulation, which may expose us to fines, penalties, seizures and injunctions under the
43
Table of Contents
Federal Food, Drug, and Cosmetic Act (FDCA) and its implementing regulations.” and “—Risks Related to Regulation and Litigation—We and our partners are subject to extensive federal and state healthcare laws and regulations (in addition to the FDCA and FDA regulations) in the operation of our health and wellness services and may be subject to fines, penalties, and injunctions if we or our partners are found to be in violation of any of such laws and regulations.”
We are subject to laws within and outside of the United States that impose strict requirements for processing personal data and significant penalties for non-compliance. Our actual or perceived failure to comply with such laws has in the past harmed our business, and could continue to harm our business in the future.
In recent years, there has been an increase in attention to and regulation of data protection and data privacy across the globe, including in the United States, the European Union and the United Kingdom. For example, we are subject to the GDPR; the UK GDPR (i.e., the GDPR as it continues to form part of the law of the United Kingdom by virtue of section 3 of the EU (Withdrawal) Act 2018 and subsequently amended); the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”); and the Brazilian General Data Protection Law (“LGPD”). These laws impose strict requirements for processing personal data and impose significant fines for violations. For example, LGPD penalties may include fines of up to 2% of the organization’s revenue in Brazil in the previous year or 50 million reais (approximately $9.3 million U.S. dollars); and, under the GDPR and the UK GDPR, we may be subject to fines of up to €20 million/£17,500,000 or up to 4% of the total worldwide annual group turnover of the preceding financial year (whichever is higher), as well as face claims from individuals based on the GDPR and UK GDPR’s private right of action. Other comprehensive data privacy or data protection laws or regulations have been passed or are under consideration in other jurisdictions, including India and Japan, as well as various U.S. states. Laws such as these give rise to an increasingly complex set of compliance obligations on us, as well as on many of the third parties with whom we work. These obligations include, without limitation, imposing restrictions on our ability to gather personal data, providing individuals with the ability to opt out of certain personal data processing, imposing obligations on our ability to sell or share data with others, and potentially subject us to fines, lawsuits, and regulatory scrutiny, any of which may materially adversely affect our business, financial condition, and results of operations.
The GDPR and the UK GDPR include obligations and restrictions concerning the consent and rights of individuals to whom personal data relates, the transfer of personal data out of the EEA and the United Kingdom, security breach notifications, and the security and confidentiality of personal data more generally, including more stringent requirements for personal data classified as “sensitive.” In addition, individuals have a right to compensation under the GDPR and the UK GDPR for financial or non-financial losses.
To the extent we are determined or alleged to have been or be out of compliance with the GDPR, UK GDPR or e-Privacy legislation, such determination or allegation could materially adversely affect our business, financial condition, and results of operations.
Because we do not have a main establishment in the European Union, we are subject to inquiries from any of the EEA and UK data protection regulators. Over the last few years, we have received and responded to inquiries from the Norwegian Data Protection Authority (“NDPA”), the Spanish Data Protection Authority, the Slovenian Data Protection Authority, the Greek Data Protection Authority, and the Austrian Data Protection Authority, among other non-EU data protection authorities, including the ICO. For example, in February 2026 we paid a NOK 65,000,000 fine (the equivalent of approximately $6,465,000 using the exchange rate as of December 31, 2025) based on a 2021 decision of the NDPA.
These types of proceedings have caused us to incur significant expense, and we have been the subject of negative publicity. The existence of the Norway proceeding and the potential for similar proceedings has negatively impacted, and may again in the future negatively impact, our efforts to retain existing users and add new users and deteriorate our relationships with advertisers and other third parties.
Additionally, we may face class action or similar group litigation in certain European jurisdictions, where legal frameworks and collective redress mechanisms allow large groups of plaintiffs to bring claims against companies for alleged violations of laws or regulations. Although class action lawsuits are less common in Europe compared to the United States, some EU countries have seen a rise in collective actions, particularly in areas like consumer protection, data privacy, and competition law. Notably, the transposition of Directive (EU) 2020/1828 across EU Member States has established or enhanced the framework for collective redress, enabling qualified entities like noyb (the European Center for Digital Rights) to represent groups of plaintiffs in data protection-related claims throughout the European Union. As a result, we could face significant legal and financial exposure, including reputational harm and substantial legal defense costs, even if we ultimately prevail in such actions. Additionally, as the legal and regulatory landscape for collective claims in Europe continues to evolve, our risk of exposure to such litigation may increase in the future. For example, in April 2025 we were served with proceedings in the English High Court, which proceedings were originally issued in April 2024,
44
Table of Contents
brought by a UK law firm on behalf of over 10,000 alleged Grindr users from a period between 2009 and 2020 alleging unlawful processing of their personal data in breach of UK data protection laws and misuse of their private information. The claimants’ legal representatives have asserted that claimants may be entitled to damages of between £1,000 or £10,000, or more. Grindr denies liability.
In addition, the United Kingdom’s exit from the European Union (“Brexit”) and ongoing developments in the United Kingdom could result in the application of new data privacy and protection laws and standards to our activities in the United Kingdom and our handling of personal data of users located in the United Kingdom. The relationship between the United Kingdom and the European Union in relation to certain aspects of data protection law remains unclear, and it is unclear how UK data protection laws and regulations will develop in the medium to longer term. For example, the Data Use and Access Act 2025 introduced certain changes to the UK GDPR, including in relation to the use of cookies for statistical and analytics purposes, and through the introduction of certain “recognised” legitimate interests for which a legitimate interests assessment is not required. As a consequence of Brexit, we are exposed to two parallel regimes (the GDPR and the UK GDPR), each of which potentially authorizes similar, but separate, fines and other potentially divergent enforcement actions for the same alleged violations.
In connection with the operation of our Woodwork business we have partnered with third parties and process health-related information on their behalf and are thus subject to the federal Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health Act, and its implementing regulations (collectively, “HIPAA”) and other applicable U.S. health data protection and privacy laws. If we fail to comply with applicable laws or experience a data breach or other security incident, we could be subject to claims, investigations, enforcement actions, or litigation. If insurance coverage or the contractual indemnification we have is insufficient to satisfy claims made against us, the claims could have an adverse effect on our business and financial condition.
Moreover, we may become subject to stringent data localization or transfer requirements, particularly for any data transfer from Europe and other jurisdictions to the United States or other countries, and we may be required to review and amend the legal mechanisms by which we make available or transfer personal data with third parties. As supervisory authorities issue further guidance on data export mechanisms, we could suffer additional costs, complaints, and/or regulatory investigations or fines if our compliance efforts are not deemed sufficient. In addition, if we are unable to transfer personal data between and among countries, it could affect the manner in which we provide our products and services or the location or segregation of our systems and operations, and adversely affect our financial results. In the event any court blocks direct collection of personal data or personal data transfers to or from a particular jurisdiction, this could give rise to operational interruption in the performance of services for customers, greater costs to implement permissible alternative data transfer mechanisms, regulatory liabilities, or reputational harm and negative publicity. Failure to comply with the evolving interpretation of data privacy and data protection laws could subject us to liability, and to the extent that we need to alter our business model or practices to adapt to these obligations, or to respond to further inquiries regarding our compliance with privacy and data protection laws, we could incur additional and significant expenses, which may in turn materially adversely affect our business, financial condition, and results of operations. Additionally, the U.S. Department of Justice issued a rule entitled the Preventing Access to U.S. Sensitive Personal Data and Government-Related Data by Countries of Concern or Covered Persons, which places additional restriction on certain data transactions involving countries of concern (e.g., China, Russia, Iran) and covered persons (i.e., individuals and entities who are designated as such by the U.S. Attorney General or considered “foreign persons” and are majority owned by, organized under the laws of, a primary resident in, or a contractor of, a covered person or country of concern, as applicable) that may impact certain business activities such as vendor engagements, sale or sharing of data, employment of certain individuals, and investor agreements. Violations of the rule could lead to significant civil and criminal fines and penalties. The rule applies regardless of whether data is anonymized, key-coded, pseudonymized, de-identified or encrypted, and may impact our ability to engage in certain transactions or agreements.
Compounded drug products and dietary supplements offered through our platform are subject to extensive regulation, which may expose us to fines, penalties, seizures and injunctions under the Federal Food, Drug, and Cosmetic Act (FDCA) and its implementing regulations.
In May 2025 we launched Woodwork by Grindr, a telehealth service that facilitates access to health care professionals employed by our partners who may, for eligible patients, make treatments available and prescribe certain medications, including, but not limited to, controlled substances and compounded medications, for erectile dysfunction, weight loss, low testosterone, vitality, muscle gain, and energy, through third-party pharmacy partners. Certain of these products are compounded drug products under Section 503A of the FDCA, which provides for certain FDA exemptions, including those that require premarket approval and labeling that bears with adequate directions for use. To market our products under these exemptions, we must comply with all Section 503A requirements.
45
Table of Contents
Section 503A permits compounding by a licensed pharmacist or physician of a drug that is not “essentially a copy” of a commercially available FDA-approved drug based on the receipt of a valid prescription for an individual patient. 503A pharmacies are not subject to cGMP requirements. Compounding under 503A is primarily regulated by state pharmacy laws and regulations governing pharmacy operations. These laws and regulations often include specific requirements for compounding operations, including requirements for licensing of pharmacists, pharmacy technicians, and pharmacies; supervision and training; inspections; sterility assurance; and recordkeeping, among other requirements. Regulations are updated periodically, generally under the jurisdiction of individual state boards of pharmacy. Failure to comply with the state pharmacy regulations of a particular state could result in a pharmacy being prohibited from operating in that state, financial penalties, and/or becoming subject to additional oversight from that state’s board of pharmacy. In addition, many states are considering imposing, or have already begun to impose, more stringent requirements on compounding operations. If insurance coverage or contractual indemnification we have is insufficient to satisfy claims made against us, the claims could have an adverse effect on our business and financial condition.
Compounding pharmacies subject to Section 503A of the FDCA and outsourcing facilities subject to Section 503B of the FDCA have recently been subject to increased scrutiny of their compounding activities by the FDA and state regulatory agencies. A governmental inquiry or action or litigation could be brought against us, our third-party telehealth provider, or the dispensing compounding pharmacy. In such a case, we may experience negative publicity and reputational harm, and additional expense required to respond to the injury, action, or litigation. Manufacturers of FDA-approved GLP-1 medications have brought private actions against compounders and outsourcing facilities, as well as prescribers of compounded medications, including against med-spas, medical practices, and telehealth providers. Similar litigation could be filed against us. Additionally, many FDA-approved GLP-1 medications have protected intellectual property, for example, related to their formulations and methods of use that other parties may use. The parties that own this intellectual property may file claims against us for infringement and other claims relating to their intellectual property, which could result in adverse judgments including fines or equitable relief, and adversely affect our ability to effectively compete.
While we believe the compounded drug products available through our platform satisfy Section 503A of the FDCA, and therefore are exempted from many regulatory requirements, if the FDA were to determine that such drugs do not satisfy Section 503A, FDA would have to approve a new drug application for the drugs currently dispensed by the 503A facility before they could be lawfully sold or otherwise distributed in interstate commerce. Failure to comply with Section 503A or obtain FDA approval to market the drugs could result in an enforcement action, including injunction, seizure, civil fine, and criminal penalties, or the issuance of an FDA warning or untitled letter. Other federal and state enforcement authorities might also take action against us if they determine that compounded drug products available through our platform or the advertisements or promotional activities of such products do not meet applicable legal or regulatory requirements.
The FDA or other federal, state, or foreign enforcement authorities may also take action if they determine our health and wellness services, related products, and promotional activities do not meet applicable legal requirements. For example, as part of the Make America Healthy Again (MAHA) Commission’s Strategy Report, the current Administration signaled an initiative to tighten controls over direct-to-consumer pharmaceutical advertising, with a particular focus on social media and digital platforms. In September 2025, the FDA announced that it had dispatched thousands of letters warning pharmaceutical companies to remove misleading ads, and in March 2026, the FDA announced the issuance of 30 warning letters to telehealth companies for making false or misleading claims regarding compounded GLP-1 products on their websites. Moreover, in February 2026, the FDA issued a statement indicating that the agency intends to restrict GLP-1 active pharmaceutical ingredients intended for use in non-FDA-approved compounded drugs that are being mass-marketed as similar alternatives to FDA-approved drugs.
In addition, Woodwork markets dietary supplements, which are subject to regulation by the FDA under the FDCA, as amended by the Dietary Supplement Health and Education Act of 1994 (“DSHEA”), and the regulations promulgated thereunder. These laws and regulations govern, among other things, product formulation, manufacturing, labeling, packaging, storage, distribution, marketing claims, and recordkeeping. Although DSHEA permits dietary supplements to make certain substantiated structure/function claims, dietary supplements generally may not be marketed with claims to diagnose, mitigate, treat, cure, or prevent disease without being regulated as drugs. FDA regulations applicable to dietary supplements also impose cGMP requirements intended to ensure the quality of dietary supplements and the accuracy of their labeling. Regulatory or enforcement actions by the FDA or other federal or state authorities could harm our reputation and have a material adverse effect on our business, financial condition, and results of operations. Further, the Administration’s enforcement priorities and policies under the FDCA and its implementing regulations are subject to change at any time. Shifts in these policies and any resulting regulatory or enforcement actions by federal or state agencies could adversely affect our business, financial condition, and results of operations.
46
Table of Contents
We and our partners are subject to extensive federal and state healthcare laws and regulations (in addition to the FDCA and FDA regulations) in the operation of our health and wellness services and may be subject to fines, penalties, and injunctions if we or our partners are found to be in violation of any of such laws and regulations.
The products and services we offer in connection with Woodwork currently and may in the future offer as we expand our health and wellness initiative and our arrangements with third-parties in carrying out these services expose us to broadly applicable federal and state fraud and abuse and other healthcare laws and regulations, including anti-kickback, self-referral, health information privacy and security, state corporate practice of medicine, fee-splitting, and professional licensing restrictions and standards.
In certain jurisdictions, the corporate practice of medicine (“CPOM”) doctrine generally prohibits non-physicians from practicing medicine, employing physicians to provide clinical services, or otherwise exercising undue influence or control over medical decisions of physicians, among other things. Many states also limit the extent to which nurse practitioners and physician assistants can practice independently. Additionally, the practice of medicine is subject to various federal, state, and local certification and licensing laws, regulations, approvals and standards, relating to, among other things, the qualifications of the provider, the practice of medicine (including specific requirements when providing health care utilizing telehealth technologies and the provision of remote care), the continuity and adequacy of medical care, the maintenance of medical records, the supervision of personnel, and the prerequisites for prescribing medication and ordering of tests.
Through our Woodwork business, we are now associated with, and may in the future become associated with, third-party telehealth providers or equivalent entities (“Affiliated Telehealth Providers”), including OpenLoop. We are dependent on our relationships with Affiliated Telehealth Providers, which we do not own or control, and our business would be adversely affected if those relationships were disrupted. We and the Affiliated Telehealth Providers may suffer losses or reputational harm from medical malpractice liability, professional liability or other claims against the healthcare professionals employed by, or contracting with, Affiliated Telehealth Providers. Affiliated Telehealth Providers may provide inappropriate medical treatment, fail to follow procedures or guidelines, engage in services outside the scope of their practice, or engage in unprofessional conduct or other activities that could lead to claims, significant defense costs, reputational harm, negative publicity, increased scrutiny by regulators and payors, or other risks, which may adversely affect our business. We and/or the Affiliated Telehealth Providers may be unable to obtain or maintain adequate insurance against these claims. Healthcare professionals providing telehealth services have become subject to a number of lawsuits alleging malpractice and some of these lawsuits may involve large claims and significant defense costs. It is possible that these claims could also be asserted against us and potential litigation may include us as an additional defendant. Any suits against us, or Affiliated Telehealth Providers, if successful, could result in substantial damage awards to the claimants that may exceed the limits of any applicable insurance coverage. Although we do not control the practice of telehealth by the Affiliated Telehealth Providers, it could be asserted that we should be held liable for malpractice of a healthcare professional employed or contracted by a Affiliated Telehealth Providers.
In addition, regulation of telehealth is evolving, and the application, interpretation and enforcement of laws, regulations and standards with respect to telehealth can be uncertain or uneven. Further, any compensation arrangement with our healthcare partners must be structured to comply with applicable state anti-kickback and self-referral restrictions. At present time, we offer any health and wellness services as cash-pay only. To the extent that we expand our health and wellness offerings to include reimbursement from third-party payors, we may become subject to additional federal and state healthcare laws, such as the federal Anti-Kickback Statute. It is possible that governmental authorities will conclude that our business practices may not comply with current or future healthcare statutes, regulations or related case law. If our operations are found to be in violation of any of these laws or regulations, we could be required to curtail or restructure our operations, and we could be subject to significant regulatory and/or legal enforcement actions, including injunctions, seizures, imprisonment, disgorgement, exclusion from participation in healthcare programs, additional reporting obligations and oversight obligations, civil fines, and criminal penalties.
Any regulatory or legal enforcement actions by federal or state enforcement authorities against us or our partners could harm our reputation and have a material adverse effect on our and our partners’ business, financial condition, and results of operations. Further, these healthcare laws are subject to change at any time. Any changes in these laws may adversely affect our and our partners’ business, financial condition, and results of operations.
47
Table of Contents