Weather, fitness, restaurant apps, and more could all be sharing your whereabouts
If you've ever given a weather or fitness app permission to know where you are, your precise location could be quietly passed along to advertisers and data brokers.
Third-party advertising tools built into Android apps are scooping up location data by default, according to a new report from the Electronic Frontier Foundation (EFF). And the app's developer might not even realise it's happening.
These tools, known as software development kits (SDKs), are bits of pre-built code that developers plug into their apps, typically to serve adverts and earn revenue. The catch? Many of these SDKs come with location data collection switched on from the start, and unless a developer actively turns it off, your whereabouts will get shared automatically.
For example, you might give a local restaurant app permission to know where you are so it can recommend nearby places to eat. However, that same location data could end up being collected by advertising tools running in the background and shared with other companies.
What makes this particularly worrying is where that data ends up. Location histories gathered by the advertising industry have previously been sold to militaries and intelligence agencies like the FBI, and used in immigration enforcement operations in the US.
If a data broker gets hacked, it becomes a security nightmare too. That means criminals could potentially see where people live, work, shop, or travel regularly, increasing the risk of identity theft, scams, stalking, or even physical security threats.
The report says: "App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs."
It continues: "Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person's location."
In practice, when a developer builds an app, they often rely on these SDKs rather than writing their own advertising code from scratch. It saves time and effort, and it gives them ready-made tools to measure ad performance and make money.
But the problem is that once you grant an app permission to access your location, that same permission is automatically inherited by any SDK embedded within it. There are no separate location permissions for SDKs specifically.
The tricky part is that the data-sharing settings aren't obvious. Developers have to actively dig into the SDK's configuration and manually switch off unnecessary collection. If they don't carefully review those settings before releasing their app, sensitive location data gets harvested and shared without the developer realising it.
The EFF's investigation flagged four advertising SDKs that collect and share location data by default — InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads. It's also possible that there are others out there that simply weren't caught.
To get a sense of the scale, two of the apps the EFF analysed had been downloaded a combined 60 million times. Neither app displayed a privacy notice or asked for user consent, and both failed to mention third-party location sharing in their Google Play Store Data Safety sections.
If you want to protect your location on an Android device, there are a few steps you can take.
You will want to first navigate to your phone's Settings, tap Location, then App location permissions. From there, you can go through each app individually and revoke access.
If you'd rather take a blanket approach, you can toggle off Use Location entirely — though that will affect apps like maps and weather where location could be needed to supply the most accurate information.
The EFF warned that developers should also review all third-party SDKs and ensure user data isn't being shared by default.
EFF Staff Technologist Lena Cohen said: "Users can take extra steps to defend their location privacy, but they shouldn't have to. Developers, regulators, and legislators must act to stop apps from leaking users' location data to advertising companies and data brokers."
Senior staff technologist Bill Budington also noted that while the SDKs they examined represent just a fraction of the wider ad ecosystem, they claim to reach billions of users across tens of thousands of apps.






