For many apps, granting permission to access your device’s precise location makes sense. Your favorite weather app needs to know where you are to get the day’s forecast, or your go-to fitness app for tracking your running route.
But some apps are also inadvertently sharing their users’ location data with third-parties, including advertisers and data brokers, because the app developer may not know that this data-sharing setting is enabled by default.
New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app.
Unless the developer actively switches off the collection, the code snippet (known as software development kits or SDKs) will inherit the app’s permissions and collect the user’s precise location data.
The EFF says many developers might not realize that they are sharing their users’ location data with third-parties by default, and urged app makers to disable unnecessary data collection whenever possible.
While advertising SDKs are promoted as a way for developers to monetize their app, the tradeoff is that the users’ location histories get fed to data brokers, who monetize that information which then gets sold to militaries, governments, and intelligence agencies, like the FBI. The data is also a security and privacy risk if it gets hacked or stolen, which some data brokers have experienced.
Among the Android apps that the EFF identified that were quietly sharing users’ location data included two that had been downloaded a combined 60 million times to date.
The EFF ran its tests by analyzing the apps’ network traffic and seeing which services are receiving the users’ location data.
Bill Budington, a senior staff technologist at the EFF, told TechCrunch that the SDKs they examined account for a small percentage of the broader advertising ecosystem but nevertheless claim to reach billions of users over tens of thousands of apps. That gives some sense of the scale of this type of location data collection.
The EFF’s report said that there are “no SDK-specific location permissions,” meaning that once the user allows their location data to be shared with the app, their location data is also shared with advertisers. The entities offering those SDKs are generally commercially incentivized to get their customers to collect more data.
“App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs,” wrote the EFF. “Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s precise location.”
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

