You may think your location is only shared with trusted apps on your phone, but a new report from the Electronic Frontier Foundation (EFF) suggests that isn't always the case.
Some Android apps may be passing your precise location to advertising companies through third-party software built into the app. Even when developers didn't intend for it to happen, you might be feeding someone the information they need to sell you products. Here's what they found.
Apps know exactly where you are
The EFF investigated advertising software used inside Android apps and found that many popular applications include third-party software development kits (SDKs). SDKs are pre-built pieces of code that developers add instead of building every feature themselves.

Some provide analytics and enable logins, while many others are designed specifically to display advertisements. The EFF's testing methods included identifying popular Android advertising SDKs and the apps that use them through public resources like Exodus Privacy and AppBrain.
The organization set up a controlled test environment, routing traffic from a test Android device through mitmproxy to inspect the data being sent over the internet. It also used the dynamic instrumentation tool Frida where apps used protections that made traffic harder to analyze.
The researchers published the captured network traffic, which shows precise location coordinates being transmitted directly by the SDKs. They discovered that advertising SDKs are often configured to collect precise location data by default. When you give an app permission to access your location, the embedded kit accesses it as well.
This doesn't necessarily mean the app developer intended to share your data or use it maliciously. Many SDKs are set up so that they automatically send location data to advertising companies by default. A developer can usually disable this behavior, but if they don't know about the setting or forget to change it, location data continues to be shared.

Defaults matter, not just for users, but for app developers as well. If app developers don't pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users' location information. Users can take extra steps to defend their location privacy, but they shouldn't have to. Developers, regulators, and legislators must act to stop apps from leaking users' location to advertising companies and data brokers.
Lena Cohen, EFF Staff Technologist.
Even without your name attached, location patterns reveal sensitive information about where you live, work, shop, or worship, making it easy to link data back to specific individuals.
Review your phone's permissions just in case
The EFF notes that similar advertising-derived location data has previously been used to track US military personnel, support immigration enforcement investigations, and power commercial surveillance tools. Specifically identified were four advertising SDKs that collect and share location data by default:
- InMobi: An Indian ad tech company founded in 2007 that operates as one of the world's largest independent mobile advertising firms.
- BidMachine: A mobile advertising platform owned by AppLovin that focuses on in-app ad auctions.
- Verve HyBid: The advertising SDK from Verve Group, a German ad tech company that specializes in programmatic mobile ads.
- Huawei Petal Ads: Huawei's advertising network built primarily for devices running Huawei Mobile Services (HMS).

You don't need to panic or uninstall all your apps, but this report is a clear reminder to review your app permissions and be selective about which tools receive precise location access.