Your Android Apps Leak Your Location. The Developers Didn't Know

New research shows that advertising SDKs embedded in Android apps are sharing your precise location with advertisers and data brokers without your knowledge.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Several apps on your Android device are not only tracking your location without telling you, but also sharing it with third-party advertisers and data brokers.

New research by the Electronic Frontier Foundation (EFF)[1] has identified several advertising Software Development Kits (SDKs) that collect and share location data, sometimes without developers being fully aware of the extent of the data collection.

App developers often integrate advertising SDKs into their applications in exchange for monetization. However, if the app has permission to access your location, that data could also be shared with the embedded SDK.

Here’s how your location data is being collected, why it’s a privacy nightmare, and what you can do to protect yourself right now as an Android user.

In this article
How is your location data shared
Advertising SDKs that share location data
Privacy risks of location data sharing
What can you do to protect yourself
Bottom line

How is your location data shared

According to the EFF’s report, there are two primary ways the location data of Android users is shared with advertisers and data brokers.

In the first method, some apps work directly with data brokers by either embedding an SDK into the software or sending users’ location data directly to the broker through server-to-server communication. This is a more deliberate and contractual route.

The second is a sneakier, larger-scale route that takes place through real-time bidding (RTB). Whenever an ad slot opens up in an app, a split-second auction takes place where various advertising companies and data brokers bid in real time for the ad slot.

For the auction to happen, the app shares certain pieces of information, called a bid request. It is this information that often contains customer location data.

Now, not all bidders are interested in actually winning the ad auction. Some participate only to gain access to the location data contained in the bid request. They’re not there to advertise their services to you — they’re interested only in the data packet itself.

The dangers of RTB-based location data sharing were exposed during the 2025 data breach of Gravy Analytics, a location data company. The exposed data revealed that the company had sourced users’ locations through thousands of apps.

What was surprising is that when researchers reached out to those apps for clarification, they had no idea or existing partnership with Gravy Analytics. This is because the company had gathered the data by abusing the RTB process.

Once an SDK has been embedded in an app, it receives the same level of access as the app itself. This means that once you allow an app to access your location, the embedded SDK could also access it, since there are no SDK-specific location permissions.

These permissions are generally of two types:

  1. Precise location, which gives apps your exact location within about 160 feet.
  2. Approximate location, which provides a less precise location within about 1.2 square miles.

Another problem is that both app developers and advertising SDKs have a financial incentive to share your location data during the bid request process, since advertisers are willing to pay a premium for precise location signals.

Advertising SDKs that share location data

Researchers at the EFF analyzed four advertising SDKs that share location data by default. Here’s what they found.

InMobi

InMobi, with 2 billion users across 150 countries, is the 10th most popular Android advertising SDK. Its own documentation states that the SDK could automatically forward location signals if available.

While there is an opt-out setting, the documentation advises developers against using it, stating that location-enriched ad impressions generate higher revenue.

Furthermore, InMobi recommends that developers request permission to access Wi-Fi network information, which could also be used to track users independently.

Back in 2016, InMobi settled with the FTC over allegations that it bypassed users’ location permissions and tracked them using Wi-Fi data without explicit consent.

BidMachine

BidMachine, with more than 600 million direct SDK users, goes a step further by allegedly misrepresenting its data collection practices. Its Google Play "App Privacy Details" page stated that it didn’t collect precise location data.

However, when EFF researchers investigated further, they found that two apps using BidMachine — QR Scanner (50 million+ downloads) and GPS Speedometer (10 million+ downloads) — were collecting precise location coordinates.

When the EFF contacted BidMachine about its findings, the company updated its documentation to more accurately reflect its data collection practices.

Verve (HyBid SDK)

Verve has 1.5 billion users across more than 10,000 applications. EFF noted an inconsistency in its Google Play Data Safety disclosure, which states that its SDK doesn’t collect information independently and that any data collection is contingent on developers obtaining explicit user consent.

When the EFF reached out to Verve for an explanation, the company said that it only reads cached network provider locations with an accuracy of approximately 1,850 feet.

Since HyBid is open source, EFF verified that the coordinates are rounded to two decimal places. Even then, this corresponds to a location accurate to roughly 0.5 square miles.

Huawei (Petal Ads SDK)

Huawei Petal Ads SDK, embedded in approximately 85,000 apps worldwide, begins its integration guide by explaining the financial benefits of requesting location permissions and acknowledges that location sharing is enabled by default.

Moreover, its opt-out option is buried in the final section of a separate Ads SDK Compliance Guide rather than being prominently displayed in its main documentation.

Privacy risks of location data sharing

The location data these applications collect is used for targeted advertising, but that’s the best-case scenario. Unfortunately, it also has far-reaching privacy implications, most notably government authorities using it for broader surveillance and nefarious crackdowns.

  1. As reported by 404 Media, U.S. Customs and Border Protection (CBP) has purchased data from the online advertising ecosystem to track citizens’ precise movements.
  2. Similarly, the U.S. Immigration and Customs Enforcement (ICE) has reportedly used similar data to monitor the movements of phones across entire neighborhoods.
  3. The Washington Post also reported that Catholic groups spent millions of dollars on app location data to identify and remove gay priests from their positions.
  4. According to Reuters, similar commercial location data has also been used to track U.S. military personnel deployed in sensitive war zones.

In addition to these specific cases, continuous location sharing could give hackers access to your movement patterns and reveal visits to sensitive places such as healthcare clinics or shelters. Such information could be used for stalking and may even lead to physical harm.

Moreover, location data can become even more revealing when combined with other personally identifiable information obtained through data brokers or previous data breaches.

In the wrong hands, this can enable highly targeted phishing attacks, which may ultimately lead to identity theft or financial fraud.

What can you do to protect yourself

Fortunately, there are several ways you can reduce the risks of location sharing on your Android device.

  1. Check app location permissions: Thoroughly audit the apps on your phone and the permissions they have been granted. You can do this by going to Settings > Location > App location permissions. Then, review every app and revoke location access if it is not essential for its functionality. For instance, QR scanners, flashlights, calculators, games, and many other utility apps do not need access to your location to function.
  2. Allow location sharing only while using an app: Even for apps that need your location, make sure you select the "Allow only while using the app" option. This reduces the amount of location data the app can collect in the background when you’re not actively using it. To do this, open Settings, go to App location permissions, and select the app whose settings you want to change. You’ll see three options — select "Allow only while using the app."
  3. Don’t allow precise location: Under the same settings page, you’ll also see a toggle for Precise location. Turn it off to share only your approximate location with apps. Doing so reduces your location accuracy from about 160 feet to roughly 1.2 square miles, adding a much-needed privacy buffer.
  4. For developers: Developers should not trust an SDK’s default settings and should actively look for privacy and opt-out options rather than assuming the SDK is privacy-first. As highlighted by the EFF’s investigation of four advertising SDKs, many SDKs enable location sharing by default while making the opt-out option difficult to find or obscuring information about it in their documentation.

Bottom line

The EFF’s new research has identified several advertising SDKs that collect your location data through Android applications. What’s more concerning is that much of this happens without developers fully understanding the extent of the data collection, let alone users.

Worse still, many SDK providers also obscure the opt-out option and encourage developers to keep location sharing enabled by default. However, you can fine-tune your Android location settings to control the amount of location data shared with these advertising SDKs.

Make sure that only apps that genuinely need location access for their functionality are granted permission. Even then, choose "Allow only while using the app" and share an approximate location instead of your precise location whenever possible.

Take Control of Your Online Privacy
5.0
Editorial Rating
Get Deal
On Incogni's website
2026 Editors’ Choice
Best Overall Data Removal Service
Privacy Protection
Incogni
PROMOTION: Save 55% with code COOKIE
  • Top-rated data removal service that scrubs your info from 420+ data broker sites automatically
  • Independently verified by Deloitte, meaning removals are actually sent, confirmed, and not just claimed
  • The Unlimited plan extends coverage to 2,000+ additional sites with human-assisted custom removals

Author Details
Krishi Chowdhary specializes in digital privacy, cybersecurity, and consumer technology. He has written extensively on online privacy tools and broader cybersecurity topics, including online scams, data breaches, age verification, and emerging digital threats. Krishi believes technology reporting should empower readers, not confuse them, and is committed to making even the most technical subjects easy to understand without compromising on accuracy or depth. His work has appeared in leading technology publications, including CNET, ExpressVPN, and TechRadar, where he has covered topics ranging from cybersecurity incidents and privacy product announcements to artificial intelligence and major technology news

Citations

[1] Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy (EFF)