All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Leonardo’s SignalTrace can pick up wireless signals from devices such as your smartphone and smartwatch as you drive past its sensors, potentially allowing those devices to be linked to a particular vehicle over time.[1]
That means surveillance could go beyond simply knowing where a particular car has been. A system like this could potentially help investigators identify the devices that repeatedly travel with it, creating another way to connect a person to a vehicle, a location, or even an investigation.
And this isn’t happening in isolation. Automatic License Plate Recognition (ALPR) cameras can already track a vehicle by its license plate and feed that information into searchable databases accessed by law enforcement and even federal agencies such as Immigration and Customs Enforcement (ICE).
But while that system tracks the car, SignalTrace could potentially track you even if you don’t own one, by identifying the devices you carry when you travel in someone else’s vehicle.
Here’s how it works and the privacy questions it raises.
How SignalTrace could put your privacy at risk
Is SignalTrace even legal
What can you do to protect yourself
Bottom line
How SignalTrace works
Every electronic gadget, be it your smartphone or smartwatch, broadcasts wireless signals in the background, such as Bluetooth or RFID pings. Signal-tracing sensors can pick these broadcasts up from any device that passes by their sensors.
Now, since these sensors sit next to a license plate reader, they can also note which devices were nearby when a specific car passed. Over repeated trips, the underlying software could notice that the same handful of device signatures keep showing up together with a specific vehicle.
SignalTrace then treats the recurring cluster of devices as a kind of signature associated with a particular vehicle. This device fingerprint could become enough to identify a vehicle, even without seeing its license plate.
What’s worrisome is that these signatures are stored in a database, which could later be searched by investigators. For instance, say that your device shows up near a different car that’s tied to a criminal investigation. This could then put you in a tricky situation.
These searchable signatures could also be correlated with other visual identifiers, such as license plate images or other camera data, to track a person across locations.
One thing to note is that the system, according to Leonardo, "does not identify people." It only collects electronic signatures, not names. This identity gap is filled by humans, most commonly investigators and police departments that already have recurring device signatures tied to a particular vehicle.
How SignalTrace could put your privacy at risk
There’s a fair share of ambiguity around what constitutes personally identifiable information. As per National Institute of Standards and Technology (NIST), PII is any piece of data that can reveal someone’s identity, either alone or combined with other pieces of information.
Leonardo, the company behind SignalTrace, says its system does not assign names and does not identify people directly, though the data can still be used to help identify suspects when combined with other records.
However, privacy researchers and commentators have pushed back on this, arguing that a persistent, searchable pattern of movement can single someone out just as effectively as personally identifiable information such as a name or phone number.
A study published in the journal Scientific Reports shines more light on this argument. Researchers analyzed 15 months of records covering around 1.5 million people and observed that just four time-and-place points were enough to uniquely identify 95% of the people.
Although the study didn’t cover SignalTrace specifically, it shows that tracking repeated movements could strip away the anonymity associated with device signals.
Moreover, the system doesn’t just risk revealing who you are but could also reveal who you are with. Now, a cluster of devices might just be a family carpool in the most harmless situation.
However, other times, your device might show up near a group of protesters or coworkers, or you might be standing near someone under investigation for unrelated reasons. These situations can put you under investigation, not because you did anything, but because of who you were with.
With cars already spying on you, car manufacturers probably have your data, such as your name, device location and driving route history, driver's license numbers, and more.
This could then be linked with your signal profile with SignalTrace and reveal your identity almost instantly, without an investigator ever needing to do the legwork of cross-referencing DMV records or other databases by hand.
There’s also the possibility that this data could eventually make its way into the hands of third parties. If SignalTrace data were shared, sold, or exposed in a breach, it could make phishing and social engineering attacks far more convincing, particularly when combined with your name, address, vehicle information, or other personal details.
Is SignalTrace even legal?
There are two important court decisions that need to be understood in connection with SignalTrace.
- In Carpenter v. United States (2018), police obtained months of cell-site location records to narrow down a robbery suspect without a warrant. The Supreme Court ruled that this was a violation of the Fourth Amendment and that people have a reasonable expectation of privacy in records of their physical movements.
- This decision was further extended in the more recent Chatrie v. United States (June 2026). In this case, police requested a geofence warrant from Google and asked the company for anonymized location data for every phone within a 150-meter radius of a bank robbery. The Supreme Court said that such a geofence warrant seeking location history is also a Fourth Amendment search.
In both cases, it’s clear that the judiciary views movement data as private enough to warrant Fourth Amendment protection, even when it’s held by a third party.
However, both cases involved obtaining location history held by a third party, such as Google. SignalTrace, on the other hand, doesn’t request such location data from a company but passively stores it by picking up wireless signals.
Also, in Carpenter, police already had a specific suspect and sought his location records. In Chatrie, by contrast, police had no identified suspect and used a geofence warrant to sweep up location data for everyone near the crime scene, later narrowing down to identify a suspect. However, SignalTrace continuously logs every device that broadcasts a signal, whether or not any crime has occurred, and stores that data in a searchable database for future queries and analysis, according to Leonardo's own materials.
The Fourth Amendment doctrine was built around targeted requests. However, whether it would extend to an always-on dragnet collection like SignalTrace is still an unanswered question.
SignalTrace also borders the gray area of the First Amendment, as highlighted by the NAACP v. Alabama case in 1958.
The state of Alabama tried to force the NAACP to hand over its full membership list as part of a legal lawsuit. However, the organization refused to do so, as NAACP membership could lead to job loss, harassment, or violence at the height of the civil rights movement.
The case reached the Supreme Court, which said that forcing an organization to disclose its members’ identities could violate the freedom of association, which is implicitly protected under the First Amendment.
SignalTrace’s use case is very similar to this precedent. It can not only recognize devices, but it’s structurally an association map, showing devices that consistently appear alongside other phones and devices. This could reveal a person’s political leanings, the places they visit regularly, organizational patterns, and much more.
In fact, SignalTrace’s modus operandi seems even more chilling, since users have no visibility into what sort of data is being collected, how it is being stored, who is using that data, or in what way.
What can you do to protect yourself
Unfortunately, there’s very little you can do as an individual to stop surveillance systems such as SignalTrace or ALPR cameras from being deployed around you. Your options are limited to minimizing the potential misuse of your data rather than preventing the collection itself.
One option is to use an identity theft protection service. These services can't stop SignalTrace from collecting a device signature, but they can alert you if your personal information appears in a data breach or on the dark web.
They can also submit data removal requests to reduce the amount of personal information publicly available about you.
Bottom line
SignalTrace is not yet an established practice, but the technology does exist. Just like ALPR, there’s no consent mechanism, and you’d essentially hand over your signal data to a third-party company, which could be used to profile you and aid in investigations.
Leonardo's defense rests on a single technicality: the system never says your name. But a database that can trace where you've been, who you've been near, and when doesn't need your name to know exactly who you are.
However, whether this new technology will stand the legal test is yet to be determined. Several cases have upheld that users’ movement data is private and protected by the Fourth Amendment. Similarly, the association map generated by SignalTrace could be in conflict with the First Amendment.
[1] New tech adds phone tracking to license plate readers, associating devices with identifiable cars