Android app developers may be unwittingly sharing their users’ location data with advertisers

The Electronic Frontier Foundation has discovered that many Android apps inadvertently share precise user location data with third-party advertisers via default SDK settings. Developers are often unaware that these code snippets continue to collect data, which is then sold to brokers and government agencies.
Why it matters
Exposes a significant privacy loophole in mobile app development that threatens user security and data sovereignty.
For many apps, granting permission to access your device’s precise location makes sense. Your favorite weather app needs to know where you are to get the day’s forecast, or your go-to fitness app for tracking your running route.
But some apps are also inadvertently sharing their users’ location data with third-parties, including advertisers and data brokers, because the app developer may not know that this data-sharing setting is enabled by default.
New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app.
Unless the developer actively switches off the collection, the code snippet (known as software development kits or SDKs) will inherit the app’s permissions and collect the user’s precise location data.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in