Developers: Beware of Ad Libraries That Betray Your Users' Location Privacy

hn_acker1 pts0 comments

Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy | Electronic Frontier Foundation

Skip to main content

AboutContact

Press

People

Opportunities

IssuesFree Speech

Privacy

Creativity and Innovation

Transparency

International

Security

Artificial Intelligence

Our WorkDeeplinks Blog

Press Releases

Events

Legal Cases

Whitepapers

Podcasts

Annual Reports

Take ActionAction Center

Volunteer

Follow EFF

ToolsPrivacy Badger

Surveillance Self-Defense

Certbot

Atlas of Surveillance

Cover Your Tracks

Street Level Surveillance

apkeep

Shop

DonateDonate to EFF

Shop

Giving Societies

Sponsorships

Other Ways to Give

Membership FAQ

Email updates on news, actions,

and events in your area.

Join EFF Lists

Copyright (CC BY)

Trademark

Privacy Policy

Thanks

Electronic Frontier Foundation

Donate

If you use technology, this fight is yours.Donate today

Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy

DEEPLINKS BLOG

By Lena Cohen and Bill Budington<br>August 4, 2026

Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy

Share It

Share on Mastodon<br>Share on Bluesky<br>Share on Facebook<br>Copy link

Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.

When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.

Defaults matter, not just for users, but for app developers as well.

An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location by default when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.

This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.

Contents:

Data Brokers Harvest Location Information From Advertising Systems

How Advertising SDKs Leak Location Data

EFF Identified Advertising SDKs That Share Location Data by Default

InMobi Encourages Keeping Location Sharing Enabled By Highlighting Financial Incentives

BidMachine Updates Previously Inaccurate Developer Documentation After EFF's Technical Analysis Observed Precise Location Data Collection

Verve Emphasizes Consent More in its Play Store Language Than its Configuration Guide

Huawei Highlights Financial Incentives for Location Data Sharing Before Showing Developers How to Opt Out

Location Data Sharing Can Happen Without Users’ Knowledge or Meaningful Consent

Location Privacy Issues Extend Beyond These Four SDKs

Fighting Back Against AdTech Companies That Enable and Encourage Location Data Sharing

Developers

Regulators

Legislators

Data Brokers Harvest Location Information From Advertising Systems

When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.

Location data brokers sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on people’s phones. Some apps partner with data brokers directly, using data-broker-developed SDKs or server-to-server transfers to sell users’ location data. Other apps leak users’ location data through advertising SDKs serving behaviorally-targeted ads through “real-time bidding” (RTB). In the process of auctioning off ad space, ad tech companies can broadcast user data to thousands of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to collect personal information contained in bid requests.

Indiscriminate data sharing through RTB can lead app developers to unknowingly share their users’ location with data brokers. In 2025, a hack of location data broker Gravy Analytics revealed thousands of apps that may have been sources of its data. When journalists reached out to the app developers, many claimed they had no relationship with or knowledge of Gravy Analytics. To prevent location...

location data users developers advertising sdks

Related Articles