Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy | Electronic Frontier Foundation
Skip to main content
AboutContact
Press
People
Opportunities
IssuesFree Speech
Privacy
Creativity and Innovation
Transparency
International
Security
Artificial Intelligence
Our WorkDeeplinks Blog
Press Releases
Events
Legal Cases
Whitepapers
Podcasts
Annual Reports
Take ActionAction Center
Volunteer
Follow EFF
ToolsPrivacy Badger
Surveillance Self-Defense
Certbot
Atlas of Surveillance
Cover Your Tracks
Street Level Surveillance
apkeep
Shop
DonateDonate to EFF
Shop
Giving Societies
Sponsorships
Other Ways to Give
Membership FAQ
Email updates on news, actions,
and events in your area.
Join EFF Lists
Copyright (CC BY)
Trademark
Privacy Policy
Thanks
Electronic Frontier Foundation
Donate
If you use technology, this fight is yours.Donate today
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
DEEPLINKS BLOG
By Lena Cohen and Bill Budington<br>August 4, 2026
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
Share It
Share on Mastodon<br>Share on Bluesky<br>Share on Facebook<br>Copy link
Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.
When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel.
Defaults matter, not just for users, but for app developers as well.
An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location by default when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.
This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.
Contents:
Data Brokers Harvest Location Information From Advertising Systems
How Advertising SDKs Leak Location Data
EFF Identified Advertising SDKs That Share Location Data by Default
InMobi Encourages Keeping Location Sharing Enabled By Highlighting Financial Incentives
BidMachine Updates Previously Inaccurate Developer Documentation After EFF's Technical Analysis Observed Precise Location Data Collection
Verve Emphasizes Consent More in its Play Store Language Than its Configuration Guide
Huawei Highlights Financial Incentives for Location Data Sharing Before Showing Developers How to Opt Out
Location Data Sharing Can Happen Without Users’ Knowledge or Meaningful Consent
Location Privacy Issues Extend Beyond These Four SDKs
Fighting Back Against AdTech Companies That Enable and Encourage Location Data Sharing
Developers
Regulators
Legislators
Data Brokers Harvest Location Information From Advertising Systems
When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. EFF began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.
Location data brokers sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on people’s phones. Some apps partner with data brokers directly, using data-broker-developed SDKs or server-to-server transfers to sell users’ location data. Other apps leak users’ location data through advertising SDKs serving behaviorally-targeted ads through “real-time bidding” (RTB). In the process of auctioning off ad space, ad tech companies can broadcast user data to thousands of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to collect personal information contained in bid requests.
Indiscriminate data sharing through RTB can lead app developers to unknowingly share their users’ location with data brokers. In 2025, a hack of location data broker Gravy Analytics revealed thousands of apps that may have been sources of its data. When journalists reached out to the app developers, many claimed they had no relationship with or knowledge of Gravy Analytics. To prevent location...