Android Apps Share Location Data With Advertisers by Default

Default On, Hard to Turn Off

Your smartphone is adept at pinpointing your location, but the real concern lies in how many other entities gain access to that information. A recent investigation by the Electronic Frontier Foundation (EFF), a prominent digital rights organization, has revealed some unsettling truths about Android applications. Embedded within these apps is third-party code capable of transmitting a user’s precise location to external companies, including advertisers and data brokers.

This data sharing occurs automatically once a user grants location permission, unless the developer proactively alters the default settings. The situation is further complicated by the absence of distinct location controls for Software Development Kits (SDKs) on the Android platform. According to the EFF report, there are “no SDK-specific location permissions,” meaning that when a user permits one app to access their location, all bundled components within that app receive the same access. This reality diverges sharply from the typical understanding of permission screens.

The EFF emphasizes that a single button press does not equate to informed consent. This gap in understanding is significant, as Android’s permission interface only identifies the app itself, neglecting to mention the third-party tools embedded within. Consequently, tapping “Allow” can inadvertently grant location data to unfamiliar companies.

Developers May Not Even Know

Many app developers might be oblivious to the fact that their default configurations are transmitting location histories to external firms. Advertising SDKs are often marketed as a means to generate revenue from free applications, with the companies behind them incentivized to encourage extensive data collection.

The EFF’s report calls for a shift in this practice: “Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person’s location.” The organization also urges developers to disable any data collection that is not essential for their app’s functionality.

Where the Location Data Ends Up

The implications extend beyond mere advertising. The EFF has traced the network traffic of these apps to identify which services ultimately receive the location data. Bill Budington, a senior technologist at EFF, noted to TechCrunch that the sample of SDKs analyzed represents only a fraction of the advertising landscape, despite vendors claiming to reach billions of users across tens of thousands of applications. This suggests that the issue may be more pervasive than the specific apps highlighted in the report.

Once collected, location data can travel far beyond the realm of advertising. It frequently reaches data brokers—companies that aggregate personal information and resell it. Unfortunately, this data is not always secure upon arrival. Some brokers have experienced data breaches, raising concerns about both privacy and security.

Location data is particularly sensitive, as it is a unique data point that cannot be reset. Unlike a stolen credit card number, which can be replaced, a record of where you sleep, work, and socialize is permanent.

What It Means for Your Money

For investors, this situation presents a hidden risk within the mobile advertising sector. App developers relying on these SDKs could encounter legal challenges and reputational damage as regulators intensify scrutiny of location data practices. Companies engaged in the buying and selling of this data face similar risks; any breach can transform a revenue-generating asset into a significant liability.

The EFF asserts that “app-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs.” While free applications may seem costless, they come with a price: the location data they disseminate, which has a market value.

The findings, initially reported by TechCrunch on August 4, 2026, serve as a stark reminder that your location is a valuable data point. Brokers aggregate, sell, and occasionally lose this information to cybercriminals. The EFF’s message is clear: the sharing of this data should not occur in secrecy.

AppWizard
Android Apps Share Location Data With Advertisers by Default