
Many Android users expect a weather app, fitness tracker or navigation tool to use their location only for the feature they asked for. But a new report from the Electronic Frontier Foundation says some apps may be passing precise location data to advertisers and other third parties without developers fully realizing it, because a default setting in third-party advertising code can quietly turn that sharing on.
How location data can leak beyond the app
The EFF says the issue centers on software development kits, or SDKs, the third-party code blocks developers add to apps for functions such as advertising and monetization. When an Android app is granted permission to access location, those SDKs can inherit that permission and collect precise location data as well, unless the developer explicitly disables the collection.
That means a developer may believe an app is using location for a limited purpose, while the embedded advertising code is also receiving the same data. According to the EFF, some app makers may not know that the setting is enabled by default.
The organization said it wants to alert developers that third-party code inside their apps can gather location data once users approve location access for the app itself. It urged developers to switch off unnecessary data collection whenever possible.
Why the EFF is concerned
The EFF’s warning goes beyond a simple privacy reminder. In the report, the group said advertising SDKs are often promoted as a way for developers to monetize apps, but the trade-off can be that users’ location histories are fed to data brokers. Those brokers then monetize the information further, and the data may ultimately be sold to militaries, governments and intelligence agencies, including the FBI, according to the report.
The EFF also pointed to the security risks of location data being stored and shared through this ecosystem. If brokers are hacked or otherwise have data stolen, users can be exposed to serious privacy harm. The organization said some data brokers have already experienced such incidents.
What the EFF found in its testing
Among the Android apps identified by the EFF were two apps that had been downloaded a combined 60 million times to date. The group said it discovered the data sharing by analyzing network traffic and identifying which services were receiving users’ location data.
Bill Budington, a senior staff technologist at the EFF, told TechCrunch that the SDKs examined in the report represent only a small slice of the broader advertising ecosystem. Even so, he said they claim to reach billions of users across tens of thousands of apps, which gives an indication of how widespread this kind of collection can be.
The report’s central point is that app-level permission prompts do not necessarily communicate what third-party code embedded in an app will do with the data. Once a user agrees to share their location with the app, that location data can also be shared with advertisers if the SDK is configured to collect it.
App permissions may not mean informed consent
The EFF argues that this model creates a consent problem. Users may understand that they are giving a weather app access to location so it can show local forecasts, or granting a running app access so it can map a route. But that same permission can also expose their precise location to advertising code running inside the app.
In the EFF’s view, app-level location permissions are not enough to establish meaningful consent for third-party advertising SDKs. The organization said users are not clearly told when their location data will be shared beyond the app they intended to use.
The report said there are “no SDK-specific location permissions,” which is part of what makes the issue harder to see and control. The EFF said the entities that provide these SDKs are generally commercially incentivized to encourage customers to collect more data.
What developers can do
The EFF’s advice to developers is straightforward: review the third-party code included in apps and disable any data collection that is not necessary. The group specifically urged developers to turn off unnecessary collection whenever possible, rather than relying on default settings in advertising tools.
That recommendation reflects the broader tension between app monetization and user privacy. Advertising SDKs can help developers generate revenue, but the report suggests that the hidden cost may be a more extensive flow of sensitive location data than developers or users expect.
- SDKs can inherit an app’s location permission once the user grants it.
- Some advertising SDKs may collect precise location data by default.
- Developers may not realize third-party code is sharing location data.
- The EFF says app-level permission alone does not equal meaningful consent for ad SDK sharing.
- Location data can pose privacy and security risks if brokers are hacked or data is stolen.
Why precise location deserves special attention
Precise location data is especially sensitive because it can reveal where a person lives, works, exercises, shops and spends time. Over time, location histories can paint a detailed picture of a person’s routines and relationships. That is why the EFF says sharing this data with advertising systems should not be the default.
The report does not suggest that all Android apps behave this way, nor does it claim that every SDK will collect location data. Instead, it warns that the framework itself can allow collection to happen silently once the app has location permission and the developer has not opted out.
For users, the practical takeaway is that a permission prompt may not tell the whole story. For developers, the EFF’s message is that privacy settings hidden in third-party SDKs deserve the same scrutiny as any other part of the app stack.
As Budington described the scale, the advertising SDKs studied may be only a small part of the ecosystem, but their reach across billions of users and tens of thousands of apps makes the problem significant. That is why the EFF is pressing app makers to examine what their embedded code is doing behind the scenes.
Source: Original report
Was this helpful?
Explore more: Mobile App Development More Mobile Technology Tech News
Last Modified: August 5, 2026 at 6:38 pm
4 views

