Default On, Hard to Turn Off
Your phone knows where you are, and that is not the problem. The problem is how many other companies get to know it too.
The Electronic Frontier Foundation, a digital rights group, took a close look at Android apps and found some uncomfortable math. Sandwiched inside those apps is third-party code that can transmit a user's precise location to outside firms such as advertisers and data brokers.
The sharing happens by default after a user grants location permission, unless a developer changes the settings first.
What makes it tricky is that Android does not have separate location controls for the SDKs. The EFF report says there are "no SDK-specific location permissions" on the platform.
So when you allow one app to see your location, everything bundled inside it gets the same access. That is not how most people understand permission screens.
The EFF is making the point that a single button is not really informed consent.
That consent gap matters because Android's permission screen only names the app, not the third-party tools inside it. Tapping "Allow" can hand location data to companies the user has never heard of.
Developers May Not Even Know
Many developers are likely unaware their default setup is sending location history to outside firms. The ad SDKs are pitched as a way to earn revenue from a free app, and the companies providing them have a financial incentive to push developers toward more data collection.
Get the free Always Be Buying eBook and learn the simple system for building wealth on any income
The report is direct about who should change. "Advertising SDKs should not make sharing personal data the default, especially for data as sensitive as a person's location," the EFF wrote.
It also recommends developers turn off any data collection they do not truly need.
Where the Location Data Ends Up
This is not only about targeting you with ads. EFF traced the apps' network traffic to see which services actually got the location data.
Bill Budington, who holds a senior technologist role at EFF, told TechCrunch that the sample of SDKs examined is just a small part of the ad business, even though those vendors claim to reach billions of people through tens of thousands of apps. In other words, the problem may be much larger than the specific apps in the report.
From there, location data can travel well beyond advertisers. It often flows to data brokers, companies that collect personal information and resell it.
And the data is not always safe once it arrives.
Some brokers have already had data stolen from them, which makes this a security issue as well as a privacy one.
Location is the rare data point that cannot be reset. A stolen credit card number can be replaced; a history of where you sleep, work, and meet friends cannot.
What It Means for Your Money
For investors, this is a risk hiding inside the mobile ad business. App makers that rely on these SDKs could face legal and reputation problems as regulators take a harder look at location data.
Companies that buy and sell that data face the same risk as any business holding a sensitive asset: one breach can turn a revenue stream into a liability.
"App-level location permissions alone cannot signal meaningful consent to location collection and sharing by third-party advertising SDKs."
A free app still has a cost. The price is the location data it sends out, and that data has buyers.
The findings, reported by TechCrunch on August 4, 2026, are a reminder that your location is a data point with a price tag. Brokers bundle it, sell it, and sometimes lose it to thieves.
The EFF's point is that this data sharing should not be a secret.
Download the free Always Be Buying eBook and start putting your money to work today
