Every time you open an app that has location permissions, your phone's precise GPS coordinates — latitude, longitude, and timestamp — can be recorded and transmitted to the app's servers. From there, the data enters a supply chain that most consumers never see.
The app developer often includes a tracking SDK (Software Development Kit) from an advertising network or data broker. This SDK runs silently in the background, collecting your location and transmitting it to the SDK provider. The SDK provider aggregates location data from thousands of apps across millions of devices. This aggregated data is then sold to data brokers, who package it into products and sell it to advertisers, insurance companies, retailers, and government agencies.
The critical link in this chain is your Mobile Advertising ID — a unique identifier assigned to your device that allows brokers to track a single phone across all apps and all locations over time. This identifier is what transforms random location pings into a detailed pattern of life: where you live, where you work, what stores you visit, what doctor you see, what place of worship you attend, and who you spend time with.
A 2018 investigation found that over 10,000 apps were harvesting location data for commercial sale. The apps span every category and include both well-known brands and obscure utilities.
Weather apps are among the most notorious location data sellers. They have a legitimate reason to request your location — they need it to show you local weather. But many collect your location far more frequently than needed for weather forecasts, tracking your movements continuously and selling the data to brokers. The Weather Channel app was sued by the City of Los Angeles for selling user location data to advertising companies.
Retail coupon apps, deal finders, and shopping companions frequently request location access to show nearby deals. Many of these apps are primarily data collection vehicles that use coupons as the incentive to get you to install them and grant location access. The coupons are the product — you are the product.
While major apps like Google Maps and Waze use location data for their core function, they also feed data into their parent companies' advertising ecosystems. Smaller navigation apps and traffic reporters may sell location data directly to brokers.
Running apps, step counters, and fitness trackers record your exercise routes and patterns. This data reveals where you run, when you exercise, and how often — information that can be correlated with home addresses and daily routines.
Many mobile games request location permissions even when the game has no location-based features. Some popular games include advertising SDKs that collect location data in the background while you play.
Perhaps the most egregious category. A flashlight app has absolutely no reason to know your location. Yet investigations have found flashlight apps requesting and collecting GPS data. These apps exist solely to harvest data from users who do not question why a flashlight needs to know where they are.
1 Check app permissions on iPhone: Settings, Privacy & Security, Location Services. You will see every app that has requested location access and whether it has been granted Always, While Using, or Never.
2 Check app permissions on Android: Settings, Privacy, Permission Manager, Location. Same view — every app with location access and its permission level.
3 Revoke "Always" access from every app that does not absolutely require it. Navigation apps may need location while using. Your weather app does not need to track you at 3 AM. Your flashlight definitely does not.
4 Delete apps you do not use. Every installed app with location permissions is a potential data leak, even if you have not opened it in months. Some SDKs collect data in the background regardless of whether you actively use the app.
5 Delete your Mobile Advertising ID. On iPhone: Settings, Privacy, Tracking, toggle off Allow Apps to Request to Track. On Android: Settings, Privacy, Ads, Delete Advertising ID. This removes the unique identifier that links your activity across apps.
6 Submit deletion requests to the data brokers that have already collected your historical location data. Venntel (privacy@venntel.com) and Fog Data Science (fogdatascience.com/opt-out) are the primary government surveillance brokers. Include your Advertising ID in the deletion request before deleting it from your phone.
When evaluating whether an app is selling your location data, watch for these indicators. The app is free but has no obvious revenue model — if you are not paying for the product, you are the product. The app requests location access that is not related to its core function. The privacy policy mentions sharing data with "partners" or "third-party advertisers." The app comes from a small developer with a sparse online presence. The app requests "Always" location access when "While Using" would suffice.
Reading an app's privacy policy before installing it takes two minutes and can reveal whether your location data will be sold. If the policy mentions sharing location data with advertising partners, analytics providers, or unspecified third parties, assume your GPS coordinates will enter the commercial data market.
The uncomfortable reality: Even after auditing your apps and deleting your Advertising ID, you cannot fully prevent location tracking. Cell towers log your phone's approximate location whenever it is powered on. Wi-Fi networks record when your device connects. Bluetooth beacons in retail stores detect your presence. The only way to be completely invisible is to leave your phone at home — which is not practical for most people. The goal is not perfection. It is reducing your exposure from thousands of data points per day to a manageable few.
We send CCPA deletion demands to Venntel, Fog Data Science, and every other broker that buys your phone's location data. We also help you find and restrict the apps that feed the pipeline. $9.95/month.
Start Your Free 7-Day TrialNo credit card required. Cancel anytime. We never sell your data.