Across mobile platforms, advertising companies provide developers with software development kits (SDKs) that make it easy to monetize their apps. But those same SDKs can automatically feed users’ location data into
ad systems that location data brokers use
to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.

When developers let advertising SDKs collect location data, they’re putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for
ICE investigations
,
global spy tools
,
outing a gay priest
,
tracking union organizers
, and
tracking US military personnel
.

Defaults matter, not just for users, but for app developers as well.

An EFF investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing users’ location
by default
when embedded in Android apps granted location permissions. Defaults matter, not just for users, but for app developers as well. If app developers don’t pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users’ location information.

This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.

Contents:

Data Brokers Harvest Location Information From Advertising Systems

How Advertising SDKs Leak Location Data

EFF Identified Advertising SDKs That Share Location Data by Default

InMobi Encourages Keeping Location Sharing Enabled By Highlighting Financial Incentives

BidMachine Updates Previously Inaccurate Developer Documentation After EFF's Technical Analysis Observed Precise Location Data Collection

Verve Emphasizes Consent More in its Play Store Language Than its Configuration Guide

Huawei Highlights Financial Incentives for Location Data Sharing Before Showin

… [more]