The app’s location permission can end up feeding a second system the user never sees. In these Android ad stacks, the SDK can turn one granted permission into a standing stream to brokers and advertisers, outside the app’s own privacy settings.
EFF reviewed public developer docs for dozens of widely used ad SDKs and identified four that collect and share location by default when an Android app has location permission: InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads. The report says the behavior is reinforced by privacy-invasive defaults, financial incentives, and unclear documentation, so developers may expose location data without realizing the broker-facing feed exists.
The risk persists after the app owner thinks they have controlled the setting, because the sharing path lives in the embedded SDK. That creates a third-party location dataset that can outlast the app’s own UI choices and user understanding.
Android app developers may be unwittingly sharing their users' location data with advertisers | TechCrunch
New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users' location data when they grant permission to the app.
Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds
SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found.
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing users’ location by default when embedded in apps granted location permissions.