Android application developers might be inadvertently disclosing their users’ location information to advertisers.

Android application developers might be inadvertently disclosing their users’ location information to advertisers.

For numerous applications, allowing access to your device’s exact location is logical. Your preferred weather application needs to understand your location to provide the daily forecast, just like your favorite fitness application for monitoring your running path. 

However, certain applications unintentionally share their users’ location information with third parties, including advertisers and data brokers, as the app developer might be unaware that this data-sharing option is set to active by default.

Recent research from the Electronic Frontier Foundation aims to alert app developers that some third-party code integrated into their applications may also gather their users’ location data once permission has been granted to the app. 

Unless the developer explicitly disables this collection, the code snippet (known as software development kits, or SDKs) will automatically acquire the app’s permissions and collect the user’s exact location data.

The EFF states that many developers may not be aware they are, by default, sharing their users’ location data with third parties and encouraged app creators to turn off unnecessary data collection whenever feasible. 

While advertising SDKs are marketed as a method for developers to monetize their apps, the trade-off is that users’ location histories are passed to data brokers, who profit from that data, which can subsequently be sold to military organizations, governments, and intelligence agencies, such as the FBI. This data also poses a security and privacy threat if it is hacked or stolen, a risk that some data brokers have faced.

Among the Android apps identified by the EFF that were discreetly sharing users’ location data were two that had been downloaded a total of 60 million times to date.

The EFF conducted its analysis by examining the apps’ network traffic and determining which services were receiving users’ location data.

Bill Budington, a senior staff technologist at the EFF, informed TechCrunch that the SDKs they reviewed represent a minor fraction of the larger advertising landscape, yet they claim to engage billions of users across tens of thousands of applications. This illustrates the extent of this form of location data harvesting. 

The EFF’s report mentioned that there are “no SDK-specific location permissions,” meaning that once the user permits their location data to be shared with the application, that data is likewise shared with advertisers. The entities providing those SDKs are typically motivated commercially to encourage their clients to gather more data.

“App-level location permissions alone cannot convey significant consent to location collection and sharing by third-party advertising SDKs,” stated the EFF. “Advertising SDKs should not default to sharing personal data, particularly for sensitive information such as an individual’s location.”

When you make purchases through links in our articles, we may receive a small commission. This doesn’t influence our editorial independence.

Leave a Reply