EFF probe finds four major ad SDKs harvesting precise location data
An investigation by the Electronic Frontier Foundation (EFF) found that four advertising SDKs—InMobi, BidMachine, Verve, and Huawei—collect and share precise user location data by default in Android applications. The study highlights how these technical defaults facilitate location-data harvesting by third-party brokers through real-time bidding (RTB) auctions, often without the developer's full awareness.
Key Takeaways
- Four SDKs—InMobi, BidMachine, Verve, and Huawei—collect precise location data by default once app-level permissions are granted.
- Technical analysis confirmed apps like QR Scanner (50M+ downloads) and GPS Speedometer (10M+ downloads) transmit precise coordinates via BidMachine.
- InMobi documentation explicitly recommends sharing precise location, stating that location-enriched impressions typically yield higher revenue.
- Verve's open-source HyBid SDK rounds coordinates to two decimal places, yet can still achieve precision within 0.5 square miles.
- The EFF identified a gap in Android's permission model where SDKs automatically inherit location permissions granted to the host app.
Why It Matters
The systematic leakage of precise location data through SDK defaults exposes developers to significant regulatory and reputational risk, as these signals are often ingested by data brokers without clear consent. This practice undermines the privacy controls of mobile operating systems, effectively turning app-level permissions into a pipeline for third-party surveillance. As regulators increasingly target the real-time bidding (RTB) ecosystem, companies relying on these SDKs must audit their data manifests to ensure compliance with emerging data minimization standards. Watch for a potential surge in FTC enforcement actions or updated Google Play Store policies specifically targeting SDK-level data inheritance in late 2026.
Additional Context
The EFF investigation aligns with a broader regulatory crackdown on the location data industry. Per the FTC, May 2026, data broker Kochava and its subsidiary reached a settlement prohibiting the sale of sensitive location data without affirmative express consent, resolving a long-standing lawsuit over the tracking of movements at health clinics and places of worship. Similarly, in January 2025, the FTC issued a final order against data broker Mobilewalla for tracking sensitive locations, following a massive 17-terabyte data breach at Gravy Analytics that exposed the location history of millions of users across apps like Tinder and MyFitnessPal. Technological safeguards are also shifting to address these leaks at the platform level. Per Google, April 2026, Android is introducing a streamlined 'location button' for one-time precise access, aiming to replace persistent 'always-on' permissions that SDKs frequently exploit. These updates coincide with the activation of 19 comprehensive state privacy laws in the U.S. as of mid-2026, including the California Delete Act's DROP platform. This platform, operational as of January 2026, allows residents to file a single request to delete personal data from hundreds of registered data brokers simultaneously, significantly complicating the business models of ad tech companies that rely on silent data harvesting through third-party libraries.
Read full article at eff.org
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source