Ad SDKs Exploiting Default Settings to Harvest Location Data, EFF Reveals
A new investigation by the **Electronic Frontier Foundation (EFF)** has exposed how several prominent advertising Software Development Kits (SDKs) are configured to collect and share users' precise location data by default, often without explicit developer or user awareness. This practice funnels sensitive personal information into a vast ecosystem of ad systems and data brokers, with significant privacy implications for millions of mobile users.
Across mobile platforms, advertising companies provide developers with SDKs that streamline app monetization. However, these same SDKs can automatically feed usersβ location data into ad systems that location data brokers use to track people. Many developers may not even be aware of this privacy violation, let alone the users who are directly affected.
When developers integrate advertising SDKs that collect location data, they're putting users at risk of more than just creepy ads. Location information sourced from the advertising industry has been used for **ICE** investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking **US** military personnel.
Defaults matter, not just for users, but for app developers as well.
An **EFF** investigation has identified several advertising SDKs that publicly acknowledge collecting and sharing usersβ location *by default* when embedded in **Android** apps granted location permissions. If app developers donβt pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose usersβ location information.
This report explains how advertising SDKs can facilitate and encourage location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation.
## Data Brokers Harvest Location Information From Advertising Systems
When an advertising SDK collects and shares location data, it becomes part of a larger ecosystem that can include advertisers, ad tech companies, and location data brokers. **EFF** began investigating the location-sharing practices of various advertising SDKs to better understand the pipeline from mobile apps to location data brokers.
Location data brokers sell information on the precise movements of billions of people without their knowledge or meaningful consent. This data is primarily sourced from apps on peopleβs phones. Some apps partner with data brokers directly, using data-broker-developed SDKs or server-to-server transfers to sell usersβ location data. Other apps leak usersβ location data through advertising SDKs serving behaviorally-targeted ads through βreal-time biddingβ (**RTB**). In the process of auctioning off ad space, ad tech companies can broadcast user data to thousands of potential advertisers. Location data brokers have participated in these auctions not just to bid on ad space, but to collect personal information contained in bid requests.
Indiscriminate data sharing through **RTB** can lead app developers to unknowingly share their usersβ location with data brokers. In 2025, a hack of location data broker **Gravy Analytics** revealed thousands of apps that may have been sources of its data. When journalists reached out to the app developers, many claimed they had no relationship with or knowledge of **Gravy Analytics**. To prevent location information from being shared with data brokers through **RTB**, developers must understand the location-sharing practices of their advertising SDKs.
## How Advertising SDKs Leak Location Data
Developers donβt have to manually, or even intentionally, share location data for it to be broadcast through **RTB** auctions. Once a user grants an app permission to access their location, SDKs embedded in the app receive the same accessβthere are no SDK-specific location permissions. That means advertising SDKs can automatically collect usersβ location data and share it in bid requests.
While apps and SDKs can estimate a usersβ approximate location from their **IP** address without requesting any permissions, location permissions provide access to estimates that are more accurate and revealing. Precise location permissions give apps (and their embedded SDKs) access to location estimates within about 160 feet, but sometimes as accurate as 10 feet. Approximate location, a separate permissions level, gives apps access to a location estimate within about 1.2 square miles.
Developers and advertising SDKs also have a financial incentive to share location data, since it can increase bid prices for an appβs ad space. While many advertising SDKs require developers to configure a setting before collecting and sharing usersβ location data in ad requests, this is not always the case. **EFF** found several advertising SDKs who publicly acknowledge sharing usersβ location data *by default* when embedded in apps granted location permissions.
## EFF Identified Advertising SDKs That Share Location Data by Default
**EFF** reviewed the public developer documentation of dozens of widely-used advertising SDKs to identify how they handle and communicate with developers about location data. In the following sections, we highlight four advertising SDKs who engage in a particularly egregious practice: collecting a user's location by default for ad targeting whenever a user has given an app location permissions. We reached out to each SDK company and the referenced app developers for comment. One company responded, and as detailed below, subsequently updated its documentation in response to our questions. Another company responded with clarifications to its