Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds

An EFF report reveals that advertising software development kits (SDKs) in mobile apps often automatically share users' location data with brokers through privacy-invasive defaults and unclear documentation, without meaningful consent. Developers risk exposing users' location unless they carefully adjust settings, prompting calls for regulatory action.

A new EFF report found that advertising software development kits (SDKs) automatically feed users’ location data to data brokers without meaningful consent. Four SDKs—InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads—collect location by default whenever the app has permission. The report warns that such data has been used for ICE investigations, spy tools, and tracking union organizers. EFF urges developers to override defaults and regulators to act, as users should not have to take extra steps to protect their privacy.