Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
A new EFF report warns that advertising SDKs in Android apps often collect and share users’ location data by default, exposing them to tracking by data brokers, law enforcement, and other entities—often without developers’ knowledge.
EFF investigation found several Android advertising SDKs automatically collect and share users’ precise location data by default when the app has location permission. This data feeds location brokers used for ICE investigations, tracking military personnel, outing a gay priest, and other abuses. Developers may be unaware of the privacy violation. SDKs like InMobi, BidMachine, Verve, and Huawei employ defaults, financial incentives, and unclear documentation to encourage location sharing. Defaults matter; developers must check settings to avoid exposing users.