Mobile Ad Software Encourages Location Data Sharing, EFF Report Finds
Developers Must Beware of Ad Libraries that Betray Users’ Privacy SAN FRANCISCO – Some software development kits (SDKs) provided by advertising companies to help developers monetize their apps are automatically feeding users’ location data into systems that location data brokers use to track people, an Electronic Frontier Foundation (EFF) report found . EFF began investigating the…
San Francisco – Ad libraries from certain advertising companies are inadvertently sharing users' location data with brokers, according to a report by the Electronic Frontier Foundation (EFF). The investigation examined the practices of several software development kits (SDKs) provided by advertising firms to help developers monetize their apps. It found that the default settings of these SDKs automatically transmit users' location data to systems used by brokers for tracking purposes, without users' knowledge or consent.
The investigation revealed how these SDKs can facilitate location data sharing through privacy-invasive defaults, financial incentives, and unclear documentation. According to Lena Cohen, an EFF staff technologist, "Defaults matter, not just for users, but for app developers as well. If app developers don't pay close attention to the location-sharing settings of their advertising tools, they could inadvertently expose users' location information."
Four advertising SDKs – InMobi, BidMachine, Verve’s HyBid, and Huawei’s Petal Ads – were highlighted for their default collection and sharing of users' location data for ad targeting whenever users grant the app location permissions. However, Cohen and Bill Budington, an EFF senior staff technologist, emphasized that this does not mean all SDKs protect location data adequately or that developers never intentionally share location data when it's not the default.
The potential misuse of location data collected by advertising SDKs is concerning. Budington pointed out that such data has been used for investigations by the Immigration and Customs Enforcement (ICE) agency, by global spy tools, to out a gay priest, to track union organizers, and to monitor US military personnel. Developers have a responsibility to protect users from these potential harms, regardless of the default settings of advertising SDKs.
The EFF report can be found at https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy. For more information on location data brokers, visit https://www.eff.org/issues/location-data-brokers, and for more on SDKs, see https://www.eff.org/deeplinks/2022/06/how-federal-government-buys-our-cell-phone-location-data. Contact for the report includes William Budington at bill@eff.org and Lena Cohen at lcohen@eff.org.
Written by urgent.news from EFF Deeplinks's reporting — not their text. Machine-written — it may contain errors, so check the original before relying on it.