For many apps, granting permission to access your device’s precise location makes sense. Your favorite weather app needs to know where you are to get the forecast for the day, and your fitness app needs it to track your running route. 

However, some apps also inadvertently share their users’ location data with third parties, including advertisers and data brokers, because the app developer may not be aware that this data-sharing setting is enabled by default.

New data from the Electronic Frontier Foundation aims to warn app developers that some of the third-party code they include in their apps may also collect users’ location data when they grant the app the appropriate permissions. 

If the developer does not actively disable data collection, the code snippet (known as a software development kit, or SDK) will inherit the app’s permissions and collect the user’s precise location data.

The EFF states that many developers may not realize they are sharing their users’ location data with third parties by default and has called on app creators to disable unnecessary data collection wherever possible. 

While ad SDKs are positioned as a way for developers to monetize their apps, the downside is that users’ location histories are passed on to data brokers, who monetize this information and then sell it to the military, governments, and intelligence agencies such as the FBI. Furthermore, this data poses a security and privacy risk in the event of a breach or theft, which some data brokers have already experienced.

Among the Android apps that the EFF found to be covertly sharing users’ location data were two apps that have been downloaded a total of 60 million times to date.

In its tests, the EFF analyzed the network traffic of apps and identified which services were receiving users’ location data.

Bill Budington, a senior technologist at the EFF, told TechCrunch that the SDKs they studied represent only a small percentage of the broader ad ecosystem, but nevertheless claim to reach billions of users across tens of thousands of apps. This provides some insight into the scale of this type of location data collection. 

The EFF report states that “there are no location permissions specific to SDKs,” meaning that once a user allows their location data to be shared with an app, that data is also shared with advertisers. Companies that offer these SDKs are generally incentivized to have their clients collect more data.

“App-level location permissions alone cannot serve as a signal of meaningful consent for the collection and sharing of location data by third-party ad SDKs,” the EFF wrote. “Ad SDKs should not have the sharing of personal data enabled by default, especially sensitive data such as a person’s location.”