Are your Android apps secretly sharing your location with advertisers? Some developers are accidentally leaving on this critical data-invading setting when using third-party SDKs

Law enforcement operations have been launched using data gathered from invasive apps

by · TechRadar

News By Benedict Collins Published 5 August 2026

(Image credit: Shutterstock)

Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter


  • Some Android apps contain invasive data-gathering SDKs that gather location data without user consent
  • Location data is then sold to advertisers, or purchased by law enforcement for targeting and tracking US citizens
  • Developers, regulators, and legislators should work together to remove the incentive for SDKs to gather this data

Monetizing an app is a key part of development. But developers frequently use third-party software development kits (SDKs) rather than develop their own monetization tools.

These SDKs often come preloaded with data-collection mechanisms that allow developers to choose what types of user data it would like to collect to sell to advertisers. Sometimes, developers leave every setting on.

According to a warning from the Electric Frontier Foundation, SDKs with their default data collection settings left on are harvesting highly invasive location data, which is then passed on to advertisers and data brokers. Critically, this data can then be purchased and used by intelligence agencies, law enforcement, and even the military.

Latest Videos FromTechRadarWatch full video here:

Authorities using advertising location data for questionable operations

Location data is very lucrative for advertisers. It helps increase the bid-price for advertising space, allowing local businesses or services to target those nearby with adverts.

The level of invasive data collected depends on the permissions the app asks for. But crucially, any permissions granted to the app itself are also passed on to the SDK by default.

Where approximate location data determined by the device IP is accurate to about 1.2 square miles, precise location data can narrow that area down to about 160 feet, or in some circumstances as small as 10 feet.

In some cases, the SDKs include documentation for developers to ensure restricted data processing is turned on for users that are subject to GDPR and COPPA, but these settings are not turned on by default.

Are you a pro? Subscribe to our newsletter

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Contact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsors