Breaking
Saturday, 29 August 2026
Sign In Register
Technology

Developers Warned About Hidden Location Privacy Risks in Ad SDKs

EFF report reveals how advertising SDKs in apps automatically share users' location data with brokers, risking privacy violations and misuse in investigations.

LeadNews24 · Aug 29, 2026 · 3 min read
Developers Warned About Hidden Location Privacy Risks in Ad SDKs

The use of advertising software development kits (SDKs) in mobile apps raises significant concerns about user location privacy, according to a new investigation by the Electronic Frontier Foundation (EFF). These SDKs, provided by advertising companies, enable developers to monetize their apps but may also automatically transmit users’ precise location data to ad systems and data brokers without explicit awareness from either developers or users. The EFF report highlights how default settings, financial incentives, and unclear documentation can lead to inadvertent privacy violations, exposing users to invasive tracking and potential misuse of their location information.

Location data collected through advertising SDKs can be exploited beyond targeted advertising. Investigations have shown that such data has been used in law enforcement operations, global surveillance, exposing personal information, and even tracking military personnel. The EFF’s findings indicate that several advertising SDKs publicly acknowledge collecting and sharing users’ location information by default when apps are granted location permissions. This practice places users at risk of unintended data exposure, often without developers realizing the implications.

The EFF examined how location data flows from mobile apps through advertising systems and into the hands of data brokers who aggregate and sell precise movement data without meaningful consent. Some apps directly partner with data brokers using specialized SDKs or server transfers, while others leak location information through real-time bidding (RTB) processes in advertising auctions. In these auctions, ad tech companies broadcast user data to thousands of potential advertisers, including data brokers who participate not only to bid on ad space but also to harvest personal information contained in bid requests.

Developers may unknowingly facilitate this data sharing when users grant location permissions. Once permission is granted, advertising SDKs embedded in the app can automatically access and transmit location data through RTB auctions, often without additional configuration. This automatic collection can yield highly accurate location estimates—within 160 feet or even as precise as 10 feet—far beyond what IP-based approximations can provide.

Financial incentives also encourage the sharing of location data. Advertising SDKs often highlight increased revenue potential when location data is included in ad requests, motivating developers to enable location sharing even if it is not necessary for the app’s functionality. The EFF identified several SDKs that enable location sharing by default when precise location permissions are granted, with documentation explicitly recommending this practice for better ad targeting.

Among the SDKs flagged by the EFF is InMobi, which claims to reach over two billion users across 150 countries. Its developer documentation states that the SDK “automatically forwards location signals when available” and emphasizes financial benefits, noting that location-enriched ad impressions typically yield higher revenue. The documentation also encourages developers to request precise location permissions and Wi-Fi network information to improve ad targeting accuracy.

Another SDK, BidMachine, updated its developer documentation following technical analysis by the EFF, which revealed that precise location data was being collected by default. The changes came after the EFF’s review highlighted discrepancies in how location data practices were communicated to developers.

The EFF’s investigation underscores the need for developers to carefully review the privacy policies and default settings of advertising SDKs they integrate into their apps. By understanding how location data is collected and shared, developers can take steps to minimize privacy risks and ensure compliance with data protection regulations such as GDPR and COPPA.

#MobilePrivacy #AdvertisingSDKs #LocationData #EFF #DataBroker #InMobi #BidMachine #AppSecurity

Originally reported by Electronic Frontier Foundation (EFF). View original source

Comments (0)

Comments are moderated and may take a little while to appear.

No comments yet — be the first to weigh in.

Related Coverage

Most Read

We use cookies to improve your experience and analyze traffic.

Manage cookie preferences

Essential

Required for the site to function. Always active.

Analytics

Helps us understand how readers use the site.

Marketing

Used to personalize ads shown to you.