EFF Report Warns: Mobile Ad Tools Quietly Push Apps to Share Where You Go
New research from the Electronic Frontier Foundation reveals how advertising software in mobile apps aggressively nudges users to surrender real-time location data, often without clear consent or understanding of where i…
A new report from the Electronic Frontier Foundation (EFF) exposes a pervasive and often hidden practice: the mobile advertising industry is systematically designing its software to encourage apps to request and share your precise location data. The report, released this week, examines dozens of popular advertising software development kits (SDKs), the pre-built toolkits that app developers integrate to show ads, and finds that many are configured by default to prompt for continuous location access, often bundling the permission with vague rewards or essential functions. This means that when you install a weather app, a game, or a shopping tool, the ad code inside it may be quietly steering you toward granting permission to track your every movement, even when the app is not in use.
The EFF analysis goes beyond simple permission requests. It details how some advertising SDKs link location sharing to features like "personalized deals" or "local offers," framing the constant collection of GPS coordinates as a benefit rather than a privacy trade-off. Once granted, this location data is not just used to serve ads within that single app. Instead, it flows into a vast network of data brokers and ad exchanges, where it can be combined with other identifiers, such as your device’s unique advertising ID, IP address, and browsing history from other apps, to build a minute-by-minute profile of your real-world routines. The report highlights a disturbing lack of transparency: many users have no idea that the free app they downloaded is monetizing their visits to doctors, schools, places of worship, or private homes. In some cases, the location data is collected with sub-meter accuracy, enough to reveal exactly which storefront you lingered in front of or which floor of a building you visited.
This aggressive collection is not accidental. The EFF notes that ad SDK providers often instruct app developers to request location permissions early in the onboarding process, using carefully crafted dialogue boxes that frame denial as a loss of functionality. A common pattern is to ask for “always on” location access upfront, even when the core feature of the app, such as a flashlight or a note-taking tool, has no need to know where you are. Some SDKs go further and track location via alternative methods like Wi-Fi network scanning and Bluetooth beacon detection, even if GPS permission is denied, stitching together a location profile from ambient signals. The report serves as a stark reminder that “free” apps are often far from free; the real product being sold is your daily path through the world.
So what can be done? While the report makes several policy recommendations, including urging regulators to enforce stricter consent rules, there are immediate steps that everyday internet users can take to push back. One of the most effective shields lies in how your device resolves internet addresses. Every time an app or website loads content, it uses the Domain Name System (DNS), the internet’s phone book, to translate human-readable names like eff.org into machine-friendly numbers. By routing your DNS queries through an encrypted, privacy-respecting resolver, you can stop your internet provider and other intermediaries from logging the digital side of your whereabouts. Although DNS encryption does not directly block location tracking by apps, it plugs a crucial leak: it prevents network observers from compiling a list of every online service your phone talks to, which alone can reveal a lot about your habits and physical location.
This is where AEU DNS becomes a practical ally. As a European, privacy-first DNS resolver, AEU DNS supports encrypted DNS over HTTPS, TLS, and QUIC. This means that even if a rogue advertising network tries to correlate your IP address with your location history, your DNS lookups remain hidden from prying eyes on the network path. It is a simple, powerful layer of defense that complements app permission reviews. Combined with the other tips listed below, it helps shrink the digital shadow that location-hungry ad tools rely on to track you across both the online and offline worlds.
Terms explained
- DNS
- The Domain Name System acts like the internet’s phone book, turning website names you type into numeric addresses that computers use to find each other.
- Encrypted DNS
- A way of securing DNS lookups so that your internet provider or network snoops cannot see which websites you are visiting; common methods include DNS over HTTPS and DNS over TLS.
- SDK
- A Software Development Kit, a pre-made set of code tools that app creators plug into their programs to add features, such as advertising, without building them from scratch.
- Tracking
- The automated collection of your behavior data, like where you go or what you tap, by companies in order to build a profile used for advertising or other analysis.
- Location data
- Information that marks where you are or have been, often gathered from your phone’s GPS, nearby Wi‑Fi networks, or cell towers, sometimes pinpointing you to within a few meters.
How to protect yourself
- Open your phone’s settings and go to the location permissions section; turn off location access for any app that does not genuinely need to know where you are, especially free games, utilities, and shopping apps.
- When an app asks for location during use, choose “Only while using the app” instead of “Always,” and avoid apps that force you to accept full tracking before you can try them.
- Set up a private, encrypted DNS resolver like AEU DNS on your device by entering its secure address in your network settings; this hides which websites and services your apps contact, making it harder for trackers to piece together your loc
- Regularly check the advertising ID settings on your device (under privacy settings) and reset it periodically, or opt out of ad personalization altogether to prevent long-term profiling.
- If you use a free Wi‑Fi network, always combine it with a VPN or encrypted DNS to stop the network operator from logging your device’s internet traffic and inferring your location from it.
Source: eff.org
