Your mobile apps, or the apps your employees and customers use, could be silently broadcasting precise location data to thousands of unknown parties. This isn’t a glitch; it’s a feature of many advertising SDKs embedded in apps, and it creates massive app data leaks that most businesses don’t even know exist. At CTS, we’ve seen firsthand how these hidden defaults can expose your business to significant privacy compliance risks and compromise user trust.
The stakes are incredibly high. Once an app has location permission, any embedded advertising SDK gets the same access, often collecting and sharing that data by default. Reports suggest that in 2025, a breach of location data broker Gravy Analytics exposed thousands of apps feeding this pipeline, with many developers claiming they had no idea. This isn’t just about creepy targeted ads; location data harvested by ad-tech SDKs has been used for serious real-world harms, including tracking individuals in sensitive situations.
I’ve watched the tech landscape evolve for 30 years, from structured cabling to cloud architecture, and every decade brings a new flavor of hidden risk. Today, it’s these invisible data flows from your mobile ecosystem. Precise location data can be accurate down to about 10 feet, and even “approximate” location can pinpoint you within a 1.2 square mile radius. This information is broadcast in real-time bidding (RTB) ad auctions, and location data brokers are joining these auctions not to buy ad space, but to harvest the location data in bid requests. It’s a goldmine for them, and a minefield for you.
Here’s what nobody is really talking about: the financial incentives. Many SDKs, like InMobi (reportedly the 10th most popular Android advertising SDK, reaching billions of users), explicitly state that “location-enriched impressions typically yield higher revenue.” They don’t make it easy to turn off, because their business model depends on it. We’ve seen client IT managers assume that if an app requests location, it’s for the app’s core function. They never consider that a third-party ad module inherited that permission and is now selling it off. It’s a classic supply-chain problem, but for data.
How to Prevent App Data Leaks
Stopping these app data leaks requires proactive measures. You can’t just hope for the best; you need a strategy to audit and control your mobile data footprint. The EFF has highlighted several SDKs that share location by default, including InMobi, BidMachine, Verve, and Huawei’s ad SDK. This isn’t an exhaustive list, but it shows the scope of the problem. Here are four concrete steps we recommend:
- Audit All Published and Used Apps: Every mobile app your business publishes, or any critical app your employees rely on, needs a thorough audit. This isn’t just about the app developer; it’s about every third-party SDK embedded within it. Use tools that can decompile apps or monitor network traffic to understand what data is being sent where.
- Review Ad SDK Location Defaults: For any app using advertising SDKs, dig into the developer documentation. Don’t just skim it. Look specifically for settings related to location data collection and sharing. Disable unnecessary sharing by default. If the SDK makes it hard to opt out, question why you’re using it.
- Implement Vendor and SDK Due Diligence: Treat ad SDKs like any other critical vendor. What are their data privacy policies? Where do they store data? Who do they share it with? If they can’t provide clear answers, or if their defaults are privacy-invasive, find an alternative. This is a supply-chain risk that can hit your compliance hard.
- Request Minimum Location Permissions: When developing or configuring apps, always request the absolute minimum location permission necessary. If an app only needs approximate location, don’t ask for precise. If it doesn’t need location at all, don’t request it. This limits the data an embedded SDK can inherit.
This isn’t just about avoiding a fine; it’s about maintaining customer trust and protecting your business reputation. Get on top of your app data leaks this week.
Frequently asked questions
What is an advertising SDK and how does it cause data leaks?
An advertising SDK (Software Development Kit) is code developers embed in apps to show ads. When an app gets location permission, the SDK often inherits that access and can automatically collect and broadcast user location data to ad systems and data brokers by default.
Why do advertising SDKs collect location data?
Advertising SDKs primarily collect location data because it allows for more targeted advertising, which reportedly increases ad revenue for the app developer. Many SDKs have these settings enabled by default, often with financial incentives highlighted in their documentation.
What are the risks of these app data leaks?
The risks include privacy violations, potential misuse of sensitive location data for tracking or investigations (as reported by EFF), damage to your business's reputation, and non-compliance with data privacy laws like GDPR or CCPA.
How can Complete Tech Solutions help my business address this?
At Complete Tech Solutions, we offer cybersecurity consulting and audit services to identify and mitigate app data leaks. We can help you review your mobile app ecosystem, assess third-party SDK risks, and implement robust data governance strategies to ensure compliance and protect user privacy.
Related reading
- 1 Backup Mistake Costing Millions (3-2-1 Rule)
- We Saw 4 Businesses Lose Everything to Bad Backups
- 90% of Companies Miss These 3 Backup Gaps
Ready to upgrade your technology?
Complete Tech Solutions designs, installs, and supports IT, cabling, security, and network infrastructure for businesses across Grand Rapids, West Michigan, and nationwide. Schedule a free site assessment and we’ll map out the right solution for your space and budget.
Learn more about our Consulting services.