Everyday Privacy

Who Buys Your Phone's Location Data (and How to Stop It)

By the RedactZero Team · July 25, 2026 · 9 min read

The short version

Your location usually does not leak. It is handed over by ordinary apps that embed a third-party advertising kit, which bundles your coordinates with your phone's advertising ID and sends them onward to data brokers and ad exchanges. Buyers include advertisers, analytics firms, other brokers, and government contractors. There is no single off switch, but there are four real ones: per-app location permissions, precise location, the advertising ID, and background refresh. Set those and the pipeline mostly dries up.

How location actually leaves your phone

Location almost always leaves through an app you installed on purpose. Many free apps embed a third-party advertising or analytics SDK - a bundle of someone else's code - that reads the location your phone already granted the app and forwards it to a company you have never heard of.

The Federal Trade Commission described this mechanism directly. In its January 2024 action against X-Mode Social and its successor Outlogic, the agency said the company collected precise location data "from third-party apps that incorporate its software development kit (SDK) into their apps, from its own mobile apps, and by purchasing location data from other data brokers and aggregators."

The consent screen you saw belonged to the app, not to the SDK. In the FTC's parallel case against InMarket Media, the agency quoted the actual prompts users saw: "Allow CheckPoints to access your location? This allows us to award you extra points for walking into stores." Nothing in that sentence tells you a data company is about to start logging where you sleep.

The advertising ID is the thread that ties it together

A single location ping is close to worthless. What makes location saleable is that every ping carries the same identifier, so thousands of scattered coordinates become one continuous trail belonging to one device. That identifier is your mobile advertising ID: the IDFA on iOS, the Advertising ID on Android.

The FTC was blunt about what that combination produces. Its X-Mode complaint states that the raw location data sold "is associated with mobile advertising IDs," that it "is not anonymized," and that it is "capable of matching an individual consumer's mobile device with the locations they visited." The agency added that some companies sell services specifically to match such data back to named people.

This is why the advertising ID is a genuine control point rather than a cosmetic setting. Break the identifier and you break the trail into unlinkable fragments.

Who actually buys it

Four groups dominate the buy side: advertisers and the ad exchanges that serve them, analytics firms measuring foot traffic for retail and real estate, other data brokers who resell and enrich the feed, and government contractors. The FTC named that last category explicitly rather than leaving it to inference.

In the X-Mode matter, the agency said the company sold consumer location data "to hundreds of clients in industries ranging from real estate to finance, as well as private government contractors." The FTC also alleged X-Mode told people their location would be used solely for ad personalization and location-based analytics, so buyers on the government side were invisible to the people being tracked.

The government purchasing side has its own paper trail. In report OIG-23-61, dated September 28, 2023, the DHS Office of Inspector General found that Customs and Border Protection, Immigration and Customs Enforcement, and the Secret Service "did not adhere to Department privacy policies or develop sufficient policies before procuring and using commercial telemetry data" - the department's term for commercially bought phone location data.

What regulators found when they looked inside

Between January 2024 and January 2025 the FTC brought a run of cases against location data companies, and the complaints put numbers on a market that normally publishes none. The scale figures below are the agency's own allegations, not industry estimates.

CompanyScale alleged by the FTCAction announced
X-Mode Social / OutlogicMore than 10 billion location data points ingested, advertised as 70% accurate within 20 meters or lessJanuary 9, 2024
InMarket MediaPrecise location from 100 million unique devices each year since 2016; nearly 2,000 audience segment listsJanuary 18, 2024
MobilewallaMore than 500 million unique advertising identifiers paired with precise location, January 2018 to June 2020December 3, 2024
Gravy Analytics / VenntelClaimed to collect, process and curate more than 17 billion signals from around a billion mobile devices dailyDecember 3, 2024

Source: FTC press releases of January 9, 2024, January 18, 2024, and December 3, 2024, and the FTC Office of Technology post "FTC Cracks Down on Mass Data Collectors" (March 4, 2024). The Gravy Analytics and Venntel order was finalized January 14, 2025.

The orders matter as precedent, but they bind four companies. Nothing about them removes the SDK from the apps still on your phone.

Why "anonymized" location is not anonymous

Location is self-identifying in a way that names are not. A trail that parks at one address every night and a different one every weekday morning has already told you where a person lives and works, and those two facts together narrow the world to a handful of people, often to exactly one.

Researchers quantified this in 2013. In "Unique in the Crowd: The privacy bounds of human mobility," published in Scientific Reports, de Montjoye and colleagues studied fifteen months of mobility data for 1.5 million people and found that four spatio-temporal points were enough to uniquely identify 95% of individuals, at hourly resolution with the spatial precision of ordinary carrier antennas.

Commercial location data is usually far more precise than that. So when a company calls its feed anonymous because it lacks your name, the claim is about the columns in the file, not about whether the file identifies you. The FTC has said the same thing in its own words in the complaints above.

Step 1: audit location permissions on iPhone

Start where the data originates. On iOS the whole per-app list lives in one screen, and walking it takes about five minutes. Apple's iPhone User Guide directs you to Settings, then Privacy and Security, then Location Services, then tap an individual app to review or change its access.

For each app, ask what it needs location for while you are not using it. Almost nothing does. Set anything that is not maps, navigation, ride-hailing, or weather to Never or to the ask-me option. Apple notes that if you set an app to Ask Next Time, you are prompted again the next time it tries.

Then handle accuracy separately. On the same per-app screen, Apple's guidance is to "leave Precise Location turned on" only where you need exact positioning, and to turn it off to "share only your approximate location." A coupon app does not need to know which side of the street you are on.

Step 2: audit location permissions on Android

Android exposes the same two decisions - who gets location, and how precisely - in one place. Google's Android Help documentation describes the path as Settings, then Location, then App location permissions, with each app assignable to one of four levels.

Those levels are "Allow all the time," "Allow only while using the app," an ask-every-time option, and "Don't allow." Move everything you can down to while-using or lower. All-the-time access is the setting that produces the overnight-and-workday pattern described earlier, and very few apps have a legitimate claim to it.

Underneath the permission choice sits a separate toggle Google labels "Use precise location." Turn it off for anything that only needs to know your city or neighborhood. Menu wording shifts a little between Android versions and manufacturers, so if the labels do not match exactly, look for the location screen and then the per-app list inside it.

Step 3: cut off or delete your advertising ID

Most people skip this step, and it is the one that breaks the trail rather than just narrowing it. Both platforms now let you sever the identifier, though they do it differently, so the mechanics are worth getting right.

On Android, Google's developer documentation for the Advertising ID describes the user path as Settings, then Privacy, then Ads, then Delete Advertising ID. Google states that once deleted, "any attempts to access the identifier will receive a string of zeros instead of the identifier." On some devices the Ads screen sits under a Security and privacy menu instead.

On iOS the equivalent control is App Tracking Transparency. Apple's guide says to go to Settings, then Privacy and Security, then Tracking, and turn off "Allow Apps to Request to Track," which stops all apps from asking. Apple describes the permission itself as covering tracking "for advertising or to share your information with data brokers." While you are there, turn off Personalized Ads under Privacy and Security, then Apple Advertising.

Step 4: close the background channels

Permissions govern what an app may collect. Background execution governs how often it gets the chance. An app that only runs when it is on screen produces a thin, gappy trail; one that wakes up all day produces a dense one that reveals routines. Trimming background activity shrinks the second case toward the first.

On iPhone, Apple's support documentation puts this under Settings, then General, then Background App Refresh, where you can turn it off entirely or app by app. Turn it off for anything that does not need fresh content the second you open it. On Android, look in each app's settings for background data and battery restriction options, which serve the same purpose.

Two more worth checking on iOS: under Location Services there is a System Services list where you can review location-based system features individually, and Apple notes that location can also be derived from Bluetooth and Wi-Fi connections, not only GPS. Turning off Bluetooth and Wi-Fi scanning when you are not using them removes another positioning signal.

Step 5: use the opt-outs the industry does offer

Industry opt-outs are weaker than device settings because they rely on companies honoring a preference rather than on your phone withholding data. They are still worth twenty minutes, because they cover the advertising middlemen your device settings cannot reach directly.

The Digital Advertising Alliance runs AppChoices, a mobile app that lets you opt out of interest-based advertising with participating companies individually or all at once. The Network Advertising Initiative publishes similar guidance for mobile devices. Neither is a legal guarantee, and neither covers a broker that never joined the program.

If you live in California, the state's Delete Request and Opt-out Platform sends one deletion request to every registered data broker at once, and location brokers that register are included. Our California DROP guide walks through it, and what to do if you are not in California covers the alternative.

What this fixes, and what it does not

Done properly, these five steps stop most new commercial collection from your phone. What they do not do is reach backward. Trails already sold sit in databases you cannot see, and no toggle retroactively deletes them - FTC orders and state deletion rights are the only levers there, and both are slow.

They also do not touch the other half of your exposure. People-search sites publish your address, phone number, and relatives from public records, entirely separately from anything your phone does. If your goal is to be harder to find rather than harder to target, that side matters at least as much, and our weekend digital footprint cleanup covers it step by step. Where location data intersects with a physical safety concern, treat it as urgent and read our guide to data brokers and stalking safety first.

Finally, none of this is one-and-done. New apps arrive with fresh permission prompts, and an app you granted location to a year ago may have added an SDK since. Re-walk the permission list every few months, the same way you would re-check a broker opt-out.

See what is already public about you

Your phone is one pipeline. Run a free exposure scan to see which data brokers likely list your name and address, plus any breaches tied to your email - no account, nothing stored.

Run a free exposure scan

Frequently asked questions

Who actually buys phone location data?

Advertisers and ad exchanges, retail and real-estate analytics firms, other data brokers, and government contractors. In its January 2024 case against X-Mode Social and Outlogic, the FTC said the company sold location data to hundreds of clients in industries ranging from real estate to finance, as well as to private government contractors.

Does my phone carrier sell my location too?

Carrier location sharing is a separate pipeline with its own history of enforcement, and the app-and-SDK pipeline described here runs independently of it. The settings in this guide only control what apps on your phone collect and share, so they do not touch anything your carrier does.

Is anonymized location data really anonymous?

No. The FTC stated plainly in its X-Mode complaint that the raw location data sold was not anonymized and was capable of matching a consumer's mobile device with the locations they visited. A trail that sits at one address overnight and another every weekday identifies a home and a workplace.

What is a mobile advertising ID and why does it matter?

It is a resettable identifier your phone gives to apps for ad targeting - the IDFA on iOS and the Advertising ID on Android. It is the thread that ties thousands of separate location pings into one continuous trail for one device, which is what makes location data sellable.

How do I delete my advertising ID on Android?

Google's documentation says to open Settings, tap Privacy then Ads, then tap Delete Advertising ID and confirm. On some devices this sits under a Security and privacy menu instead. After deletion, apps that request the identifier receive a string of zeros.

What is the equivalent of that on an iPhone?

Go to Settings, then Privacy and Security, then Tracking, and turn off Allow Apps to Request to Track. Apple's guide says every app that then asks is treated as if you tapped Ask App Not to Track. Separately, turn off Personalized Ads under Privacy and Security, then Apple Advertising.

Will turning off location tracking break my apps?

Rarely, if you make the change app by app. Maps, ride-hailing, and weather apps genuinely need location while you use them, so leave those on While Using. Games, flashlights, shopping-rewards apps, and most social apps work fine on Never or on approximate location.

Do government agencies really buy this data?

There is documented use. In report OIG-23-61, dated September 28, 2023, the DHS Office of Inspector General found that CBP, ICE, and the Secret Service procured and used commercially bought phone location data without first completing the privacy assessments required by DHS policy and the E-Government Act of 2002.

Does opting out delete the location history already collected about me?

Not by itself. Changing your settings stops new collection but does not reach back into databases that already hold your trail. FTC orders have forced specific companies to delete historic location data, and some state privacy laws give you a deletion right, but neither is automatic.

Sources: FTC press releases on X-Mode Social and Outlogic (January 9, 2024), InMarket Media (January 18, 2024), Gravy Analytics and Venntel (December 3, 2024 and January 14, 2025), and Mobilewalla (December 3, 2024); FTC Office of Technology, "FTC Cracks Down on Mass Data Collectors" (March 4, 2024); DHS Office of Inspector General report OIG-23-61 (September 28, 2023); de Montjoye et al., "Unique in the Crowd: The privacy bounds of human mobility," Scientific Reports (2013); Apple iPhone User Guide and Apple Support on Location Services, app tracking permissions, personalized ads, and Background App Refresh; Google Android Help on app location permissions and Google Play Console documentation on the Advertising ID; Digital Advertising Alliance (AppChoices) and Network Advertising Initiative. Additional RedactZero opt-out guides are updated and dated individually.