Illustration for How to Check if an App Is Selling Your Location Data

How to Check if an App Is Selling Your Location Data

That flashlight app probably doesn’t need to know where you’ve been all day. But there’s a decent chance it knows exactly that, and that somewhere, that detail is worth money to someone.

Location data is one of the most valuable things your phone collects, and one of the least visible. You can’t see it leave your device. There’s no notification that says “this app just sold your movements to a data broker.” The only way to find out what’s happening is to go look, and most people never do.

Here’s how to actually check.

Why location data is worth so much

Location data doesn’t just say where you are right now. Strung together over weeks and months, it says where you live, where you work, where your kids go to school, what doctor you visit, and what places of worship or events you attend. That kind of pattern is valuable to advertisers, and it’s also valuable to data brokers who bundle it up and resell it to whoever will pay.

Not every app that asks for your location is doing this. Plenty of apps need it for the feature to work at all, a weather app or a map app being the obvious examples. The problem is the apps that ask for location access they don’t need, then pass that data along as a business model. Your job isn’t to panic about every app on your phone. It’s to figure out which ones deserve that access and which ones are just collecting it because you let them.

Check what permissions each app actually has

Start with your phone’s settings rather than the app itself. Both iPhone and Android let you see, app by app, what each one is allowed to access.

On iPhone: Go to Settings, then Privacy & Security, then Location Services. You’ll see a list of every app with a location permission and whether it’s set to Never, Ask Next Time, While Using the App, or Always.

On Android: Go to Settings, then Location, then App Location Permissions. You’ll see a similar breakdown.

What to look for:

  • Apps with “Always” access that have no real reason to track you when they’re closed. A ride-share app might need this. A note-taking app doesn’t.
  • Apps you rarely open that still have location turned on. If you haven’t used it in months, it doesn’t need to know where you are.
  • Any app whose location need isn’t obvious. If you can’t explain in one sentence why a game or a shopping app needs your exact location, that’s worth a second look.

Switch anything unnecessary to “While Using the App” or “Never.” This alone cuts off a lot of background data collection without breaking anything you actually use.

Read the privacy policy, but skip to the part that matters

Nobody reads the whole privacy policy, and you don’t have to. Most of them follow a similar structure, and there’s usually a section called something like “How We Share Your Information” or “Third Parties.” That’s the part worth your time.

Look for phrases like “we may share information with advertising partners,” “we may share aggregated or de-identified data,” or “third-party service providers.” These are common ways apps describe selling or sharing your data, even when they avoid the word “sell.” If the policy mentions sharing location data specifically with advertisers, analytics companies, or unnamed “partners,” treat that as a yes, this app is part of the location data trade.

If you can’t find a privacy policy at all, or it’s vague to the point of saying nothing, that’s a red flag on its own. A legitimate app with nothing to hide usually explains itself clearly.

Look for the built-in privacy labels

Both major app stores now require some disclosure before you even download something, which saves you a step.

On the App Store, scroll to the “App Privacy” section on any app’s page. It lists what data the app says it collects and whether that data is linked to your identity or used to track you across other apps and websites. “Data Used to Track You” is the category to pay attention to; it means the app has told Apple it may share your information, including location, with data brokers or advertisers.

On Google Play, look for the “Data safety” section on the app’s listing. It works similarly, showing what data is collected and whether it’s shared with third parties.

These labels are self-reported by the app developers, not independently verified, so treat them as a starting point rather than a guarantee. But they’re a fast way to compare two similar apps before you install either one.

Watch for signs an app is more curious than it needs to be

A few patterns are worth noticing even outside the settings menu:

It asks for location before you’ve done anything that requires it. A permission prompt the moment you open an app, before you’ve tried to use a map or tag a photo, suggests the app wants the data by default rather than needing it for a specific feature.

It’s a free app with no obvious business model. If you’re not paying for it with money, something else is usually funding it. Location and other personal data are common ways free apps stay free.

It’s part of a larger ad network. Some seemingly unrelated apps, games especially, are built on shared advertising software development kits that collect data across many different apps at once. A privacy policy that mentions “advertising SDKs” or “third-party analytics tools” is describing this setup.

None of these signs mean an app is doing something illegal. Most of this activity is disclosed, technically, in the fine print. It’s just built to be found only by people willing to look, which is most of the point of this article.

What to do once you’ve found a problem app

If you find an app that’s collecting more than it needs or sharing your location with parties you didn’t expect:

  • Revoke the permission first. Turn location access to “Never” or “While Using the App” rather than deleting the app right away, if you still want to use it.
  • Delete the app if you don’t need it. Uninstalling removes ongoing access, though it doesn’t erase data already collected and shared in the past.
  • Opt out where the option exists. Some apps and data brokers offer a way to request deletion of your data or opt out of sale, often buried in account settings or the privacy policy itself.
  • Review this periodically, not just once. App permissions can reset after updates, and new apps get added to your phone more often than you’d think.

This kind of check is worth doing any time you set up a new device, alongside the other basics covered in how to set up a new smartphone safely. It’s also worth revisiting when you’re reviewing broader privacy habits, like the settings covered in Instagram and TikTok privacy settings worth checking before school starts, or when you’re looking at your search history and privacy more generally.

None of this makes your location data invisible. It just closes the gaps that are easiest to close, on the apps most likely to be careless with what they know about you. That’s a reasonable place to start, and it’s more than most people ever do.

A quick safety note

This article is general information, not professional security, legal, or medical advice. No single tool or setting makes anyone completely safe; security works in layers. If you are dealing with a live incident, such as active fraud, ransomware, or a child in danger, contact the appropriate professionals or authorities. For a threat to a child, report it to the NCMEC CyberTipline at report.cybertip.org and to local law enforcement.

Tags: , , , , , ,
Previous Post
Illustration for Smart Doorbell and Camera Privacy: What Neighbors and Guests Should Know
Safe Devices & Apps

Smart Doorbell and Camera Privacy: What Neighbors and Guests Should Know

Next Post
Illustration for What a Password Manager Actually Does, and Why It's Worth the Switch
Passwords & Account Security

What a Password Manager Actually Does, and Why It’s Worth the Switch