Most people assume the police need a warrant to track their movements, and in many countries that is technically true. Legal protections like the Fourth Amendment in the United States, Section 8 of Canada's Charter of Rights and Freedoms, and similar rules in other democracies exist for exactly this reason. But today, the app you opened to check tomorrow's forecast may have already sold your location data, including where you slept last night.
This is not a conspiracy theory. It is a business model. In this article, I will explain how ordinary apps became surveillance tools, how the hidden data supply chain behind online advertising works, and what you can realistically do to reduce your exposure.
If you have read my guide on how online ads turn your phone into a tracking device, you already know the basics. This article goes deeper into the part most people never hear about: what happens to your location data after the ad loads.
How ordinary apps became surveillance tools
Apps used for navigation, shopping rewards, local news, and weather often contain advertising systems. To show you a relevant ad, those systems frequently collect your location. That is the entry point.
The problem is what happens next. Your location data can flow from the app into a searchable commercial database, and those databases can later be used by law enforcement. In some cases, investigators can open a web browser, draw a box on a map, choose a date range, and see every phone that entered that area.
No warrant was ever shown to Apple, Google, or your carrier. The data was already for sale.
Fog Reveal and location tracking
One well-known example is Fog Reveal, a tool built by a data broker called Fog Data Science. It lets investigators search location histories gathered from popular phone apps.
The tool can show where phones were and how they moved afterward, sometimes going back up to 90 days. And because the data comes from the advertising ecosystem rather than the phone itself, this can all happen without the phone maker or the carrier ever being involved.
In other words, the traditional legal checks that apply when police ask a carrier for location records often simply do not apply to data a broker already collected and packaged for sale. This gap exists in most countries, not just one.
The hidden data supply chain
Your location data usually does not stay in one place. It moves through a chain that looks like this:
- An app with an ad SDK collects your location along with usage details
- That data is passed to advertising networks and data brokers
- Brokers aggregate data from thousands of apps into detailed profiles
- Buyers, including analytics firms and in some cases government contractors, purchase access
A single app may not feel dangerous on its own. But once its data enters this chain, it gets combined with data from other apps and becomes part of a much larger surveillance system. One app sees a fragment. The supply chain sees the whole picture.
Why location data is so powerful
Location data can reveal where you sleep, where you pray, where you work, and where you go for medical care or personal reasons. That is exactly the kind of information search-and-seizure protections in the US, Canada, Europe, and elsewhere were written to protect.
Even if your name is removed, the data can often be tied back to you. Research has shown repeatedly that with only a few location data points, a person can be re-identified. Where you are at 3 a.m. is a strong hint about where you live.
Why "anonymous" data is not truly anonymous
The advertising industry likes to say the data it sells is anonymous. Technically, that is often true. There is usually no name or phone number attached to each record.
But practically, it does not matter.
If a device appears at the same address every night, it is trivial to infer that this is the person's home. Once you have a home address, public records, property databases, and voter rolls can put a real name to it. This is a standard technique, and it is exactly how tools like Fog Reveal are used in practice.
So when a company says its location data is anonymous, what it really means is that they removed the easy part of the identification. The hard part, linking the pattern to a person, is still very doable.
Real-time bidding: every ad is a data leak
Every time an ad loads on your phone, something called a bid request is sent out to many companies at once. The ad space is auctioned in milliseconds, and that request can include what app you are using, what you were viewing, your device details, and where you were at that moment.
Here is the part that surprises people: even the companies that lose the auction may still have received your data. Hundreds of firms participate in these auctions, and each bid request is a small packet of information about you flying across the internet.
Multiply that by the dozens of apps on your phone and the hundreds of ads you see per day, and you get a near-continuous stream of location and behavior data leaving your device. I broke this mechanism down in more detail in my guide on how your phone is tracked in 2026.
Why Apple's protections are not enough
Apple's App Tracking Transparency (ATT) system, introduced in 2021, did reduce some tracking. It gives you the prompt that asks whether an app can track you across other companies' apps and websites, and many people say no.
That was a real improvement. But it is not a complete fix:
- Trackers can still use fingerprinting, where tiny details about your device and behavior are combined into a unique identifier
- Companies can collect data inside their own app without triggering the prompt
- Location can still be collected by apps you deliberately granted location access to
- The advertising ecosystem has simply shifted toward these alternative methods
The bigger issue is the business model behind free apps. Free apps are not charities. They make money from advertising, and advertising works better with more data. As long as that incentive exists, the industry will keep finding ways to collect.
How to reduce your exposure
You cannot fully opt out of this system without giving up your phone, but you can shrink your footprint considerably. These are the steps I consider most effective:
- Audit your location permissions. Most apps do not need Always access. Set location to Ask Every Time or Never for anything that does not truly need it
- Delete apps you rarely use, especially free utilities like flashlights, QR scanners, and weather apps from unknown developers
- On Android, check which apps have "precise location" enabled and turn it off where approximate is enough
- On iPhone, review the Privacy and Security settings and look at which apps recently accessed your location
- Use a web browser instead of an app where possible. Sites in a browser with good privacy settings leak far less than a dedicated app with an ad SDK
- If you need a weather app, use your phone's built-in one or a paid app without an ad SDK
For a broader plan that covers carriers, apps, and the web in one place, I put together a practical guide on how to reduce tracking without breaking everything.
The simple takeaway
Free apps are not always free. In many cases, you are paying with your data, and your location is the most valuable part of it. Your smartphone is constantly creating a record of where you go, and that record can be bought, sold, and searched in ways most people never expect.
Search-and-seizure protections still matter, whether that is the Fourth Amendment, Section 8 of the Charter, or your country's equivalent. But right now, the easiest path to your location history is not a wiretap. It is a receipt from the advertising industry. That is why privacy protection matters so much in today's digital world.
Need help improving your privacy setup?
If you want to lock down your phone's location sharing but do not want to dig through settings and research every app yourself, I can help. I offer privacy setup, app permission audits, and personalized hardening for your phone and home network. Reach out through the contact page and let us talk about your setup.
Frequently asked questions
Can apps sell my location without me knowing?
In many cases, yes. The app may disclose it in a privacy policy most people never read, and the collection happens through the advertising SDK embedded in the app. If you granted location permission, the flow of data can be legal even if you never consciously agreed to selling it.
What is Fog Reveal?
Fog Reveal is a location search tool sold to law enforcement. It works on data purchased from the advertising ecosystem rather than from phone carriers, which means investigators can search years of location history without a warrant to the carrier. Reports have shown hundreds of agencies have used it.
Is anonymous location data really anonymous?
Technically it often has no name attached. Practically, no. If a device shows up at the same home address every night, that address can be matched against public records to identify the person. A few location points are usually enough to re-identify someone.
Does App Tracking Transparency stop location tracking?
Not fully. It limits cross-app tracking when you deny the prompt, but fingerprinting, first-party collection inside an app, and permissions you granted yourself can still expose your location. It reduced tracking, it did not end it.
What are the most effective settings to change today?
Go through your location permissions and set them to Ask Every Time or Never for apps that do not need location, delete unused free apps, disable precise location where approximate is enough, and prefer your phone's built-in apps over free third-party utilities loaded with ads.