CipherWatch All articles
Threat Awareness

Always Watching: The Hidden Mechanics of App Location Tracking and What You Can Do About It

CipherWatch
Always Watching: The Hidden Mechanics of App Location Tracking and What You Can Do About It

Photo: smartphone location tracking privacy map pins, via images.mobilefun.co.uk

Most Americans assume that denying a location permission request means an app simply cannot track them. The reality is considerably more complicated. A growing body of evidence reveals that mobile applications routinely exploit technical and legal gray areas to gather precise location data far beyond what users ever consciously authorized. Understanding how this happens — and how to stop it — requires a closer look at the machinery operating quietly beneath every tap and swipe.

The Permission Dialog Is Not the Whole Story

When an app asks to access your location, the request arrives wrapped in reassuring language: "Allow while using the app," "Allow once," or "Don't allow." Both iOS and Android have made meaningful strides in recent years to present these choices clearly. Yet the permission dialog itself is only one entry point into a much larger system.

Background location access — the ability for an app to record your position even when it is not open on your screen — is technically a separate permission tier. On iOS, it requires users to explicitly select "Always Allow," a choice that Apple has deliberately buried beneath more restrictive defaults since iOS 13. Android similarly introduced a dedicated "Allow all the time" toggle, accessible only through the device's settings menu rather than the in-app prompt. The problem is that many apps request background access for purposes that have no logical connection to the feature being offered. A coupon application, a weather widget, or a flashlight utility has no operational need to know where you are at 2 a.m. Yet all three categories have, at various points, been documented requesting or quietly obtaining persistent location data.

How Constant Tracking Actually Works

Beyond explicit permissions, developers have access to a suite of technical mechanisms that can approximate or supplement location data through indirect means. These include:

IP-based geolocation. Every internet connection carries an IP address that can be mapped to a rough geographic area. No permission is required, and the precision, while coarser than GPS, is often sufficient to identify a user's city or neighborhood.

Wi-Fi and Bluetooth scanning. Apps with access to Wi-Fi network lists or nearby Bluetooth devices can cross-reference those signals against public databases to triangulate position with surprising accuracy — sometimes within a few meters — without ever triggering a formal location permission request.

Sensor fusion. Accelerometers, barometers, and gyroscopes are classified as "non-dangerous" sensors under Android's permission model, meaning apps can read them freely. Researchers at Princeton and other institutions have demonstrated that combining these data streams can infer movement patterns and, under certain conditions, approximate location.

Third-party SDKs. Perhaps the most consequential mechanism is the software development kit ecosystem. When developers integrate advertising, analytics, or social-login libraries into their apps, those third-party code packages often carry their own data-collection logic. A developer may have no intention of harvesting location data, yet the SDK embedded in their app does exactly that, operating under a separate set of terms the end user never reviewed.

Real-World Examples of the Gap

In 2021, a Federal Trade Commission investigation found that several popular retail apps were transmitting precise geolocation data to data brokers continuously, even when users had selected the most restrictive sharing option available. A 2023 investigation by researchers at the University of California, San Diego, identified more than two hundred applications on the Google Play Store that collected location data through Wi-Fi scanning while displaying no location permission indicator whatsoever in the system UI.

The downstream consequences are not abstract. Data brokers aggregate these location streams into detailed mobility profiles — records of which medical offices, religious institutions, political rallies, or domestic-violence shelters a person has visited. These profiles are bought and sold with minimal regulatory oversight, and in several documented cases, they have been obtained by law enforcement without a warrant, by employers screening candidates, and by stalkers purchasing commercially available data packages.

Why Regulators Have Moved Slowly

The legislative landscape in the United States remains fragmented. The Federal Trade Commission has authority to pursue unfair or deceptive practices and has levied fines against specific actors, but there is no comprehensive federal privacy statute governing location data. State-level frameworks — California's CCPA and CPRA, Virginia's CDPA, and a handful of others — impose disclosure requirements and opt-out rights, but enforcement is resource-intensive and penalties are modest relative to the profits generated by data brokerage.

The core difficulty is definitional. Location data collected through Wi-Fi scanning or sensor fusion does not always meet the legal threshold for "precise geolocation" as defined in existing statutes. Industry lobbying has consistently argued that aggregated or inferred location information falls outside the scope of privacy protections designed for GPS coordinates. Closing that definitional gap requires either new legislation or sustained regulatory litigation — neither of which moves quickly.

Auditing and Restricting Your Location Permissions

While systemic solutions remain pending, individual users can substantially reduce their exposure through a disciplined review of device settings.

On iPhone (iOS 16 and later):

  1. Open SettingsPrivacy & SecurityLocation Services.
  2. Review each app listed. Any app set to "Always" that does not provide navigation, emergency services, or a feature you actively use in the background should be changed to "While Using the App" or "Never."
  3. Scroll to the bottom and tap System Services to review Apple's own location uses, including "Significant Locations," which maintains a history of frequently visited places. This can be disabled and its history cleared.
  4. Enable Precise Location only for apps that genuinely require it — mapping applications, for instance. Weather apps, retail apps, and social platforms function adequately with approximate location.

On Android (version 12 and later):

  1. Open SettingsPrivacyPermission ManagerLocation.
  2. Examine each app under "Allowed all the time." Revoke background access for any application that lacks a clear functional justification.
  3. Navigate to SettingsPrivacyPrivacy Dashboard to view a timeline of which apps accessed your location in the previous 24 hours. This is one of the most useful diagnostic tools available.
  4. Consider enabling Wi-Fi scanning and Bluetooth scanning controls under SettingsLocationLocation Services. Disabling these prevents apps from using network signals for covert triangulation.

General hygiene across both platforms:

The Broader Principle

Location data is among the most sensitive categories of personal information a device can generate. Unlike a password, which can be changed after a breach, a historical record of your physical movements cannot be unrecorded. The permissions dialog is a starting point, not a guarantee. Treating it as the latter is precisely the assumption the broader data-collection ecosystem depends on.

All Articles

Related Articles

Tagged, Tracked, and Sold: The Invisible Architecture Behind Every Online Purchase You Make

Tagged, Tracked, and Sold: The Invisible Architecture Behind Every Online Purchase You Make

When Images Become Weapons: A Victim's Guide to Fighting Non-Consensual Intimate Image Abuse

When Images Become Weapons: A Victim's Guide to Fighting Non-Consensual Intimate Image Abuse

The Encryption Paradox: How Authorities Access Locked Messages Without Breaking the Code

The Encryption Paradox: How Authorities Access Locked Messages Without Breaking the Code