The morning begins with nothing that feels particularly private.
Check the weather.
Open a map.
Watch a video.
Read a message.
Search for somewhere to eat.
Scroll through a social feed on the way to work.
None of those actions looks like completing a personal questionnaire.
Together, however, ordinary smartphone use can produce information about location, interests, routines, purchases, devices, relationships and behaviour.
The important correction is that your phone does not literally "know" all of this in one human-like mind.
Different services can know different pieces.
The privacy problem begins when those pieces persist, travel or become useful for drawing conclusions that were never directly typed into a profile.
One screen can hide several companies
A user sees an app.
Behind that interface can be code from several organisations.
Software development kits, usually called SDKs, allow developers to add services such as analytics, advertising, crash reporting, login systems, maps and payments without building every component from scratch.
That architecture is normal software development.
It also means privacy cannot always be understood by asking only what the company whose logo appears on the screen does.
The phone screen can show one app while the data flow behind it involves several organisations.
The InMarket case shows how that can work
In 2024, the US Federal Trade Commission finalised an order against advertising and data company InMarket Media.
The FTC alleged that InMarket obtained location information both from its own applications and from third-party apps incorporating the company's SDK.
According to the regulator, that location data was combined with other information for advertising and marketing.
The FTC said consumers were not adequately informed about how their location information would be used and alleged that InMarket failed to ensure third-party apps using its SDK had obtained informed consent.
Regulator case / InMarket
A location permission can serve more than one purpose
The FTC said some consumers were told location would support an app feature such as shopping rewards or reminders, while the same information was also combined with other data for targeted advertising.
The final order prohibited InMarket from selling or sharing precise location data and required deletion of previously collected location information unless specified conditions were met.
This is why reading a permission prompt literally is not always enough to understand the full data relationship.
Location may genuinely be necessary for a feature.
The separate question is what else happens after it has been collected.
Location changes meaning when it becomes a history
One coordinate is often boring.
Repeated coordinates are not.
A movement history can potentially reveal where a device spends nights, where it appears during working hours and which locations recur.
Some of those locations can be sensitive.
A hospital.
A church, mosque or synagogue.
A union office.
A political gathering.
A shelter.
A military installation.
That does not mean every company collecting location data is building lists of those visits.
US enforcement cases show that such products have existed.
Gravy Analytics claimed billions of location signals
In December 2024, the FTC brought a case against Gravy Analytics and its subsidiary Venntel.
The complaint said Gravy claimed to collect, process and curate more than 17 billion location signals from around one billion mobile devices every day.
The regulator alleged that the companies sold sensitive location data without obtaining verifiable consent for the commercial and government uses at issue.
The FTC also alleged that Gravy used location information to identify consumers who had visited sensitive places, including healthcare facilities and places of worship.
The order was finalised in January 2025 and prohibited specified sales and uses of sensitive location information.
Daily location signals Gravy Analytics claimed to collect, process and curate, according to the FTC complaint.
Mobile devices Gravy said those daily signals could represent.
Year the FTC finalised its order restricting sensitive-location-data practices.
Another broker collected hundreds of millions of advertising IDs with location
The Mobilewalla case exposed another path through the advertising ecosystem.
The FTC alleged that between January 2018 and June 2020, Mobilewalla collected more than 500 million unique consumer advertising identifiers paired with precise location data.
The regulator said the company obtained data from real-time advertising bidding exchanges and third-party aggregators.
According to the complaint, consumers were often unaware Mobilewalla had obtained the information.
Regulator case / Mobilewalla
More than 500 million advertising identifiers paired with precise location
The FTC said Mobilewalla's raw location data was not anonymised and could be associated with individual mobile devices and sensitive locations.
The final January 2025 order banned Mobilewalla from selling sensitive location data and restricted its collection of information from real-time advertising exchanges.
What exactly is an advertising identifier?
Online advertising does not always need a person's legal name.
A system can obtain commercial value from recognising that interactions probably belong to the same device or user.
Mobile operating systems have historically provided advertising identifiers for this purpose.
Those systems have changed substantially as privacy controls have tightened.
On current Android devices using Google Play services, users can manage advertising preferences and reset or delete the device's advertising identifier.
That is useful.
It is not equivalent to deleting every account, every purchase history or every piece of first-party information previously collected by every service on the phone.
Apple's tracking permission is narrower than many people assume
Apple's App Tracking Transparency system requires apps to ask permission before tracking a user across other companies' apps and websites for purposes such as advertising or sharing information with data brokers.
A user can deny permission when the request appears or change that decision later.
They can also turn off the ability for apps to request tracking permission.
This is a significant privacy control.
But the word "tracking" has a specific meaning inside that system.
Denying cross-company tracking does not mean the app forgets everything a person does while directly using the app's own service.
If a user searches, follows accounts, watches videos or buys something while signed in, the company operating that service may still process information necessary or permitted for its own functions, subject to its policies and applicable law.
Android separates precise and approximate location
Modern Android gives users several levels of location permission.
An app can be allowed location all the time, only while the app is being used, each time it asks, or not at all.
Users can also choose whether an app receives precise or approximate location where the platform supports that choice.
Google describes approximate location as an area of roughly three square kilometres or larger, while precise location is more specific.
That distinction matters.
A weather service may be useful with only approximate location.
Turn-by-turn navigation may require much greater precision.
The privacy question is whether the access requested is proportionate to what the feature actually does.
Permissions are not the whole privacy story
Camera, microphone, contacts and location permissions are visible because operating systems make them explicit.
Other data arise simply by using a service.
Which screen was opened.
Which button was pressed.
Which video was watched.
How long a session lasted.
Which search produced a purchase.
Which device and software version were used.
A person can therefore deny microphone access and still generate a substantial behavioural record through ordinary use.
Different kinds of information
Not all phone data enters the system in the same way
Directly provided
A name, delivery address, uploaded photograph, payment details or information typed into a profile.
Permission-based
Location, camera, microphone, contacts and other device resources controlled through operating-system permissions.
Behavioural
Searches, clicks, viewing history, interaction patterns and other information produced while using a service.
Technical
Device characteristics, network information, software versions and other signals required or useful for operating, securing and measuring services.
Inferred
Predictions generated from other information, such as likely interests or commercial categories. An inference is not the same thing as a fact supplied directly by the user.
Inferences can be useful and still be wrong
This distinction matters.
If somebody gives a service their age, the service has an age the user supplied.
If an advertising system estimates that person's age range from behaviour, it has an inference.
The prediction may be accurate.
It may not be.
The same applies to interests.
Watching several videos about running does not prove somebody is a runner.
It may make an advertisement for running shoes more likely to succeed.
Advertising often needs useful probability, not perfect biography.
A purchase says more than what was purchased
Commercial behaviour produces patterns too.
Retailers may know what an account buys, when it buys, how often it returns and which promotions produce a purchase.
Loyalty programmes can connect transactions across time.
Delivery services need addresses.
Payment systems maintain their own records.
None of those systems necessarily has the same information or shares it with the others.
The important point is that ordinary commerce creates data far beyond a social-media profile.
“Anonymous” needs a definition
Removing a legal name from a dataset is not automatically the same thing as making it impossible to connect information to a person or device.
The risk depends on what remains.
Highly detailed location histories are a clear example.
Even without a name attached, repeated visits to distinctive locations can make the dataset sensitive.
That does not mean every de-identified dataset can be re-identified.
Strong anonymisation techniques exist.
It means the label should describe an actual method, not substitute for one.
The regulators have challenged exaggerated anonymity claims
In its Mobilewalla case, the FTC specifically restricted the company from misrepresenting the extent to which location information was de-identified.
The Gravy Analytics order similarly imposed requirements around historic location information, including deletion or making retained information de-identified or non-sensitive under specified conditions.
The issue is not semantic.
Whether data can still be connected to an identifiable person changes the privacy risk enormously.
Browsers are part of the same wider ecosystem
Smartphone privacy does not stop at installed apps.
Websites can use cookies, pixels, scripts and other technologies for functions including authentication, analytics, security and advertising.
Some are necessary for a requested service.
Others are designed to measure or follow behaviour beyond what is needed to load the page.
The legal treatment depends on the technology, purpose and jurisdiction.
Britain updated its tracking guidance in 2026
In April 2026, the UK's Information Commissioner's Office published final guidance covering what it calls storage and access technologies.
That includes cookies, tracking pixels, device fingerprinting and similar technologies.
The guidance reflects the current Privacy and Electronic Communications Regulations alongside relevant UK GDPR requirements and changes introduced by the Data (Use and Access) Act.
At the same time, the ICO said 99 per cent of the UK's top 1,000 websites were meeting the compliance standards it was checking for cookie banners following focused enforcement and engagement work.
That is progress.
A compliant banner still cannot make every user enthusiastic about reading one.
Consent fatigue is a design problem
People encounter cookie and privacy choices repeatedly.
If accepting takes one large button while rejecting requires opening several menus, the interface itself influences the decision.
Regulators have increasingly focused on whether choices are meaningful rather than merely technically present.
The ICO's current online-tracking work explicitly emphasises meaningful control.
A privacy system that trains users to press the fastest button has failed as communication even if the legal text behind it is enormous.
Fingerprinting explains why one identifier is not the entire problem
Advertising identifiers are relatively easy to understand because they are deliberately created identifiers.
Fingerprinting refers more broadly to attempts to distinguish a device or browser through combinations of technical characteristics.
The important point for ordinary users is not how to construct such a fingerprint.
It is why deleting one identifier does not mathematically guarantee that every system becomes incapable of distinguishing one device from another.
Modern browsers and operating systems increasingly attempt to reduce unnecessary identifying signals.
The ICO's 2026 guidance expressly covers fingerprinting within the wider category of tracking technologies.
App-store disclosures help before installation
Google Play requires developers to complete a Data safety section describing categories of information their apps collect, use and share, including practices involving SDKs.
Users can inspect that information before installing an app.
It is a useful transparency tool.
The information is supplied and maintained by the app developer, which remains responsible for its accuracy.
A disclosure therefore helps answer what an app says it does.
It is not a reason to stop thinking about whether the collection itself is necessary.
Apple can show how often sensitive permissions are actually used
Apple's App Privacy Report gives users another view.
When enabled, it can show how frequently applications access privacy-sensitive data or sensors such as location, camera and microphone during the previous seven days.
It also provides information about app network activity.
This does not explain the meaning of every network connection.
It makes previously invisible activity more inspectable.
Data brokers occupy the part of the system most users never deliberately visit
People generally know when they installed Instagram, ordered from a shop or opened Google Maps.
They may have no equivalent relationship with a downstream analytics company or data broker.
The broker industry also contains different businesses.
Some products support advertising.
Others support identity verification, fraud prevention, risk analysis or government customers.
The privacy concern is often opacity rather than the mere existence of another company.
A person cannot make an informed choice about an organisation they do not know has information about them.
Real-time advertising auctions can expose more than an advert
The Mobilewalla enforcement action is especially revealing here.
Real-time bidding exists to allow advertising opportunities to be auctioned rapidly.
The FTC alleged Mobilewalla retained information from bid requests even when it did not win the advertising auction.
The final order banned the company from collecting data from those exchanges for purposes unrelated to participating in the auction.
For the ordinary user, the important lesson is simple.
A complicated advertising system may involve data movement that is almost completely invisible from the webpage or app where the advertisement appears.
Important distinction
This does not mean every advert is secretly tracking your precise location.
Advertising systems use many different technologies and data sources. Platform restrictions, consent requirements and business practices vary.
The FTC cases document specific practices by specific companies. They show what has happened in the data economy, not that every app, advertising network or broker behaves identically.
Deleting an app is not the same as deleting an account
Uninstalling software removes that installed copy from the device.
It does not necessarily erase the account stored on the company's servers.
It does not automatically erase purchase records, historic messages, transaction information or other data already held under the company's retention policy.
Those are separate actions.
Apple itself notes that changing privacy settings on the device controls the access available to apps on that device, while privacy choices for a third-party service may also need to be changed through that provider's account or website.
Account deletion is not always immediate destruction of every record either
Services can have legitimate reasons to retain particular information for limited periods.
Fraud prevention.
Financial accounting.
Legal obligations.
Dispute resolution.
Security logs.
The correct question is not whether a service keeps absolutely nothing under any circumstance.
It is what it keeps, why, for how long and whether the retention is proportionate.
Data minimisation is less exciting than another privacy toggle
The strongest privacy protection is sometimes information that never needed to exist.
Data minimisation is a core principle of UK data-protection law.
Organisations should limit personal information to what is adequate, relevant and necessary for the stated purpose.
That principle attacks the problem before another consent screen is necessary.
Information that was never collected cannot later be leaked in a breach.
It cannot be sold.
It cannot be repurposed.
It cannot remain forgotten inside an old database.
Privacy does not mean your map app cannot know where you are
An absolutist definition of privacy would make modern smartphones mostly useless.
Navigation requires location.
Delivery requires an address.
Messaging requires processing messages.
Banking requires identity and transaction records.
Security systems may need technical information about the device connecting to them.
The serious privacy questions are about necessity, proportionality, transparency, retention and secondary use.
First-party data is different from cross-company tracking
This distinction is easy to lose when talking about privacy controls.
Imagine somebody uses the same streaming service every evening.
The service can know which videos that account watched because providing a viewing history is part of the direct relationship.
Tracking that same person across unrelated companies' apps and websites is a different data relationship.
Apple's tracking controls specifically target that cross-company category.
Treating every form of data collection as identical makes it harder to understand which control actually changes what.
Privacy labels cannot replace reading the consequence
"Location."
"Analytics."
"Personalisation."
"Advertising."
These words describe categories.
They do not automatically tell a user what happens next.
A good explanation should answer the practical question.
If I refuse this data, what feature stops working?
If I allow it, who receives it?
Is it used only now or stored?
Is the information used to provide what I asked for or for another purpose as well?
The system knows patterns even when nobody reads a biography
Advertising and recommendation systems operate at enormous scale.
Nobody needs to sit in an office reading an individual person's browsing history line by line.
Software can classify behaviour automatically.
That classification does not have to be philosophically correct.
It only has to be statistically useful for the purpose the system is trying to achieve.
Show an advert.
Recommend a video.
Detect suspected fraud.
Prioritise a notification.
Decide which product is displayed first.
The convenience is real
Privacy reporting can become dishonest if it describes every form of data use as pure extraction with no benefit to the user.
Location can make a map immediately useful.
Purchase history can make returns easier.
Analytics can reveal that an app crashes on a particular phone.
Fraud systems can stop stolen cards.
Recommendations can help somebody discover something they genuinely like.
The question is not whether data can produce value.
It obviously can.
The argument is about how much information is necessary to produce that value and what additional uses occur afterward.
The practical controls are better than they used to be
Modern smartphones give ordinary users meaningful controls that did not exist in the same form years ago.
Those controls cannot remove somebody from the information economy completely.
They can reduce unnecessary collection.
Practical privacy checks
What users can realistically review
- Check which apps have permanent location access and reduce it when background location is unnecessary.
- Use approximate rather than precise location where the feature does not require exact positioning.
- On iPhone, review Settings → Privacy & Security → Tracking and individual tracking permissions.
- Consider enabling Apple's App Privacy Report to inspect recent permission access and network activity.
- On Android, review individual app permissions and whether each app receives precise location.
- Review Android advertising controls and reset or delete the advertising ID if desired.
- Check Google Play's Data safety section before installing unfamiliar apps.
- Delete unused accounts when appropriate rather than assuming uninstalling the app removed the underlying account.
- Use access, deletion, objection or other legal data rights where they apply.
Perfect invisibility is not a realistic goal for most people
A smartphone is a communications device connected continuously to outside services.
Using one necessarily produces some information.
Trying to eliminate every possible data point can turn privacy into an impossible project.
A more useful objective is reducing unnecessary exposure.
Does the flashlight need contacts?
Does a simple game need permanent precise location?
Does an old account need to remain active indefinitely?
Does a service explain why a permission is required?
Is a tracking choice actually optional?
Privacy is also about power
The most important information is not always a secret.
Where somebody goes to work is not necessarily secret.
Neither is the supermarket they use.
Neither is liking a particular band.
The sensitivity can arise from accumulation and asymmetry.
One person remembers several facts about themselves.
A system can store thousands of observations, preserve them over time and compare them automatically.
That changes the relationship even when every individual observation looks mundane.
What your phone does not know
A prediction is not understanding.
A device can record that someone visited a hospital.
It does not necessarily know why.
A platform can observe that somebody watched ten videos about pregnancy.
It does not know whether the viewer is pregnant, studying medicine, helping a friend or simply curious.
A retailer can see that somebody bought children's clothes.
It does not automatically know whether they have a child.
Data can be extraordinarily revealing.
It can also invite conclusions that exceed what the evidence supports.
That is why inferred data deserves scrutiny too
The Gravy Analytics complaint alleged that the company sold characteristics relating to matters including health decisions, political activities and religious viewpoints derived from location information.
The fact that a characteristic is inferred rather than directly supplied does not make it harmless.
If an organisation acts on the inference, an inaccurate prediction can still affect the person it describes.
Privacy therefore overlaps with accuracy and accountability.
The data economy is changing because regulators and platforms are changing it
It would be inaccurate to describe mobile tracking as though nothing has changed since the early smartphone era.
Apple introduced cross-app tracking permission.
Android allows deletion of its advertising identifier and increasingly granular permission controls.
App stores require privacy disclosures.
Browsers have tightened older tracking mechanisms.
Regulators have pursued cases involving precise location data.
UK regulators have pushed large websites towards more compliant cookie banners.
The privacy environment is not static.
The business incentive did not disappear
Measurement remains valuable.
Advertisers still want to know whether campaigns work.
Platforms still want recommendations to improve.
Developers still want analytics.
Retailers still want to understand customers.
Fraud systems still want enough information to distinguish normal behaviour from suspicious behaviour.
Technology therefore continues to negotiate between collection and privacy rather than moving permanently towards one extreme.
The phone is only the beginning
This is perhaps the most important conclusion.
Smartphone privacy is often discussed as though everything sits physically inside the handset.
Much of the relevant information exists elsewhere.
Cloud accounts.
Retailer databases.
Advertising systems.
Analytics platforms.
Websites.
Data suppliers.
The phone is the sensor, interface and identity device through which many of those systems become part of ordinary life.
What privacy realistically means in 2026
The morning remains ordinary.
Weather.
Maps.
Messages.
Videos.
Shopping.
None of those actions has to feel invasive.
The profile emerges from accumulation.
Your phone does not need to understand you in the human sense.
The services around it can obtain value from something much simpler.
Enough signals to recognise patterns.
Enough history to make predictions.
Enough continuity to know that today's activity probably belongs with yesterday's.
That is why privacy is not only about hiding secrets.
It is about deciding how ordinary behaviour becomes information, how long that information survives, who receives it, and what can be concluded after enough pieces are placed together.
Reporting note
Sources used for this investigation
This article draws on Federal Trade Commission complaints and final orders involving InMarket Media, Mobilewalla, Gravy Analytics and Venntel; current Apple documentation covering App Tracking Transparency and App Privacy Report; current Android and Google Play documentation covering location permissions, advertising controls and Data safety disclosures; and the UK Information Commissioner's Office's April 2026 Storage and Access Technologies guidance and online-tracking enforcement work. Allegations from regulatory complaints are identified as allegations and are not presented as independent findings by Crazy News.
If you believe this article contains a factual error, visit our corrections page .