The Data Brokers Selling Your Location to Anyone Who'll Pay

Illustration of a data broker counting money after selling a person's location data to a shadowy buyer

You've probably never heard of Gravy Analytics, Venntel, or Mobilewalla. They've very likely heard of you.

These are data brokers — companies whose entire business is buying, packaging, and reselling location data pulled from the apps on your phone, often without you ever meaningfully agreeing to it. In December 2024, the FTC finally forced two of them into settlements over exactly what critics have warned about for years: selling precise records of where specific people go, including to therapists' offices, addiction treatment centers, domestic violence shelters, and places of worship. The settlements were a real win. They also cover a tiny fraction of an industry that's still, for the most part, operating exactly as before.

What These Companies Actually Do

Gravy Analytics and its subsidiary Venntel collected precise location data from third-party app suppliers without ensuring the people generating that data had given informed consent. The FTC found the resulting data could be — and was — used to build profiles sorted by sensitive characteristics: political affiliation, religious attendance, health conditions, family status. As FTC Commissioner Alvaro Bedoya put it bluntly: "You may not know anything about Gravy Analytics, but Gravy Analytics may know quite a bit about you."

Mobilewalla's method was different but arguably worse. The company pulled location data from real-time bidding exchanges — the split-second ad auctions that happen every time an app on your phone loads an ad — in ways that violated those exchanges' own terms of service. That data, unanonymized, was reportedly sold in ways that let buyers track specific individuals to medical facilities and domestic abuse shelters, and was even used to monitor union organizers and people attending political rallies. Then-FTC Chair Lina Khan noted plainly that "real-time bidding technology can be exploited to surveil Americans" with essentially no safeguards built in.

The Settlement — and Its Limits

Under the FTC's orders, both companies now have to stop selling or using sensitive location data outside narrow national-security and law-enforcement exceptions, build out programs to actually identify sensitive locations (medical facilities, schools, religious sites, military installations), and stop licensing the associated data to third parties. Mobilewalla faces additional restrictions specifically around data pulled from failed ad-auction bids, plus new deletion requirements.

What the settlements don't do is touch the hundreds of other data brokers still operating the same basic playbook, legally, in most states, today. This is an industry-wide business model, not a two-company problem — Gravy and Mobilewalla just happened to be the ones the FTC caught and had jurisdiction to act against before a change in administration slowed the pace of new enforcement.

Where This Data Actually Comes From

None of this requires anyone to hack your phone. It comes from ordinary apps — weather apps, flashlight apps, games, fitness trackers — that request location permissions for a stated purpose and then sell access to that data stream on the side, sometimes through software development kits (SDKs) buried deep enough in the app that even the app's own developers may not fully understand what's being collected or where it ends up. The data gets aggregated, cross-referenced with other data sets, and sold to advertisers, insurers, and — through intermediaries — sometimes to government agencies that use commercial data purchases specifically to sidestep the warrant requirements that would apply if they tried to get the same information directly from a phone carrier.

That last part is not hypothetical. Venntel's own government contracts, predating this settlement, included sales to federal agencies for exactly that kind of location tracking — a workaround privacy advocates have been flagging for years as a direct end-run around Fourth Amendment protections.

What You Can Actually Do

You can't fully opt out of an industry this size, but you can meaningfully shrink your exposure:

  • Audit location permissions app by app, not just at the OS level. Set permissions to "while using the app" at minimum, and revoke them entirely for anything that doesn't need your location to function.
  • Use a Faraday bag or pouch when you genuinely need your phone's location and network radios fully offline — for sensitive appointments, protests, or travel where you don't want a location trail generated at all.
  • Check whether your state has a consumer data privacy law with a deletion right — California, Texas, and a growing list of others now let you request that data brokers delete your information, though you typically have to do it broker by broker.
  • Use opt-out services that automate broker-by-broker deletion requests, since doing it manually across hundreds of brokers isn't realistic for most people.
  • Support broader "sensitive location" legislation at the state level — several states are now considering rules similar to what the FTC imposed on Gravy and Mobilewalla, but as a baseline requirement for the whole industry rather than a case-by-case enforcement action.

The Other Side

The location data industry argues, not unreasonably, that aggregated and anonymized location data genuinely does power useful things — traffic prediction, retail site selection, epidemiological research, and ad targeting that keeps many free apps and services running without a subscription fee. Industry representatives point out that most data-sharing is technically disclosed somewhere in a privacy policy, and that users do click "allow" on the location permission prompt, even if they don't read what follows.

Privacy advocates respond that "technically disclosed" and "meaningfully consented to" are very different things when the disclosure lives in a 40-page terms-of-service document, and that "anonymized" data has repeatedly been shown to be re-identifiable once it's cross-referenced with other data sets — which is precisely the FTC's core finding against both Gravy Analytics and Mobilewalla. The debate over how much friction should exist before this kind of data changes hands is a real one. Whether the current level of friction — effectively none — is defensible is a much harder case to make with a straight face.


Sources referenced: the Federal Trade Commission, EPIC, Hunton Andrews Kurth, Lexology, and Privacy at UC Davis.


Related gear

If you want your phone's radios fully dark when it matters, our Faraday Bag Jacket and Mission Darkness TitanRF Faraday Fabric block WiFi, cell, and RFID signals outright. And our Ghost Protocol field guide covers data broker opt-outs in more depth than we could fit here.

0 comments

Leave a comment

Please note, comments need to be approved before they are published.