Skip to content
← Data brokers: who sells your life

Lesson 2 of 4 · 9 min

How your data gets out: apps, cookies, location and public records

Four everyday paths carry your information to data brokers: the software inside your apps, trackers on websites, your phone’s location, and records you cannot opt out of.

The previous lesson described what data brokers hold. This one follows four concrete paths your information travels to reach them: the third-party code bundled inside ordinary apps, cookies and pixels on websites, your phone’s location, and public records you cannot prevent from existing in the first place.

Apps and the software development kits inside them

Most apps are not built entirely by the company whose name is on them. Developers commonly add third-party software development kits (SDKs) for things like analytics, crash reporting or advertising. Apple’s own developer documentation, which requires apps to disclose this, defines “third-party partners” as “analytics tools, advertising networks, third-party SDKs, or other external vendors whose code you’ve added to your app”, and it warns developers directly against “placing a third-party SDK in your app that combines user data from your app with user data from other developers’ apps to target advertising or measure advertising efficiency, even if you don’t use the SDK for these purposes.” In other words, an SDK a developer added for one reason can, on its own, forward data that ends up combined with data from entirely unrelated apps.

Cookies and pixels on the websites you read

On the web, the same idea shows up as cookies. Cloudflare’s Learning Center explains that a first-party cookie, set by the site you are looking at, is different from a third-party cookie, set by a domain that is not the one shown in your address bar — most often an advertising or analytics company embedded on many different sites. Because that third party sees you again every time you land on another site carrying its cookie, it can build a record of your browsing across sites you never told it you were visiting. The FTC’s own consumer guidance confirms this happens beyond cookies too: sites “may track your online activity by using a cookie or pixel to identify you even after you leave the site”, and in apps, “advertisers may use a unique advertising identifier to track you”, sometimes alongside device fingerprinting, which recognises your browser or device from its particular settings rather than from a stored file at all.

Your phone’s location, often without a special sensor at all

Location is one of the more sensitive categories, and the FTC has taken direct enforcement action over it. In 2022, the agency sued Kochava, a broker it described as selling “massive amounts of precise location data collected from tens of millions of mobile users.” The FTC’s alert noted that this kind of data can reveal visits to “medical care, places of worship, reproductive health, homeless shelters and domestic violence shelters, and addiction recovery”, and as a demonstration, FTC staff said they were able to use Kochava’s data to identify a device that visited a women’s reproductive health clinic and trace it back to a specific home. That data starts with an app that asked for location permission, then, separately from anything your mobile carrier can already work out from which cell towers your phone connects to, passed the location onward to outside companies.

Public records: the source you cannot opt out of

The FTC’s 2014 study of nine major data brokers found that all but three obtained data directly from federal sources such as the Census Bureau and the Social Security Administration’s death records, and that state and local governments supplied property records, voter registration, court records and professional licenses. Some of that flow does have legal limits: the FTC report notes that at least twenty-two U.S. states restrict commercial use of voter registration records, and the federal Driver’s Privacy Protection Act restricts disclosure of motor vehicle records outside specific purposes. But the underlying records themselves — a property deed, a marriage record, a court filing — exist because the law requires them to, whether or not you would prefer they did not.

PathTypical carrierWhat it can reveal
App SDKsAnalytics, crash-reporting or ad code bundled into an appBehaviour and identifiers combined across unrelated apps
Cookies and pixelsThird-party trackers embedded on many websitesBrowsing activity across sites you never visited on purpose
LocationApps with location permission; carrier tower dataPrecise, sometimes sensitive places and movement patterns
Public recordsGovernment registries (property, court, voter, vehicle)Identity-linked facts you cannot prevent from existing

Key takeaways

  • Third-party SDKs bundled inside apps can transmit data that gets combined with data from other, unrelated apps.
  • Third-party cookies and tracking pixels let a company recognise you across many different websites, not just the one you are looking at.
  • Apps with location permission can transmit your location to outside service providers, separately from what your mobile carrier can already calculate.
  • The FTC has sued a data broker for selling precise location data that could reveal visits to health clinics, places of worship and shelters.
  • Government public records feed data brokers directly and legally, and individuals cannot opt out of the records themselves.

Check yourself

  1. 1. What does Apple warn developers about regarding third-party SDKs?

    • That SDKs always slow down apps
    • That an SDK can combine a user’s data with data from other developers’ apps to target advertising, even unintentionally — Right.
    • That SDKs are illegal in all app stores
    • That SDKs cannot access the internet

    Apple’s own guidance says this combination can happen even if the app’s developer did not intend to use the SDK for that purpose.

  2. 2. What is a third-party cookie, as Cloudflare describes it?

    • A cookie set only by the site shown in your address bar
    • A cookie set by a domain other than the one you are currently viewing, often used for tracking — Right.
    • A cookie that deletes itself immediately
    • A type of encryption key

    A third-party cookie belongs to a different domain than the site you are visiting, letting that domain recognize you across many sites.

  3. 3. What did the FTC say Kochava sold?

    • Encrypted messages between users
    • Massive amounts of precise location data collected from tens of millions of mobile users — Right.
    • Only aggregated, anonymous statistics
    • Credit card numbers

    The FTC’s 2022 action described Kochava as selling precise, individually traceable location data at large scale.

  4. 4. Why can you not simply opt out of the public records that feed data brokers?

    • Because opting out is illegal
    • Because records like property deeds and court filings exist because the law requires them, independent of a person’s preference — Right.
    • Because public records do not contain personal information
    • Because data brokers do not use public records

    The FTC’s study found government sources like property and court records feed data brokers directly, and these records exist by legal requirement.

Do it with FireAI

Put this lesson into practice on your own Mac.

Sources

Put it into practice on your Mac

Try every feature free for 17 days, no card needed.

Download for Mac Docs