# EFF: InMobi, BidMachine, Verve Ad SDKs Leak Location by Default

By Dana Docket · 2026-08-05 · Licensing & Legal · https://datacommenter.com/eff-inmobi-bidmachine-verve-ad-sdks-leak-location-by-default/
About the author: Legal correspondent for the data economy: scraping suits, copyright-and-AI litigation, privacy enforcement, and data-broker rules.

> An EFF investigation published August 4, 2026 by Lena Cohen found that ad SDKs from InMobi, BidMachine, Huawei, and Verve — embedded in apps reaching a combined billions of users…

Original reporting: [EFF Deeplinks](https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy)
_AI-assisted commentary, editorially reviewed. Quoted excerpts belong to the original outlet._

Can a developer who simply drops a popular ad SDK into an Android app assume they’re not funneling users’ precise whereabouts to data brokers? EFF’s investigation says no. Reviewing developer documentation for dozens of widely used advertising kits, EFF singled out InMobi (which claims over 2 billion users across 150-plus countries), BidMachine (600 million direct SDK users), and Verve’s HyBid (1.5 billion users across more than 10,000 apps) as SDKs that collect and share location data by default the moment an app has been granted location permission — no separate opt-in required.

The evidence holds up under scrutiny, and it gets worse on inspection. BidMachine’s Google Play disclosure had claimed precise location was “not collected,” but EFF’s own technical analysis of network traffic from two apps — QR Scanner and GPS Speedometer — showed the SDK transmitting precise coordinates to a BidMachine domain. Only after EFF contacted the company, on July 31, 2026, did BidMachine correct that disclosure by August 3; it still hasn’t added instructions for developers who want to opt out. InMobi, meanwhile, actively steers developers toward keeping location sharing on, telling them “location-enriched impressions typically yield higher revenue” — the same company that settled with the FTC in 2016 over allegations it tracked location without permission.

> Default settings, not fine print, are turning ordinary apps into unwitting nodes in the location-broker supply chain.

The stakes go beyond creepy ad targeting. EFF ties this pipeline to real-time-bidding auctions where bid requests broadcast user data to thousands of potential advertisers — the same mechanism implicated in the 2025 breach of location broker Gravy Analytics, after which many app developers told journalists they had no idea their data was reaching the broker at all. Precise location permission can expose a user’s position to within about 160 feet; even the “approximate” tier EFF examined narrows someone’s movements to roughly 1.2 square miles, granular enough to expose visits to clinics, places of worship, or union meetings.

For the data industry, this is a liability story as much as a privacy one. It echoes the warning from Hinshaw & Culbertson’s health-privacy alert that state consumer-health and geolocation laws now treat precise location as sensitive data regardless of whether HIPAA applies — meaning a default SDK setting a developer never touched could trigger regulatory exposure. It also lands amid a broader reckoning with embedded third-party code: Samsung and LG have both moved this year to ban smart-TV apps carrying residential-proxy SDKs, per TechCrunch’s August 3, 2026 reporting, after finding that code developers didn’t fully understand was quietly repurposing their platforms. The pattern across both stories is the same — SDKs doing things behind documentation that developers, and regulators, are only now catching up to.

Watch for whether the FTC revisits location-sharing defaults given InMobi’s 2016 settlement history, whether Google tightens Play Store disclosure requirements in response to EFF’s findings, and whether state attorneys general start treating “we didn’t know our SDK did that” as a compliance failure rather than a defense.

> In response to our request for comment, BidMachine stated that it wasn't possible for them to get location information “unless the user has granted the app the relevant permission through the operating system.” They also stated that“publishers are responsible for configuring their apps' permission and consent flows.”
> — [EFF Deeplinks](https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy)

[Read the full story at EFF Deeplinks →](https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy)

---

Cite this analysis: https://datacommenter.com/eff-inmobi-bidmachine-verve-ad-sdks-leak-location-by-default/
Cite primary facts: https://www.eff.org/deeplinks/2026/07/developers-beware-ad-libraries-betray-your-users-location-privacy
Need the underlying datasets (alt data, market data, AI training data)? Source licensed vendors via Brickroad: https://brickroad.network
More machine-readable access: https://datacommenter.com/llms.txt

## Participate

- Comment on a passage: MCP `add_note` (include `source_url` when available).
- Suggest an editorially reviewed correction: MCP `suggest_edit`.
- Open factual questions: none.
