Survey finds significant portion of popular apps send user personal information like email and location to Apple, Google, and other third parties
User data plundering by Android and iOS apps is as rampant as you suspected — Most commonly shared data for Android is e-mail addresses; for iOS, it's GPS data.
Context & Ripple Effects
This 2015 survey was the early baseline for a decade of app-privacy auditing: it found popular Android and iOS apps routinely shipping personal data — email addresses on Android, GPS location on iOS — to third parties including the platforms themselves. Later reporting kept confirming the pattern rather than correcting it: researchers documented 24 iOS apps sending GPS and Wi-Fi identifiers to data monetization firms in a 2018 iOS study, and Privacy International found major Android apps still passing personal data to Facebook at launch, conduct flagged as possible GDPR violations.
First-order effects
- Android and iOS users of popular apps have their email addresses and GPS location transmitted to third parties — including Apple and Google — often as a side effect of embedded SDKs rather than any explicit user choice.
- App developers are exposed on both ends: their users' data flows outward through third-party code they ship, and their brands absorb the reputational hit when audits name them.
Second-order effects
- Regulators gain ready-made evidence: Privacy International's follow-up findings that apps shared data with Facebook without consent put European developers directly in GDPR's crosshairs, raising compliance costs across the app ecosystem.
- Platform holders face pressure to build user-facing controls — Apple's later App Tracking Transparency regime was the direct response, though researchers later found apps sending identifying information despite opt-outs.
Third-order effects
- The structural problem is the SDK supply chain itself: by 2025, a hack of location-data firm Gravy revealed thousands of apps feeding brokers like Candy Crush and Tinder, with developers themselves unaware — meaning no amount of app-store policy fixes a layer neither platform nor developer controls.
- If the pattern holds, accountability migrates from individual apps to the data-broker intermediaries, forcing disclosure requirements and audits aimed at the SDK and monetization layer rather than the app store.
The trend: App data harvesting has proven a decade-long structural leak — from this 2015 survey through ATT-era workarounds and the Gravy breach — where third-party SDKs and brokers keep extracting user data faster than platform controls can close the tap.