A hack of data company Gravy reveals Candy Crush, Tinder, and thousands of other apps are used to collect user location data; app developers may not even know
A hack of location data company Gravy Analytics has revealed which apps are—knowingly or not—being used to collect your information behind the scenes.
Context & Ripple Effects
This disclosure extends a long-running record of app-mediated location sharing: earlier reporting found precise location data moving to dozens of companies at high frequency through a broad location-data marketplace, while studies of dating apps showed how location could itself become an exposure point for identifiable users.
What is newly consequential is the apparent distance between consumer-facing apps and the location-data intermediary: the Gravy breach makes that downstream collection chain visible, including where developers may lack awareness of it.
First-order effects
- Gravy Analytics and the apps identified in the exposed data face immediate scrutiny over what location signals were collected, how they entered Gravy's systems, and which parties received them.
- Developers whose apps appear in the data have a concrete reason to review embedded partners and data flows, even where the collection was not knowingly arranged by the developer.
Second-order effects
- Location-data buyers and intermediaries, including Gravy subsidiary Venntel, face greater diligence risk because a breach can reveal the upstream app sources behind data products.
- App publishers may reassess SDKs and other third-party integrations as a supply-chain privacy issue, rather than treating location permission as a self-contained user-consent decision.
Third-order effects
- If such disclosures recur, location-data markets may be judged increasingly by traceability from app permission to downstream buyer, pushing consent architecture toward clearer accountability across intermediaries.
- The episode reinforces that privacy exposure can arise from opaque data-routing layers, not only from an app's visible features; whether that produces lasting changes depends on how developers, platforms, and buyers respond.
The trend: This is one data point in the shift from app-level privacy concerns to scrutiny of the full intermediary chain that monetizes permissioned location data.