/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

A hack of data company Gravy reveals Candy Crush, Tinder, and thousands of other apps are used to collect user location data; app developers may not even know

A hack of location data company Gravy Analytics has revealed which apps are—knowingly or not—being used to collect your information behind the scenes.

Wired Joseph Cox

Context & Ripple Effects

This disclosure extends a long-running record of app-mediated location sharing: earlier reporting found precise location data moving to dozens of companies at high frequency through a broad location-data marketplace, while studies of dating apps showed how location could itself become an exposure point for identifiable users.

What is newly consequential is the apparent distance between consumer-facing apps and the location-data intermediary: the Gravy breach makes that downstream collection chain visible, including where developers may lack awareness of it.

First-order effects

  • Gravy Analytics and the apps identified in the exposed data face immediate scrutiny over what location signals were collected, how they entered Gravy's systems, and which parties received them.
  • Developers whose apps appear in the data have a concrete reason to review embedded partners and data flows, even where the collection was not knowingly arranged by the developer.

Second-order effects

  • Location-data buyers and intermediaries, including Gravy subsidiary Venntel, face greater diligence risk because a breach can reveal the upstream app sources behind data products.
  • App publishers may reassess SDKs and other third-party integrations as a supply-chain privacy issue, rather than treating location permission as a self-contained user-consent decision.

Third-order effects

  • If such disclosures recur, location-data markets may be judged increasingly by traceability from app permission to downstream buyer, pushing consent architecture toward clearer accountability across intermediaries.
  • The episode reinforces that privacy exposure can arise from opaque data-routing layers, not only from an app's visible features; whether that produces lasting changes depends on how developers, platforms, and buyers respond.

The trend: This is one data point in the shift from app-level privacy concerns to scrutiny of the full intermediary chain that monetizes permissioned location data.

Discussion

  • @skynetandchill.com @skynetandchill.com on bluesky
    Data brokers exploited thousands of apps to surveil users' locations and sell it to anyone who paid for it.
  • @kashhill @kashhill on bluesky
    The fact that your location data is being sold not necessarily by individual apps but being obtained by companies through the bidding process to place ads is not widely understood but so important: www.404media.co/candy-crush- ...
  • @onekade @onekade on bluesky
    Use Tinder, Grindr, or Microsoft Outlook on your phone?  Data brokers are selling your location data to anyone with the money to buy it—foreign governments, cops, Trump creeps, stalkers, literally anyone. www.wired.com/story/gravy-...
  • @robertdownen Robert Downen on bluesky
    A hack has exposed that some of the world's most popular apps are likely being co-opted by rogue members of the advertising industry to harvest sensitive location data on a massive scale — and potentially sold to US law enforcement.
  • @wchr@mastodon.social Wolfie Christl on mastodon
    So, there's evidence that a few thousand mobile apps shared location data with the data broker Gravy Analytics (Unacast), whose subsidiary Venntel sold to ICE, CBP, FBI, DEA and other US govt agencies, probably via intermediaries and RTB, including data on Europeans:  —  https://…
  • @ff00aa@mastodon.social @ff00aa@mastodon.social on mastodon
    Back when I had a dating app (and it was successful for its time) I implemented my own advertising system so that I'd never risk executing outside code.  Seemed like the most basic precaution, how could I possibly not do that?  Of course I can count on one hand the total number o…
  • @josephfcox Joseph Cox on x
    New from 404 Media: data hacked from location giant Gravy reveals thousands of ordinary apps hijacked to steal your location data. Candy Crush, MyFitnessPal, Tinder. Period trackers, prayer apps. Because of how data collected, apps may not even know https://www.404media.co/...
  • r/Android r on reddit
    Candy Crush, Tinder, MyFitnessPal: See the Thousands of Apps Hijacked to Spy on Your Location