Report: 17K Android apps, some with 100M+ installs, collect info that can be used to create a permanent record of user's activity on the device for ad targeting
Some apps may track your activity over time, even when you tell them to forget the past. And there's nothing you can do about it.
Context & Ripple Effects
This report extends a decade-long thread: back in 2015, researchers found free Android apps quietly connecting to thousands of tracking and ad domains ([[a:828869]]), and surveys that same year showed popular apps shipping email and location to third parties. What changed by 2019 is scale and persistence — 17,000 apps, some with 100M+ installs, collecting signals rich enough to reconstruct a user's on-device history for ad targeting.
The sharpest angle is the failure of user controls: the finding lands a year after an investigation showed Google's own apps storing time-stamped location even when location history was paused ([[a:932361]]), and months before Privacy International found major apps still sending launch-time data to Facebook despite earlier warnings. Together they sketch a pattern where opt-outs govern what's shown to users, not what's actually collected.
First-order effects
- Users who clear history or reset advertising identifiers get no real erasure — the underlying collection continues, so the practical effect of Android's privacy settings is weaker than they appear.
- App publishers and their embedded ad/analytics SDKs are the direct beneficiaries: high-install apps become durable profiling infrastructure, monetizing activity records regardless of user preference.
Second-order effects
- Google faces mounting pressure to close the gap between its user-facing privacy controls and what third-party code inside apps can do — the same control-versus-reality problem exposed by the paused-location-history investigation.
- Advertisers gain an incentive to favor channels built on these persistent signals, raising the competitive bar for privacy-forward rivals whose targeting is limited by honoring deletions.
Third-order effects
- If the pattern holds, scrutiny shifts from individual apps to the SDK layer itself — pushing platforms and regulators toward auditing and governing embedded third-party code rather than relying on per-app permissions.
- Persistent cross-app profiling hardens into the default economics of free mobile software, making 'forget me' rights structurally hollow unless collection, not just retention, becomes the regulated act.
The trend: Mobile tracking is converging on persistent, SDK-driven profiling that survives user privacy controls, shifting the battleground from individual app behavior to platform-level governance of embedded code.