Report: the official COVID-19 contact tracing app for North Dakota is sharing location data with Foursquare and an advertising ID with Google
seems that the creators weren't trying to share the data, but the use of 3rd party components led to data leaking. Sounds like a job for... #SBOM and SW component transaprency! https://www.washingtonpost.com/ ... Albert Fox Cahn / @foxcahn : So, #NorthDakota decided to create a #ContactTracing app that ran all its data through Foursquare?! Oh, and it associates you “anonymous” locatation data with your NAME and advertising ID?🤯 Repeat after me “Tech won't save us, it will make things worse” https://blog.jumboprivacy.com/ ... @jason_kint : Confirming. Not good. https://twitter.com/... @saysdana : Anytime someone asks you to download an app, shouldn't you question it? If it was my Governor in CA, I'd still question it and make sure it was vetted properly. Something is very wrong with this whole thing. We're missing more of the story. https://twitter.com/... Geoffrey A. Fowler / @geoffreyfowler : North and South Dakota's contact-tracing app Care19 promises your location “will not be shared with anyone.” But a new study finds it is sending data to Foursquare. States are scrambling with few resources to make these apps. Who's vetting them? https://www.washingtonpost.com/ ... Jennifer Valentino-DeVries / @jenvalentino : I have some interesting data points about this! My colleagues & I wrote a story several weeks ago about the crazy glut of Covid apps. @Aaron_Krolik evaluated the code and traffic from this N.D. app (among others), and Foursquare was definitely NOT in there at that time. 1/ https://twitter.com/... Ken Yeung / @thekenyeung : Is there a reason why a contact tracing app would need to send data, even if it was “benign” to Foursquare? Shouldn't this be prevented? https://www.fastcompany.com/ ... @granick : North Dakota's location tracking contact tracing app sends location data and a unique user identifier to Foursquare—and other data to Google and a bug-tracking company: https://www.fastcompany.com/ ... #ContactTracing Roger McNamee / @moonalice : The state of @NorthDakota has implemented a contact tracing app with privacy invasions that violate its own terms of service, per @JumboPrivacy. https://www.fastcompany.com/ ... Ryan Calo / @rcalo : ND app sending data to Foursquare and Google? Why we need privacy legislation for automated (and all) contact tracing. https://www.fastcompany.com/ ... https://twitter.com/... Rebecca MacKinnon / @rmack : This is EXACTLY why we need a strong national data privacy law, NOW! https://twitter.com/... Charlie Warzel / @cwarzel : so @JumboPrivacy just published a report that North Dakota's contact tracing app is sharing user location data with Foursquare. Which, idk about you, sounds not great. https://blog.jumboprivacy.com/ ... Harry McCracken / @harrymccracken : Typical app practices may not cut it when public health is involved. https://www.fastcompany.com/ ... Thanks: @technologizer
Context & Ripple Effects
The finding lands a day after [[a:953880|Apple and Google opened their Exposure Notification API to states building contact tracing apps]], an explicitly privacy-constrained alternative to homegrown builds. North Dakota's Care19 app went its own way, and reporting shows it routing user location through Foursquare while tying 'anonymous' location records to names and Google advertising IDs — directly against its stated privacy promises.
It is also not an isolated pattern: US authorities had already begun consuming anonymized mobile-ad location data for pandemic planning, and earlier coverage traced how China and South Korea's smartphone-based tracking seeded Western app experiments amid privacy objections. The difference here is that a state government's own tool, not a data broker, is doing the leaking.
First-order effects
- North Dakota's health authority must answer for a trust breach at the exact moment voluntary app adoption decides whether contact tracing works; users who believed the privacy promise are having location histories linked to their identities via advertising IDs.
- Foursquare and Google are cast as unintended recipients of sensitive pandemic data, forcing both companies to clarify what they received and whether it complies with their own developer policies.
Second-order effects
- Other states weighing custom-built tracing apps face pressure to adopt the decentralized Exposure Notification API instead, since the Apple-Google framework's constraints make this class of third-party data sharing structurally harder.
- Privacy advocates gain a concrete exhibit for audits of government apps' third-party SDKs — the same supply-chain scrutiny that later surfaced sensitive tracing data exposed in an Android log.
Third-order effects
- If the pattern holds, government software procurement shifts toward mandatory transparency over embedded third-party components (the SBOM argument), because vendors' privacy promises prove unverifiable without them.
- Contact tracing splits into two camps — centralized state-built apps with richer data and larger leak surface versus the constrained Apple-Google API — with public trust, not feature sets, deciding adoption.
The trend: Pandemic-era government apps are colliding with the reality that third-party SDKs quietly export user data, pushing public-health software toward the decentralized Apple-Google Exposure Notification model and component-level transparency requirements.