You install one app.
That does not mean only one company is inside it.
Mobile apps commonly include third-party software development kits, or SDKs, that provide analytics, advertising, crash reporting, maps, authentication, payments, and other functions the app developer does not want to build from scratch.
If an app receives device location and passes it to one of those SDKs, the location can move beyond the company whose icon the user recognizes.
That is where a simple permission can turn into a supply chain.
The X-Mode case made the pipeline unusually visible
In 2024, the Federal Trade Commission finalized an order against location-data broker X-Mode Social and its successor Outlogic. The FTC said the companies obtained precise location information from third-party apps that incorporated the company’s SDK, from its own apps, and from other brokers and aggregators. The data was associated with mobile advertising IDs and sold or licensed to hundreds of clients.
See the FTC’s final X-Mode/Outlogic order announcement and case page.
The FTC said the raw data could reveal visits to sensitive places such as medical clinics, houses of worship, and domestic-abuse shelters. The order restricted the sale or sharing of sensitive location data and imposed additional safeguards.
The important architectural point is broader than one company.
The app can be the collector the user sees.
The SDK can be the recipient the user does not.
One permission can serve several relationships
A weather app may have a legitimate reason to request location.
So might a navigation app, ride service, delivery app, or local-events app.
But the fact that the app needs location for its visible feature does not answer every downstream question:
- Which embedded libraries receive the coordinates?
- Are they given precise or approximate location?
- Is an advertising identifier attached?
- How often is the event sent?
- How long is it retained?
- Is it sold, licensed, or shared onward?
The permission dialog alone cannot answer those questions.
A point becomes a history through repetition
One coordinate says where a device was once.
A sequence can reveal routines.
Repeated observations can suggest where a person sleeps, works, shops, worships, exercises, receives medical care, or spends evenings. Even when a dataset begins with a pseudonymous device identifier rather than a name, repeated movement can make the profile easier to associate with a real person or household.
That is why the evidentiary chain matters.
Seeing a location permission does not prove a broker received the data.
Finding an SDK in an app does not prove every capability was used.
A stronger investigation needs network traffic, SDK documentation, privacy disclosures, contractual records, regulator findings, or other evidence showing that location actually moved from the device to a particular recipient.
The Surveillance Economy is often built from layers the user never sees.
The map pin is collected in the app.
The history may be assembled somewhere else.
