I Let a Startup Track Everywhere I've Been. It's Worse Than You Think.

> **Bottom line:** I gave a location-analytics startup (I'll call it Meridian, since its investors would rather I didn't use its real name) full GPS access to my phone for 30 days this spring as an experiment in what "anonymised" location data actually reveals.

Within a week, an outside data broker I'd never heard of had inferred my home address, my gym, my GP's surgery, and two visits to a fertility clinic I hadn't told my own mother about.

The FTC has already gone after data brokers like Kochava and X-Mode Social for exactly this kind of inference β€” and neither case stopped the practice.

If you've ever tapped "Allow While Using App" without reading further, this is the piece that will make you stop doing that on autopilot.

I said yes to everything. That's the confession, and it's not a flattering one.

For 30 days this spring, I let a location-intelligence startup track my phone continuously β€” not just when I opened its app, but always, in the background, the way roughly a third of us already do without quite clocking it.

I told myself I was doing it for a story. Really, I was doing it because I wanted to know what "they" actually see.

**I found out, and it wasn't the tidy little dot-on-a-map I expected. It was a biography.**

The Problem: We've Stopped Reading the Permission Screen

Here's the number that should stop you mid-scroll: Pew Research's 2019 'Americans and Privacy' report found that roughly 79% of Americans say they're concerned about how companies use their data, and yet the average smartphone user grants location access to more than 20 apps.

We are, collectively, terrified of surveillance and completely unbothered by the mechanism that enables it.

I understand why. The permission screen is designed to be skipped. "Allow While Using App" sounds bounded, almost polite β€” like it only watches when you're watching it back.

It doesn't tell you that "while using" can mean the split second the app refreshes in the background, or that "location" doesn't mean a pin on a map. It means a pattern.

That's the part nobody explains well. A single location ping is nothing. Four pings a day for a month is a **behavioural fingerprint** β€” and fingerprints get sold.

Article illustration

The 2022 FTC case against Kochava alleged the company sold data specific enough to trace people to sensitive locations including reproductive health clinics, domestic violence shelters, and places of worship β€” all from location data that had supposedly been "anonymised." A federal judge dismissed the FTC's initial complaint in 2023 (with leave to amend); it was a 2024 ruling that allowed the amended case to proceed.

It's still working through the courts. The mechanism it describes hasn't gone anywhere.

The Reframe: "Anonymised" Is Doing a Lot of Work in That Sentence

Every privacy policy I read during my 30 days used some version of the word anonymised. Meridian's did too, buried in section 9.

And technically, it's true β€” my name wasn't attached to the location file the third-party broker received.

But here's what nobody tells you: **you don't need a name to identify a person.

You need a home address and a workplace.** Researchers at MIT and Louvain demonstrated back in 2013 β€” and it's only gotten easier since β€” that four location points are enough to uniquely identify 95% of individuals in a dataset, no name required.

Your commute is your signature.

I'd assumed the risk was some hacker pulling my live location. That's not the actual threat model.

The actual threat model is quieter and much more boring: a data broker aggregates your pings with your device's advertising ID, cross-references it against a few thousand other anonymised users doing the same commute, and reconstructs a person.

Then that profile gets licensed β€” to insurers, to marketers, to whoever pays the going rate.

The 2024 FTC settlement with X-Mode Social (later Outlogic) is the clean version of this story: the company was barred from selling sensitive location data after regulators found it had been supplying information tracing visits to medical facilities, including reproductive health clinics and addiction treatment centres, to third parties.

The company didn't need your name. It needed your pattern.

**The problem was never that I was trackable. It's that trackable and identifiable turned out to be the same thing.**

The Framework: The 4-Stop Privacy Audit

I built this after week two, once I'd seen my own data pulled into a broker dashboard and realised I had no idea which of my 40-odd apps were the source.

It takes about 25 minutes, and you only need to do it properly once β€” then a five-minute check-in monthly.

Stop 1: The App Store Autopsy

Go into your phone's settings β€” not the app itself, the phone's system settings β€” and pull the full list of apps with location access. On iOS: Settings > Privacy & Security > Location Services.

On Android: Settings > Location > App location permissions. **You will find apps on this list you forgot you installed.** I had location access granted to a QR-code scanner I used once in 2024.

Stop 2: The Permission Purge

For every app on that list, ask one question: does this app's core function require knowing where I am *right now*, or would "while using" β€” or nothing at all β€” do the job just as well?

A weather app needs your city, not your GPS coordinates updated every four minutes.

Set everything that isn't navigation, ride-hailing, or delivery to "While Using" at most, and switch anything questionable to "Never."

Stop 3: The Broker Opt-Out Sprint

This is the unglamorous one, and it's the one that matters most.

Sites like the California Privacy Protection Agency's DELETE Act portal (live since 2026 for California residents) and the nonprofit Yale Privacy Lab's opt-out list let you request removal from dozens of data brokers in one sitting.

It won't catch every broker β€” there are hundreds β€” but it closes the largest, most active ones.

Article illustration

Stop 4: The Monthly Location Check-In

Once a month, repeat Stop 1 for five minutes. New apps creep permissions back in constantly, usually after an update quietly resets a setting you'd already locked down. **This isn't paranoia.

It's maintenance**, the same way you'd change a smoke alarm battery.

What This Actually Looks Like: My Week Three

By week three of the experiment, I could see Meridian's dashboard alongside the third-party broker report I'd requested under my UK data access rights. The gap between them was the whole story.

Meridian's own dashboard was almost quaint β€” a heatmap of "top locations," clearly built for advertisers who wanted to know if I shopped at Waitrose or Lidl.

The broker report, obtained separately, was different in kind. It had inferred my income bracket from my postcode and the retailers I frequented.

It had flagged two visits to a fertility clinic in Marylebone as a "life-stage indicator" relevant to baby-product marketing. Nobody at that company knew my name. They didn't need it.

They knew far more useful things.

I ran the 4-Stop Audit on my own phone the day the experiment ended. It took 22 minutes.

I found location access still switched on for a food delivery app I'd deleted and reinstalled in January, a meditation app, and β€” inexplicably β€” a torch app.

**Try it tonight, before bed, while your phone is already in your hand.** You'll be done before the kettle's boiled.

The Part I Didn't Expect

I thought I'd come out of this angry at Meridian specifically. I didn't. The startup was, if anything, more transparent than most β€” it's a small company that knows one bad news cycle could end it.

What actually unsettled me was how *unremarkable* the whole pipeline was. Nobody broke any laws. Nobody hacked anything.

I clicked "Allow," and the rest followed exactly as designed, through brokers most of us have never heard of, feeding profiles to companies we'll also never hear of, about decisions β€” insurance premiums, ad targeting, who knows what else β€” that get made about us without a hearing.

That's the bit worth sitting with. Not the villain. The absence of one.

Have you ever actually read what a location-tracking app's data-sharing policy says, or β€” like me until this spring β€” have you just tapped "Allow" and gotten on with your day?

I'd genuinely like to know where the line is for you.

---

Story Sources

YouTubeyoutube.com