MobileSpie Gallery
Security & Privacy

50 Apps, One Uncomfortable Truth: We Found Out Exactly Who's Buying Your Personal Data

MobileSpie

Let's be honest — most of us click "Accept" on privacy policies the same way we click "Skip" on a YouTube ad. Fast, reflexive, zero thought. But those documents aren't just legal boilerplate. They're contracts that let companies package up details about your life and sell them to people you've never heard of.

We wanted to know exactly how bad it's gotten. So the MobileSpie team spent the better part of six weeks combing through the privacy policies, app store disclosures, and documented API connections of 50 mainstream apps across five categories: social media, fitness tracking, shopping, streaming, and food delivery. We cross-referenced those findings with known data broker partnerships and Federal Trade Commission filings where available.

What came back wasn't pretty.

The Categories That Came Out Worst

Not all apps are equally hungry for your information. Fitness and health apps turned out to be among the most aggressive data monetizers — which is uncomfortable, given that they sit on some of your most intimate details. Apps in this space frequently share data with what their policies vaguely call "wellness partners" and "research organizations." In practice, that often means health data aggregators who sell anonymized (but surprisingly re-identifiable) data sets to insurance companies, pharmaceutical marketers, and employer wellness programs.

Shopping apps were a close second. Retail and deal-hunting apps don't just track what you buy — they track what you almost bought, how long you hovered over a product, what time of day you browse, and whether you responded to a push notification. That behavioral profile gets packaged and sold to advertising networks, often within seconds of you closing the app.

Social media, perhaps unsurprisingly, sat at the top in terms of raw data volume collected — but interestingly, the biggest platforms were sometimes more transparent about it than mid-tier apps trying to punch above their weight.

What's Actually Being Sold

Here's where it gets specific. Across the 50 apps we reviewed, the most commonly shared (and monetized) data categories included:

Several apps we reviewed disclosed sharing data with upwards of 200 third-party "advertising partners" — a number that appears in the fine print of their consent management platforms but is rarely surfaced anywhere a normal user would see it.

The Companies Doing the Buying

The data buying side of this equation is dominated by a relatively small group of players. The big advertising technology firms — companies running the programmatic ad infrastructure that powers most of the internet — are consistent recipients. Data brokers like Acxiom, LiveRamp, and Epsilon show up repeatedly in partnership disclosures and known integrations. Credit-adjacent data firms and "identity resolution" companies round out the picture.

What's notable is how the data gets transformed before it's used. Your raw location history doesn't get handed to a car dealership in a spreadsheet. It gets processed, modeled, and turned into an audience segment — something like "suburban commuters, 30–44, likely in-market for a lease" — and that segment gets auctioned off in real time every time you load a webpage or open an app with ads.

You're not the product in the old-school sense. You're more like a data point in a model that's the product. It's arguably worse.

A Few Apps That Stood Out (For Better and Worse)

Without naming every app in our list, a few patterns stood out. Food delivery apps were surprisingly forthcoming about their data practices in their updated post-2023 policies — possibly because of increased regulatory scrutiny in California and other states. Several disclosed data sharing clearly and offered opt-outs that actually worked.

On the other end, some mid-tier fitness and period-tracking apps had policies that were either so vague as to be meaningless or actively contradicted by their SDK integrations. One app claimed not to sell data while simultaneously running a Meta Pixel and a Google Analytics integration that funneled behavioral data to both platforms — which, depending on how you read California's CCPA, qualifies as a "sale" under the law.

Streaming apps varied wildly. Larger platforms with their own ad businesses had detailed, if dense, disclosures. Smaller streaming services often outsourced their entire ad stack to third parties and appeared to have limited visibility into — or control over — what those partners did with the data.

What You Can Actually Do About It

We're not going to tell you to delete all your apps and live off the grid. That's not realistic. But there are practical moves that genuinely reduce your data footprint:

Reset your advertising ID regularly. On iPhone, go to Settings → Privacy & Security → Tracking. On Android, head to Settings → Privacy → Ads. Resetting this ID breaks the continuity of your profile across apps.

Opt out of "data sharing" in every app that offers it. It's buried, but it's there. Check each app's settings under "Privacy" or "Ad Preferences." Some apps, particularly those operating under California law, are required to honor these requests for all US users.

Use a DNS-based tracker blocker. Apps like NextDNS or the built-in iCloud Private Relay can block known data broker endpoints at the network level — before your data ever leaves your phone.

Read the "data shared with third parties" section, not the intro. Privacy policies bury the real information. Ctrl+F for "third parties," "partners," and "sell" — those sections tell you more than the friendly opening paragraphs ever will.

Be selective about fitness and health apps specifically. The sensitivity of health data combined with the current regulatory gray zone makes this category particularly high-risk. Stick to apps from developers with clear, auditable privacy commitments — or use your phone's native health app, which has stronger platform-level protections.

The data economy isn't going anywhere. But understanding how it works is the first step to not being completely invisible inside it — while your information stays very, very visible to everyone else.

Back to Gallery

More Stories

15 Apps, One Lab, Zero Mercy: What's Really Happening on Your Phone Behind the Scenes

Your Location Is Never Really Off: The Hidden Ways Apps Track You Anyway

Your Location Is Never Really Off: The Hidden Ways Apps Track You Anyway

Your Phone Is Crying Wolf 80 Times a Day — Here's How to Make It Stop