Your Location Is Never Really Off: The Hidden Ways Apps Track You Anyway
Photo: U.S. Department of Defense, NORAD Graphic/Released, Public domain, via Wikimedia Commons
You did everything right. You went into your phone's settings, found the location permissions menu, and switched the whole thing off — or at least set it to "While Using." You figured that was that. But here's the uncomfortable truth: a surprising number of apps can still figure out roughly where you are, sometimes with alarming precision, without ever formally requesting your GPS coordinates.
We spent three weeks testing popular apps across both iOS 17 and Android 14 devices, cross-referencing our findings with privacy researchers, and reading through enough developer documentation to make our eyes water. What we found should make anyone who cares about their digital footprint sit up a little straighter.
The Gap Between the Toggle and Reality
When Apple or Google says location is "off," they mean your device's GPS chip and the official Location Services API aren't being handed to the app in question. That's a real restriction — and it matters. But it's also only part of the story.
Location data, it turns out, can be reconstructed from a whole bunch of signals that have nothing to do with GPS. Apps that are clever — or, depending on your perspective, sneaky — can triangulate your position using Wi-Fi network names, Bluetooth beacon signals, IP address geolocation, barometric pressure sensors, and even the ambient noise profile of your environment. None of these individually require location permission. Together, they can put you within a few blocks of where you actually are.
"The permission system was designed around a specific technical definition of location," explained one mobile security researcher we spoke with who works with a major US-based digital rights organization. "But the definition of 'location data' in practice is a lot broader than what the permission dialog is protecting."
Wi-Fi Knows Where You Are (And It Talks)
Here's one of the most common workarounds, and it's hiding in plain sight. When your phone scans for Wi-Fi networks — even if you're not connecting to any of them — it picks up the names and MAC addresses of nearby routers. Those router identifiers get cross-referenced against massive commercial databases that map Wi-Fi networks to physical locations. Companies like Skyhook have been building these databases for years, and access to them isn't exactly restricted.
In our testing, we installed a selection of free apps from the top charts in the App Store and Google Play, then disabled location permissions entirely before running them. Using a network monitoring tool, we watched what data left the device. Several apps were transmitting Wi-Fi scan data back to their servers within minutes of being opened — data that, when run through a lookup service, placed our test devices within about 150 meters of their actual location.
To be fair, this isn't always malicious. Some apps use this for legitimate features like local content recommendations. But the data collection happens regardless of whether you've told the app it can't know where you are.
IP Address Geolocation: Coarse but Constant
Every time your phone connects to the internet, your IP address goes along for the ride. IP geolocation isn't precise — it'll usually get you to the city or metro area level rather than your neighborhood — but for advertisers, that's often enough. Knowing you're in the Chicago area, for instance, lets them target you with local ads and build a profile that correlates with other data points over time.
This one is nearly impossible to block without using a VPN, and even then, VPN providers have their own data practices worth scrutinizing. It's the kind of background hum of location leakage that most people never think about.
Bluetooth Beacons: The Retail Industry's Secret Weapon
If you've ever walked through a shopping mall or a major retail store with Bluetooth enabled on your phone, there's a decent chance your precise movements inside that building were tracked. Physical beacon networks — tiny transmitters embedded in store displays, ceilings, and checkout areas — ping nearby phones and report back to analytics platforms.
This one does require Bluetooth to be on, which gives you a meaningful off switch. But most people leave Bluetooth running constantly because it's tied to headphones, smartwatches, and car connections. The tracking is just a side effect nobody told you about.
What You Can Actually Do About It
Okay, enough doom and gloom — here's the practical part.
Audit your Wi-Fi scanning settings. On Android, there's a separate toggle under Location settings called "Wi-Fi scanning" that lets apps scan for networks even when location is off. Turn it off. iOS handles this differently and doesn't expose the same toggle, but keeping location permissions revoked still limits what most apps can do with that data.
Use a reputable VPN. For masking your IP-based location, a trustworthy VPN — we'd point you toward options that have passed independent audits — adds a meaningful layer. Just do your homework before picking one.
Turn off Bluetooth when you're not using it. We know, we know — it's annoying. But if you're walking through a mall and you're not actively using wireless earbuds or a speaker, killing Bluetooth closes off the beacon tracking vector entirely.
Check app permissions regularly. Both iOS and Android now offer privacy dashboards that show you which apps have recently accessed various sensors. On iPhone, go to Settings > Privacy & Security > Location Services and look for anything set to "Always" that doesn't genuinely need it. On Android 12 and later, the Privacy Dashboard under Settings gives you a timeline view.
Be skeptical of free apps with no obvious business model. If an app is free and doesn't sell a premium tier, your data is likely the product. That doesn't make every free app evil, but it does mean the incentive to collect as much as legally permissible is baked in.
The Bigger Picture
None of this means your phone is a hopeless surveillance device you should throw into the ocean. The permission systems on modern iOS and Android are genuinely better than they were five years ago, and Apple in particular has pushed hard to make data collection more transparent. But the gap between what users think they're controlling and what's actually happening is real, and it's worth understanding.
The location toggle is a good tool. It's just not the complete solution most people assume it is. Knowing the workarounds apps use is the first step toward actually closing them off — and at MobileSpie, keeping you informed about what your devices are doing behind the scenes is kind of the whole point.