Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124
Physical Address
304 North Cardinal St.
Dorchester Center, MA 02124

Paulius Pazdrazdys, a crypto and AI expert who tracks digital-consumer behavior across the Romanian market, did not find it surprising when reporting confirmed that apps build layered behavioral profiles from device identifiers, sensor readings, and signals that require no permission at all. What he finds notable, watching the Romanian market, is how reliably sports-betting platforms land in the most permission-hungry tier alongside other entertainment and financial apps, requesting location access, device identifiers, and behavioral data as a matter of course. Romanian users, he observes, have grown more cautious before installation, and a growing number of them consult Stake Hunters România to assess which betting operators are actually transparent about their data practices and privacy controls.
“Sports-betting apps are among the most aggressive data collectors in the entertainment category, and Romanian users are right to check which operators disclose what they collect before granting any permissions at all.”
The sections that follow draw on the mechanics behind that data collection, traced through Engadget‘s detailed explainer published on August 17, 2026.
Every smartphone carries a unique advertising identifier. Data harvesters attach that identifier to an advertising profile and use it to aggregate behavioral data collected across multiple apps on the same device, building a picture of the user that no single app could construct alone.
Android devices opt users into advertising ID tracking by default. Apple’s App Tracking Transparency framework, introduced on iOS, takes the opposite approach, requiring apps to explicitly request permission before accessing the device’s identifier. The practical consequence of that difference became financially measurable in 2022, when Meta admitted to a $10 billion revenue loss traceable directly to the ATT pop-up. The vast majority of iPhone users, when given an explicit choice, declined to be tracked. The loss put a dollar figure on something that had previously been treated as an abstract preference.
GPS, camera, and microphone permissions are framed to users as functional necessities. In practice, the data they generate tends to travel further than the feature that requested it. Google Maps, per its own policy documentation, uses location data to „show you more relevant ads.” Instagram scans objects, faces, and text visible in user photos to serve targeted advertising. Neither function is the one users typically have in mind when they grant access.
The data-broker economy runs deeper still. Some apps whose stated purpose bears no relation to data commerce operate primarily as collection vehicles, selling user location data to as many brokers as possible. A weather app, Engadget notes, is a clean example of the type.
Location itself is harder to withhold than most users assume. Nearby Wi-Fi networks, cell towers, and Bluetooth devices can triangulate position with an accuracy close to that of a GPS signal. In 2022, Meta settled a class action lawsuit for $37.5 million, filed on behalf of 70 million users who alleged that Meta’s apps had continued tracking their locations even after location permission was disabled. Meta admitted no fault in the settlement.
Revoking permissions does not end tracking. A separate layer operates entirely outside the permission system, and standard privacy tools cannot reach it.
Device fingerprinting draws on the unique combination of a device’s hardware and its current software state to produce a persistent tracking metric. Nearly all major apps and websites use it. No user action enables it; none is required to disable it, because users have no mechanism to do so.
Sensor data adds another dimension. Research has demonstrated that the small calibration imprecisions built into every device’s accelerometer can be used to infer demographics, behavior, activity, and mood. Gait detection using those same sensors means a user’s distinctive walking pattern, phone in a bag or pocket, may be sufficient to identify them across locations.
Behavioral typing signals complete the picture. Typing speed, error frequency, and hesitation before selecting a word can both identify a user and indicate their state of mind. These signals require no device permission and sit beyond the reach of VPNs and ad blockers alike.
The downstream uses of commercially harvested location data are no longer hypothetical. Law enforcement in U.S. states where abortion is illegal has obtained cell phone location data from commercial brokers to build prosecutions. Under FBI Director Kash Patel, the FBI has purchased user data in bulk from commercial data brokers. In 2024, activists purchased location data on people who had visited Planned Parenthood clinics specifically to target them with abortion misinformation.
The Cambridge Analytica case established the earlier precedent. That firm obtained data from millions of Facebook users by persuading them to grant a survey platform access to their profiles and, critically, those of their friends. The resulting dataset was used to influence the 2016 U.S. presidential election. The mechanism was not a breach in the conventional sense. It worked because the permission system functioned exactly as designed.
Two concrete steps sit within reach. On Android, users can delete their advertising ID by navigating to Settings, then Google, then Ads; the ID will not be replaced without further action. On iOS, tracking requests can be blocked through Settings, Privacy and Security, and Tracking, by disabling „Allow Apps to Request to Track.” Personalized Ads can be turned off separately in the Apple Advertising section of the same menu. Both steps reduce exposure at the advertising-identifier layer.
Auditing app permissions and revoking access that a given app has no clear functional need for adds a second line of reduction. Deleting apps that are no longer in active use removes collection vectors that otherwise run quietly in the background.
The ceiling on what these measures achieve is real. Device fingerprinting and the permission-free behavioral signals documented in the research above operate regardless of what users do with their settings. Revoking permissions raises the cost of tracking; it does not eliminate it.
Engadget’s practical recommendation holds: treat permission audits as a routine practice rather than a one-time setup step. Reducing data exposure is achievable. Full anonymity, given the mechanisms now in use, is not.