A developer describing a self-tracking experiment says leaked location data can be traced through ordinary app traffic, even when a phone’s location services are turned off for every app. The report begins with a broader leak from Gravy Analytics and ends with the author finding his own data trail in advertising and analytics requests.
The central claim is not that one single app secretly knew everything. It is that multiple services, including ad networks and third-party platforms, received enough identifiers, timestamps and contextual data to reconstruct a location profile. In the account, the author says he found at least three apps on his iPhone that appeared in the leak list and then used network inspection to watch what was being transmitted after launching a single app.
The excerpt describes requests going to Unity-related endpoints, including one that contained geo data, IP information, timestamps and an identifier. It also mentions data moving from Unity Ads to Moloco Ads to Bwin, with the result that the ad shown in the game matched the user profile. That is the pattern the author treats as the smoking gun: location data does not need to be bundled in a single obvious field to be exposed.
The report also says Facebook was another destination where a geodata point appeared, reinforcing the idea that data sharing can happen across several intermediaries rather than through a single obvious broker. The author’s concern is less about one app misbehaving than about an ecosystem where many companies receive enough fragments to piece together where a person has been.
There is a second warning in the story: configuration and telemetry calls may reveal details that are not obviously personal on their face, but still expand the profile of a user’s device and behavior. The packet says the author found Unity config data that included information such as screen brightness, memory amount and volume settings. Taken together, those details do not prove a person’s identity alone, but they show why advertising infrastructure can be far more revealing than people assume.
The evidence here is a first-person technical account, not a regulatory finding. Still, the conclusion is clear enough. If leaked geolocation data can be stitched together from the ad stack, then the boundary between app usage and physical tracking is thinner than many users believe. What makes the account unsettling is the normality of the data path. None of the individual requests described in the excerpt sound extraordinary on their own, yet taken together they appear to create a usable map of a person’s movement and device state.
The story is also a reminder that privacy failures can be distributed. One company may collect a timestamp, another may receive a location hint, and a third may end up benefiting from the combined profile. That fragmentation makes it difficult for users to see where the exposure begins and ends, which is exactly why the author’s experiment is useful: it turns an abstract concern into a concrete chain.


