PRIVACY2026-06-06T14:00:45.967548+00:005 min read

The FTC Just Banned a Company for Selling Your Location to Anyone Who'd Pay

Data broker Kochava tracked hundreds of millions of phones and sold their location history — including visits to abortion clinics, domestic violence shelters, and churches. The FTC just permanently banned them. Here's what it means for you.

The FTC Just Banned a Company for Selling Your Location to Anyone Who'd Pay

They Knew Where You Were. They Sold It.

Every day, apps on your phone quietly collect your location. Every movement. Every stop. Every place you visit. They sell this data to brokers — companies you've never heard of, who have no relationship with you, who owe you nothing.

One of those brokers was Kochava.

On May 4, 2026, the Federal Trade Commission permanently banned Kochava and its subsidiary from selling sensitive location data without explicit consumer consent. It's the result of a years-long investigation that exposed just how detailed — and dangerous — this data really is.


What Kochava Was Selling

Kochava aggregated location data from hundreds of millions of mobile devices and packaged it for sale. Buyers could purchase histories showing exactly where a device had been — tied to a persistent identifier that followed the device across time.

The FTC's investigation found this data included visits to:

  • Abortion clinics and reproductive health providers
  • Domestic violence shelters
  • Religious sites — mosques, churches, synagogues
  • Mental health facilities
  • Addiction treatment centers
  • Immigration and legal aid offices

This isn't abstract. A location history that shows someone visited a domestic violence shelter is a weapon in the hands of their abuser. A history showing clinic visits can be used in states that criminalize abortion. A pattern of mosque attendance can be used to discriminate, surveil, or target.

And Kochava was selling it to anyone who'd pay.


How Your Data Got There

You didn't sign up for Kochava. You've probably never heard of them. But here's how your data ended up in their database:

Step 1 — You downloaded an app A weather app, a game, a flashlight. Many apps contain third-party SDKs — code libraries from data brokers embedded by developers in exchange for payment.

Step 2 — The app asked for location permission Maybe it needed your location for a legitimate reason. Maybe it didn't. You tapped "Allow" and forgot about it.

Step 3 — The SDK started collecting The broker's SDK inside the app began recording your location in the background, even when you weren't using the app.

Step 4 — The data was sold Your location history — timestamped, tied to your device's advertising ID — was bundled with millions of others and sold on the open market.

This is legal. It happens at massive scale. Kochava is one company. There are hundreds more.


What the FTC Ban Actually Does

The ruling requires Kochava to:

  • Stop selling sensitive location data without explicit consumer consent
  • Delete historical data that was collected without proper consent
  • Implement a data deletion program for consumer requests

What it doesn't do: it doesn't affect the dozens of other data brokers operating the same model. It doesn't give you back the data that's already been sold. It doesn't undo what buyers already know about you.

This ruling matters as a precedent. But it's not a solution.


How to Limit Location Data Collection Right Now

1. Audit app permissions on your phone Go to Settings → Privacy → Location Services. Every app with "Always" access is collecting your location continuously. Revoke anything that doesn't genuinely need it.

2. Set location to "While Using" instead of "Always" For apps that need location (maps, ride-sharing), use "While Using App" only. Never "Always."

3. Reset your advertising ID regularly Your advertising ID is the persistent identifier data brokers use to track you. Resetting it breaks the linkage.

  • iPhone: Settings → Privacy → Tracking → reset advertising identifier
  • Android: Settings → Google → Ads → reset advertising ID

4. Opt out of data broker databases Services like DeleteMe, Privacy Bee, or the California DELETE Act (if you're in CA) let you submit removal requests to major data brokers. It's tedious but effective.

5. Use a VPN selectively A VPN masks your IP-based location, but doesn't stop in-app location collection. Use both layers.


The Bigger Picture

The FTC ban on Kochava is significant — but it took years of litigation to achieve, and Kochava is one player in a multi-billion dollar industry that operates with almost no regulation in most U.S. states.

Your location data is being collected right now, by apps you've forgotten you installed, through SDKs you didn't know existed, and sold to buyers you'll never identify.

The only reliable defense is reducing what you give away in the first place.


Stay invisible. Follow HackDecoded.

Sources

WHAT TO DO RIGHT NOW
  1. 01Audit your phone app permissions — revoke location access from any app that does not need it
  2. 02Opt out of data broker sites using DeleteMe or manually via each broker's opt-out page
  3. 03Use a privacy-focused DNS (Cloudflare 1.1.1.1 or NextDNS) to block trackers at the network level
  4. 04Review your smart device settings and disable "personalised advertising" options
RECOMMENDED PROTECTIONAFFILIATE

IncogniAutomatically removes your personal data from broker sites

Get Incogni
Privacy audit checklist →
// FAQ

Common Questions About Privacy

Can smart TVs spy on me and what can I do about it?

Yes. Most smart TVs use Automatic Content Recognition (ACR) to track what you watch. To stop it: go to your TV settings and disable ACR, Samba Interactive TV, or "Viewing Data" sharing. Also disable the microphone and camera in settings when not in use.

What are data brokers and how do I remove my information?

Data brokers collect and sell your personal information. To opt out: visit each broker directly (Whitepages, Spokeo, BeenVerified, Acxiom) and submit removal requests. Paid services like DeleteMe automate this ongoing process.

Does a VPN actually protect my privacy?

A VPN hides your traffic from your ISP and masks your IP address. It does not make you anonymous. Use a no-logs VPN as one layer of privacy, especially on public Wi-Fi. Pair it with a privacy browser like Firefox or Brave and uBlock Origin.

// RELATED

More in privacy

Reclaim Your Privacy: A Step-by-Step Guide to Deleting Yourself From Data Brokers
2026-06-19T08:00:35.726019+00:00 · 6 min read
Your Smart TV Is Watching You Watch It — Here's How to Stop It
2026-06-06T14:00:46.068988+00:00 · 5 min read

Stay invisible. Follow @hack_decoded