Your location sold in real-time for 3 years without you knowing.
Citizen Lab published on April 9, 2026, a detailed analysis of Webloc, a mass surveillance tool built on mobile advertising data. Its confirmed clients include ICE, the US military, and foreign intelligence services. All without a warrant. And the feed source? The ad network where all your apps swim permanently.
What’s happening
Cobwebs Technologies, acquired by Penlink, has been selling Webloc for several years. The Citizen Lab Report No. 191, published on April 9, 2026, dissects its workings with contracts to back it up.
Two feed channels. The first: Real-Time Bidding (RTB), the real-time ad auction system that triggers every time an app displays an ad. At each bid, your mobile ad ID (MAID), IP address, and Wi-Fi location transit to dozens of buyers. Webloc buys these streams. The second: SDKs integrated directly into popular apps, weather, fitness, navigation, dating, collecting and reselling location.
The result: a database covering 500 million devices worldwide, with a 3-year history, and continuous monitoring documented in Penlink’s commercial contracts. Confirmed clients: ICE (US immigration agency), US military, US police, Hungarian intelligence, Salvadoran police.
No judicial warrant required. The data comes from the ad market, not an Apple or Google requisition.
Why it’s important for you
Apple launched App Tracking Transparency (ATT) in April 2021. Citizen Lab acknowledges it explicitly in their report: ATT “restricted access to location data”. It’s real, it’s effective, and it’s one of the rare times an Apple privacy decision had a documented impact on commercial surveillance.
But the circumvention is structural. ATT blocks cross-app ad tracking. It doesn’t block location collection by apps that legitimately need it. The weather app giving you rain in 10 minutes has your location permission. That permission can also feed an ad SDK that resells those coordinates on the RTB market.
The problem isn’t that you allowed ad tracking. The problem is that functional location, the kind you grant apps that have a real use for it, can end up in the same circuit.
And RTB itself escapes your direct control. Every ad display in an app triggers a bid where your data transits to dozens of potential buyers, without your notice, without notification, without opt-in.
Read: Privacy macOS: settings to change immediately, the section on IDFA/tracking covers iOS ATT settings that limit this exposure surface.
The historical profile is the other uncomfortable dimension. Three years of movements is enough to reconstruct your home, workplace, medical habits, social circles. This isn’t targeted surveillance on a specific person. It’s mass surveillance, where anyone can be searched retroactively. All without a judicial warrant.
Who’s targeted? Formally, Webloc is sold to law enforcement and intelligence services. But databases like this have a nasty habit of leaking, being bought by intermediaries, changing hands. Penlink isn’t the only player on this market.
What you need to do
The Citizen Lab report targets iOS 14.5 and later.
Practically, in order of effectiveness:
-
Check ATT: Settings > Privacy & Security > Tracking. “Allow Apps to Request Tracking” should be turned off. If apps already have permission, revoke them one by one from this menu.
-
Review location: Settings > Privacy & Security > Location Services. For each app, the rule is simple, “Never” if the app can function without it, “While Using” if it really needs it, never “Always” unless actively navigating. Disable “Precise Location” for all apps that don’t absolutely need it (in each app’s info, not a global setting).
-
Reset the IDFA: Settings > Privacy & Security > Tracking > turn off then turn on again. This generates a new advertising ID. It doesn’t delete the existing history in third-party databases, but it cuts off the feed for new collections.
-
Remove suspect SDK apps: third-party weather, fitness, dating apps that constantly request location are the most exposed vectors. Use Apple’s native apps (Weather, Maps) whenever possible, they don’t resell data.
The real limit: these measures reduce the surface, they don’t eliminate it. RTB functions at the scale of the entire ad ecosystem. As long as legitimate apps have your location and embed third-party SDKs, a fraction of the stream can continue to feed these markets. It’s a risk reduction, not a suppression.
Technical terms? Check the glossary.