Where you live, where you work, when you are out. Most apps upload all of it to a server. Here is what that has cost people, and why Steady Pace is built so it can't.
A leak like this needs no hack. It needs an app that uploads where you go and a setting you never changed. The same public traces that outlined a base in Syria can outline a stranger's street, their gym, and the hours they are away from home. Researchers have shown that four location points are enough to pick one person out of a million.
Once your movements become data, they have a price. It is cheap, and there is a buyer.
12ยข
the price one broker charged for a U.S. soldier's location record. CNN ↗
61 million
phones whose week of movements one broker sold at once. FTC ↗
11,000+
things one data broker tracks about each of 2.5 billion people. Acxiom ↗
87%
of people are identifiable from just ZIP code, birthday, and gender. EFF ↗
A short and incomplete history of location and health data getting out, sold, or handed over. Every item below is a real, reported incident.
Troops were still exposing CENTCOM base routines in the Middle East through public Strava posts.
Stars and Stripes ↗A sailor's logged run on Strava revealed the position of an aircraft carrier at sea.
Bitdefender ↗Samsung Health told users to share medications and menstrual data with its AI or lose synced data.
Notebookcheck ↗The FBI director testified the FBI had resumed buying Americans' location data from brokers.
TechCrunch ↗1,400 Strava activities from seven bodyguards exposed the Swedish prime minister's home and movements.
Euronews ↗Broker Gravy Analytics was hacked, leaking about 17 terabytes of precise location data on millions.
NBC News ↗A jury found Meta liable for using period-app data to target ads.
The Register ↗Le Monde found French nuclear-submarine crews leaking patrol dates through their Strava runs.
Euronews ↗Ransomware leaked about 72 million Under Armour customer records, including names and locations.
Malwarebytes ↗Oura's deal with a defense contractor raised fears over access to health and reproductive data.
Slate ↗A lawsuit alleged Whoop shared users' health data with a third-party tracker without consent.
Milberg ↗The FTC banned brokers Gravy Analytics and Venntel from selling sensitive location data.
FTC ↗Reporting found ICE moving to buy a tool tracking hundreds of millions of phones every day.
404 Media ↗The FTC acted against a carmaker for selling drivers' precise location without consent.
FTC ↗Le Monde tracked the bodyguards of Biden, Trump, Macron, and Putin through their Strava posts.
Semafor ↗Researchers pinned Bumble, Hinge, and Grindr users to within about two metres.
TechCrunch ↗A regulator banned a broker from selling sensitive location data, the first ban of its kind.
FTC ↗Strava's new terms banned third parties from using its data to train AI, after an API crackdown.
TechRepublic ↗A broker's tool tracked a phone to an abortion clinic with no warrant needed.
404 Media ↗A broker sold the location data of visitors to 600 reproductive-health clinics.
The Record ↗Senate documents confirmed the NSA buys Americans' internet browsing records from data brokers.
US Senate ↗A stalkerware breach exposed data from 2.4 million customers of a covert phone-surveillance app.
TechCrunch ↗Automakers were found secretly sharing driving data with insurers through a data broker.
The New York Times ↗A Senate probe found carmakers selling driver data for as little as 26 cents per car.
US Senate ↗A study de-anonymized Strava heatmap users and found their home addresses.
BleepingComputer ↗A regulator found GoodRx shared prescription and health data with Facebook and Google.
FTC ↗BetterHelp was found to have shared mental-health data with Facebook and Snapchat.
FTC ↗The 23andMe breach exposed genetic and ancestry data on about 6.9 million users.
HIPAA Journal ↗A regulator found a fertility app shared data with Google and overseas analytics firms.
TechCrunch ↗A man used Strava to monitor a jogger's routes; a court granted a stalking order against him.
The Sun ↗A privacy review called cars the worst product category it had ever reviewed for privacy.
Mozilla Foundation ↗Reuters found workers at a carmaker privately sharing intimate videos from customers' car cameras.
Reuters ↗Researchers bought about 5,000 US servicemembers' records for as little as 12 cents each, sortable by base.
CNN ↗SafeGraph sold a week of location data on abortion-clinic visitors for about 160 dollars.
Vice ↗Records showed a US agency buying vast quantities of cellphone location data without warrants.
ACLU ↗Two US agencies contracted a broker selling location data harvested from dating apps.
The Intercept ↗A regulator sued a broker for selling data that traced visits to abortion clinics.
CNN ↗A company was found selling app-sourced location data cheaply to local police.
EFF ↗Gay and bisexual dating apps and prayer apps sold users' location data to a broker.
The Markup ↗A woman was tracked on Strava and murdered by a rival who followed her routes to find her.
Fox News ↗Fake Strava segments were used to surveil about 100 personnel at six secret Israeli military bases.
Bitdefender ↗Researchers defeated Strava's privacy zones and located users' homes with up to 85% success.
Dark Reading ↗A firm demonstrated tracking the phones of CIA and NSA staff using ordinary app location data.
The Intercept ↗Google paid $391.5 million to 40 US states over misleading location-tracking practices.
NJ Attorney General ↗A woman used an AirTag to find her boyfriend, then ran him over and killed him.
The Register ↗A sex trafficker used a family-tracking app as an electronic leash on a teenage victim.
Forbes ↗A broker sold timestamped location data from 61 million unique devices in a single week.
FTC ↗Life360 sold precise location data on tens of millions of people, including children.
The Markup ↗A Catholic priest was outed after a publication bought his Grindr location data.
Washington Post ↗A regulator found the Flo app shared fertility and pregnancy data with Facebook, Google, and others.
FTC ↗A prayer app sold user location data through a broker.
Vice ↗The US Treasury bought a location-data app to investigate people.
The Intercept ↗An unsecured third-party database exposed 61 million Fitbit and Apple Health records.
AppleInsider ↗Peloton's unauthenticated API let anyone pull riders' private profile and workout data.
TechCrunch ↗Researchers found Nike Run Club, Runkeeper, and MapMyRun lacked two-factor login and allowed weak passwords.
TechCrunch ↗A US intelligence agency admitted buying Americans' phone location data without warrants.
The Hill ↗One broker advertised 11,000-plus data attributes on 2.5 billion people.
Acxiom ↗The Untappd beer check-in app was used to track military and intelligence staff at the Pentagon and Camp Peary.
Bellingcat ↗The Muslim Pro app, with 98M+ downloads, sent location data to a broker that reached the US military.
Vice ↗Venntel sold app location data to ICE, CBP, and the FBI, who tracked phones worldwide.
Vice ↗Garmin's fitness services were knocked offline for days by a ransomware attack.
BleepingComputer ↗Strava turned its Flyby feature off for everyone after it exposed nearby strangers and enabled stalking.
BleepingComputer ↗US special operations bought location data drawn from Muslim prayer-app users.
Vice ↗The Secret Service bought a phone-tracking tool built on app location data.
Vice ↗An antivirus company was found selling users' browsing data through a subsidiary.
Vice ↗The New York Times tracked named Secret Service and Pentagon staff from a leaked 12-million-phone dataset.
The New York Times ↗The Flo period app sent menstruation and pregnancy data to Facebook.
CNBC ↗A pregnancy app sold aggregated employee pregnancy data to their employers.
Washington Post ↗Los Angeles sued a weather app for covertly selling users' location data.
NBC News ↗A study found 99.98% of Americans could be re-identified from almost any dataset.
Nature Communications ↗Google's location store was found feeding police geofence warrants that snared innocent people.
The New York Times ↗Strava's global heatmap exposed the perimeters and patrol routes of secret military bases.
CNN ↗Polar Flow exposed names and home addresses of 6,500+ personnel at 200+ military and intelligence sites.
Bellingcat ↗The US military said it was refining wearable-device rules after the Strava heatmap exposed base activity.
The Register ↗Grindr shared users' HIV status and location with two third-party firms.
BuzzFeed News ↗Under Armour's MyFitnessPal breach compromised about 150 million accounts.
CNBC ↗Analysts traced Russian soldiers' movements inside bases, including in Crimea, through Strava.
Atlantic Council DFRLab ↗Google was found storing location data even when users turned Location History off.
Associated Press ↗Researchers found flaws in a fertility app that let attackers reach users' sensitive data.
TechCrunch ↗Four points re-identified 90% of people in a set of credit-card records on 1.1 million people.
Science ↗Runtastic left live workout maps unsecured by default, letting attackers track runners in real time.
Pen Test Partners ↗Tinder's API leaked distances, letting anyone triangulate a user's exact location.
Include Security ↗Strava began selling athletes' data to transport agencies; one paid $20,000 for cyclists' movements.
Gizmodo ↗Four location points were enough to uniquely identify 95% of 1.5 million people in phone data.
Scientific Reports ↗Anonymized Netflix ratings were de-anonymized using a little outside knowledge.
Narayanan and Shmatikov ↗The New York Times re-identified an anonymous searcher from a released AOL dataset.
The New York Times ↗A researcher showed 87% of Americans are identifiable from ZIP, birth date, and gender alone.
EFF ↗Steady Pace has no account and no server, and it makes no network connections at all. Your runs are written to your phone and stay there. Each one is anonymized on the device: the whole route is shifted by an offset that is worked out locally and then discarded, so the coordinates saved on your phone do not match the ground you ran, and the shift cannot be reversed. Put the phone in airplane mode and every feature still works.
No account. No server. No network connections. Nothing to leak. The strongest privacy promise is not a policy you have to trust. It is an app that cannot spill what it never collects.
Tracking a run is useful. The risk comes from apps that send your location somewhere it can be stored, sold, or spilled. Pick a tool that keeps your runs on your phone and asks for nothing else.
No. The app makes no network connections at all. There is no account and no server, so your runs have nowhere to go. They are written to your phone and stay there, and deleting the app deletes them.
Each run's whole route is shifted by an offset that your phone works out and then discards. The coordinates saved on your phone no longer match where you ran, and because the offset is gone, the shift cannot be reversed by us or by anyone reading the file.
The shape of the route is kept, because that is the map, while its true location is discarded. A shared run shows the shape of your loop sitting in the open ocean, far from the streets around your home.
You can test it. Put your phone in airplane mode and go for a run. Everything still works, because nothing was ever being sent. A promise you can check beats a privacy policy you have to trust.
Set a target pace. A tone rises when you slow and falls when you speed up, so you hold it without looking at your phone. No ads, no account, no subscription.
Download on the App Store