Candy Crush Saga shares your data with 131 different third-party companies. Temple Run connects to 73. Subway Surfers links to 68. These are not obscure apps from shady developers. They are among the most downloaded mobile games in history, with billions of installs between them.
When people ask which apps sell their data, they usually imagine malware or sketchy utility apps with names like “Battery Optimizer Pro.” The reality is far more mundane and far more profitable. The apps selling your data are the ones you use every day, made by companies you recognize, sitting in the top charts of every app store.
The legitimate data marketplace dwarfs the sketchy one
The illegal spyware industry gets headlines, but the legal data broker ecosystem processes orders of magnitude more personal information. A typical gaming app with 50 million installs and seven ad networks embedded generates more exploitable data per day than a thousand stalkerware apps combined.
The difference is legitimacy. When a dating app shares your location history with 23 analytics partners, that’s just “monetization strategy.” When a flashlight app does it, we call it surveillance. The data flows are identical. The business models are identical. One gets venture funding, the other gets banned.
Major publishers have optimized this system to surgical precision. King (the Candy Crush developer, now owned by Microsoft) doesn’t sell your data directly. Instead, it embeds software development kits from companies like AppLovin, Unity Ads, Google AdMob, Facebook Audience Network, and dozens of others. Each SDK collects its own set of identifiers, behavioral signals, and device fingerprints. Each one feeds its own data marketplace.
You are not the customer of these apps. You are the inventory.
The SDK supply chain is intentionally opaque
App developers often don’t know what data their own apps collect. This is not an accident. The SDK model creates plausible deniability by design. A developer integrates five analytics tools and three ad networks, and those eight SDKs pull in their own dependencies, which pull in more dependencies. By the time an app ships, it might be running code from 40 different companies, and the original developer has no practical way to audit what happens when that code executes.
I’ve seen this pattern repeatedly in app teardowns. A fitness app claims to collect only “basic usage statistics” in its privacy policy. The actual data flow includes precise GPS coordinates every 30 seconds, uploaded to six different servers, processed by companies the developer has never heard of. When questioned, the developer genuinely doesn’t know this is happening. The SDK documentation never mentioned it.
The financial incentives flow backwards. Ad networks pay per impression, per click, per install. The more data they collect, the better they can target ads, the higher the click rates, the more money everyone makes except the user. No individual company has an incentive to collect less data. The system rewards maximum extraction.
The top 100 free apps contain an average of 6.2 tracking libraries
This number comes from systematic analysis of popular Android apps, stripping out the actual code and looking at which third-party SDKs are embedded. Gaming apps average higher (7.8 trackers). Social apps average lower (4.1 trackers), mostly because the platform itself does all the surveillance and doesn’t need outside help.
Paid apps track less. Apps that cost $4.99 average 2.1 third-party trackers. The surveillance economy runs on “free.” Every free app needs to make money somehow, and the easiest path is to become a data collection node in someone else’s advertising infrastructure.
Weather apps are particularly aggressive. A popular free weather app might show you a five-day forecast that costs the developer roughly $0.0003 to generate via API calls. That same app embeds tracking code that generates $0.12 per user per month in aggregate data value. The weather is the excuse. The location tracking is the product.
What selling actually means in practice
Data brokers speak carefully. They don’t “sell” data, they say. They offer “data enrichment services” or “audience insights” or “measurement solutions.” The distinction is semantic. Money flows one direction, access to personal information flows the other.
Here’s how it works in practice. An advertiser wants to reach “women aged 25 to 34 who recently searched for engagement rings and live within 50 miles of a luxury mall.” A data broker like LiveRamp or Oracle Data Cloud takes that requirement and matches it against profiles built from thousands of apps. They identify 47,000 devices that fit the criteria. The advertiser buys access to show ads to those specific devices. The apps that contributed data get a small revenue share.
Your data is never “sold” as in “here’s a spreadsheet with names and addresses.” It’s sold as access. The advertiser never sees your personal information directly, but they reach you with surgical precision based on that information. This is somehow supposed to be more privacy-friendly. It is not.
The secondary markets are worse
Primary data collection is just the beginning. Once information enters the broker ecosystem, it gets resold, repackaged, combined with other data sets, enriched with public records, and sold again. A location ping from a grocery app gets merged with credit card transaction data (purchased from banks), demographic data (purchased from data aggregators), and browsing history (purchased from ISPs). The resulting profile knows more about you than your closest friends.
Some of this enriched data ends up in places nobody intended. Insurance companies buy “lifestyle indicators” to adjust premiums. Employers buy “behavioral risk scores” to screen applicants. Landlords buy “financial stability predictions” to evaluate renters. The grocery app developer had no idea their SDK was feeding this chain.
The apps that don’t sell your data are easy to identify
They cost money. They have no ads. They collect only what they need to function. Signal doesn’t sell data because Signal doesn’t collect data worth selling. Minecraft (the paid version) doesn’t sell data because Microsoft already makes $8 per download. The New York Times app has trackers, but far fewer than free news apps, because subscriptions provide another revenue source.
This creates a harsh choice. Either pay for software, or become the product. There’s no middle path at scale. The economics don’t support it. A developer who tries to be ethical and avoid trackers while keeping the app free will get outcompeted by developers who monetize more aggressively.
The tragedy is that most users would rather pay once than be surveilled forever, but the app stores have trained everyone to expect software for free. We created this market. We normalized the idea that entertainment and utility should cost nothing. Developers adapted by finding another way to get paid. We just didn’t realize the price was this high.