You open a weather app. It fires an event: app_open, device_id, lat/long rounded to three decimal places, timestamp. That event leaves your phone in about 40 milliseconds. What most people assume happens next is vague: “it gets sold to advertisers.” That sentence is doing a lot of hiding. The actual pipeline has five or six distinct stages, each run by a different company, and none of them look like “selling data” in the way people picture it. Here’s the real sequence, stage by stage.

stage one: the event gets batched, not sent

Trackers rarely fire in real time. Most SDKs (Meta’s, AppsFlyer’s, Braze’s) hold events in a local queue and flush every 15 to 60 seconds, or on app background, to save battery and reduce server load. So your weather app’s location ping doesn’t travel alone. It goes out bundled with 8 to 12 other events from the same session: which screen you viewed, how long you dwelled, whether you tapped an ad. The receiving server doesn’t get “you opened the app.” It gets a small behavioral transcript.

stage two: identity resolution, the part nobody explains

The server has a device advertising ID (GAID on Android). Alone, that’s just a string. The valuable step is stitching: matching that GAID to other identifiers the same company has seen tied to the same device or household, things like a hashed email from a loyalty signup, a router IP, a Wi-Fi SSID hash. Companies like LiveRamp and Neustar exist specifically to do this stitching as a service. A 2023 audit by the Irish Council for Civil Liberties estimated that a single GAID gets cross-referenced against an average of 4 to 7 other identity graphs within its first day of being seen by a major ad exchange. The point of stitching isn’t to know your name. It’s to know that “device 8f21…” and “device b04c…” are the same human, so campaigns can follow you across your phone, your smart TV, and your laptop without ever learning who you are in a legal sense.

stage three: the auction you never see

If the app shows ads, your data enters real-time bidding (RTB), the protocol that decides which ad you see in the time it takes a page to render. Here’s the part that surprises people: every RTB auction broadcasts your profile (device ID, rough location, inferred interests, app category) to every registered bidder on the exchange, whether or not they end up winning the ad slot. Google’s own disclosures put the number of bid requests processed daily industry-wide north of 300 billion. The ICCL’s 2022 complaint against the RTB industry calculated that the average European adult has their data broadcast to bidders roughly 376 times a day. Losing bidders don’t have to discard what they saw. Most exchange terms of service let them retain bid request data for “measurement and modeling” for up to 30 days, sometimes longer. So even ads you never saw still leaked your profile to a room full of companies.

stage four: enrichment, where the profile gets fatter

Raw behavioral data (app opens, screen dwell, location) is thin on its own. Data management platforms enrich it by appending third-party attributes purchased in bulk: estimated household income bracket, presence of children in the home, credit tier, even inferred political lean. Acxiom and Oracle’s now-shuttered BlueKai were built around exactly this business, buying anonymized behavioral exhaust and stapling demographic guesses onto it. The result isn’t “the weather app knows your income.” It’s that the identity graph your device ID belongs to now carries an income estimate, contributed by a completely different data source that has never touched your phone.

stage five: it becomes a segment, not a record

Individual profiles are rarely sold retail. What gets sold is the segment: “female, 25-34, likely renters, high grocery spend, in-market for a car in the next 90 days.” Your device ID sits inside that bucket alongside tens of thousands of others. Advertisers buy access to the segment, not to you specifically. This is why deleting your data from one company rarely helps: your device ID has already been folded into a dozen downstream segments maintained by companies you’ve never heard of and never consented to directly.

why “delete my data” requests barely dent this

A GDPR or CCPA deletion request typically reaches the company you interacted with directly. It does not reach the identity graph operators, the RTB exchanges that cached your bid requests for 30 days, or the segment files already licensed to a data management platform last quarter. A 2023 study by Consumer Reports testing deletion requests against major brokers found that 40% of companies either didn’t respond within the legal window or provided data that was clearly incomplete. The pipeline is built to be distributed precisely so no single deletion request can unwind it.

what this actually means for your phone

None of this requires an app to be “spyware” in any dramatic sense. A weather app with a single ad SDK is enough to enter this pipeline. The practical lever you have isn’t deletion, it’s prevention: limiting ad tracking at the OS level, using apps that don’t run RTB-integrated ad SDKs at all, and treating “free with ads” as a specific technical commitment, not a marketing phrase. The data doesn’t get “sold” once. It gets stitched, auctioned, enriched, and bucketed, on a loop, for as long as the app stays on your phone.