You have probably seen the number. “This app contains 7 trackers.” Maybe in a scan result, maybe in a news article, maybe in a Play Store review from someone angrier than you. But what does that actually mean? What is a tracker, technically? What does it do inside the app on your phone? And why should a normal person care?
These are fair questions. The privacy community throws the word “tracker” around like everyone already knows what it means. Most people do not.
A tracker is code that reports to someone else
When a developer builds an app, they rarely write everything from scratch. They use libraries, which are pre-built chunks of code that solve common problems. Need crash reporting? Import a library. Need analytics? Import a library. Need to measure ad performance? Import a library.
Each of these libraries is written and maintained by a third-party company. Firebase by Google. Adjust by Adjust GmbH. AppsFlyer by AppsFlyer Ltd. When the developer imports the library, that company’s code starts running inside the app. On your phone. With whatever permissions the app has.
A tracker is one of these libraries whose primary or secondary function is collecting data about you and sending it somewhere that is not the app developer’s own server. You can see how AppXpose detects these tracker signatures at the bytecode level.
What trackers actually see
The specifics depend on the tracker, the app’s permissions, and the Android version. But most commercial trackers collect some combination of:
- Device identifiers: your advertising ID, device model, OS version, screen resolution. Enough to build a fingerprint even without a persistent ID.
- Usage data: when you open the app, how long you stay, which screens you visit, which buttons you tap, where you scroll.
- Location: if the app has location permission, many trackers will read it. Even if the tracker’s stated purpose is crash reporting.
- Network information: your IP address, WiFi network name, carrier. Your IP alone is enough to geolocate you to a city.
- Referral data: where you came from, which ad you clicked, which campaign brought you in.
A single tracker seeing this is unremarkable. Seven trackers seeing this, across 40 apps, all correlating data through shared identifiers, is a surveillance infrastructure. Not in theory. In practice, today, on the phone in your pocket. Our research data from 3,745 analyzed apps documents the scale of this problem across the Play Store.
How they get into apps
Developers rarely add trackers with malicious intent. The process is mundane.
A developer wants to know why their app crashes on Samsung devices. They add Firebase Crashlytics. It takes four lines of code and solves the problem. What they may not realize is that Crashlytics shares a codebase with Firebase Analytics, and the default configuration sends usage data alongside crash reports.
Another developer wants to measure which marketing channel brings the most installs. They add Adjust. Adjust needs device identifiers to do attribution. Now every user who opens the app has their device fingerprinted by a company in Berlin they have never heard of. You can see this in action in the Facebook app scan results, where multiple attribution and analytics SDKs stack on top of each other.
This is how a simple weather app ends up with 9 trackers. Not because the developer is evil. Because each tool solved a real problem and each tool came with a passenger.
We documented the most common ones in our scan of 32 popular apps. Firebase Analytics appeared in 94% of them. Facebook’s SDK in 62%. The numbers are not outliers. They are the baseline.
Why “I have nothing to hide” does not apply
The standard response to tracker warnings is “I have nothing to hide.” This misunderstands the problem.
Trackers do not care about your secrets. They care about your patterns. Which apps you open at 2am. How often you visit the pharmacy. Whether you searched for divorce lawyers or pregnancy tests or debt consolidation. None of these are secrets in isolation. All of them are valuable in aggregate, to advertisers, to insurance companies, to data brokers who sell profiles to anyone willing to pay.
You are not hiding something. You are leaking a continuous stream of behavioral data to companies whose entire business model is selling that stream. The question is not whether you have something to hide. The question is whether you want 30 companies you have never heard of building a profile of your daily life.
What you can do about it
You cannot avoid trackers entirely. They are in virtually every app on the Play Store. But you can make informed decisions.
Scanning your most-used apps takes minutes and changes how you think about what is on your phone. When you see that your flashlight app has 11 trackers and your calculator has zero, the decision to switch becomes obvious. When you see that two note-taking apps do the same thing but one has 3 trackers and one has 9, you pick the one with 3.
AppXpose exists to make that comparison possible. Not to scare you, not to tell you what to do, but to give you the information you would have wanted before you tapped install.
The trackers are not going away. But the assumption that nobody checks is the reason they got this bad. Every scan is a small vote against that assumption.