Location History Is The Most Sensitive File You Own
The file nobody thinks to worry about
People spend a lot of energy worrying about their passwords, their browser cookies, their search history. Location history barely registers as a concern, which is strange, because it’s arguably the most revealing dataset most people generate. It’s not an abstraction like “browsing habits.” It’s a literal timestamped record of where your body was, minute by minute, for months or years.
Most privacy advice treats location as one data point among many. It isn’t. It’s closer to a skeleton key. If you know where someone sleeps, where they work, where their kids go to school, and where they go on Tuesday nights, you know almost everything else you’d want to know about them, without ever reading a single message they sent.
How your phone knows where you are
Modern phones combine three separate location systems, and understanding each one matters because they don’t all get disabled the same way.
GPS gives the most accurate fix but drains battery and is slow to lock indoors. Wi-Fi positioning is the workhorse: your phone scans nearby Wi-Fi access points, even ones you never connect to, and matches their SSIDs and BSSIDs against a database that Google and Apple have built by driving cars and crowdsourcing phones for over a decade. That database is why your phone can locate you indoors in seconds without a GPS signal at all. Cell tower triangulation is the fallback, less precise but still good enough to place you within a neighborhood using signal strength from towers your carrier already talks to.
None of this requires an app to be “spying” on you in the sense people imagine. The operating system itself is the primary collector. iOS logs Significant Locations in a system-level file that powers features like traffic predictions and calendar suggestions. Android’s Location History, part of what Google now folds into your Timeline, does the same thing at the account level. These aren’t rogue apps. They’re core OS functionality that happens to produce an extremely detailed movement log as a side effect.
Where the data actually goes
Once your location is captured, it doesn’t stay in one place. A location fix can end up in several places simultaneously:
The OS vendor’s own account-linked history, used for features but also retained and, depending on settings, used for advertising and product improvement. Individual apps that request location permission, which increasingly means far more apps than you’d guess, since location access is often bundled into permission requests for features that don’t obviously need it. Third-party SDKs embedded inside those apps, which is where things get harder to see. A weather app or a flashlight app might include an ad SDK that quietly collects location on its own schedule, tied to an advertising ID rather than your name, and sells access to that stream through a real-time bidding exchange or a location data broker.
This is the part people underestimate. Your location isn’t leaking from one channel you can plug. It’s leaking from a dozen small channels stitched together by the advertising and data broker industry, most of which you never interact with directly and have no visibility into.
Why it’s so easy to identify you from it
Anonymized location data gets sold and shared on the premise that stripping your name off it makes it safe. This premise doesn’t hold up well against how distinctive movement patterns actually are.
Research on large mobility datasets has repeatedly found that people’s movement is unusually unique: a small handful of location points, often just a few, is enough to pick one specific person out of a dataset containing hundreds of thousands of others, because almost nobody shares the exact same combination of home, workplace, and daily route. You don’t need a name attached to a location trail to de-anonymize it. You just need to cross-reference it against one other dataset that does have a name, which is exactly what data brokers, ad exchanges, and anyone buying that data are set up to do.
This is also why “it’s just for ads” undersells the risk. An advertising ID that never touches your legal name can still be resolved back to you, your household, and your daily patterns by anyone with the right secondary dataset. Ad targeting and re-identification use the same infrastructure.
The threat models worth actually thinking about
It helps to separate who’s likely to have your location data, because the response is different for each.
Advertising and data broker exposure is the most common and the least dramatic: your movement patterns feeding into ad targeting and being resold as aggregate or semi-aggregate data. This is worth reducing but rarely worth panicking about on its own.
Someone with brief physical access to your unlocked phone is a different problem entirely. Find My, Google Timeline, and messaging apps with live location sharing can hand a stalker or an abusive partner your real-time position with almost no technical skill required. This is one of the more common real-world harms from location data and it has nothing to do with corporations or hackers.
Data breaches at companies that store location logs are a third category. Location history sitting in a company’s database is only as safe as that company’s security practices, and it’s been demonstrated more than once that breached datasets can include far more granular location data than users expected was even being stored.
Legal requests to platform companies for account data, including location history, are a documented and routine part of how these companies operate. This piece isn’t the place to advise on the legal mechanics of that process, and there’s no privacy tool that changes whether a company complies with a valid legal request for data it holds. What you can control is how much location data exists to be requested in the first place, which is a data minimization question, not a legal one.
What actually reduces your footprint
There’s no single switch that makes this go away, and anyone selling you one is skipping the part where they explain how their product interacts with GPS, Wi-Fi positioning, and cell tower data, because it usually doesn’t.
Start with the account-level history. On an iPhone, Settings, Privacy and Security, Location Services, System Services lets you review and disable Significant Locations. On Android, Google’s Timeline settings let you turn off Location History entirely or set it to auto-delete on a schedule. Turning this off doesn’t stop your phone from knowing where it is; it stops that history from being retained and tied to your account long-term.
Next, go through app permissions individually rather than trusting the initial prompt. Most phones now offer “While Using the App” as a middle ground against “Always,” and a meaningful number of apps request Always without a real feature reason. iOS’s App Tracking Transparency and Android’s equivalent settings limit whether your advertising ID gets shared across apps, which cuts off one of the main paths location data takes into the broker ecosystem, though it doesn’t stop the app itself from collecting location for its own use.
Live location sharing deserves a specific look, separate from the OS-level settings. Check Find My, Google Maps location sharing, and any messaging app you use, for standing shares you set up once and forgot about. These are the ones most likely to matter to the physical-access threat model above.
A VPN is worth having for a lot of reasons, but it does not touch GPS, Wi-Fi positioning, or cell tower location. Your IP address and your device’s GPS coordinates are collected through completely separate mechanisms, and a VPN only affects the former. Anyone telling you a VPN hides your location in the GPS sense is describing something the technology doesn’t do.
Aim for less exposure, not none
None of this adds up to invisibility, and it shouldn’t try to. Your carrier can still place your phone near a cell tower. Physical world sightings, license plates, and payment records exist outside anything a phone setting can touch. The realistic goal is reducing how much detailed, retained, cross-referenceable location data exists about you and who has routine access to it, not achieving a state where you can’t be located at all. That’s a more honest goal, and it’s also the one that’s actually achievable with the settings sitting in your phone right now.
If you want more explainers like this that stick to how the tracking actually works instead of how scary it sounds, The Privacy Wire is where we put them.