Child-tracking app that oldsters love sells exact location information

by keishaclinic

Life360, a well-liked household security app utilized by 33 million folks worldwide, has been marketed as an effective way for fogeys to trace their youngsters’s actions utilizing their cellphones. The Markup has realized, nevertheless, that the app is promoting information on children’ and households’ whereabouts to roughly a dozen information brokers who’ve bought information to nearly anybody who desires to purchase it. 

By means of interviews with two former workers of the corporate, together with two people who previously labored at location information brokers Cuebiq and X-Mode, The Markup found that the app acts as a firehose of knowledge for a controversial trade that has operated within the shadows with few safeguards to stop the misuse of this delicate info. The previous workers spoke with The Markup on the situation that we not use their names, as they’re all nonetheless employed within the information trade. They mentioned they agreed to speak due to considerations with the situation information trade’s safety and privateness and a need to shed extra gentle on the opaque location information economic system. All of them described Life360 as one of many largest sources of knowledge for the trade. 

“We have now no means to substantiate or deny the accuracy” of whether or not Life360 is among the many largest sources of knowledge for the trade, Life360 founder and CEO Chris Hulls mentioned in an emailed response to questions from The Markup. “We see information as an essential a part of our enterprise mannequin that enables us to maintain the core Life360 providers free for almost all of our customers, together with options which have improved driver security and saved quite a few lives.”

A former X-Mode engineer mentioned the uncooked location information the corporate obtained from Life360 was amongst X-Mode’s most beneficial choices as a result of sheer quantity and precision of the information. A former Cuebiq worker joked that the corporate wouldn’t be capable to run its advertising and marketing campaigns with out Life360’s fixed circulation of location information. 

The Markup was in a position to verify with a former Life360 worker and a former worker of X-Mode that X-Mode—along with Cuebiq and Allstate’s Arity, which the corporate discloses in its privateness coverage—is among the many corporations that Life360 sells information to. The previous Life360 worker additionally informed us Safegraph was among the many consumers, which was confirmed by an electronic mail from a Life360 govt that was seen by The Markup. There are probably extra corporations that profit from Life360’s information primarily based on these companions’ clients. 

Hulls declined to reveal a full listing of Life360’s information clients and declined to substantiate that Safegraph is amongst them, citing confidentiality clauses, which he mentioned are within the majority of its enterprise contracts. Information companions are solely publicly disclosed when companions request transparency or there’s “a selected purpose to take action,” Hulls mentioned. He did verify that X-Mode buys information from Life360 and that it’s one in all “roughly one dozen information companions.” Hulls added that the corporate could be supportive of laws that may require public disclosure of such companions.

X-Mode, SafeGraph, and Cuebiq are identified location information corporations that provide information and insights gleaned from that information to different trade gamers, in addition to clients like hedge funds or corporations that deal in focused promoting. 

Cuebiq spokesperson Invoice Daddi mentioned in an electronic mail that the corporate doesn’t promote uncooked location information however supplies entry to an aggregated set of knowledge by way of its “Workbench” instrument to clients together with the Facilities for Illness Management and Prevention. Cuebiq, which receives uncooked location information from Life360, has publicly disclosed its partnership with the CDC to trace “mobility traits” associated to the COVID-19 pandemic.

“The CDC solely exports combination, privacy-safe analytics for analysis functions, which utterly anonymizes any particular person person information,” Daddi mentioned. “Cuebiq doesn’t promote information to legislation enforcement companies or present uncooked information feeds to authorities companions (in contrast to others, akin to X-Mode and SafeGraph).”

X-Mode has bought location information to the U.S. Division of Protection, and SafeGraph has bought location information to the CDC, in accordance with public information.

X-Mode and SafeGraph didn’t reply to requests for remark.

The Life360 CEO mentioned that the corporate applied a coverage to ban the promoting or advertising and marketing of Life360’s information to any authorities companies for use for a legislation enforcement function in 2020, although the corporate has been promoting information since not less than 2016. 

“From a philosophical standpoint, we don’t imagine it’s acceptable for presidency companies to try to acquire information within the business market as a approach to bypass a person’s proper to due course of,” Hulls mentioned. 

Households would in all probability not just like the slogan, ‘You may watch the place your children are, and so can anybody who buys this info.'”

– Justin Sherman, Duke Tech Coverage Lab fellow

The coverage additionally applies to any corporations that Life360’s clients share information with, he mentioned. Hulls mentioned the corporate maintains “an open and ongoing dialogue” with its clients to make sure they adjust to the coverage, although he acknowledged that it was a problem to observe companions’ actions. 

Life360 discloses within the superb print of its privateness coverage that it sells the information it gleans from app customers, however Justin Sherman, a cyber coverage fellow on the Duke Tech Coverage Lab, mentioned individuals are in all probability not conscious of how far their information can journey.

The corporate’s privateness coverage notes Life360 “might also share your info with third events in a kind that doesn’t moderately determine you straight. These third events might use the de-identified info for any function.”

“Households in all probability wouldn’t just like the slogan, ‘You may watch the place your children are, and so can anybody who buys this info,’ ” Sherman mentioned.

Two former Life360 workers additionally informed The Markup that the corporate, whereas it states it anonymizes the information it sells, fails to take vital precautions to make sure that location histories can’t be traced again to people. They mentioned that whereas the corporate eliminated the obvious figuring out person info, it didn’t make efforts to “fuzz,” “hash,” combination, or scale back the precision of the situation information to protect privateness. 

Hulls mentioned that every one of Life360’s contracts prohibit its clients from re-identifying particular person customers, together with different privateness and security protecting practices. He mentioned that Life360 follows “trade finest practices” for privateness and that solely sure clients like Cuebiq obtain uncooked location information. The previous X-Mode engineer mentioned that the corporate additionally obtained uncooked information from Life360. The corporate depends on its clients to obfuscate that information primarily based on their particular purposes, Hulls added.

Do you’re employed at Life360, X-Mode or every other firm that buys or sells location information? We’d like to talk with you. You may attain out securely on Sign at 646-355-8306 or electronic mail [email protected].

“A few of our information companions obtain hashed information and a few don’t primarily based on how the information can be used,” the Life360 founder mentioned.

In the meantime, promoting location information has turn out to be increasingly central to the corporate’s well being because it’s struggled to realize profitability. In 2016, the corporate made $693,000 from promoting information it collected. In 2020, the corporate made $16 million—practically 20 % of its income that 12 months—from promoting location information, plus a further $6 million from its partnership with Arity. 

Whereas nonetheless reporting a lack of $16.3 million final 12 months, the corporate is increasing its enterprise to incorporate different “digital security” merchandise, rolling out information breach alerts, credit score monitoring, and identity-theft-protection options. Publicly traded on the Australian Securities Alternate with plans to go public within the U.S., Life360 has additionally acquired corporations that broaden its monitoring—and probably its data-gathering capability. In 2019, the corporate bought ZenScreen, a household screen-time monitoring app. And in April, it bought the wearable location machine firm Jiobit, aimed toward monitoring youthful youngsters, pets, and seniors, for $37 million. Hulls mentioned Life360 has no plans to promote information from Jiobit units or its digital security providers.

On Nov. 22, Life360 additionally introduced plans to purchase Tile, a monitoring machine firm that helps discover misplaced objects. Hulls mentioned the corporate doesn’t have plans to promote information from Tile units.

“I’m certain there are many households who do discover very actual consolation in an software like this, and that’s legitimate,” Sherman mentioned. “That doesn’t imply that there aren’t ways in which different individuals are harmed with this information. It additionally doesn’t imply that the household couldn’t be harmed with the information in ways in which they’re not conscious of, akin to that location information getting used to focus on advertisements [or] utilized by insurance coverage corporations to determine the place they’re touring and enhance their charges.” 

Hulls mentioned that Life360 doesn’t share customers’ non-public info with insurers in ways in which may have an effect on insurance coverage charges. 

The Information Pipeline

Life360’s app permits the person to see the exact, real-time location of mates or members of the family, together with the velocity at which they’re driving and the battery degree on their units. 

Marketed as a security app, Life360 is fashionable amongst dad and mom who need to observe and supervise their children from afar. The app affords a lot of the performance of Apple’s built-in location-sharing options, but it surely contains emergency security options akin to an SOS button and car crash detection. The corporate says these options have saved lives. 

However Life360’s location-based options are additionally sources of knowledge factors for a rising, multibillion-dollar trade that trades in location information gathered from cell phones. Advertisers, authorities companies, and buyers are keen to spend tons of of hundreds of {dollars} for location information and the insights that may be derived from them. 

Whereas youngsters can use the app (with parental consent), Life360’s coverage states that the corporate doesn’t promote information on any customers beneath 13. The Kids’s On-line Privateness Safety Rule (higher often known as “COPPA”) creates restrictions on digital providers utilized by youngsters beneath 13, and Life360 has detection strategies like requiring a scan of a dad or mum’s ID for underage customers. Life360 does “disclose” youthful youngsters’s info to 3rd events “as wanted to investigate and detect driving habits information, carry out analytics or in any other case ,[sic] help the options and performance of our Service,” in accordance with its privateness coverage, however not “for advertising and marketing or promoting functions.” 

Entrepreneurs use location information to focus on advertisements to folks close to companies, whereas buyers purchase information to find out reputation primarily based on foot site visitors. Authorities companies have purchased location information to trace motion patterns and in a single case to help “Particular Operations Forces mission necessities abroad.”  

“It feels like the corporate’s pointing to a few circumstances the place, certain, they helped any person, they had been in a position to do one thing good,” Sherman mentioned. “However then they won’t discuss the entire different circumstances the place the shopping for and promoting of this information is probably very dangerous.”

In July, a high-ranking Catholic priest resigned after a Catholic information outlet outed him by utilizing location information from the homosexual relationship app Grindr linked to his machine. The information was obtained by an unknown vendor, and the report claimed to point out that the priest frequented homosexual bars. There isn’t any indication that Life360 was concerned on this incident. 

Grindr, like different apps that feed information into this trade, is required to ask for location permissions when a person first opens the app. 

“We aren’t conscious of any occasion the place our information has been traced again to people by way of our information companions,” Hulls mentioned. “Moreover, our contracts comprise language particularly prohibiting any reidentification, and we’d aggressively take motion in opposition to any breach of this time period.”

In Life360’s case, due to how the app works, it asks for the broadest location permissions doable for purposeful functions. Many apps that use location information enable customers to grant entry solely whereas it’s in use. As a result of Life360 is for monitoring whereabouts in actual time, the app asks for location information always—and doesn’t perform except that permission is turned on. 

A disclaimer seems in smaller print on the backside of the permissions display screen: “Your location information could also be shared with Companions for the needs of crash detection, analysis, analytics, attribution and tailor-made promoting.” Customers can disable the sale of their location information within the privateness settings, although that setting shouldn’t be disclosed in or a part of the immediate. 

Life360’s Hulls mentioned that tens of millions of its customers have used this function to choose out of their information being bought.

Find out how to Disable the Sale of Your Location Information within the Life360 App

  1. Faucet on the gear icon for “Settings”

  2. Faucet on “Privateness & Safety”

  3. Faucet on “Do Not Promote My Private Info”

  4. Toggle the button subsequent to “Private Info Gross sales” to the off place

For many who haven’t opted out, their Life360 information could also be shared with the corporate’s companions inside 20 minutes of being recorded, a former Life360 worker mentioned.

Hulls mentioned this description was “directionally correct,” saying it solely utilized to sure companions and use circumstances.

“For instance, some use circumstances, like highway site visitors probing, which powers journey time estimates in automotive navigation methods and GPS apps, require very contemporary information,” he mentioned.

Privateness researchers and app retailer operators usually search for information brokers’ code in apps for indicators of an app sending information off to 3rd events. However Life360 collects its information straight from the app and supplies it to information brokers by way of its personal servers.

Apple’s and Google’s app shops don’t have any manner of detecting this switch of location information to a 3rd occasion. “It is sensible to ship this information straight from the server facet from the app vendor so it will possibly by no means be traced or noticed by anybody,” mentioned Wolfie Christl, a researcher who investigates digital monitoring.

Hulls mentioned Life360’s technique of offering information by way of its personal servers wasn’t an intentional effort to evade detection from researchers and app shops.

“That is utterly unrelated. We have now our personal proprietary sensor expertise, which we began constructing in 2008 nicely earlier than the emergence of the information trade, and we keep away from utilizing SDKs that might have a unfavourable battery influence or different interaction with our personal sensor expertise,” he mentioned.

Google didn’t touch upon why Life360 was in a position to promote information this manner regardless of its coverage in opposition to promoting location information. Apple spokesperson Adam Dema responded with a hyperlink to Life360’s privateness coverage however didn’t remark concerning the firm’s information gross sales to corporations like SafeGraph and X-Mode.

Hulls mentioned Life360 de-identifies the information it sells, which might embody a tool’s cellular promoting ID, IP tackle, and latitude and longitude coordinates collected by Life360’s app. 

Hulls clarified that “de-identification” includes eradicating usernames, emails, telephone numbers, and different varieties of identifiable person info earlier than the information is shared with Life360’s clients. The information bought nonetheless features a machine’s cellular promoting ID and latitude and longitude coordinates. 

Even with out names or telephone numbers, researchers have repeatedly demonstrated how “anonymized” location information can simply be related to the folks from whom it got here.

And privateness consultants word that cellular promoting IDs are extra helpful than identifiers like names. 

“This code can be utilized to trace and comply with you throughout many life conditions,” Christl mentioned. “As such, it’s a significantly better identifier than a reputation.”

Controversial Companions

The placement information trade operates largely out of public view and with little oversight or regulation. A few of Life360’s companions have confronted controversy up to now over how they deal with information and privateness. 

Began in 2013 as Drunk Mode, a novelty app that “prevents customers from drunk dialing,” X-Mode was reportedly banned from the large app shops after Vice’s Motherboard reported that the corporate was promoting location information from Muslim prayer apps like Muslim Professional to U.S. authorities contractors related to nationwide safety, elevating considerations about unconstitutional authorities surveillance. 

Public information present that X-Mode obtained not less than $423,000 from the U.S. Air Pressure and the Protection Intelligence Company for location information between 2019 and 2020. The corporate additionally bought information on People in profiled units, like individuals who had been drivers or prone to store at department shops, in accordance with Motherboard.

In August, X-Mode was bought by mental property intelligence agency Digital Envoy and rebranded as Outlogic. 

In response to the backlash over X-Mode’s promoting location information to protection contractors, its new house owners mentioned the corporate would cease promoting U.S. location information to such corporations.

“We can not touch upon the practices of one other firm or what that firm does with information it receives from different sources,” Hulls mentioned. “Nonetheless, Life360 has labored carefully with X-Mode to make sure that X-Mode and all of its information clients don’t promote information originating from Life360 to legislation enforcement companies or to any authorities company for use for a legislation enforcement function.”

SafeGraph is without doubt one of the greatest corporations within the location information enterprise, and its buyers embody enterprise capitalist Peter Thiel; Prince Turki Al Faisal Al Saud, former head of Saudi intelligence; and Life360’s chief enterprise officer, Itamar Novick.

The corporate makes a speciality of information that associates locations of curiosity with uncooked coordinates, including a layer of that means to the uncooked location information that the corporate ingests. SafeGraph was recognized as not only a buyer of Life360’s information but additionally a significant associate in an electronic mail from a Life360 govt that was seen by The Markup. 

In April, as first reported by Motherboard, SafeGraph was awarded a $420,000 contract to promote information to the Facilities for Illness Management described as “Information Gathering and Reporting.” The Washington Put up additionally reported that SafeGraph shared billions of telephone location information with the D.C. Division of Well being by way of its spinoff firm Veraset.

The corporate brazenly sells location information on Amazon’s information market, together with a $240,000 yearly subscription to information on folks throughout the U.S. Veraset has boasted of promoting location information for functions together with advertising and marketing, actual property, investing, and metropolis planning.

Sen. Ron Wyden has flagged SafeGraph as a “information dealer of concern” to Google, Wyden’s chief communications officer, Keith Chu, mentioned in an electronic mail. The Democrat from Oregon has made a number of makes an attempt to talk with SafeGraph to study extra about how the corporate obtains, sells, and shares People’ location information, however the firm by no means responded, Chu mentioned. 

Cuebiq additionally labored with the Facilities for Illness Management, with a $208,000 contract awarded in June for aggregated location information, in accordance with public information.  

The CDC didn’t reply to requests for remark. 

In the course of the starting of the coronavirus pandemic, Cuebiq grew to become a predominant supply of location information for information retailers trying to report on folks’s actions after cities and states issued stay-at-home orders. Shops together with The New York Occasions and NBC Information obtained location information from Cuebiq for his or her analyses.

It’s been prompt that location information brokers like Cuebiq are utilizing the pandemic to enhance their public status by presenting themselves as instruments for public well being somewhat than as mechanisms for surveillance. 

Cuebiq’s Daddi mentioned the corporate’s information has helped within the aftermath of pure disasters and public well being crises.

Security vs. Privateness

Life360 has positioned itself as “the main digital security model for households.” However consultants say households who use it will not be essentially enthusiastic about their digital safety.

“An app that claims to be a household security service promoting precise location information to a number of different corporations, this can be a whole catastrophe,” Christl mentioned. “It might be an issue if it’s every other app, and it’s much more an issue when it’s an app that claims to be a household security service.”

An app that claims to be a household security service promoting precise location information to a number of different corporations, this can be a whole catastrophe.”

– Wolfie Christl, researcher

Life360 has confronted considerations over privateness up to now. In mid-2020, teenagers, displeased on the privateness invasion of an app that allowed their dad and mom to minutely observe their actions, took to TikTok to encourage their friends to bomb the app with unfavourable critiques. Over the course of a month, the app obtained greater than 1,000,000 one-star critiques, driving the common ranking down from 4.6 to 2.7 stars.

Hulls responded by including a “bubbles” function that reveals dad and mom a extra imprecise location of their baby (however nonetheless permits dad and mom to see precise places with a further step). He additionally recruited and paid teenagers to hawk the app on TikTok, leading to a “viral surge in downloads,” in accordance with the corporate. 

These teenagers, nevertheless, had been seemingly not conscious that their dad and mom had been hardly the one ones aware about information on their actions. 

Samira Madi, an 18-year-old pupil in Texas, began utilizing Life360 when she was 15. She didn’t have an issue with the corporate sharing her location information for advertising and marketing and promoting functions, which the corporate readily disclosed.

After studying about who Life360 was promoting information to, and the size it was bought at, Madi felt that the corporate crossed a line. 

“I had no concept it will be handed round this manner,” Madi mentioned in an electronic mail. “This considerations me as a result of I’d not need my location information to presumably be bought to folks with unwell intentions.”

This text was initially revealed on The Markup and was republished beneath the Artistic Commons Attribution-NonCommercial-NoDerivatives license.

Related Articles