X/Twitter The Most Aggressive Social Media App Collecting Users Location Information

X/Twitter The Most Aggressive Social Media App Collecting Users Location Information

A comprehensive analysis of the top 10 social media platforms reveals that X (formerly Twitter) stands out as the most invasive collector of user location information, gathering both precise and coarse location data across all categories listed in Apple’s App Store privacy framework. 

This extensive data harvesting raises significant privacy concerns as location tracking can expose intimate details about users’ personal and professional lives.

Key Takeaways
1. X collects both precise and coarse location data for every use case.
2. Location tracking can uncover sensitive personal details.
3. Only Reddit avoids identity linkage; mitigate via disabling services, VPNs, and permission audits.

Location Data Harvesting 

Unlike its competitors, X collects location data for every possible purpose outlined in App Store privacy policies. 

Google News

The platform gathers both precise location data coordinates with three or more decimal places in latitude and longitude, and coarse location data with lower resolution accuracy. 

This comprehensive approach includes third-party advertising, internal marketing, analytics, product personalization, app functionality, user tracking, and unspecified “other purposes.”

A visual breakdown highlighting how various social media platforms, including X, collect users' precise location data for multiple purposes.
A visual breakdown highlighting how various social media platforms, including X, collect users’ precise location data for multiple purposes. (Source: Surfshark)

The study reveals that 60% of analyzed social media platforms collect precise location data for third-party advertising, including X, Instagram, Threads, Facebook, Pinterest, and Snapchat. 

However, X’s approach extends beyond advertising into tracking territory, where it may combine location information with data from other applications or websites. This practice potentially enables data sharing with data brokers who can subsequently sell user information to third-party businesses.

Surfshark reports that the location tracking methodologies employed by these platforms utilize various geolocation vectors including Global Positioning System (GPS) coordinates, Bluetooth Low Energy (BLE) beacons, Wi-Fi access point triangulation, cellular tower positioning, and Internet Protocol (IP) address geolocation. 

Even when users disable precise location sharing through system settings, platforms can still derive approximate locations through these alternative data sources.

The privacy implications of aggressive location tracking extend far beyond simple geographical awareness. 

Continuous location monitoring at 30-minute intervals can construct detailed behavioral profiles revealing employment locations, salary brackets inferred from workplace addresses, medical conditions through healthcare facility visits, and potentially compromising personal relationships through overnight location correlations.

Among the analyzed platforms, only Reddit implements user-centric privacy protections by declaring that location data will not be linked to user identity. 

TikTok and Reddit demonstrate more conservative approaches by exclusively collecting coarse location data rather than precise coordinates. 

In contrast, X’s comprehensive data collection strategy encompasses both precision levels across all functional categories.

The study methodology examined App Store privacy labels for X, Instagram, Threads, Facebook, Pinterest, Snapchat, LinkedIn, TikTok, YouTube, and Reddit as of August 11, 2025. 

While 90% of platforms collect coarse location data and 60% gather precise coordinates for internal advertising purposes, X’s universal collection approach represents the most extensive location data harvesting among major social media applications.

Technical mitigation strategies for users include disabling location services at the operating system level, utilizing Virtual Private Network (VPN) services to mask IP-based geolocation, and regularly auditing app permissions through system privacy settings. 

However, complete location privacy remains challenging given the multiple data vectors available to determined platforms.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.


Source link

About Cybernoz

Security researcher and threat analyst with expertise in malware analysis and incident response.