Gravy Analytics and Sensitive Location Data
An overview of FTC enforcement, advertising-based data collection, and the security risks associated with large-scale retention of sensitive mobility data
Series: The Data Brokers | The Shield Blog
Reading time: 16 minutes
Overview
In December 2024, the Federal Trade Commission announced an enforcement action against Gravy Analytics and its subsidiary Venntel, alleging unlawful collection, use, and sale of precise location data associated with sensitive locations.
According to the FTC, the companies collected location data without verifiable consumer consent, used the data to identify visits to sensitive locations, and sold or shared the information with downstream customers, including government entities.
In January 2025, weeks after the FTC announced an order requiring deletion of historical location data, Gravy Analytics disclosed a security incident involving unauthorized access to its cloud infrastructure and potential exposure of large volumes of location data.
This article explains what regulators alleged, how the data was collected, and why large-scale retention of sensitive location data presents ongoing privacy and security risks.
FTC Enforcement Action
On December 3, 2024, the Federal Trade Commission alleged that Gravy Analytics and Venntel engaged in unfair practices in violation of the FTC Act.
According to the complaint, the companies:
- Collected precise geolocation data without verifiable consumer consent
- Used location data to identify visits to sensitive locations
- Created products based on inferred sensitive characteristics
- Sold or shared data with downstream customers, including government entities
- Retained large volumes of historical location data
The FTC’s order required the companies to:
- Stop selling, sharing, or using sensitive location data
- Implement a sensitive location data protection program
- Delete previously collected historical location data
- Notify customers from the prior three years to delete received data
The order was finalized in January 2025.
Gravy Analytics’ Business Model
Gravy Analytics operated as a location data broker focused on collecting and analyzing precise, real-time location information from mobile devices.
According to the FTC, the company claimed to:
- Process billions of location signals per day
- Track hundreds of millions of devices globally
- Maintain location accuracy within approximately one meter
- Retain multiple years of historical location data
Location histories of this precision and duration can enable inference of routine movement patterns, often referred to as “patterns of life,” including where individuals live, work, seek medical care, or practice religion.
How the Data Was Collected
The FTC alleged that Gravy Analytics collected location data largely through the digital advertising ecosystem, particularly through real-time bidding (RTB) systems.
In RTB environments:
- A user opens an app or website
- An ad auction occurs in milliseconds
- Device identifiers and location signals are broadcast to multiple bidders
- Data may be retained by bidders regardless of whether they win the auction
According to the FTC, Gravy Analytics collected and retained location data from RTB streams for purposes unrelated to ad placement.
Security researchers later reported that leaked datasets appeared to contain location signals associated with thousands of apps whose developers stated they had no direct relationship with Gravy Analytics.
Government Customers and Downstream Use
Gravy Analytics operated a subsidiary, Venntel, which marketed location data products to government and private sector customers.
Public reporting and government contract records indicate that Venntel licensed location data to multiple U.S. government agencies.
According to the FTC, Venntel’s products advertised the ability to identify device movement patterns, including home locations, work locations, and visits to other government facilities.
The FTC raised concerns that commercial location data can enter government workflows through intermediaries without direct consumer awareness.
The Security Incident
In January 2025, Gravy Analytics disclosed that a third party had gained unauthorized access to its cloud infrastructure.
Public reporting indicated that the exposed data may have included:
- Large volumes of historical location records
- Precise GPS coordinates and timestamps
- Persistent device identifiers
- Customer and internal company information
Security researchers analyzing sample data reported the presence of location signals associated with sensitive locations, including healthcare facilities, places of worship, shelters, and government buildings.
The incident occurred weeks after the FTC announced its order requiring deletion of historical location data.
Why This Matters
1. Sensitive locations can be inferred from location data
Precise location histories can reveal visits to healthcare facilities, places of worship, shelters, and other sensitive sites, even when individuals do not publicly disclose their activities.
2. Advertising data can be repurposed
Data collected through advertising systems can be reused for analytics, profiling, or investigation depending on who gains access to it.
3. Persistent identifiers enable re-identification
Even without names, repeated location patterns and device identifiers can allow individuals to be re-identified over time.
4. Retained data creates security risk
The longer sensitive data is retained, the greater the potential exposure in the event of a breach or unauthorized access.
5. Consent is often unclear
The FTC has emphasized that contractual assurances within data supply chains may be insufficient to establish meaningful consumer consent.
Protecting Yourself
1. Limit location permissions
Review which apps have access to location services and reduce access wherever possible.
2. Manage your advertising ID
Reset or delete your advertising ID periodically to reduce long-term linkability.
- On iPhone: Settings > Privacy & Security > Tracking > toggle off “Allow Apps to Request to Track”
- On Android: Settings > Privacy > Ads > delete or reset advertising ID
3. Reduce exposure to ad-based tracking
Privacy-focused browsers and tracking protections can reduce some forms of advertising-based data collection.
4. Be cautious with sensitive app categories
Apps related to health, religion, dating, and recovery often involve higher-risk data.
5. Consider device use at sensitive locations
For individuals seeking to minimize traceability, options include disabling location services temporarily or avoiding carrying a device to certain locations.
The Bottom Line
The Gravy Analytics case illustrates how precise location data can be collected through advertising systems, retained at scale, and exposed through both commercial use and security incidents.
The FTC’s enforcement action restricted Gravy Analytics’ ability to sell or use sensitive location data and highlighted risks associated with large-scale retention of mobility data.
The case underscores a broader issue within the data broker ecosystem: consumers often lack visibility into how far their location data travels once it enters complex advertising and resale chains.
Sources
- Federal Trade Commission, press release on action against Gravy Analytics and Venntel (December 2024)
- Federal Trade Commission, final order regarding Gravy Analytics and Venntel (January 2025)
- Public reporting by 404 Media, WIRED, TechCrunch, and NBC News on the Gravy Analytics data breach (January 2025)
- FTC complaint materials related to location data brokers
