The Origin Story
In 2012, Joshua Anton was a student at the University of Virginia who built an app called Drunk Mode. The app helped users avoid calling or texting selected contacts while intoxicated. It was offered for free and reached more than a million downloads, according to reporting from the period.
Anton later founded X-Mode Social in 2013. Reporting and regulatory filings describe X-Mode’s business as collecting location signals from mobile apps and licensing that data to third parties.
The Business Model
X-Mode distributed a software development kit (SDK), which app developers could embed in their apps. When integrated, the SDK collected location data on a recurring basis and transmitted it to X-Mode.
Public reporting described compensation paid to developers at rates such as:
- $0.03 per U.S. user per month
- $0.005 per international user per month
X-Mode’s SDK was reported to be present in hundreds of apps distributed by dozens of developers.
By 2020, reporting described X-Mode as tracking:
- 25 million devices in the United States per month
- 40 million devices elsewhere, including parts of the European Union, Latin America, and Asia-Pacific
In many implementations, the location data was associated with a Mobile Advertising ID (MAID), an identifier used in mobile advertising ecosystems. MAIDs can be used to recognize the same device over time and may be linkable to other datasets depending on downstream parties’ capabilities and practices.
X-Mode licensed location data to a range of customers described in reporting, including advertisers, analytics firms, consulting organizations, research organizations, and government contractors.
Reports Involving Religious and Dating Apps
In November 2020, journalist Joseph Cox at Vice Motherboard reported that certain mobile apps were transmitting precise location data to X-Mode. The reporting described this based on technical analysis of app network traffic.
Apps referenced in coverage included:
- Muslim Pro, a prayer and Quran app with a large global user base
- Muslim Mingle, a dating app
- Qibla Compass, a prayer-related app
- Prayer Times: Qibla Finder, another prayer-related app
Additional research groups, including the Yale Privacy Lab, reported that other community-focused apps had also shared data with X-Mode or similar location data intermediaries.
A key concern raised by journalists and privacy researchers at the time was whether users had clear, prominent notice that location data could be shared with third-party data brokers and resold to additional parties.
NOTE:
In this section, focus on what was reported and documented. Avoid implying intent by app developers unless a source explicitly states it.
Government Contractor Customers
In 2020, Senator Ron Wyden’s office investigated location data practices and, according to reporting, asked X-Mode about sales involving government-related customers. X-Mode stated that it licensed its data to a limited number of technology companies, some of which may work with government or military services.
Vice Motherboard reported links involving defense contracting and U.S. Special Operations Command (USSOCOM) use cases. The U.S. military also publicly stated that some access to location-data-derived tools supported overseas mission requirements, and that internal procedures were used to protect privacy and civil liberties.
This reporting contributed to broader public debate about how commercially collected location data can move through multiple intermediaries and eventually support government uses, depending on procurement paths and contractual terms.
An Example of an App Declining Location Monetization
The Markup reported that Scruff, a dating app serving LGBTQ+ users, declined offers to monetize user location data through certain third-party arrangements. Scruff later described changes to its advertising approach, including reducing reliance on third-party programmatic ad systems and shifting toward subscriptions and direct advertising.
This example is often cited to illustrate that app publishers make different choices about monetization, and that privacy risk can vary significantly between apps even within the same category.
Public Response and Platform Enforcement
After the 2020 reporting, multiple responses were reported publicly, including:
- Muslim Pro stated it terminated relationships with certain data partners after the investigation.
- Advocacy organizations called for additional oversight and public inquiry into the use of commercially sourced location data.
- Apple and Google took steps to restrict X-Mode’s SDK from their app ecosystems, and developers were instructed to remove the SDK to avoid enforcement actions.
Apple stated that certain practices violated its developer terms. Coverage at the time also noted that enforcement across large app ecosystems can be inconsistent, and that removal may not occur uniformly across all apps or versions.
Rebranding and Continued Presence
In August 2021, X-Mode was acquired and later rebranded as Outlogic, according to reporting. Subsequent investigations by TechCrunch and ExpressVPN’s Digital Security Lab described that X-Mode-related components were still detected in some apps after platform enforcement actions, based on their analysis at the time.
The FTC Action
On January 9, 2024, the Federal Trade Commission (FTC) announced a settlement involving X-Mode Social and Outlogic related to the collection and sale of sensitive location information. The FTC described this as a notable enforcement action in the location data broker space.
The FTC’s complaint and related materials described several practices and risks, including:
Selling location data linked to persistent identifiers
The FTC described the sale of location data associated with Mobile Advertising IDs, which can enable persistent tracking of a device over time.
Handling of sensitive locations
The FTC alleged that the company did not implement adequate safeguards for sensitive locations until relatively late in its operations, and that location trails could reveal visits to sensitive places.
Creation of audience segments
The FTC described practices involving building audience segments based on visits to certain categories of locations, including healthcare-related locations, for marketing purposes.
Opt-out and notice concerns
The FTC described concerns that users did not receive adequate notice in some contexts and that opt-out mechanisms were not reliably honored.
Downstream controls
The FTC described risks that data can be resold or used beyond intended contractual limits when downstream controls are insufficient.
The Settlement Terms
Based on FTC announcements and the published order, the settlement required restrictions and programmatic changes, including:
- Limits on selling or sharing sensitive location data associated with defined sensitive locations
- A sensitive locations program, including identifying sensitive locations and implementing technical filtering
- Deletion requirements for certain previously collected data and derived products, subject to the terms of the order
- Supplier assessment requirements intended to verify that location data was collected with appropriate notice and consent
- Downstream safeguards designed to reduce the risk of sensitive inferences or identification of individuals
The FTC finalized the action in April 2024.
The Company’s Response
Outlogic publicly stated that it disagreed with aspects of the FTC’s characterization and indicated it would comply with the order’s requirements through additional technical processes.
Why X-Mode Matters
The X-Mode and Outlogic reporting and the FTC action are frequently cited because they illustrate broader issues common to the location data ecosystem:
1. High-trust apps can still create privacy risk
Apps that users rely on for daily routines, religious practice, transportation, or community connection may still include third-party SDKs that collect data for monetization.
2. “De-identified” does not always mean “non-linkable”
Location trails and persistent device identifiers can sometimes be linked back to individuals, especially when combined with other datasets.
3. Disclosure and meaningful consent vary widely
Notice can be buried in long privacy policies or presented in unclear ways, depending on the app and platform implementation.
4. Platform enforcement is not uniform
App store policy actions can reduce certain behaviors, but third-party code may persist in some apps due to developer updates, app versions, or incomplete removal.
5. Enforcement often follows public reporting
In several cases in the location data industry, investigative reporting and public attention preceded regulatory action.
Protecting Yourself
1. Audit app permissions
Review which apps have location access and whether that access is necessary.
- On iPhone: Settings > Privacy & Security > Location Services
- On Android: Settings > Location > App permissions
CYBERSAFETY TIP:
Set location access to While Using whenever possible. Avoid granting Always location access unless it is required for core functionality.
2. Limit ad identifier tracking
- On iPhone: Settings > Privacy & Security > Tracking > Turn off “Allow Apps to Request to Track”
- On Android: Settings > Privacy > Ads > Delete or reset advertising ID (options vary by device version)
CYBERSAFETY TIP:
Resetting or deleting the advertising ID can reduce long-term linkability across apps, especially when combined with limiting background location permissions.
3. Use extra caution with sensitive categories
Apps related to health, faith, dating, and community services can involve sensitive inferences if location or usage data is shared broadly.
4. Review privacy disclosures for third-party sharing
Look for statements about third-party SDKs, advertising partners, analytics partners, or data sharing for “marketing” or “research” purposes.
5. Reduce phone exposure during sensitive activities
When appropriate, consider steps such as disabling location services temporarily, using airplane mode, or leaving the phone behind. Practicality and safety vary by situation.
NOTE:
This section provides general privacy guidance and should not be interpreted as legal advice.
The Bottom Line
The reporting on X-Mode and the FTC’s action against X-Mode and Outlogic show how location data can be collected through third-party SDKs, combined with persistent identifiers, and sold through complex commercial pathways.
For consumers, the main takeaway is that location collection is often not limited to map or navigation apps, and third-party components can expand data sharing beyond what users expect. Reviewing permissions, understanding tracking identifiers, and selecting apps carefully can meaningfully reduce exposure.
Sources
- Federal Trade Commission, “FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data” (January 9, 2024)
- Federal Trade Commission, “FTC Finalizes Order with X-Mode and Successor Outlogic” (April 12, 2024)
- Federal Trade Commission, Complaint and Order materials, X-Mode Social and Outlogic
- FTC Business Blog, discussion of location data enforcement (January 2024)
- Vice Motherboard, reporting on X-Mode and location data sales (November to December 2020, January 2021)
- The Markup, reporting on app data sharing and X-Mode (January 2022, January 2024)
- TechCrunch, reporting on X-Mode tracking after app store actions (January 2021, January 2024)
- ExpressVPN Digital Security Lab, reporting on SDK presence in apps (February 2021)
