Every safety app is watching you
Hundreds of millions of people keep a safety or location-sharing app on their phone. Life360 has nearly 98 million monthly users [1]; Snap Map has more than 400 million [2]; with Citizen and the family-locator apps, the people-facing safety apps clear half a billion users between them. Then there are the location-finding networks built into the phones themselves like Apple's Find My, on by default across 2.35 billion Apple devices [3], and Google's Find Hub, across more than a billion Android devices [4]. For most people carrying a phone, something is already set up to report where they are. The instinct behind all of it is sound: when something goes wrong - a crash, a medical emergency, a walk home that feels off - you want the people who matter to find you fast. Being reachable when you most need it is a real need, not paranoia. For some readers the stakes run higher than a missed check-in - a targeted break-in, an extortion attempt, a kidnapping. The instinct is the same; only the threat model changes.
The catch is how they deliver it. Continuous background location isn't a setting in these apps; it's the core product. They know where you are around the clock, keep that history for weeks (in some cases up to 18 months), and a striking number of them sell it. In this market, a safety app has mostly been a data broker with a panic button glued on.
Where your location actually goes
In December 2021, The Markup published an investigation revealing that the family-safety app Life360 was selling precise location data on its tens of millions of users. Life360 was marketed in app stores as the way to keep your kids safe. It was selling those users' precise locations - mostly children and families - to about a dozen data brokers, among them X-Mode, Cuebiq, Arity, and SafeGraph, within roughly 20 minutes of collection. A former X-Mode engineer called the Life360 feed "among X-Mode's most valuable offerings due to the sheer volume and precision of the data." [5]
Follow that in sequence. Your phone reports your location; 20 minutes later a broker holds that point with your device ID attached. Research going back to 2013 shows four such points are enough to re-identify about 95% of people in a supposedly anonymized dataset. [6] Aggregation is not anonymity.
And the brokers aren't the end of the line. US Customs and Border Protection, ICE, and the Department of Homeland Security have spent millions buying Americans' location data without warrants - Venntel alone sold CBP around $2 million worth in 2019 and 2020. [7]
For $160, a Vice reporter bought a week of visitor data covering more than 600 Planned Parenthood clinics: home census blocks, dwell times, and where each device went next. [8]
In 2018, Strava's fitness heatmap accidentally traced the outlines of US military bases in Iraq, Afghanistan, and Syria from soldiers' jogging routes.[9] None of those people opted into any of it. They just had an app on.
Follow that in sequence. Your phone reports your location; 20 minutes later a broker holds that point with your device ID attached. Research going back to 2013 shows four such points are enough to re-identify about 95% of people in a supposedly anonymized dataset. [6] Aggregation is not anonymity.
And the brokers aren't the end of the line. US Customs and Border Protection, ICE, and the Department of Homeland Security have spent millions buying Americans' location data without warrants - Venntel alone sold CBP around $2 million worth in 2019 and 2020. [7]
For $160, a Vice reporter bought a week of visitor data covering more than 600 Planned Parenthood clinics: home census blocks, dwell times, and where each device went next. [8]
In 2018, Strava's fitness heatmap accidentally traced the outlines of US military bases in Iraq, Afghanistan, and Syria from soldiers' jogging routes.[9] None of those people opted into any of it. They just had an app on.
The emergency back door no privacy policy covers
There's a second leak that sits above anything an app's privacy policy can promise.
Emergency Data Requests let police skip the warrant in genuine life-or-death situations, and Apple, Google, and Meta all honor them. In 2021, members of the group LAPSUS$ - most of them teenagers - worked out the trick. They broke into police department email accounts, forged emergency requests on real letterhead, and sent them in. The platforms had no fast way to tell a real request from a fake one. Bloomberg confirmed in March 2022 that both Apple and Meta had handed over user data including IP addresses, phone numbers, physical addresses to forged requests. [10] Some of it was used to harass and extort the people it exposed. In November 2024, the FBI issued a formal warning that fake EDRs were still being weaponized at scale. [11]
When an attacker sends a forged request, they don't need to try to hack the safety app or the phone. The app's own privacy policy is irrelevant at that layer, because the leak is upstream of anything its vendor controls. The 2021 disclosure changed none of this, it's how the system still works in 2026.
Emergency Data Requests let police skip the warrant in genuine life-or-death situations, and Apple, Google, and Meta all honor them. In 2021, members of the group LAPSUS$ - most of them teenagers - worked out the trick. They broke into police department email accounts, forged emergency requests on real letterhead, and sent them in. The platforms had no fast way to tell a real request from a fake one. Bloomberg confirmed in March 2022 that both Apple and Meta had handed over user data including IP addresses, phone numbers, physical addresses to forged requests. [10] Some of it was used to harass and extort the people it exposed. In November 2024, the FBI issued a formal warning that fake EDRs were still being weaponized at scale. [11]
When an attacker sends a forged request, they don't need to try to hack the safety app or the phone. The app's own privacy policy is irrelevant at that layer, because the leak is upstream of anything its vendor controls. The 2021 disclosure changed none of this, it's how the system still works in 2026.
A safety system doesn't mean a safe response
A 43-year-old woman in Akron, Ohio suspected her ex-boyfriend was tracking her. She hired a private investigator, who found an AirTag hidden in her car. Four hours later, the ex shot her dead outside her home, then turned the gun on himself. [12]
A consumer tracker with no protective response built around it is often more useful to the person doing the hunting than the person being hunted. The same feature that finds a lost wallet finds a fleeing partner. Apple's safeguard (the "Item Found Moving With You" alert) can take four to eight hours to fire on an iPhone by Apple's own estimate. [13]
Notice the gap none of these products closed: when the danger is real, who responds, and how fast? A notification to the victim is not a plan. What's missing is an immediate, organized response carried out by the people who care most - family, friends, a trusted circle - set off by the person in trouble and reaching the right people in seconds, not hours.
A consumer tracker with no protective response built around it is often more useful to the person doing the hunting than the person being hunted. The same feature that finds a lost wallet finds a fleeing partner. Apple's safeguard (the "Item Found Moving With You" alert) can take four to eight hours to fire on an iPhone by Apple's own estimate. [13]
Notice the gap none of these products closed: when the danger is real, who responds, and how fast? A notification to the victim is not a plan. What's missing is an immediate, organized response carried out by the people who care most - family, friends, a trusted circle - set off by the person in trouble and reaching the right people in seconds, not hours.
Most people improvise their own safety
In most of the cases we've reviewed, the victim had done nothing to prepare. No threat model, no protocol, no watchers, no prearranged response. People who would never travel without insurance, or run a company without backups, leave their own physical safety entirely improvised.
We get it, personal security feels paranoid, until it isn't. The fix isn't a bunker or a detail of bodyguards. It's a small amount of preparation done in calm conditions: deciding who your people are, what they should do, and how they hear from you when it matters.
What comes next
Knowing all this, the sane move is to find a safety app that makes none of these trades, one that can still get help to your people without tracking you, selling you, or holding anything a hacker or a forged request could pull. We went looking for it. It didn't exist, so we built it.
That's the other half of this story: A Safety App That Can't Track You - how Gart works, and how to use it.