Morning Overview

Some settings on your phone keep tracking your location even when you think they’re off

Turning off “location” in a phone’s settings feels like flipping a switch that goes dark, but the reality is more layered. A modern smartphone determines and shares its whereabouts through several independent systems, and disabling one does not necessarily silence the others. The result is that a device can continue to generate a trail of location information even when its owner believes tracking is fully off, because some of that tracking happens below the level of the app permissions most people adjust.

Understanding the distinction matters for anyone who cares about privacy. There is a difference between an app that stops reading a phone’s GPS and a carrier network that inherently knows which cell tower a phone is connected to, and only one of those is controlled by a toggle in the settings menu.

Two layers of location tracking

A phone’s location can be pinned down through more than one technology at once. As a technical matter, mobile phone tracking works by measuring radio signals between the device and cell towers or by using the phone’s GPS receiver, and modern handsets often combine those methods with nearby Wi-Fi and Bluetooth signals to sharpen the estimate. Each method has a different owner and a different off switch.

GPS-based location, the kind an app uses to show a map or tag a photo, is the layer most users think of, and it is governed by the app permissions and the master location toggle in the settings. Network-based location, by contrast, is a byproduct of how cellular service works at all. The phone must talk to a tower to make calls and carry data, and that connection reveals its approximate position to the carrier regardless of any setting the user changes.

Carrier network location that settings don’t touch

The layer people most often overlook is the carrier’s own view of the network. Mobile carriers know roughly where a device is because they know which towers it connects to, and more advanced methods triangulate a phone’s position from the signal strength and timing across several nearby towers, which is more precise in dense urban areas where towers are packed close together. That information exists as long as the phone is powered on and registered to the network, whether or not the owner has switched off app-level location.

This is why an aggressively “location off” phone can still be located, in a legal request to a carrier or in some analytics feeds, at the tower level. It is also why turning off GPS improves privacy against apps but does little against the network itself. Short of turning the phone off or putting it in airplane mode, the connection to the cellular network keeps producing coarse location data.

How ‘off’ can still mean ‘on’

Even within the settings a user does control, “off” is often narrower than it appears. Disabling location for a single app does not stop the operating system’s own system services, some of which use location for functions like emergency calling, time-zone setting, or finding a lost device. On top of that, apps that once had location permission may retain copies of previously collected data, and some services infer location indirectly from a Wi-Fi network name or an IP address even without GPS access.

Permissions can also drift. An app granted “allow while using” access can quietly gather a surprising amount of movement data during normal use, and a software update or a re-installation can reset a permission the user thought they had revoked. The practical lesson is that a single toggle rarely delivers the total silence people assume it does, and periodic review is the only way to keep settings matching intentions.

The data-broker market for location

Where the collected location goes is what turns a technical footnote into a privacy problem. A large industry of data brokers buys, packages, and resells location information harvested from apps, and regulators have taken enforcement action against companies for handling it improperly. The Federal Trade Commission ordered the data broker X-Mode Social and its successor Outlogic to stop selling sensitive location data, describing how precise movement records can reveal visits to medical clinics, places of worship, and other sensitive destinations.

It was not an isolated case. The agency also took action against Gravy Analytics and Venntel over the unlawful sale of location data that tracked people to sensitive sites. Those actions illustrate that the location generated by an ordinary phone can travel far beyond the app that first collected it, ending up in commercial datasets that can be cross-referenced to identify individuals despite claims of anonymization.

Limiting what a phone reveals

Users cannot switch off the carrier’s network-level awareness without disabling connectivity, but they can meaningfully shrink the app-driven trail. Setting apps to access location only while in use, or denying it entirely to apps that have no need for it, cuts the flow at the source. Both major mobile platforms let owners review which apps have requested location and how often, and turning off advertising identifiers and opting out of ad personalization limits how easily brokers can stitch records together.

For maximum privacy in a specific moment, airplane mode or powering the device off severs the network connection that produces tower-level data. Short of that, the realistic goal is control rather than invisibility: knowing which layer a given setting actually governs, checking permissions regularly, and treating any promise of a single “off” switch with healthy skepticism.

This article was produced with AI assistance and reviewed by Morning Overview editors.


More from Morning Overview