37% of the world's most popular apps request access to a user's location, according to NordVPN's December 2023 analysis of mobile apps across 18 categories. That figure sits well below the location-sharing rates found among children's apps and background-tracking apps, which several studies published between 2021 and 2025 put much higher. This post breaks down what percentage of apps collect location data, how that number moves by platform and app category, and what happens to location data once an app has it.
Figure 1: A little over a third of popular apps ask for a user's location before that data ever reaches a privacy policy disclosure. Source: NordVPN, December 2023.
What percentage of apps collect location data?
37% of popular apps request access to a user's location, per NordVPN's December 2023 review of the world's most-downloaded mobile apps in 18 categories. That makes location the third most requested sensitive permission behind cross-app activity tracking (42%) and roughly level with camera access (35%).
The 37% figure measures apps that request the location permission, which is the technical gate an app has to pass through before it can read GPS coordinates, Wi-Fi positioning, or cell-tower data from a device. Requesting the permission does not guarantee a user grants it, and granting it does not guarantee the app actually collects location data on every session. But industry researchers and app-store reviewers both treat "requests location access" as the standard proxy for "collects location data," because it is the only step that shows up consistently in static analysis of an app's manifest or entitlements file.
NordVPN's researchers pulled a cross-section of the most popular apps globally, spanning 18 categories from social media to shopping to health, rather than a single app store's top chart. That breadth is why the 37% figure reads lower than category-specific numbers further down this page: navigation, weather, and children's apps request location far more often than the average app in a general population, and they pull the category average up when counted separately.
Figure 2: Location sits near the top of the permissions apps request most, just ahead of camera access. Source: NordVPN / Nord Security, "Over 7 Out of 10 Apps Collect More Information About You Than They Should" (December 2023).
Location is not the only channel apps use to infer where a user is. IP address, Wi-Fi network names, and even the language and currency settings on a device can all place a user within a few miles without ever touching the location permission at all, so the 37% figure is a floor on location-adjacent tracking, not a ceiling on it.
Do more apps request location in the background or the foreground?
Foreground location, granted only while a user has the app open, is the far more common request. Apptopia's 2021 analysis of the top 1,500 free U.S. apps, reported by Forbes, found 66% requested foreground location access, compared with 40% that requested background location access, which keeps working after a user closes the app or locks the phone.
The gap between those two numbers matters because background location is the more invasive of the two categories app stores track separately. Apple and Google both require a distinct justification and disclosure for background location under their current developer policies, and background access is what lets an app build a continuous movement history rather than a single snapshot of where a user happened to be during a session. A weather app checking local conditions on launch needs foreground access. A fitness tracker mapping a full run, or an ad network building a visit-frequency profile of nearby stores, needs background access, and that is the category regulators and app-store reviewers scrutinize hardest.
Figure 3: The 37% headline figure for all popular apps sits well below the rate for children's apps and top-chart foreground requests. Sources: Statista (Q1 2022, children's apps), Apptopia via Forbes (2021, top 1,500 apps), NordVPN (Dec 2023, popular apps overall).
Apps that only need foreground access rarely ask for background permission, since app-store review teams reject that combination when the stated purpose does not justify it. The apps that do request background location tend to cluster in navigation, fitness, ride-hailing, and advertising-supported free apps, where continuous location is either core to the product or valuable to the ad business funding it.
How many children's apps collect and share location data?
Children's apps request and share location data at rates well above the general app population. 76% of leading children's apps on Google Play and 67% on the Apple App Store could transmit location data to advertisers, according to a Q1 2022 analysis cited by Statista, and a separate Pixalate report found that 97% of child-directed apps with no recorded parental consent still shared location data in the open programmatic advertising bid stream during Q1 2023.
Figure 4: Most leading children's apps on Google Play could pass location data to advertisers, even though only a fraction of parents ever see that disclosure. Source: Statista, Q1 2022.
The pattern holds in more recent data too. Pixalate's Q1 2024 Google vs. Apple COPPA Risk Scorecard Report, built from a scan of 5.1 million apps, found 47% of likely child-directed apps request access to personal information through permissions such as camera, microphone, or location. Its Q2 2024 follow-up found child-directed apps were 50% more likely than non-child-directed apps to share both GPS coordinates and IP address in the open programmatic ad bid stream, the marketplace where ad space is bought and sold in real time. Under COPPA and similar children's privacy rules, an app aimed at kids under 13 is supposed to get verifiable parental consent before collecting precise geolocation, which makes the 97% no-consent sharing rate a direct compliance gap rather than a gray area.
One sentence takeaway: a children's app is roughly twice as likely to expose location data to advertisers as an app aimed at a general audience.
What happens to location data after an app collects it?
Once an app has location access, that data frequently moves beyond the app itself. NordVPN found 42% of popular apps request permission to track a user's activity across other apps and websites, the mechanism that lets a location reading collected in one app get matched to behavior in another. NowSecure's August 2025 mobile risk assessments, covering 50,000 tested apps, found 49% connect to third-party trackers, and separately that 77% of the same app set carried common forms of personally identifiable information, including location, alongside contact and account data.
Pixalate's Q4 2023 Global Abandoned Mobile Apps Report puts a number on how long that exposure can persist without any active maintenance: among 1.89 million abandoned Google Play and App Store apps it identified, 5,388 were still sharing user location data in the advertising bid stream despite no longer receiving developer updates. An app does not need to be actively maintained, or even particularly popular, to keep a location feed flowing to third parties once that pipe has been built.
Figure 5: Studies with larger, fully automated scans do not consistently report higher exposure rates than smaller curated samples, which suggests the underlying practice, not the study method, drives the gap. Sources: NordVPN (Dec 2023), Apptopia via Forbes (2021), NowSecure (Aug 2025), Pixalate (Q1 2024).
For a site or app that collects location data for any reason, from delivery estimates to ad targeting, the disclosure obligation does not depend on how the data is used afterward. If your app or website reads a user's location, that collection point, its purpose, and any third parties it is shared with belong in your privacy policy before the feature ships. You can generate a privacy policy that covers geolocation collection, background tracking, and third-party sharing disclosures in the sections app-store reviewers and regulators check first.
Should your app request location access?
Not every feature that touches location needs the permission itself, and app-store review teams increasingly reject requests that outrun their stated purpose.
Figure 6: A simple justification test before requesting location access, matching the standard app-store review checklist. Source: Apple App Store Review Guidelines and Google Play policy, as summarized in industry developer guidance.
Location access that survives this test still has to be disclosed, and both major app stores now require a specific data-safety or nutrition-label entry naming location as a collected data type before an app can ship an update. Treating the permission request and the policy disclosure as two halves of the same launch checklist, rather than two separate tasks handled by different teams, is the most common gap that trips up smaller developers during app-store review.
Location data collection at a glance
| Source | Sample | Share reporting location exposure | Year |
|---|---|---|---|
| NordVPN / Nord Security | Popular apps globally, 18 categories | 37% request location access | 2023 |
| Apptopia (via Forbes) | Top 1,500 free U.S. apps | 66% foreground / 40% background location | 2021 |
| Statista | Leading children's apps, Google Play | 76% could transmit location to advertisers | 2022 |
| Statista | Leading children's apps, Apple App Store | 67% could transmit location to advertisers | 2022 |
| Pixalate | Likely child-directed apps (5.1M scanned) | 47% request camera, microphone, or location | 2024 |
| Downstream behavior | Share of apps | Source (year) |
|---|---|---|
| Child-directed apps with no parental consent that still shared location in the ad bid stream | 97% | Pixalate (2023) |
| Apps that connect to third-party trackers | 49% | NowSecure (2025) |
| Apps that request permission to track activity across other apps and sites | 42% | NordVPN (2023) |
| All popular apps that request location access | 37% | NordVPN (2023) |
The Bottom Line
37% of popular apps request a user's location, and that share climbs sharply once you narrow the population to children's apps, navigation-adjacent categories, or anything monetized through open programmatic advertising. The gap between the 37% general-population figure and the 66-97% range found in more targeted studies is not really a measurement disagreement. It reflects the fact that location access clusters heavily in a handful of app categories, and those categories are also where third-party ad tech is most aggressive about pulling that data into the bid stream. For any site or app that collects location data, the practical takeaway is the same regardless of which end of that range it falls into: the permission request, the in-app disclosure, and the privacy policy language covering geolocation all need to describe the same collection and sharing practices, because app-store reviewers, regulators, and increasingly users themselves are now checking all three.
Frequently Asked Questions
What percentage of apps collect location data? 37% of popular apps request access to a user's location, according to NordVPN's December 2023 study of the world's most-downloaded mobile apps across 18 categories. Location ranks behind cross-app tracking permission requests, which affect 42% of the same app set.
Do more apps request location in the background or the foreground? Foreground location, used only while the app is open, is requested far more often. Apptopia's 2021 permissions analysis of the top 1,500 free U.S. apps found 66% requested foreground location access, compared with 40% that requested background location access, which continues even after the app is closed.
What percentage of children's apps share location data with advertisers? 76% of leading children's apps on Google Play and 67% on the Apple App Store could transmit location data to advertisers, per a Q1 2022 industry analysis cited by Statista. A separate Pixalate report found 97% of child-directed apps that collected no parental consent still shared location data in the open programmatic ad bid stream in Q1 2023.
Where does an app's location data usually end up? Much of it reaches third parties. NordVPN found 42% of popular apps request permission to track user activity across other apps and websites, and NowSecure's 2025 mobile risk assessments found 49% of tested apps connect to third-party trackers, many of which resell or reuse location signals for ad targeting.
Where the Numbers Come From
- Nord Security. (2023). "Over 7 Out of 10 Apps Collect More Information About You Than They Should." NordVPN research lab analysis of popular mobile apps across 18 categories, published 8 December 2023. 37% of apps request location access.
- Forbes. (2021). "Top Permissions: The Biggest 1,500 iOS Apps Request Globally." Permissions data from Apptopia, covering the top 1,500 free apps in the U.S., published 26 March 2021. 66% foreground location, 40% background location.
- Statista. Share of leading children's apps that could transmit location data to advertisers, Q1 2022: 76% on Google Play, 67% on the Apple App Store.
- Pixalate. (2024). "Q1 2024 Google vs. Apple COPPA Risk Scorecard Report." Scan of 5.1 million mobile apps across Google Play and the Apple App Store. 47% of likely child-directed apps request camera, microphone, or location permissions.
- Pixalate. (2023). "Q1 2023 Children's Privacy Age Screening Report." 97% of reviewed likely child-directed Google Play apps with no recorded parental consent still shared location data in the open programmatic advertising bid stream.
- Pixalate. (2024). "Q2 2024 Google vs. Apple COPPA Risk Scorecard Report." Child-directed apps found to be 50% more likely than non-child-directed apps to share both GPS location and IP address in the open programmatic advertising bid stream.
- Pixalate. (2024). "Global Abandoned Mobile Apps Report, Q4 2023." Among 1.89 million abandoned apps identified across Google Play and the Apple App Store, 5,388 were still sharing user location data in the advertising bid stream.
- NowSecure. (2025). "New NowSecure Research Targets Mobile App Privacy Risks." Mobile risk assessments across 50,000 apps tested through August 2025. 77% carried common forms of personally identifiable information, including location; 49% connected to third-party trackers.
Note: All figures verified as of July 2026. Sample sizes and methodology vary by source, from curated cross-category panels (NordVPN) to full app-store scans in the millions (Pixalate), so figures are not directly interchangeable across studies and are presented here with their original population noted. This post's underlying figures are scheduled for a refresh at least twice a year to track newer editions of the Pixalate and NowSecure reports.