AccuWeather for iOS Sending Location Data to Monetization Company Even When Location Sharing is Off [Updated]

Popular and well-known iOS weather app AccuWeather has been caught collecting and sharing user location data even when location sharing permissions are turned off, according to a blog post recently shared by security researcher Will Strafach.

According to Strafach, AccuWeather was partnering with data monetization firm Reveal Mobile to collect GPS coordinates, including speed and altitude, the name and BSSID of a user's Wi-Fi router, and whether a device has Bluetooth on and off, all of which was available to Reveal Mobile when location services were enabled.

accuweatherbackgroundaccess
With location services disabled, AccuWeather was still sending the Wi-Fi router name and BSSID, which still offered Reveal Mobile location data.

During a testing period of 36 hours, specifically while the AccuWeather application was not in the foreground, my test iPhone (located on a desk in an office building) sent the above information to RevealMobile a total of 16 times, occuring roughly once every few hours.

Reval Mobile is a firm that uses location data to gather information on a user's home, work, and frequently visited locations, pairing that data with demographic targeting criteria to allow retailers to deliver targeted ads. From the company's website:

By expanding the use case of location data to pre- and post-shopping experiences, entirely new possibilities open up for online and offline retailers. The value lies in understanding the path of a consumer and where they go throughout the day. Traveling from home to work to retail to soccer practice to dinner is vital to knowing the customer, and represents the new opportunity of mobile location data.

In response to Strafach's blog post, Reveal Mobile says the data it collects is anonymized and grouped into audience segments. "We offer no product or service that permits anyone to see an individual device's location data," reads a statement on the Reveal Mobile website. The company also says it does not reverse engineer a device's location when location sharing is turned off.

We do not attempt to reverse engineer a device's location based upon other data signals like Bluetooth when location services are disabled. In looking at our current SDK's behavior, we see how that can be misconstrued. In response to that, we're releasing a new version of our SDK which will no longer send any data points which could be used to infer location when someone opts out of location sharing. We do collect IP address, but do not use this data to determine location, as covered in our privacy policy.

AccuWeather vice president of emerging platforms David Mitchell told ZDNet that AccuWeather will use data through Reveal Mobile for "audience segmentation and analysis, to build a greater audience understanding and create more contextually relevant and helpful experiences for users and for advertiser."

Following Strafach's discovery, many people have been uninstalling the AccuWeather app, and given the wealth of weather apps available in the App Store, this is not surprising. AccuWeather does not apparently have plans to end its relationship with Reveal Mobile, so users may want to find another weather app.

Update: AccuWeather and Reveal Mobile have provided a joint statement on the issue:

Despite stories to the contrary from sources not connected to the actual information, if a user opts out of location tracking on AccuWeather, no GPS coordinates are collected or passed without further opt-in permission from the user.

Other data, such as Wi-Fi network information that is not user information, was for a short period available on the Reveal SDK, but was unused by AccuWeather. In fact, AccuWeather was unaware the data was available to it. Accordingly, at no point was the data used by AccuWeather for any purpose.

AccuWeather and Reveal Mobile are committed to following the standards and best practices of the industry. We also recognize this is a quickly evolving field and what is best practice one day may change the next. Accordingly, we work to update our practices regularly.

To avoid any further misinterpretation, Reveal is updating its SDK and pushing out new versions of the SDK in the next 24 hours, with the iOS update going live tonight. The end result should be that zero data is transmitted back to Reveal Mobile when someone opts out of location sharing. In the meanwhile, AccuWeather had already disabled the SDK, pending that update.

Reveal has stated that the SDK could be misconstrued, and they assure that no reverse engineering of locations was ever conducted by any information they gathered, nor was that the intent.

AccuWeather will work with Reveal to restore the SDK when it has been amended and will continue to update its ULAs to be transparent and current with evolving standards. AccuWeather and Reveal continue to enhance methods for handling data and strive to provide superior, seamless, and secure user experiences.

We are grateful to have a supportive community that highlights areas where we can optimize and be more transparent.

Update 2: AccuWeather has updated its app to remove the Reveal Mobile SDK.

Top Rated Comments

farewelwilliams Avatar
86 months ago
"The value lies in understanding the path of a consumer and where they go throughout the day."

no means no.
Score: 72 Votes (Like | Disagree)
826317 Avatar
86 months ago
Disgusting business practice. It's so difficult to find genuinely honest businesses these days..
Score: 50 Votes (Like | Disagree)
camnchar Avatar
86 months ago
Repeat after me: “if you don’t pay for the product, you ARE the product”
Score: 50 Votes (Like | Disagree)
Munky Avatar
86 months ago
This was my go to weather app. Any suggestions for a replacement?

App store reviews are already getting hit hard.
Wunderground.
Score: 24 Votes (Like | Disagree)
now i see it Avatar
86 months ago
AccuWeather does not apparently have plans to end its relationship with Reveal Mobile....
But we have plans for AccuTracker. Long press/click X.
Score: 23 Votes (Like | Disagree)
maflynn Avatar
86 months ago
Well, looks like Accuweather is getting deleted off my iDevices.
Score: 23 Votes (Like | Disagree)

Popular Stories

reset password request iphone

Warning: Apple Users Targeted in Phishing Attack Involving Rapid Password Reset Requests

Tuesday March 26, 2024 4:34 pm PDT by
Phishing attacks taking advantage of Apple's password reset feature have become increasingly common, according to a report from KrebsOnSecurity. Multiple Apple users have been targeted in an attack that bombards them with an endless stream of notifications or multi-factor authentication (MFA) messages in an attempt to cause panic so they'll respond favorably to social engineering. An...
maxresdefault

Apple to Launch New iPad Pro and iPad Air Models in May

Thursday March 28, 2024 11:07 am PDT by
Apple will introduce new iPad Pro and iPad Air models in early May, according to Bloomberg's Mark Gurman. Gurman previously suggested the new iPads would come out in March, and then April, but the timeline has been pushed back once again. Subscribe to the MacRumors YouTube channel for more videos. Apple is working on updates to both the iPad Pro and iPad Air models. The iPad Pro models will...
Generic iOS 18 Feature Purple

iOS 18: What to Expect From 'Biggest' Update in iPhone's History

Wednesday March 27, 2024 11:10 am PDT by
At least some Apple software engineers continue to believe that iOS 18 will be the "biggest" update in the iPhone's history, according to Bloomberg's Mark Gurman. Below, we recap rumored features and changes for the iPhone. "The iOS 18 update is expected to be the most ambitious overhaul of the iPhone's software in its history, according to people working on the upgrade," wrote Gurman, in a r...
maxresdefault

Apple Announces WWDC 2024 Event for June 10 to 14

Tuesday March 26, 2024 10:02 am PDT by
Apple today announced that its 35th annual Worldwide Developers Conference is set to take place from Monday, June 10 to Friday, June 14. As with WWDC events since 2020, WWDC 2024 will be an online event that is open to all developers at no cost. Subscribe to the MacRumors YouTube channel for more videos. WWDC 2024 will include online sessions and labs so that developers can learn about new...
apple maps 3d feature

Apple Maps May Gain Custom Routes With iOS 18

Tuesday March 26, 2024 3:10 pm PDT by
Apple may be planning to add support for "custom routes" in Apple Maps in iOS 18, according to code reviewed by MacRumors. Apple Maps does not currently offer a way to input self-selected routes, with Maps users limited to Apple's pre-selected options, but that may change in iOS 18. Apple has pushed an iOS 18 file to its maps backend labeled "CustomRouteCreation." While not much is revealed...
General iOS 17 Feature Orange Purple

Apple Releases Revised Versions of iOS 17.4.1 and iPadOS 17.4.1 With Updated Build Number

Wednesday March 27, 2024 5:59 am PDT by
Apple on late Tuesday released revised versions of iOS 17.4.1 and iPadOS 17.4.1 with an updated build number of 21E237, according to MacRumors contributor Aaron Perris. The updates previously had a build number of 21E236. The revised updates are available for all iPhone and iPad models that are compatible with iOS 17 and iPadOS 17, but they can only be installed via the Finder app on macOS...
applephilschiller

Apple's Phil Schiller Works 80 Hours a Week Overseeing App Store

Wednesday March 27, 2024 2:03 pm PDT by
With the App Store and app ecosystem undergoing major changes in the European Union, The Wall Street Journal today shared a profile on App Store chief Phil Schiller, who is responsible for the App Store. Though Schiller transitioned from marketing chief to "Apple Fellow" in 2020 to take a step back from Apple and spend more time on personal projects and friends, he is reportedly working...