TL;DR: ICE doesn't need to hack your phone. It pays a few companies to hand over the data your apps already collected. A Muslim prayer app with 98 million downloads, a weather app, a Craigslist tool, all part of the same commercial surveillance supply chain that feeds immigration enforcement. Here is the eight-step journey your location data takes from your pocket to an ICE officer's dossier, complete with the dollar amounts, company names, and legal loopholes that make it possible.

The Pipeline No One Told You About

ICE spent $2.8 billion on data and technology in fiscal year 2024. Not on agents. On data.[1]

That money buys something more powerful than any informant network: a commercial surveillance infrastructure built by the ad industry and repurposed for deportation. Your phone has been contributing to it every day, silently, without your knowledge or consent.

The pipeline has eight distinct steps. Each step involves different companies, different legal frameworks, and different opportunities for you to interrupt the flow. Most people only know about one or two of them. Here is all eight.

Step 1: You Open an App

Not a suspicious app. An ordinary one.

In 2020, Motherboard and the Intercept obtained leaked data from a company called X-Mode. The dataset included Muslim Pro, a Muslim prayer and Quran app with approximately 100 million downloads worldwide, which had been selling location data to X-Mode, which in turn sold it to US military contractors. Salaat First, another Muslim prayer app with over 10 million downloads, was also in the supply chain via a French broker called Predicio.[2]

The apps themselves weren't spyware. They needed your location to calculate prayer times based on where you are. That's a legitimate feature. But once they had your location, many of them monetized it.

Other apps confirmed in these data pipelines:

  • Fu* Weather, over a million downloads, used for weather forecasts
  • Weawow, weather app
  • Waze, navigation app, named by Fog Data Science as a Venntel data source
  • Starbucks app, named by Fog Data Science as a Venntel data source
  • Storm tracker apps, follow local severe weather
  • A popular Craigslist client
  • A phone "level" utility app
  • A Muslim dating app

The pattern: apps that need location access for a stated purpose, prayer times, weather, local classifieds, quietly share that data with third parties. The app developers often get paid for the access. You agreed to it somewhere in a privacy policy you never read.[3]

Step 2: The SDK You Never Installed

Inside these apps sits invisible code you didn't download. Software Development Kits, SDKs, are pre-built libraries that app developers plug in to add features. An analytics SDK, an ad SDK, a monetization SDK. They come from third parties. The app developer may barely know what's in them.

An SDK from a company like X-Mode or Predicio doesn't ask your permission separately. You gave permission (theoretically) when you agreed to the app's terms. The SDK inherits that permission and starts harvesting: GPS coordinates, timestamps, device identifiers, Wi-Fi network names, IP address, behavioral signals.

This data leaves your phone without a second confirmation. It goes directly to the SDK company's servers. The app developer gets a small revenue share. You get nothing.[3]

X-Mode, before the FTC banned it from selling sensitive location data in January 2024, embedded its SDK in hundreds of apps and collected more than 10 billion location data points, 70 percent accurate to within 20 meters.[4] Predicio, a French firm, paid app developers directly for access to their users' data and was connected to Venntel, an ICE contractor.

Step 3: The Ad Auction That Broadcasts Your Location

The other collection channel is subtler and more pervasive. It's called real-time bidding (RTB), and it happens every time a free app displays an advertisement.

When an ad slot opens on your screen, the app sends a bid request to an ad exchange. That bid request contains: your IP address, your device fingerprint, your advertising ID (the IDFA on iPhone, GAID on Android), your location, and behavioral inferences about who you are.

This package goes to hundreds or thousands of potential advertisers simultaneously. In under 100 milliseconds, the auction closes, someone wins, and an ad loads. But every losing bidder in that auction also received your location data. They didn't win the ad, but they got the data. And they kept it.[5]

Customs and Border Protection acknowledged this in a document obtained by 404 Media, the first time CBP admitted its purchased location data is partially sourced from real-time bidding. ICE, not to be outdone, posted a Request for Information on January 23, 2026, explicitly asking ad tech companies what they could provide. It was the first time ICE used the phrase "Ad Tech" in official federal procurement documents.[6]

Step 4: The Aggregator Buys It All

At this point, billions of location signals per day are flowing from thousands of apps to dozens of data companies. The aggregators are the next layer: companies that buy signals from multiple SDK providers and RTB feeds, clean and deduplicate them, and build a unified picture of every device.

Gravy Analytics / Venntel is the clearest example. Gravy Analytics collects more than 17 billion location signals daily from approximately one billion mobile devices. Venntel is its government-facing subsidiary, the entity that sold directly to DHS, ICE, and CBP.

In December 2024, the FTC finalized an order against Venntel, finding the company had illegally sold location data on sensitive categories, including medical facilities, religious sites, and political events. The FTC ordered Venntel to stop selling precise location data for those categories and to delete historical data. A damning indictment of the business model. But the data that was already sold to the government? It wasn't recalled.[4]

Senator Ron Wyden sent a letter to the DHS Inspector General on March 3, 2026, citing specific contracts and demanding an investigation into whether ICE's location data purchases violated federal law.[7]

Step 5: The Government Buys Without a Warrant

This is the step that shouldn't be legal but is.

In 2018, the Supreme Court ruled in Carpenter v. United States that police need a warrant to obtain your historical cell-site location information (CSLI) from a phone carrier. But the Court didn't address one thing: what happens when the government skips the carrier and just buys the same data from a commercial broker?

That question remains unresolved. The government's position, tacit and mostly untested in court, is that buying data is not the same as compelling a carrier to hand it over. You voluntarily shared your location with an app. The app shared it with a broker. The broker sold it to the government. No warrant required at any step.[8]

Known ICE and DHS location data contracts:

Penlink / Webloc

$2.3 million no-bid contract (September 2025); a second no-bid contract of $2.9 million followed in April 2026, with a potential total award of $8.3 million. Webloc tracks up to 500 million devices across 30+ countries. Agents can query three years of historical location data. Built by Israeli firm Cobwebs Technologies, now operated by Penlink after a 2023 merger.[9]

Babel Street / Locate X

Up to $27 million FBI contract for 5,000 licenses (2022). Separate ICE and CBP contracts going back years. Agents can draw a geofence around any location and see every phone that visited it, identified by advertising ID. Babel Street taps the RTB bid stream directly, no app SDK needed.[10]

Venntel / Gravy Analytics

DHS contracts for mobile phone location data going back years. ICE and CBP used Venntel data to identify immigrants who were later arrested. Now subject to FTC order, but historical data already in government systems.[4]

ICE Ad Tech RFI (Jan 2026)

On January 23, 2026, ICE publicly solicited more vendors, specifically asking about "Ad Tech compliant and location data services available to federal investigative and operational entities." The shopping spree continues.[6]

Step 6: The Profile Gets Built

Location data alone tells you where someone goes. It doesn't tell you who they are, where they live, who their family is, or whether they have legal immigration status. That's what the intelligence layer is for.

Thomson Reuters CLEAR is used by more than 3,400 law enforcement agencies. DHS currently holds a contract worth $22.8 million, expiring in 2026. CLEAR aggregates: utility records, property records, vehicle registrations, court filings, social media data, purchase histories, credit headers, phone records, and more. Give it a name or address and it returns a network map of every associated person, phone, address, and vehicle.[1]

LexisNexis Accurint / Risk Solutions: two contracts, a $9.75 million DHS contract from 2021 and a separate $22 million ICE contract expiring in 2028. Their database holds over 78 billion records on individuals. The same company that helps lawyers research case law also sells surveillance dossiers to immigration enforcement.[1]

At this stage, the location signals from your prayer app combine with your utility bills, your rental history, your vehicle registrations, and your family members' addresses. Threads from different companies, pulled together into one file.

And then it gets worse.

In January 2026, ICE and the Centers for Medicare and Medicaid Services signed a data-sharing agreement giving ICE access to records on nearly 80 million Medicaid patients. Health insurance data. Used to locate people.[11]

Step 7: The Algorithm Picks a Target

Palantir's ELITE app (Enhanced Leads Identification and Targeting for Enforcement) takes all of this and renders it as a map.

Open ELITE, and you see a density visualization: clusters of people with what the system calls an "immigration nexus" across a city. Zoom in. Select a cluster. Select an individual. The app generates a dossier: photograph, alien registration number, date of birth, last known address, and an Address Confidence Score between 0 and 100.[12]

The score combines location data, utility connections, Medicaid enrollment address, vehicle registrations, and whatever else is in the linked databases. Higher score means Palantir thinks you're more likely to be at that address right now.

By May 2026, ICE had effective access to data on 20 million people through Palantir-powered systems.[13]

This is what the $30 million ImmigrationOS contract, signed August 2025, prototype delivered September 2025, was building toward: a platform where a single officer can turn commercial data into an arrest queue. Palantir has collected over $81 million in ICE contracts since January 2025 alone. Palantir built it. ICE paid for it. Your apps fed it.

Step 8: The Arrest

Under oath in an Oregon federal court in 2026, ICE officers confirmed they used the ELITE app to identify arrest locations. Officers were ordered to make eight arrests per team per day during enforcement operations.[12]

The ELITE app told them where to go. The data behind that app started with someone opening a weather forecast.

This isn't hypothetical. The Citizen Lab's April 2026 report on Webloc confirmed ICE as a customer, alongside the U.S. military, Texas DPS, and police departments in Los Angeles, Dallas, Baltimore, and Tucson.[9] ICE used Webloc to track specific devices at specific times and places. The tool offers historical data going back three years. An agent can see everywhere a phone has been for 36 months, no warrant, no judge, just a subscription fee.

What This Looks Like in Practice

In 2025, Google handed over subscriber data on Amandla Thomas-Johnson, a doctoral student who briefly attended a pro-Palestine protest, to DHS, without giving him the advance notice Google had promised users for nearly a decade. He learned about it after the fact. The EFF subsequently asked California and New York attorneys general to investigate Google's compliance practices.[14]

He didn't download a suspicious app. He went to a protest. Google had his account data. DHS sent a subpoena. Google complied.

The data-broker pipeline is just one vector. The broader architecture, commercial surveillance fused with government enforcement, catches people from multiple directions at once.

How to Reduce Your Exposure

You cannot opt out of a pipeline you don't know exists. But you can interrupt it at several points.

At the App Layer

  • Revoke location permissions from apps that don't strictly need them. iOS: Settings → Privacy & Security → Location Services. Android: Settings → Privacy → Permission Manager. Set weather, prayer, and utility apps to "While Using" at most, never "Always."
  • Delete apps you don't actively use. Background location access continues as long as the app is installed.
  • Use browser-based versions instead of apps where possible. Weather.com in Safari collects far less than a native weather app with "Always On" location.

At the Advertising ID Layer

  • Reset your advertising ID regularly, this breaks the historical record, though it doesn't stop collection going forward. iOS: Settings → Privacy → Tracking → turn off "Allow Apps to Request to Track." Android: Settings → Google → Ads → Delete advertising ID.
  • On iOS 14.5+, apps must ask permission before accessing your IDFA. Choose "Ask App Not to Track" whenever prompted.

At the RTB Layer

  • Use a VPN to mask your IP address in bid requests. This degrades the geographic precision of RTB-sourced data.
  • Use an ad blocker that blocks tracking. uBlock Origin on desktop; AdGuard or Brave on mobile. These prevent many SDK pings from reaching aggregators at all.

At the Broker Layer

  • Submit opt-out requests to data brokers. LexisNexis, Thomson Reuters CLEAR, and Venntel all have opt-out processes, though they're deliberately obscure and not all data types are covered. Services like DeleteMe or Privacy Bee automate this across multiple brokers.
  • Freeze your credit reports at all three bureaus. Data brokers frequently pull from credit header data.

At the Device Layer

  • Use a secondary device or burner phone for sensitive activities. If your primary device has years of location history, separating it from sensitive locations limits the profile Webloc-type tools can build.
  • Leave your phone at home when attending protests, religious services, or medical appointments. This sounds extreme until you understand that Palantir can geofence specific addresses and pull every device that visited them.

None of these steps is perfect. But each one interrupts the pipeline at a different layer. Using all of them makes you significantly harder to track.

The Eight Steps, Summarized

  1. You open an app, prayer, weather, local classifieds, that requests location access
  2. An embedded SDK harvests your GPS coordinates, device ID, and behavioral data
  3. RTB ad auctions broadcast your location to hundreds of companies with every ad load
  4. Aggregators (Gravy Analytics/Venntel, X-Mode) buy from thousands of SDKs and RTB feeds, building unified device histories
  5. ICE buys the data via Webloc, Babel Street, or direct aggregator contracts, no warrant, no judicial oversight
  6. Profile enrichment via LexisNexis and Thomson Reuters CLEAR fuses location with identity, utility, financial, and Medicaid records
  7. Palantir ELITE/ImmigrationOS generates a map of targets with confidence-scored addresses, prioritized for arrest
  8. An ICE team hits eight arrests per day using the dossier the algorithm built

At no step was a warrant required. At no step was a judge consulted. Your apps were talking to the government the whole time.

References

  1. NPR / OPB (March 2026): Your data is everywhere. The government is buying it without a warrant
  2. Motherboard / Vice: Leaked Location Data Shows Another Muslim Prayer App Tracking Users
  3. EPIC (2024): How Data Brokers Harm Immigrants
  4. FTC / The Record (2024): FTC targets companies that collected and sold sensitive location data
  5. EFF (March 2026): Targeted Advertising Gives Your Location to the Government, Just Ask CBP
  6. The Register (January 2026): ICE takes aim at data held by advertising and tech firms
  7. Sen. Wyden letter to DHS OIG (March 2026): Letter on ICE purchasing location data
  8. Yale Law & Policy Review: End-Running Warrants: Purchasing Data Under the Fourth Amendment
  9. Citizen Lab (April 2026): Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech
  10. Vice / Motherboard: Secret Service Bought Phone Location Data from Apps, Contract Confirms
  11. EFF (January 2026): Report: ICE Using Palantir Tool That Feeds On Medicaid Data
  12. IBTimes UK (2026): ICE Officers Confirm Under Oath That Palantir's ELITE App Identified Arrest Targets
  13. Latin Post (May 2026): ICE Agents Now Have Access to Data on 20 Million People Through Palantir System
  14. Prism Reports (January 2025): ICE is swiftly expanding its sprawling surveillance apparatus

Related coverage: How Palantir's ImmigrationOS Decides Who Gets Deported · Data Brokers Selling You to ICE: The $10M Contract Story · How the Ad Industry Built a Surveillance Machine · The Data Broker Loophole: Buying Your Location Without a Warrant