*THIS IS A SERIES! BE SURE TO START AT PART 1! [Click Here]*
Although this was originally intended to be a deep dive into Flock, the road took me elsewhere, and this road that few other researchers are traveling is incredibly important because it all ties together in the end. This may sound confusing for a moment, but trust me, it won’t be, so stick with it.
The advertising industry is collecting data on us. Data collected contains “Mobile Advertising IDs” (MAIDs), which identify a phone or other mobile device and the person using it. The 32-character hyphen-separated MAID assigned to your device is a special code that only your device has (e.g., 919F1D1F-F195-4C8B-AF47-58683FE11DB9).These codes enable us to be targeted with advertisements. This is why someone who loves to travel will see a lot of ads for places to travel no matter what website they are on, whereas someone who is a gamer will get lots of game-centered ads.
The advertising industry has ongoingly insisted that while people are being tracked, the MAID anonymizes them; therefore, their identity is wholly unknown to the advertiser. They further insist that, due to the anonymity, what they are doing is not actually surveillance. However, the US Federal Trade Commission (FTC) recently clarified that advertising IDs “offer no anonymity in the marketplace” because advertising businesses commonly link consumers’ MAIDs to other information about them, such as names, addresses, IP addresses, and phone numbers. Therefore, once a MAID has been assigned to your device, that device has been assigned to you as a person. It might as well be listed on your driver’s license because it is no secret.
SDKs
Recall how I said previously that Cobwebs Webloc technology “relies on data purchased from mobile apps and digital advertising.” This means Cobwebs is actively involved in the purchase of this data that is being harvested from us without our knowledge and typically without our understanding. Meaning, even if we do give an app consent to know our location, we assume this is for functionality and do not understand that they are then tracking and surveilling us.
The software used to capture this data is called “software development kits,” known as SDKs for short. These are programs / scripts that are embedded into the code of the application. So these aren’t something we can see unless we access the entire code for the application and then go through it, line by line, looking for an inserted SDK.
To recap, the MAID is the unique identifier assigned to our device. An SDK is embedded into the app to transmit data. It tells the data harvesting company what action we took and assigns that action to us via the MAID. Although the MAID is indeed a randomized set of numbers or letters, because businesses layer our MAID with other details, such as our name, address, or email address, it is no longer anonymous; therefore, these data harvesting entities know precisely who we are and what we are doing, which, despite their denial, is surveillance.
So what exactly is this scraped data being used for? An investigation by EFF uncovered that, amongst other things, it has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Would you like to know where specifically this data is coming from? Meaning, what specifically has a data harvesting SDK in it? The answer is ordinary consumer apps, such as games or weather apps. In fact, the advertising (data harvesting) company Huawei claimed its Petal Ads SDK software is embedded in more than 85,000 apps worldwide—and this is just one company. Another company that sold the US military data collected through its SDK embeds, was pulling data from 400 apps, including Muslim prayer and family safety apps.
WHAT WE ARE ACTUALLY CONSENTING TO
When you install an app, you will likely grant it permissions. We assume the purpose of these permissions is so that the app can function properly, but it is a double-edged sword. Let’s look at what different permissions allow for.
- The “Location” Permission — Location data isn’t limited to the application learning you are from Boise, Idaho, or that you live on First Street. Location permissions include the transmission of GPS coordinates, Wi-Fi networks, and even Bluetooth beacons. Now you’re thinking, “That doesn’t happen to me because I don’t ever grant these things permissions!” I hate to inform you, but an EFF investigation identified numerous advertising SDKs that collect and share users’ location by default. Further, they found that even if you declined to give the app permission to know your exact location, they bypassed location permission and tracked their precise locations through WiFi network data. Additionally, when Apple released its App Tracking Transparency initiative and Google made improvements in Android permissions, access to geolocation data was much more limited. To get around those restrictions, data harvesters created apps that require access to location data such as weather, navigation, fitness, and dating apps.
- “Access Contacts” — As you can assume, this means the application is able to access names, phone numbers, email addresses, and whatever else is stored in your phone as contacts. Even if you do not allow apps to access your contacts, everyone else in the world does on every app, so your family tree and little circle of life is known by thousands of assorted companies all over the world—companies which you never opted in to.
“Access Photos”—This may sound self-explanatory, but it is deeper than the advertiser just looking at all the pics you took of your cat. Should the purpose of the app secretly be data harvesting, they can also analyze metadata associated with those files and potentially obtain GPS/location information. Worse, they can copy or upload the actual image or video to a remote server if the SDK is programmed to do so, potentially perform facial recognition on your images, or even use them to build out a new biometrics program. Once you give them permission to access your gallery, they have free rein to use every last image to build user profiles or, who really knows what, because the SDK has no obligation to tell us how specifically it uses our images.
Now if you’re like me, you always photograph important documents because you know you will lose the paper within 48 hours. Should you grant an application permission to access photos and files, and should the purpose of the app be to scrape information, they will soon know that you just refinanced your home and you were invited to a wedding on January 8th. Equally, if the permission granted is for photos and files, the “and files” part is the kicker. This means every single file on your device, whether that be a document you downloaded from the IRS or a digital book you’ve been reading.
- “Access Microphone/Camera”—Arguably, the microphone / camera permission is more valuable than photos / files. Camera permission can allow for biometric scans, and I assume you already know what a microphone does.
- Read Device information — allows the SDK to obtain phone model, operating system, language, carrier, IP address, advertising ID and other technical identifiers. While this information may seem very insignificant, it can be used to build user profiles. As you can see, this is no longer a 32-digit randomized code assigned to a device because they now have your IP address and so much other info.
- Usage behavior (which may instead be called “Usage Data,” “Product Interaction” or something along the lines of “collect component usage statistics.”) This permission grants the app the ability to monitor what you click, search for, watch, and buy; how long you stay on a screen; and what features you use. Even if you don’t grant specific permission for the application to monitor your full device, just by installing the app, you are agreeing to have it monitor what you do within the app itself.
- Browsing/activity information—this permission allows everything you do online to be indexed. This is incredibly valuable data. Take a moment and view your browsing history by opening a web browser page and clicking the three dots menu icon in the upper right. Scroll down to “History” and start skimming. As you skim, know that companies, at this very moment, could have access to every single search you performed. As a researcher of the hidden hand, you would not believe how f*cked up my web history is. I cringe at the thought of it being associated with me as a person.
- Transaction information — Here, your purchases, subscriptions, and interactions with the app are recorded.
Even at this point in the story, there will be people who say, “I don’t give a hoot if some company knows I go to church on Sundays,” so let me explain what is going on in more detail:
According to the FTC, a company called X-Mode installed its SDK into over 300 apps to collect precise location data, which included latitude/longitude, timestamps, and a mobile advertising identifier. These apps included games, fitness trackers, and even religious apps. After harvesting the data, X-Mode sold it to third parties, including advertisers, analytics companies, consulting firms, research organizations, and private government contractors. Because the location pinpoints were tied to MAIDS, all anonymity was lost, and everyone who downloaded the apps could be identified by name or email addresses obtained from other sources. You see, that is what they are doing, my friends. They obtain data from one source that tells them the exact routes someone takes, such as:
Device #847293
- Monday: medical facility
- Tuesday: pharmacy
- Wednesday: home
- Thursday: specialty clinic
- Friday: pharmacy
- Sunday: Lutheran church
Device #769569
- Monday: office complex
- Tuesday: office complex
- Wednesday: office complex, elementary school
- Thursday: office complex
- Friday: office complex, elementary school
- Saturday: Home improvement store
- Sunday: Home improvement store
Then they combine the information with other datasets, and they learn who people are, what medical conditions they have, where they work, what faith they practice, if they have children, where those kids go to school, and who their relatives are, and so much more. Perhaps that is why it is called the “World Wide Web”—it is a web around the world; we are caught in it. It’s not “internet,” it’s “enter net”; enter the World Wide Web.
This information isn’t only sold to advertisers; it is also sold to government contractors, police, private detectives—anyone who wants to purchase it. This includes people engaged in black market activity like identity theft, mortgage theft, credit card fraud, and more. Even human traffickers could buy it. It’s mind-blowing.
THE DATA HARVESTING INDUSTRY
“Once I started asking what happens to the information collected by surveillance systems, I discovered something much larger: an entire industry exists to collect, aggregate, match, analyze and monetize information about individuals.”
InMobi and BidMachine are companies that provide advertising SDKs (software development kits) that developers can embed inside an app. Once embedded, these scripts will begin scraping data. So let’s say I make an app for Shadowbanned Library. I then secretly incorporate their SDK into it. I offer the app for download; you download it. You grant it location permission under the belief that this will allow the app to appear in your language, meaning if you are in America, it will be in English, whereas if you are in Germany, it will be in German, and so on. All along you are none the wiser that the SDK could be pulling your precise location and sending it off to be sold in an advertising system where it will be layered with so much other scraped data that your entire existence is for sale to anyone who wants to purchase it. (FYI: No, Shadowbanned Library does not have an app, and no, we would never embed this scraping bullshit or sell your data because the practice is disgusting.)
BUSTING APPS
I wanted to find out the names of apps that have been busted harvesting and selling data. Remember that this is no simple task because, in order to find out if an SDK is actively transmitting data, someone has to access all of the code and really examine what specifically it is doing, and there are not many researchers who have the know-how or desire. That said, I was able to track down several, and many of these might surprise you.
A 2026 investigation by the Electronic Frontier Foundation examined advertising SDKs embedded in Android apps and found two specific apps that were transmitting precise location coordinates to an advertising SDK. The first is QR Scanner, which advertises itself as a “fast and easy QR code scanner, QR code reader, or barcode scanner for Android.” This app has over 50 million downloads.
Who the hell would have ever thought a barcode scanning app is a data harvesting app?
The next is GPS Speedometer, which targets bikers, runners, boaters, and drivers. It has more than 10 million downloads.
Family GPS Locator & Tracker, which has over 50,000 downloads. We cannot prove this is transmitting harvested data, but it says right here that it is linked to both InMobi and BidMachine networks, so you be the judge.
Next is Document Scanner - OCR & Smart, which has over 100,000 downloads.
Water Eject - Audio Lab Expert, which claims to instantly remove water from your cell phone, has 50,000 downloads.
As ChatGPT pointed out to me, this app also requests CAMERA and RECORD_AUDIO, according to the permission listing for the current version.
Prank Sound, Voice & Fake Call has over 100,000 downloads, and it too features SDKs for InMobi and BidMachine, and, unlike the others, it is confirmed that this app is indeed sharing harvested data.
Metal Detector, Ruler, Decibel is a very popular app, with over one million downloads. I bet exactly zero of the people who have this on their phone know what it is being used for.
Live Wallpapers & Screensavers also has over one million downloads, but unlike the others, if you read the fine print, it admits what it is doing.
Those are just a few of an ocean of apps that are engaged in data scraping. A company called Verve says its HyBid SDK reaches more than 1.5 billion users across 10,000+ apps worldwide. Another company, Huawei Petal Ads, has its SDK installed in more than 85,000 apps. And don’t think that an app you are downloading has only InMobi or only BidMachine SDKs on it.
WalkEarn: Make Money advertises itself as a way to earn money while getting healthy by walking. In fact, my spouse downloaded it for a friendly competition at work, but my sweetheart wasn’t the only one. WalkEarn has over five million downloads.
Shockingly, an investigation performed by Exodus revealed that this application featured 28 trackers, including InMobi, BidMachine, AppsFlyer, AppLovin, Facebook Ads, and more. [You will need to translate the site to read the investigation].
Exodus also found that the app Text Free, which has a whopping 50 million downloads, was loaded with 30 trackers!
Want your socks blown off? Remember how we discussed Truecaller earlier? This caller ID app has over one billion downloads.
Exodus discovered it has 31 trackers in version 26.2.5, including:
- BidMachine
- InMobi
- Criteo
- AppLovin
- AppsFlyer
- Facebook Ads
- Google AdMob
- Firebase Analytics
- CleverTap
- Huawei Mobile Services
- And dozens more!
Do you remember how I said previously that Penlink-Cobweb’s Tangles program was pulling information from Telegram, Facebook, Truecaller, and more? I am willing to bet that this is because all of these programs, including Telegram, have SDKs, and Penlink-Cobwebs has access to all of them. For all we know, these companies (meaning the government contractors) are the ones making these free cell phone apps just for the purpose of surveilling us. This got me wondering about a bigger company like…
NEXT READ: FACEBOOK & OFFLINE DATA HARVESTING - WE ARE BEING TRACKED LIKE DEER
Thanks for reading this article! This is the last time I will bring this up, but tomorrow is the second class in my six-week-long class, The False Flag Masterclass. It is absolutely fantastic. I decided to give you a short preview below because I am confident that you will want to take it.
That was just a snippet of the introduction class. The full presentation is nearly an hour long. Tomorrow we will be getting into the CIA’s false flag manual and so much more. Because the replay is available, you have time to catch up on the first class and join me for the second, Thursday, October 1st, 2026, at 3pm PDT / 6pm EDT. Best of all, the entire class—all six weeks—is only $25. There is nothing else to buy, and no subscription is required. Click here to grab yourself a seat.
Aside from that, if you want to further support my work, buy me a coffee, make a Ko-Fi donation, or shop my eBooks and download and preserve true history.
Oh! One more thing, Truth Be Told: The Mega Event is now available on a thumb drive!
If you didn’t grab a ticket to the 7-hour-long livestream, you can pick up a thumb drive and see all five authors’ presentations. The event got outstanding reviews. Click here to order it on a thumb drive, and we will get it mailed out to you quick. International shipping is now stupid expensive, so if you are outside of the United States, you are unfortunately better off grabbing a ticket to watch the livestream replay. Click here to watch the livestream or click here to order it on a thumb drive.
If you want to make sure you are updated when new articles, eBooks, events, and podcasts are released, be sure to sign up for WhatsApp notifications:














