Your Car Is Spying on You How Auto Apps Share Data With Big Tech

TL;DR
- Northeastern University researchers found companion apps from major automakers routinely send driving, location, and personal data to Big Tech firms like Google, Apple, Meta, and Amazon, often without clear driver consent.
- The shared data goes far beyond diagnostics, including precise GPS history, VIN and device IDs, driving speed and braking patterns, and phone contacts that can be used for advertising and profiling.
- Drivers can limit exposure by tightening app permissions, disabling data-sharing settings, using in-car privacy modes, and pressuring automakers and regulators for opt-in consent.
The Passenger You Didn't Invite
Your car knows where you go to work, where your kids go to school, how fast you drive on the highway, and what music you play on the way there. According to new research from Northeastern University, it is not keeping those secrets.
A team studying connected vehicles and their companion mobile apps found that modern cars function less like transportation and more like smartphones on wheels, quietly transmitting detailed driving and personal data to major tech companies in the background. Even when the car is parked, the apps on your phone keep talking.
What The Researchers Actually Tested
The Northeastern team analyzed companion apps for top-selling vehicles in the U.S., including apps from Ford, Toyota, GM, Honda, Tesla, Hyundai, BMW, Stellantis, and others on both Android and iOS. Using network traffic interception and code analysis, they tracked where data goes when you start the car, lock the doors, plan a route, or simply have the app installed.
The results were stark. Nearly every app tested communicated with third-party domains owned by Big Tech, not just the automaker. Most transmissions happened automatically at app launch or vehicle startup, before users could meaningfully opt out.
What Information Is Being Shared
This is not just anonymous engine diagnostics. The researchers found the apps regularly collect and forward a rich mix of personal and behavioral data.
Precise location history was the most common, including real-time GPS, frequent destinations, and trip routes. Many apps also sent the Vehicle Identification Number, or VIN, tied to account name, email, phone number, and phone device identifiers.
Driving behavior was another major category, including speed, acceleration, hard braking, mileage, fuel or battery level, tire pressure, and door lock status. Some apps accessed far more phone data than needed, such as contacts, calendar entries, and infotainment voice queries.
When combined, that package can reveal your home address, workplace, religious services, medical visits, driving style, and daily routine.
Which Companies Receive It
The data does not stay with Ford, Toyota, or GM. The study found four dominant recipients.
Google was by far the most common, receiving data via Firebase Analytics, Crashlytics, Google Maps SDKs, and ad services embedded in almost all Android auto apps. Apple received device and usage telemetry from iOS versions, along with Siri and Maps interactions.
Meta received app events and advertising identifiers through the Facebook SDK, often used for measuring ad conversions. Amazon Web Services and Alexa Auto integrations received voice commands, location lookups, and smart-home linkages.
Additional trackers from data brokers, analytics firms like Mixpanel and Braze, and insurance-related telematics partners were also observed in network traffic.
Why Automakers Say They Do It
Automakers argue the collection powers features drivers want: remote start, stolen vehicle tracking, predictive maintenance, live traffic, crash response, and personalized infotainment. Third-party SDKs, they say, are needed for crash reporting, maps, and push notifications.
Privacy advocates counter that the same data pipeline doubles as a monetization pipeline. Driving scores can be sold to data brokers and insurers, location trails can fuel targeted ads, and persistent identifiers allow profiles to be stitched together across apps and websites.
Notably, the Northeastern researchers found privacy policies were vague, lumping safety, product improvement, marketing, and third-party sharing under broad language that gives drivers little real choice.
How This Affects Your Insurance And Ads
The stakes are not theoretical. In recent years, drivers have reported rising insurance premiums after their automakers shared hard-braking and speeding data with brokers like LexisNexis and Verisk. The new findings suggest companion apps make that sharing easier and more continuous.
Location and behavioral profiles can also feed ad targeting. Visit a dealership, fast-food chain, or medical clinic regularly, and that pattern, tied to an advertising ID, becomes valuable to marketers.
Security experts warn the aggregation itself is a risk. A database linking VIN, name, live location, and home address is a prime target for hackers, stalkers, and law enforcement overreach.
How Drivers Can Protect Their Privacy
You cannot make a connected car fully dumb again without losing key features, but you can sharply reduce what leaves the vehicle.
Start with your phone. On iOS and Android, deny the auto app access to precise location, contacts, microphone, and background tracking unless essential. Set location to While Using the App and turn off Precise Location. Disable ad personalization and reset your advertising ID.
Next, dig into the automaker's privacy portal. Most major brands now offer opt-outs for data sharing, marketing, and telematics under settings labeled Connected Services, Data & Privacy, or Consent Management. Opt out of data sharing for insurance and third-party marketing, and request deletion of historical data.
In the car itself, use Privacy Mode if available, avoid logging into Google or Alexa directly through infotainment when possible, and disconnect Bluetooth profiles you do not use. If you sold or returned a car, perform a factory reset of the infotainment system and remove the vehicle from your app account.
What Comes Next
The Northeastern researchers are calling for opt-in, not opt-out, consent for non-safety data collection, along with mandatory disclosure of every third-party recipient and data retention limits. They also recommend platform-level controls from Apple and Google to block unnecessary cross-app tracking by auto apps.
Regulators are paying attention. The Federal Trade Commission, Federal Communications Commission, and several state attorneys general are already probing connected-car data practices, while California's Delete Mechanism and similar state privacy laws could force automakers to offer one-click deletion.
Until then, assume your car is talking about you when you are not listening. The convenience of remote start and live maps comes with a backseat passenger: Big Tech, riding along for every mile.
Get All The Latest Updates Delivered Straight To Your Inbox For Free!