Case study · 2020 to 2025 · filed 30 September 2026

A prayer app sent users' locations to a broker that sold to military contractors

Muslim Pro uses your location to set prayer times and the direction of Mecca. In 2020 it was also sending that location to a data broker whose customers included US defence contractors.

Muslim Pro is a prayer and Quran app, and it uses your location to work out prayer times and which way Mecca is. In November 2020 Motherboard tested it and found it was also sending precise coordinates, the name of the wifi network, a timestamp and the phone model to X-Mode, a data broker. The privacy policy did not name X-Mode, and no screen told users. Senator Ron Wyden said X-Mode's lawyers had confirmed that it sold location data from US phones to military customers through defence contractors.

A day later Muslim Pro ended all its data partnerships. It said the X-Mode deal was four weeks old and called reports that it sold data to the US military "incorrect and untrue". Singapore's data regulator opened an investigation, and a group of French users filed a criminal complaint.

A leaked sample later showed four more prayer apps selling location to X-Mode in 2019. In January 2024 the FTC banned X-Mode from selling data that could track visits to places of worship, clinics and shelters. A year later Muslim Pro's name appeared in files hacked from another broker, Gravy Analytics. The app said it did not authorise its ad networks to collect location.

What it shows

An app that needs your location for one job can pass it on for another. Here it went out through advertising code to a broker, and from the broker to buyers the app never named. After the app ended its own deals, its name turned up in another broker's files through the ad networks.

For your own record

Check which apps have your location and set it by hand where the app allows it. Ask the app who it has shared your location with, ad networks included, and ask it to delete what it holds.

More case studies

Grindr A Catholic group bought app data to find priests who used Grindr Phone data with no names on it, showing which devices used Grindr and where they went, was on sale through brokers. A Catholic group in Denver bought it, matched phones to parishes and seminaries, and passed what it found to bishops.
CatholicVote Phones seen inside Catholic churches were used to find voters A political group bought location data that came from ordinary phone apps, drew a line around Catholic churches, and sent ads to the people whose phones had been inside. The churches did not know.
Gloo A church marketing firm predicted who might be depressed, divorcing or addicted Gloo told churches it could predict who might have a marriage in trouble, depression or a drug addiction, from data it bought about Americans. After The Wall Street Journal asked, it stopped using mental health data and its main data supplier left.