$25K and One Word Bought Your Clinic Visits
The FTC spent four years suing to stop it. Whoever already bought the feed keeps it.
Introduction
Twenty-five thousand dollars and a free AWS account got you in. One word in the justification field, the word "business," was enough to clear review, and Kochava approved some buyers in 24 hours. What that subscription bought was a feed of 94 billion location pings a month, accurate enough to drop a specific phone inside an abortion clinic, a domestic violence shelter, a mosque, or an addiction recovery center, then trace it back to the house it slept in. If your phone was one of the 125 million Kochava logged every month, you were in the feed. The FTC sued to stop this in August 2022 and finally won on June 26, 2026. Nothing in that order deletes a record that already changed hands.
What $25,000 Put on the Table
Kochava is a Sandpoint, Idaho company most people have never heard of, which is roughly the point. It sits in the plumbing of the app economy as a mobile measurement partner, the kind of firm that tells an advertiser which ad made you install a game. The location business ran on the side. The FTC's 2022 complaint quoted Kochava's own sales pitch: "raw latitude/longitude data" at "volumes around 94 billion+ geo transactions per month, 125 million monthly active users, and 35 million daily active users." When Kochava tried to get the case thrown out, the judge refused, pointing to the allegation that those coordinates could place a person "within less than 10 meters" and had been doing it "for at least the past year."
The free sample is the part that stuck with me. To pitch the paid feed, Kochava handed prospective buyers one rolling week of data for nothing, over 327 million rows covering 61.8 million unique devices, no contract required. The FTC took that sample, picked one device, and traced it from a women's reproductive health clinic to a single-family home, where the same phone turned up at least three evenings that week. It pulled that off with no subpoenas and no outside databases, just the feed doing what it was sold to do.
The paid gate was barely higher. The complaint describes a $25,000 listing on Amazon's AWS Marketplace where a buyer could sign up with an ordinary personal email, describe the intended use as "business," and get approved "in as little as 24 hours." Amazon pulled the listing around June 2022, a couple of months before the lawsuit landed. You don't approve a buyer in 24 hours if you're actually vetting them. Moving access quickly was the whole business.
You Installed a Weather App, Not Kochava
Almost nobody in that feed agreed to be there, at least not knowingly. Kochava didn't collect the location data itself; it collected through other people's apps. Its software development kit was embedded in at least 10,000 apps globally, by the FTC's count, dropped in by developers who wanted free attribution measurement. In exchange, per Kochava's own terms, the developer granted the company a "perpetual, irrevocable, worldwide, transferable, unrestricted license" to the data the app collected. You downloaded a weather app, a game, a fitness tracker, a flashlight. A license you never read handed your movements to a data broker you'd never heard of, with no expiration date.
Here's the part the settlement doesn't touch. App developers don't integrate Kochava for fun. They do it because the platforms they advertise on push them toward certified measurement partners. Meta, Google Ads, TikTok, and Snapchat all certify Kochava as a measurement partner, and in December 2025 Kochava announced its own program naming those same companies as certified partners. The certification system is what put the SDK into thousands of apps at scale. The platforms got their attribution numbers, Kochava got the residual location data, and the order entered last week says nothing about any of it. It binds Kochava and its subsidiary, not the apps still running the SDK or the certification machinery that made it normal.
The Buyers Nobody Has to Name
The complaint never names a buyer, and that silence is doing real work. What the record gives us instead is categories: advertisers, insurance companies, political campaigns. One audience segment Kochava packaged was labeled "Likely Republican Voter," built from people who turned up at "Republican focused political events and events and venues affiliated with conservative topics," according to Commissioner Melissa Holyoak's statement quoting the second amended complaint. That same complaint describes a single customer that contracted for a "minimum of 150 million" U.S. consumers every month, asking for every data point Kochava had.
What a buyer can do with a feed like this isn't a thought experiment. In Wisconsin, an anti-abortion group called the Veritas Society bought location data from a different broker, Near Intelligence, and used it to push ads to people who had visited Planned Parenthood. One ad read, "Took the first pill at the clinic? It may not be too late to save your pregnancy." It was served 14.3 million times. Senator Ron Wyden laid out that campaign in a 2022 letter to the FTC, after the Wall Street Journal first reported it. Kochava didn't run it, and Near Intelligence isn't Kochava. But Kochava sold the same kind of feed into the same market, and targeting like that is exactly the harm the FTC spent four years arguing this data makes possible.
Who Benefits
Start with the obvious one. Kochava ran the data marketplace as a second revenue stream next to its measurement business, charging $25,000 subscriptions and, by the amended complaint's account, tens of thousands of dollars a month from its bigger customers. It's a private company, so there's no public total, but the 2022 complaint makes the model plain: collect through other people's apps at almost no cost, then resell at subscription margins.
The harder beneficiary to see is the company's reputation. Kochava's public line was that it sourced "100% of the geo data" in its marketplace from brokers who "represent that the data comes from consenting consumers." When the FTC sued, CEO Charles Manning told the trade press the agency was trying to make an example of his company and had refused to define what "sensitive location data" even meant. He had also publicly knocked competitors for non-anonymized location tracking while running this operation himself. The one-word approvals and the free clinic-to-home sample are hard to square with the consent story. Saying the right thing about privacy while selling the feed is its own kind of cover, and it held for four years.
Then there's Collective Data Solutions. In the middle of the litigation, Kochava moved its data broker business into CDS, a wholly-owned subsidiary that the FTC says took over the operation. The agency had to amend its complaint a second time, in July 2024, just to name the new entity, and it argued the two ran as a "common enterprise," the same business under a cleaner name. A fresh corporate shell is a useful thing to own when the old one is being sued.
The buyers benefit most quietly of all. They got precise behavioral targeting without paying to collect anything, and because the order names and binds only Kochava and CDS, the data they already purchased sits in their systems with no obligation attached. An insurer modeling risk off addiction-clinic visits, or a campaign profiling voters by where they worship: whoever bought in keeps what they bought.
Four Years, One Subsidiary, and a Two-Year Window
The case took nearly four years, and the delay wasn't only Kochava stalling. The FTC filed in August 2022 on a 4-1 vote. In May 2023, Judge B. Lynn Winmill threw the complaint out, finding the agency had alleged mostly theoretical harm rather than a real likelihood of injury. The FTC refiled with specifics, survived the next motion to dismiss in February 2024, then spent another year adding CDS after the business moved. The defendants signed the deal in March 2026, and the court entered it on June 26.
Read the stipulated order and the ban is genuinely broad. Going forward, Kochava and CDS can't sell, license, or share sensitive location data unless the consumer gave affirmative express consent for a service they actually asked for. Sensitive locations cover five categories: medical facilities, places of worship, schools and childcare for minors, shelters for homeless people and domestic violence survivors, and military or federal law enforcement sites. Within 90 days, the defendants have to deidentify the historical location data they still hold.
The catch is in Provision XII. That deletion duty falls on Kochava and CDS, for the data they hold. For the data already sold, the order only requires them to notify customers who received it within the two years before entry, telling those buyers to deidentify it. No provision forces a buyer to delete anything. And the two-year clock means everything sold before roughly June 2024 sits outside even the notification step. That covers 2022 and 2023, the operation's peak, right after the FTC sued and before it slid into CDS.
There's also no fine, and that's not the FTC going soft. After the Supreme Court's 2021 ruling in AMG Capital v. FTC, the agency can't get monetary relief through the unfairness authority it used here. The order runs 10 years, where comparable Biden-era settlements ran 20, and its sensitive-location definition is narrower than those earlier orders, dropping categories like LGBTQ+-serving venues and union halls.
Kochava was the first broker to refuse the FTC's settlement and litigate, which forced the agency to prove its Section 5 theory in court for the first time. It largely lost that fight in the end, and the case law the litigation produced is part of why X-Mode, InMarket, Gravy Analytics, and Mobilewalla all settled faster. Kochava's resistance helped build the legal road the FTC now drives on. It also bought four more years of selling, and ran out the clock on the window that would have reached the data.
The Bottom Line
The ban is real. The next person who wants to buy a map of where you sleep, pray, vote, and get treated can't get it from Kochava the way the last one did. But the order is built to stop the next sale, not recover the last one. The records from 2022 and 2023 are still sitting in the systems of buyers the FTC never named and never sanctioned, and under the order the only path runs through Kochava and CDS directly: Provision VII, the right to ask them to disclose who received your data, and Provision IX, the right to ask them to delete what they still hold. Neither provision reaches any buyer. The burden is entirely yours, one request at a time, directed at the seller — not at whoever is holding the data now.
So the question the order leaves open is the one it was never built to answer: what does a company that legally bought a record of your private movements owe you now that the selling has stopped? Under current federal law, the answer is nothing.