GHOSTPORT
← Back to Dev Log

A Single Clerk Signed Off On Tracking Every Nevadan's Phone

$12,000 a year. A federal grant paid for it. The governor never saw the contract.
May 16, 2026 • GhostPort Technologies

In January 2026, the Nevada Department of Public Safety signed a contract with a Virginia company called Fog Data Science. The contract bought near-real-time access to the location histories of cellphones across the state — without warrants, without judicial oversight, and without the approval process that's supposed to apply to major surveillance purchases.

The reason it slipped past the governor, the attorney general, and the secretary of state is almost insulting in its simplicity. The contract was small enough — about $12,000 a year, paid for with a federal grant — that under Nevada procurement rules it only needed sign-off from a single state clerk. The Nevada Independent and the Associated Press both confirmed the mechanics in April. No legislator was told. No public comment was taken. No court order was obtained.

For the price of a used Honda Civic, Nevada bought the ability to draw a box on a map and pull back every smartphone that pinged inside it.

What Fog Reveal actually does

Fog Data Science sells a product called Fog Reveal. The interface is a web portal. An investigator draws a geofence on a map, picks a date range, and the system returns a list of mobile advertising IDs — the unique identifiers your phone broadcasts to apps. Click any of those IDs and you get that device's full pattern of life: every other place it pinged, going back as much as two to three years.

That's not a phrase we made up. "Pattern of life" is the language Fog uses in its own marketing materials, recovered by the Electronic Frontier Foundation through public-records requests in 2022. The EFF documents include training slides explicitly instructing officers that no warrant or court order is required to run searches.

"You can cover a lot of ground with 250 queries." — Beryl Lipton, Electronic Frontier Foundation, to The Nevada Independent, April 2026

Nevada's contract allows more than 250 queries a month. Each query can return thousands of devices. The math gets ugly fast.

The deal, by the numbers

$12,000/yr
Contract value
250+
Queries per month allowed
1
State clerk who signed off
0
Warrants required by contract

Access is limited on paper to the Nevada Threat Analysis Center and the Investigation Division. DPS has said publicly that the tool will not be used for traffic stops or "broad or indiscriminate monitoring." Those are agency policy commitments, not legal restrictions. Nothing in the contract prevents the policy from shifting next year, or the year after.

Where the data comes from

Fog doesn't collect the data itself. It buys it from data brokers who buy it from app developers who embed third-party tracking SDKs in their apps. The full chain looks like this:

  1. You install an app. Buried in its dependencies is a tracking SDK from a company you've never heard of.
  2. The app asks for location permission. Maybe you grant "while using." Maybe you grant "always." Either way, when the app is active, the SDK reads your GPS coordinates.
  3. The SDK sends your location, your advertising ID, and a timestamp back to its vendor — not to the app developer.
  4. The SDK vendor sells the data to an aggregator like Venntel (a subsidiary of Gravy Analytics).
  5. Fog Data Science licenses the aggregated feed and wraps it in a search interface for law enforcement.
  6. Police draw a geofence. You appear on the map. No one ever told you any of this would happen.

If this sounds speculative, it isn't. In January 2025, hackers breached Gravy Analytics and dumped the underlying dataset. 404 Media confirmed that location pings tied to Tinder, Grindr, Candy Crush, and other major apps appeared in the broker's database — often routed through third-party SDKs the apps themselves had never publicly disclosed. The pipeline isn't theoretical. It's been documented in court filings, FTC orders, and now a real-world data breach.

The Federal Trade Commission has spent the last three years pulling threads in this ecosystem. X-Mode / Outlogic was banned from selling sensitive location data in January 2024. InMarket Media was sanctioned the same month. Kochava was sued in 2022. And in December 2024, the FTC went directly after Gravy Analytics and Venntel — the upstream supplier feeding Fog's product — with a proposed order banning the sale of sensitive location data altogether.

The "guardrails" problem

When pressed on the deal, Nevada DPS pointed to its internal policies: only trained investigators, only specific investigations, only "limited, controlled circumstances." The ACLU of Nevada's Jacob Valentine called the contract "alarming" and said it represented "more and more attempts to track where we are at all times and circumvent the warrant process." A Clark County public defender, John Piro, called it flatly "unconstitutional."

The problem with policy-based guardrails is that they're not law. They're not subject to judicial review. They have no enforcement mechanism beyond the agency policing itself. There's no public audit, no transparency requirement, no statutory penalty for misuse. If an analyst runs a query outside the stated scope — on a protest, on a political rival, on an ex-spouse — the only check is internal.

⚠ WHAT THE CONTRACT DOESN'T REQUIRE

No warrant. Per Fog's own training materials, agencies are told warrants are not required.

No judicial review. No judge sees the query. No probable cause is established.

No notification. If your device appears in a query result, you are not told. Ever.

No audit trail accessible to the public. You cannot request the list of queries that included your device.

The legal posture (and why it's shaky)

Fog's legal theory rests on what's called the third-party doctrine: the idea that data you've voluntarily shared with a third party (in this case, an app) is no longer protected by the Fourth Amendment. The 2018 Supreme Court case Carpenter v. United States rejected this theory for historical cell-site location data held by phone carriers, ruling that police generally need a warrant to access it.

The unresolved question is whether Carpenter extends to data that police buy on the commercial market rather than compel from a carrier. Vendors like Fog argue it doesn't, because the user "consented" by accepting an app's privacy policy. Civil liberties groups argue that buying around a warrant requirement is exactly the constitutional violation Carpenter meant to prevent.

Senator Ron Wyden has been pushing the Fourth Amendment Is Not For Sale Act for several years — legislation that would explicitly require warrants for government purchases of location data. It passed the House in April 2024 and has been stuck in the Senate since. Until it passes or a court rules definitively, agencies like Nevada DPS can keep operating in the gap.

The opt-out reality

Fog Data Science maintains an opt-out page at fogdatascience.com/opt-out. To opt out, you submit your mobile advertising ID. Their privacy policy promises processing within ten business days. There is no confirmation, no proof of deletion, and no audit trail.

Read carefully and the opt-out's limits become obvious:

If you live in California: use DROP

California residents have a real tool. The Delete Request and Opt-out Platform (consumer.drop.privacy.ca.gov), authorized by the California Delete Act and operated by the California Privacy Protection Agency, lets you submit one deletion request that hits over 500 registered data brokers. Starting August 2026, those brokers have 90 days to comply — and then every 45 days, the system re-runs your deletion against any new data they've collected. It's the most powerful single privacy tool currently available in the United States. If you're a California resident, use it.

If you live in Nevada (or anywhere else)

You're stuck with the per-broker grind. File Fog's opt-out. Then file Venntel's. Then Gravy's. Then Acxiom's, LexisNexis's, Epsilon's. Use Privacy Rights Clearinghouse's data-broker list as a starting point. Services like DeleteMe, Optery, and Kanary automate parts of this for a subscription fee. None of it is a one-and-done.

What actually reduces your exposure

This is the part we want you to take seriously. Privacy work is layered. No single step solves the problem — but several steps stacked together meaningfully shrink your footprint.

Reset or delete your advertising ID first

On Android 12 and newer: Settings → Privacy → Ads → Delete advertising ID. This zeros out the identifier entirely; apps requesting it get a string of zeros. On iOS: Settings → Privacy & Security → Tracking and toggle "Allow Apps to Request to Track" off across the board. Do this before filing opt-outs, otherwise you're opting out an ID that's about to be retired anyway.

Lock down location permissions on every app

Open your phone's settings, go to permissions, find location, and walk through the list. Anything that doesn't have a clear reason to know where you are — set it to Never. Weather, news, prayer apps, social, games: almost none of them need background location, and most don't need precise location even in the foreground. Use the "Approximate" setting wherever your phone offers it.

Block ad/tracking SDKs at the network level

DNS-level blocking on your home network — via Pi-hole, NextDNS, AdGuard Home, or a privacy-focused router — stops a large fraction of tracking SDKs from phoning home while your devices are on Wi-Fi. It doesn't follow your phone when you leave, but it cuts daily exposure significantly.

Consider what apps you actually need

The Gravy breach made one thing clear: even apps that publicly deny selling data can show up in broker databases, because a third-party SDK they bundled was the actual source. The most reliable defense is fewer apps. Audit your phone. Delete what you don't use. Prefer mobile web over native apps where you can.

What does NOT counter this kind of tracking

A VPN alone does not stop Fog. Fog reads GPS coordinates from your phone's sensors via SDKs embedded in apps. Those coordinates leave your device through the same encrypted VPN tunnel as any other traffic. A VPN hides your IP address from servers. It does not stop your phone from telling apps where you are.

Browser private/incognito mode is irrelevant. The pipeline runs through native apps, not browsers.

Deleting apps without resetting your ad ID isn't enough. The ID persists. Old pings tied to it remain joined to your new behavior.

Trusting privacy policies isn't a defense. The Gravy breach proved that apps which deny selling data still feed brokers, because the SDKs they bundle do the selling on their behalf.

Sign the petition

Nevada bought warrantless surveillance for the price of a small used car, and the only signature on the paperwork was a state clerk's. That's not a procedural quirk — it's a structural failure. Surveillance contracts at any dollar amount should require warrants and judicial oversight.

If you're a Nevada resident, your name carries more weight here. If you're not, sign anyway — the same procurement gap exists in dozens of states, and what gets normalized in Nevada won't stay in Nevada.

Require a warrant for location surveillance

We are calling on Nevada's elected officials and federal representatives to require warrants for government use of commercially purchased location data, and to close the procurement loophole that let this contract bypass executive review.

signatures so far
Signatures will be delivered to:
  • → Office of the Governor of Nevada
  • → Nevada Attorney General
  • → Nevada Secretary of State
  • → Nevada State Legislature (Senate Judiciary & Assembly Judiciary committees)
  • → United States Senators from Nevada
  • → Sen. Ron Wyden's office (Fourth Amendment Is Not For Sale Act sponsor)

GhostPort builds privacy-first network hardware. We make a router. The router can't fix every problem on this page — specifically, it can't stop an app on your phone from reading the GPS sensor and selling the result. What it does, automatically, for every device on your network: encrypt your DNS, block known tracking domains, and prevent your ISP from logging and selling your browsing history. That's the network-layer piece of the puzzle. The app-layer piece is up to you: reset your ad ID, audit your permissions, and consider whether you really need every app you have. Layered defense is the only kind that works.

Cut the network-layer pipeline at the source.

ghostporttechnologies.com
Encrypted DNS. Tracker blocking. Every device. Automatic.

Sources

  1. Aldrete, Isabella. "Nevada police may be tracking your phone's location without a warrant. Here's how." The Nevada Independent, updated April 10, 2026. thenevadaindependent.com
  2. Associated Press syndication, "Nevada police may be tracking your phone's location without a warrant," April 2026, carried by Washington Post, KTVB, Madison Courier, and others.
  3. Cyphers, Bennett. "Inside Fog Data Science, the Secretive Company Selling Mass Surveillance to Local Police." Electronic Frontier Foundation, August 31, 2022. eff.org
  4. EFF Fog Data Science FOIA document collection. eff.org/cases/fog-data-science-foia
  5. Burke, Garance and Dearen, Jason. "Tech tool offers police 'mass surveillance on a budget.'" Associated Press, September 2, 2022. apnews.com
  6. Cox, Joseph. "Hackers Claim Massive Breach of Location Data Giant Gravy Analytics, Threaten to Leak Data." 404 Media, January 7, 2025. 404media.co
  7. Federal Trade Commission. "FTC Takes Action Against Gravy Analytics, Venntel for Unlawfully Selling Location Data." December 3, 2024. ftc.gov
  8. Federal Trade Commission. "FTC Order Will Ban X-Mode and Outlogic from Selling Sensitive Location Data." January 9, 2024. ftc.gov
  9. Carpenter v. United States, 585 U.S. 296 (2018). supremecourt.gov
  10. Fog Data Science opt-out page. fogdatascience.com/opt-out
  11. California Privacy Protection Agency, Delete Request and Opt-out Platform (DROP). privacy.ca.gov/drop
🎨
ACCENT COLOR
A+
TEXT SIZE