Mobile Games Exposed Broad User Tracking in May 2026

Research revealed that top free Android games routinely transmit granular personal data to international advertising firms.

Updated on Sept. 29, 2026 in Cybersecurity

Bold flat-color editorial illustration showing a stylized server tower and a geometric data cluster, symbolizing digital user data harvesting.
A Proton investigation found that 100 top free Android games frequently transmit device, payment, and location metadata to international third-party ad-tech firms. AI Illustration. Upload story photo >

Live Poll

Do you trust the free mobile games you download to keep your personal data secure?

An analysis of the top 100 free Android games, which have reached 20 billion cumulative global downloads, found that these applications frequently funnel user-identifiable information to third-party ad-tech firms. Proton conducted this investigation into data harvesting practices during May 2026.

Why it matters

Data collection from free-to-play titles serves as a foundational pillar of the global ad-tech ecosystem, enabling companies to aggregate device, payment, and location metadata. This widespread practice highlights the privacy risks inherent in mobile software that relies on external tracking to monetize its user base.

Researchers identified up to 36 distinct trackers within a single application. In May 2026 alone, mobile games in the US shared data with Chinese-linked entities across 15.8 million downloads, while Russian-linked entities received data from 13.7 million downloads.

The players

Proton

A provider of encrypted communication and privacy-focused digital tools that frequently publishes research on data security.

Google Play Store

The primary digital distribution platform for Android applications where the analyzed games are hosted.

Mixpanel

An analytics software company that suffered a significant user-identifiable metadata breach.

The details

Mobile games utilize embedded trackers—small code snippets integrated into the app—to transmit user information to external ad-tech companies. This process can be mitigated by VPNs (virtual private networks) that feature built-in filtering mechanisms, which operate by intercepting and blocking DNS (domain name system) requests to known tracker addresses before the telemetry data leaves the physical device. The information harvested often includes device type, usage habits, payment credentials, age, gender, and precise physical location.

Timeline

  1. November 2025: A data breach at Mixpanel exposed user-identifiable metadata.

  2. May 2026: Proton conducted its analysis of mobile game download and tracking data.

The Tech Race

This research follows a pattern established by the November 2025 Mixpanel data breach regarding the exposure of user-identifiable metadata. The findings highlight how embedded analytics infrastructures continue to funnel sensitive information to third parties despite increasing public scrutiny.

Users can restrict outbound tracking by utilizing VPNs that provide DNS-level filtering to block requests to known ad-tech domains. These tools act as a barrier to prevent personal data from leaving the device while playing free-to-play mobile games.

The takeaway

The ubiquity of trackers in free mobile games suggests that users should assume their location and usage metadata are being continuously exported. Readers should monitor future industry reports on privacy-preserving ad-tech standards as a gauge for whether mobile developers begin to prioritize data minimization.

Further reading

For more on the current state of digital privacy and security, visit Cybersecurity.

Source note: This article includes information reported by TechRadar.

Live Poll

Do you trust the free mobile games you download to keep your personal data secure?

Mobile Games Exposed Broad User Tracking in May 2026 | Highwise Tech