For many apps, granting permission to access your device’s precise location makes sense. Your favorite weather app needs to know where you are to get the day’s forecast, or your go-to fitness app for tracking your running route.

But some apps are also inadvertently sharing their users’ location data with third parties, including advertisers and data brokers, because the app developer may not know that this data-sharing setting is enabled by default.

New findings by the Electronic Frontier Foundation aim to warn app developers that some of the third-party code they place in their apps may also collect their users’ location data when they grant permission to the app.

Unless the developer actively switches off the collection, the code snippet (known as software development kits, or SDKs) will inherit the app’s permissions and collect the user’s precise location data.

The EFF says many developers might not realize that they are sharing their users’ location data with third-parties by default, and urged app makers to disable unnecessary data collection whenever possible.