Pairing the myCadillac app with a 2024 Cadillac Lyriq added 26 advertising and tracking companies to the list of outside firms receiving data from the car and its owner, according to a peer-reviewed study by Northeastern University researchers who ran their tests at Consumer Reports’ Connecticut track. The Nissan Ariya and Toyota Corolla Cross each picked up 25 more when their apps were paired. The Chevrolet Blazer and Buick Envista picked up 23 apiece.
An owner can’t do much about what the car’s own modem sends. The app runs on a phone the owner controls, so it is the one piece of the connected-car setup where a driver has some leverage. That leverage is real but partial, and the way the researchers ran their tests shows where it runs out.
What the Northeastern team measured
The paper, “Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem,” will be presented at the ACM Internet Measurement Conference in Karlsruhe, Germany, which runs October 12 to 16. Its nine authors tested 21 vehicles from 19 brands and 30 companion apps between October 2024 and August 2025. Consumer Reports supplied the fleet, which the team estimates would have cost more than $1.2 million to assemble on its own.
For the cars, the researchers set up a custom Wi-Fi access point on a Raspberry Pi and logged every packet with tcpdump. That traffic was encrypted, so they could see where it went but not what it carried. They also drove 11 of the EVs into a car-sized Faraday tent that cut cellular signals by about 93 decibels, to see whether traffic that normally rides the cellular link would shift to Wi-Fi. For the apps, they used iPhones with custom root certificates routed through mitmproxy, which let them decrypt and read what each app sent.
Nineteen of the 21 vehicles contacted at least one third party over Wi-Fi. Seven of the 30 apps sent sensitive identifiers, including VINs, email addresses, phone numbers, and precise location, to third parties associated with advertising and tracking. Five sent a VIN along with another piece of personal information. On average, the researchers found, pairing an app roughly doubled a vehicle’s exposure to advertising and tracking companies. The Auto Wire covered the overall findings when the study surfaced and the VIN problem in particular; this piece is about what an owner can do with them.
The pattern varies by brand. Consumer Reports’ chart of the researchers’ Wi-Fi logs shows the Tesla Model 3 itself reaching 34 advertising, tracking, and analytics domains, the most of any car tested, while the Tesla app added just two companies. The GM apps went the other way: the Lyriq, Blazer, and Envista apps each added more than 20 companies, on top of cars that contacted relatively few such firms on their own. For the Teslas, most of the measured exposure came from the car. For the three GM vehicles, most of it came from the phone.

The researchers said yes to every prompt
During installation and login, the team accepted every permission request the apps made, including tracking, location, calendar access, Bluetooth, and notifications. A Consumer Reports employee then signed in with the account tied to a car on the lot, and the testers used every feature: finding nearby chargers, locating the car, reading service history, and, where the app allowed it, opening the trunk.
That was the right way to find the upper limit. It also means the study describes a phone set up the way many phones end up after a hurried first launch. The researchers’ public materials don’t report how much of that traffic a “no” would have stopped, so how many of the Lyriq’s 26 would disappear with a denied prompt is unconfirmed. What owners can do is make sure their phones aren’t configured like the test phones.
What Apple’s tracking switch blocks, and what it leaves to the honor system
Since iOS 14.5, apps have had to ask before tracking. Apple’s support page says that when you choose Ask App Not to Track, the developer “can’t access the system advertising identifier (IDFA), which is often used to track.” Turning off Allow Apps to Request to Track under Settings, Privacy & Security, Tracking applies that answer to every app automatically.
The same page says the app is also not permitted to track you with other identifying information, such as your email address. Those two protections work differently. The phone enforces the first one by withholding the identifier. The second is an App Store rule the developer is expected to follow, and the phone has no way to inspect what an app puts inside an encrypted request. Apple’s definition of tracking is also narrow: linking your data with other companies’ data for targeted ads or ad measurement, or handing it to data brokers. An automaker that sends a VIN to an analytics vendor under a service contract will argue that isn’t tracking. According to the researchers, all 14 manufacturers that responded to their disclosure said the data flows matched contracts that limit how vendors may use personal information. The researchers called those contracts and policies often overly broad.
Federal rules at 49 CFR 565.13 require a 17-character VIN, bar any two vehicles built within a 60-year window starting with the 1980 model year from sharing one, and require it to be readable through the glass from outside the car near the left windshield pillar. An email address can be changed. A VIN stays with the car for its whole life and through every owner, and anyone walking past in a parking lot can read it. When an app sends a VIN and an email to the same company, that company can tie a specific car to a specific person, and no phone setting reaches back to undo that.
Your phone’s location and your car’s location are separate signals
On an iPhone, Settings, Privacy & Security, Location Services lists each app’s access. Apple’s guide says turning Precise Location off shares only your approximate location.
That setting covers the phone’s position. When the app shows where your car is parked, the position comes from the car, through the automaker’s servers, and the phone’s location switch has no say over it. The HondaLink case shows the difference. The researchers found the app sending VINs and location data to Amplitude, an analytics company. After they shared the findings, Honda told Amplitude to delete the data and updated the app to stop sending geolocation, according to Northeastern. Honda spokesperson Andrew Quillin told Northeastern the data was “never available for independent use or sale.” The fix came from Honda’s app code and its vendor, not from any switch available to owners.
Privacy requests reach data that phone settings can’t
The paper’s central complaint is that privacy policies say data may go to third parties without naming them. Some owners can get the names. Oregon’s Department of Justice says the state’s consumer privacy law lets residents get a list of the specific entities that received their data, and that all auto manufacturers must comply regardless of the law’s size thresholds.
GM’s U.S. Consumer Privacy Statement, last updated June 17, 2026, offers every covered consumer the right to access, correct, and delete their personal information. Depending on the state, it also offers opt-outs from targeted advertising and sale, plus a list of the third parties receiving that information. Requests go through the online form or 1-866-MYPRIVACY; GM says it does not accept them by email. The Federal Trade Commission’s final order of January 14, 2026, requires GM to create a way for all U.S. consumers to request a copy of their data and its deletion. It also requires consent before collecting or sharing connected-vehicle data and bars GM for five years from sharing certain consumer data with consumer reporting agencies.
Regulators have also gone after the friction in these processes. In March 2025, California’s privacy agency fined Honda $632,500, saying it required Californians to provide excessive personal information to exercise their privacy rights, offered privacy choices through a tool that didn’t present them evenly, and shared personal information with ad tech companies without contracts containing the required protections. The data itself is cheap. A 2024 investigation by Sen. Ron Wyden found Honda had shared data from 97,000 cars with the broker Verisk, which paid $25,920, or 26 cents per car.
Opting out of the car costs features
Seven manufacturers told the researchers that reading and accepting the terms of every third-party app or service in the vehicle, even preinstalled software, is the owner’s job. Per those companies’ own policies, declining can disable navigation, driver-assistance features, or over-the-air updates. Tesla goes further. Owners who decline its data-sharing agreement are warned, Consumer Reports found, that it “may result in your vehicle suffering from reduced functionality, serious damage, or inoperability.”
Even a full disconnect has exceptions written into it. GM’s privacy statement says owners can unenroll from OnStar by calling 1-888-4ONSTAR or pressing the blue button, but GM may still collect location and vehicle information when the blue button is pressed. On battery-electric models, an overheating high-voltage battery may also trigger collection after unenrollment. That is a safety function most owners would want, and it is one more case where an unenrolled car still reports to GM.
Five manufacturers blamed embedded web browsers inside their apps for the third-party traffic. Three of them said those pages ask users to accept or reject cookies, but the researchers’ screen recordings didn’t always show the prompt appearing. Three of the 17 manufacturers contacted never responded.
Four settings and requests worth making now
- On iPhone, go to Settings, Privacy & Security, Tracking, and turn off Allow Apps to Request to Track. It costs nothing, and Apple says the app keeps its full capabilities either way.
- Set the car app’s location access to While Using and turn off Precise Location unless a feature you rely on stops working.
- File a privacy request with your automaker. Ask for a copy of your data, and if your state allows it, the list of specific third parties that received it. Oregon residents have that right by law.
- Before selling or trading in the car, remove it from your app account and request deletion, since the VIN that identified you will keep identifying the car for the next owner.
The study gets its formal presentation the week of October 12. Honda changed its app after seeing the researchers\’ data. The other six automakers whose apps sent identifiers have now seen the same kind of evidence. Whether their next app updates stop sending VINs and emails to analytics vendors can be retested with the same method the Northeastern team published.
Would you give up remote start, the app, and over-the-air updates to keep your car’s data off ad-tech servers, or is that a trade you’d rather not make?
