Popular travel app used by 23M lets anyone spy on users, including soldiers
The company was warned about its privacy issues last year.

Polarsteps can be used to spy on users. By Cybernews / Shuttestock / VanderWolf Images.
- Follow the Money found Polarsteps data could expose photos, videos, locations, and home addresses.
- Researchers said they could access 230 million media files and 1 billion location points from nearly 2 million trips.
- The report says some private trips and fully private accounts still revealed sensitive travel and account details.
- Polarsteps denies a breach but says it added stricter access controls and stronger protections for secret links.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
If you’re a Polarsteps user who loves to share your travels on the app, be aware that anyone could find out what you were up to this past summer. The app exposed enough data to track users – sometimes to within a meter, an investigation has found.
According to Follow the Money, Polarsteps had already been warned back in December about its privacy problems.
But the Amsterdam-founded travel app, used by more than 23 million people, still managed to leave users’ photos, locations, and home addresses exposed to anyone through an unsecured data feed. This even included trips logged but put in private mode.
The numbers are impressive. Essentially, anyone could connect to the Polarsteps API and pull user names, 230 million photos and videos, and 1 billion GPS locations from nearly 2 million trips.
Since that’s enough to plot journeys on a map and follow them in near real time, the app served as a free gift to stalkers and threat actors. Even accounts set fully to private showed who a user followed, who followed them, and which device they logged in from.
Check if your data has been leaked
According to Follow the Money (FTM), the most sensitive exposed location data was home addresses. Researchers managed to pin down dozens of addresses from the exact location saved inside users’ photos – for instance, a shot of packed suitcases taken at home.
FTM even accurately tracked dozens of military personnel from the US, the United Kingdom, and the Netherlands to within meters, pinpointing sensitive locations such as military bases and active overseas missions.
The report says soldiers were found in uniform, in Black Hawk helicopters, next to fighter jets, and on US Space Force bases. Needless to say, hostile intelligence services hunt for this type of information all the time.
The data leak wasn’t a hack – no passwords were taken, no accounts entered. Anyone could connect to Polarsteps servers and scrape the data.
Notably, the photo-location data appeared nowhere in Polarsteps’ privacy policy, even though last year, a French cybersecurity researcher, Louis Couderc, noticed he could access the data of users who hadn’t granted him permission.
As per FTM, Couderc contacted Polarsteps and was assured the app was taking care of the issue. But the vulnerability persisted for at least 6 more months, and the researcher took his findings to the media.
The Dutch Ministry of Defence has reacted swiftly and banned Polarsteps from service phones. But Polarsteps is adamant that no data breach occurred because FTM only had access to public trip data.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“For clarity: all trip data that was never made public by the user has remained private, and no authentication was bypassed (i.e., no passwords were breached, and no one got access to any Polarsteps account or private trips),” the company said in a statement.
Polarsteps has explained that it always communicates to users that when they switch their privacy settings to “Anyone”, anyone can see their data, even people not using the app. Indeed, the company’s own website warns travelers that sharing location details in real time “can make you a target.”
Still, Polarsteps admits it could have done better and says it has already implemented stricter API controls to prevent large-scale access to its public user data.
The company also said it strengthened protections around the secret link feature, which allows people to share trips with non-followers.