Geofence warrants. The investigation tool that does not need a suspect.

Short answer

A geofence warrant works backwards from a normal investigation. Police draw a polygon on a map and a time window, then ask Google or another data holder for every device that pinged inside it. The Supreme Court has now ruled on the practice. Understanding how the query is built and which databases feed it is what tells you which controls actually reduce exposure.

How a geofence query is constructed

A traditional warrant names a target. The police identify a suspect, build probable cause about that person, and ask a judge to authorize a search of that person’s home or accounts. The geofence warrant inverts the logic. The police identify a place and a time, and ask the judge to authorize a search for everyone who was there.

The classic case is a bank robbery. Police know the time of the robbery within minutes and the location within feet. They draw a polygon around the bank covering the time window of the crime, and they serve Google with a warrant asking for every device that produced location data inside that polygon. Google returns a list.

That list is the starting point. From the initial set, sometimes hundreds of devices, police narrow by behavior. Devices that arrived at the start of the window and left at the end are interesting. Devices that lingered are interesting. Devices that took a path consistent with a getaway car are interesting. The narrowing is iterative. Each round of narrowing requires another step in the warrant process, but the practical effect is a search that begins with everyone and ends with one or two suspects.

The same logic applies to murder investigations, riot prosecutions, anti-government protests, and increasingly, lower-stakes crimes where Google’s data is just easier to query than traditional investigation. The technology has been operational since 2016, with use growing sharply since 2020.

Whose data is in the search radius

The list of providers that have received geofence warrants is small and largely centered on Google. Google’s Sensorvault, the internal name for the location history database, is the primary target because Android plus Google Maps plus Gmail plus Chrome together produce continuous location data on hundreds of millions of US devices.

Apple’s exposure is different. Apple does not maintain a centralized database of user location histories that Apple itself can query. Find My is end-to-end encrypted, with even Apple unable to read the location data of users who have it enabled. The Apple location history that does exist on a per-device basis is on the device itself, accessible only with the device unlocked. This structural difference comes from a design choice Apple made years ago that, in this specific scenario, gives iPhone users meaningfully less exposure than Android users to geofence queries.

That does not make Apple devices invisible. Police pursuing an iPhone owner can compel Apple for iCloud backup data, App Store activity, payment records, and other information that may include location-adjacent data. The point is narrower. For the specific tool of a geofence query, Apple’s centralized location footprint is much smaller than Google’s, and the query returns fewer iPhone hits per polygon.

Other targets that have received geofence warrants include Facebook (Meta) for users with location services enabled in the Facebook or Instagram apps, Snap for Snap Map users, and increasingly, ad networks that aggregate location data sold by third-party apps. The ad-network channel is the fastest-growing. We covered that ecosystem in your phone carrier sells your location data, which describes the same data flowing through a different door.

What the Supreme Court ruling changes

The court did not ban geofence warrants. It held that geofence warrants are subject to traditional Fourth Amendment scrutiny, that probable cause must be particularized, and that the breadth of the geographic and temporal scope is now reviewable by courts. The practical effect is that geofence warrants get harder to obtain, more often denied, and when issued, more narrowly scoped. The detailed walk-through of the ruling and what it changes operationally sits in our piece on the Supreme Court geofence warrants ruling and what it actually means for civilians.

That is meaningful, but it is not the end of the practice. Federal investigators are already adapting by serving narrower warrants on better-justified facts. State and local agencies, especially in smaller jurisdictions, are sometimes still issuing the broader warrants because the magistrate hearing them has not seen the new case law yet. A geofence warrant issued by a state or county magistrate this week may still be looser than what would survive Supreme Court scrutiny.

The ruling raises the bar without moving it high enough to affect every case. If you are operating in a context where you might appear in a geofence query, the ruling helps your case if it reaches a federal appeal, but it does nothing in the moment the query actually runs.

What actually reduces your exposure

Five controls, in increasing order of friction. Use whichever level matches your actual exposure. The framework for that decision is in how to build a threat model in 20 minutes, and the related limits of incognito mode are worth keeping in mind here.

Level 1. Disable Location History on Google

This is the single highest-leverage control for Android users and for anyone who uses Google Maps. Settings, then Personal Info and Privacy, then Location, then Location History, then off. Then go to Activity Controls and pause Web and App Activity. Then go to maps.google.com/locationhistory and delete the existing history.

With Location History off, your device still produces location data for active queries (you ask Maps for directions, Maps knows where you are), but the continuous background log that feeds Sensorvault stops being written to your account. Google itself has reframed this in the last two years and the controls have moved around. As of 2026, the on-device-only setting (Timeline stays on your phone, never syncs to Google’s servers) is the default for new Android users. For older accounts, the setting may still be cloud-synced. Check yours.

Level 2. Reduce app permissions across the device

Most apps that ask for location do not need it. Weather apps, news apps, ride-hail apps when you are not riding, social apps. Each app with location permission produces data that may be sold to ad networks and aggregators that, in turn, are now occasional targets of geofence-style queries. Settings, then Privacy and Security, then Location Services. Audit every app. Default to While Using. Set to Never for anything that does not have a clear, current need.

Level 3. Disable advertising ID

On both Android and iOS, the advertising ID is the persistent identifier that ad networks use to stitch together location data sold by multiple apps into a continuous trail. On iOS, App Tracking Transparency lets you deny tracking on a per-app basis and a global toggle exists in Settings, Privacy and Security, Tracking. On Android, the equivalent is in Settings, Google, Ads, Reset Advertising ID and Delete Advertising ID. Doing this once meaningfully degrades the trail; doing it monthly degrades it further.

Level 4. Carry less

For specific situations where you are aware that a geofence query might run, the most reliable control is not to be there with a phone. Protests in jurisdictions known for aggressive prosecution. Visits to places that are politically sensitive in the current climate. The phone has to be off. Off is not airplane mode. Off is power button. The baseband can negotiate with cell towers in airplane mode in ways that produce log entries. Off does not.

If you cannot be without a phone for the period in question, a clean travel device is a better answer than your daily driver.

Level 5. Local-first apps and de-googled phones

For people whose threat model includes regular geofence exposure, GrapheneOS on a Pixel device is the most operationally complete answer. The device runs Android with Google services either disabled or sandboxed, no automatic data sync to Google, and no Sensorvault contribution. The trade-off is the loss of certain Google-tied features, which shrinks every year as the alternatives mature. The option works today and is the right answer for users whose threat model justifies it.

Frequently asked questions

If I never use Google services, am I out of geofence range?

Mostly, but not entirely. Apps that you would not associate with location often pass it through to ad networks that, in turn, can be served. Apps that prompt you to share location are obvious; apps that bundle a third-party advertising SDK fetching location independently are not. The cleanest answer is the operating-system-level controls, applied universally, plus a regular audit of which apps actually need the permission they have.

Does using a VPN help against geofence warrants?

Not directly. A VPN affects the network path of your traffic. Location data from a phone is collected by the operating system through GPS, Wi-Fi triangulation, and cell tower data, and is uploaded to the relevant service before any VPN logic applies. The VPN can hide which IP address logged into Maps. It cannot hide that the device with your account was at coordinates X at time Y.

Are geofence warrants used outside the United States?

Yes, with different legal frameworks. Several European countries have analogous tools under different names. The UK has used location-based queries through Investigatory Powers Act warrants. Continental European agencies use Mutual Legal Assistance Treaties to request data from US providers. The legal scrutiny is generally higher in the EU due to GDPR, but the underlying technical capability is the same.

If I am served a target letter saying my device appeared in a geofence, what do I do?

Talk to a lawyer before responding. Do not delete location data on your phone or in your Google account. Doing so after notice may constitute spoliation. Preserve the device, preserve the data, and let counsel handle the response. The lawyer’s job from there is to challenge the breadth of the warrant under the post-Supreme-Court framework and to present any innocent explanation for the presence.


There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.

Similar Posts