An exclusive test cited by The Reporter found that Amap transmitted iPhone location data far more frequently than two other navigation apps. In the test, Amap sent location data once every 3 seconds on average, while Google Maps sent data about once every 5 minutes and NaviKing 3D about once every 22 minutes. Across the route, researchers captured 8,713 requests in total, with Amap accounting for 4,130, compared with 3,454 for Google Maps and 1,129 for NaviKing 3D.
Three reset iPhones ran the same route in Taipei
The test was conducted by The Reporter’s data team using three factory-reset iPhones. Each phone ran one app: Amap, Google Maps, or NaviKing 3D. The route started in Taipei’s Zhongshan District, passed areas near the Ministry of National Defense, Songshan Airport, the Investigation Bureau, and the Air Force Operations Command, and ended at the Presidential Office. The trip covered 30.75 kilometers in about 1 hour and 25 minutes.
To inspect app traffic, the team set up a proxy server with mitmproxy and installed SSL certificates on the phones to decrypt HTTPS packets. For Amap, the engineering team also decompiled the APK and said the data was wrapped with “Little-endian XXTEA encryption” and Base64 encoding.
Uploaded data included more than GPS coordinates
According to the report, Amap did not send only GPS location. The packets also included barometer, gyroscope, ambient light sensor, accelerometer, and direction data, and the traffic was sent to Alibaba Cloud servers in Hangzhou, Shanghai, and Nanjing. The Reporter quoted Liu Yen-po, chairman of the Taiwan Digital Security Development Association, as saying that this level of high-frequency transmission “should not be normal for navigation software,” because such calculations are generally expected to be handled on the device.
By comparison, the report said Google Maps and NaviKing 3D mainly transmitted the GPS data needed for navigation, with server locations in Taiwan, Japan, or Singapore. It also noted that Amap uploads became denser around the Presidential Office, Beian Road, Songshan Airport, and underneath the Keelung Road overpass.
CAID remained after reinstalling the app
The report said it found a fixed code labeled CAID inside Amap’s packets. In the team’s test, deleting and reinstalling Amap did not change the identifier. It changed only after the entire phone was wiped. The same CAID was also found in Baidu Search packets, which the report said suggests it can be used to identify the same user across different apps.
Based on technical documents reviewed in the report, CAID stands for CAA Advertising ID. It was developed in 2021 by the China Academy of Information and Communications Technology and the China Advertising Association, and was described as a device-fingerprinting identifier. The report added that Baidu Search asked for user consent before using it, while Amap did not present the same kind of notice.
Questions extend from privacy to security
The report cited experts who said that persistent uploads of location and device data can raise concerns over personal data exposure and security. It also pointed to China’s National Intelligence Law, Data Security Law, and Cybersecurity Law as relevant legal frameworks for access to data, oversight of cross-border information, and obligations for technical support.
Taiwan’s Ministry of Digital Affairs had already barred public agencies from using Amap on April 23, 2025 under its cybersecurity rules. On May 27, it published a review saying the app showed 11 cybersecurity risk behaviors on Android and 8 on iOS. The Reporter also noted that its test could observe only traffic sent from the phone side and could not determine how the data was used after reaching servers in China.

