You can audit Android and see that it leaks like a sieve. Ever seen “read phone state and identity”?
I remember when I was an Android developer dealing with several issues relating to the fact that one carrier put a proxy in the networking stack.
Here is a recent example:
https://www.theregister.co.uk/2016/11/15/android_phoning_hom...