> The 1,325 apps that violated permissions on Android used workarounds hidden in its code that would take personal data from sources like Wi-Fi connections and metadata stored in photos.
> Researchers found that Shutterfly, a photo-editing app, had been gathering GPS coordinates from photos and sending that data to its own servers, even when users declined to give the app permission to access location data.
> Some apps were relying on other apps that were granted permission to look at personal data, piggybacking off their access to gather phone identifiers like your IMEI number. These apps would read through unprotected files on a device's SD card and harvest data they didn't have permission to access. So if you let other apps access personal data, and they stored it in a folder on the SD card, these spying apps would be able to take that information.
So basically, they can't read your location, but they can read other things that contain your (previous) location and other information about you.
Edit: The article links to the original research[0], which seems to describe/link to different methods that the apps use. I haven't had time to read it yet, but it seems interesting.
[0] https://www.ftc.gov/system/files/documents/public_events/141...