For the next week or so, I got many ads on my phone about underwater packages for Hawaii, along with ads for various snorkeling and swimming gear. Now I had never researched any of that on my phone, however obviously my brother has. And the ad trackers saw that both my phone and his had communicated out over the same IP address (my parents wifi) on other random internet connections, so that is probably why they were then targeting my tracker cookie with ads that would be related to his tracker cookie. (This is all technically "easy" for the trackers to do, and seems logical that they would, because "why not").
On an unrelated note, I was making a peanut butter sandwich, started browsing some sites, and started getting ads for Skippy peanut butter. My phone must have smelled the peanut butter in the air.
It was impressively creepy and a good way of surprising her with something she hadn't said anything about but was considering buying.
But, recently I started thinking about the average user, who will install anything and approve any permissions requested without reading it. And imperfect App Store reviews approving a Trojan horse accidentally.
Am I positive someone hasn’t inadvertently allowed mic access to a malicious party? I wonder if that person’s phone may, in fact, be listening to them.
Experiment design is important! I completely believe that this happened to your friends and I also don't think it means what you/they think it does
(That is: you need to completely isolate yourself; music practice room on a college campus where nobody is wearing a watch or phone and repeat the experiment. If it turns out that you still see ads for that thing, then the experiment didn't prove anything)