
Every time you open a news site or launch a mobile app, dozens of ad companies and data brokers may be collecting information about you — your location, your browsing habits, what you buy, and more. This happens mostly in the background, governed by obscure technical files that most people never see. A powerful new free service called DecryptAds now makes it easy to find out exactly who has permission to track you on any site or app.
DecryptAds, launched this week by security researcher Zach Edwards and two co-founders, works by continuously scraping and cross-referencing the public disclosure files that websites and apps are required to publish: ads.txt, app-ads.txt, buyers.json, and sellers.json. These files list the adtech companies allowed to serve ads or collect data for each publisher. The data has always been technically public — it just required significant technical effort to parse and correlate across thousands of sites. DecryptAds does that work automatically and presents the results in a readable format. A search for ESPN, for example, reveals 143 ad partners and 19 registered data broker domains permitted to harvest user data from the sports network’s properties.
Edwards, who is also a threat researcher at Infoblox, says the tool was designed with security and privacy use cases in mind: tracing the source of malvertising campaigns that deliver malware, identifying ad networks connected to adversarial nations, and detecting networks of AI-generated spam websites. “Supply-chain integrity issues rarely live in a single file,” the site notes. “They show up as broken cross-references between ads.txt, app-ads.txt, and sellers.json files.” The tool also highlights data brokers specifically, pulling from registration databases that four U.S. states — California, Oregon, Texas, and Vermont — now require data brokers to file in if they buy or sell consumer data.
