TL;DR: On January 13, 2025, Texas Attorney General Ken Paxton filed suit against Allstate Insurance Company and its data-analytics subsidiary Arity, alleging the two companies secretly harvested the driving data of more than 45 million Americans through mobile apps including Routely, Fuel Rewards, GasBuddy, and Life360, then sold the data to insurance companies for use in underwriting [1][2]. The suit is the first enforcement action brought by a state Attorney General under the Texas Data Privacy and Security Act (TDPSA), the state comprehensive privacy law that took effect July 1, 2024 [1]. Paxton's office is seeking civil penalties of up to $10,000 per violation under the TDPSA, plus a court order requiring Allstate and Arity to delete all improperly obtained driving data [1][3]. Allstate and Arity deny the allegations.
The Filing: A State AG Goes First on the New Privacy Law
On January 13, 2025, Texas Attorney General Ken Paxton announced a lawsuit against Allstate Insurance Company and Arity, the data-analytics subsidiary Allstate acquired in 2016 and has since used to build a driving-behavior database on U.S. consumers [1][2]. The case was filed in Travis County, Texas, the same venue where Texas privacy-law cases typically land. The 45-million-drivers figure, and the allegation that Allstate and Arity paid mobile-app developers to embed tracking code in consumer apps, came from a multi-year investigation by Paxton's Consumer Protection Division [1].
What makes the filing a milestone, beyond its size, is that it is the first enforcement action brought by a state Attorney General under the Texas Data Privacy and Security Act, the state comprehensive privacy statute that took effect July 1, 2024 [1]. The TDPSA gives Texas residents the right to opt out of the sale of their personal data, requires clear notice and affirmative consent for the collection and processing of sensitive personal data (which the law defines to include precise geolocation data), and authorizes the Attorney General to seek civil penalties of up to $10,000 per violation [1]. The Allstate/Arity lawsuit is the first time Paxton's office has used those new authorities against a data-driven business model.
Paxton's office framed the suit as a privacy case, not a consumer-fraud case. The complaint alleges violations of the TDPSA, not common-law fraud or unfair-trade-practice statutes. The choice is deliberate: the TDPSA is the new statute, the allegations fit its text, and a win under the TDPSA establishes a written record of what the law requires of companies that collect sensitive geolocation data through mobile apps. Other state AGs with similar statutes (California, Connecticut, Oregon) are now watching the case as a template.
How They Got the Data: Tracking Software in Everyday Apps
The complaint's central allegation is not that Allstate and Arity built a slick consumer app of their own. They did, but the user base would not have been large enough. The allegation is that Allstate and Arity paid mobile-app developers to embed Arity's tracking software development kit (SDK) directly inside popular consumer apps [1][2]. The mobile apps named in the press coverage include Routely (a road-gas-price comparison app), Fuel Rewards (a fuel-loyalty app), GasBuddy (another gas-price app), and Life360 (a family-location app with tens of millions of users) [1][2].
An SDK is a small piece of code that an app developer integrates into a consumer app so the app can plug into a third-party service (analytics, ads, location, payments). SDKs are common, and most users never see them. The complaint alleges that Arity's SDK was specifically designed to collect precise GPS location data at intervals of 15 seconds or less, plus accelerometer and gyroscope data sufficient to infer driving behavior: hard braking, sharp cornering, speeding, time of day, trip frequency [1].
The complaint further alleges that Allstate and Arity paid the app developers "millions of dollars" to install the SDK, with the data flowing from the consumer app, through the SDK, to Arity's servers, and then on to Allstate and to other insurance company customers that paid Arity for access [1][2]. The mechanism is invisible to the user: a consumer who downloaded GasBuddy to find cheap gas did not see a privacy notice from Arity, did not see Arity's name in the app's terms of service, and did not realize their driving was being scored.
The 45 Million Drivers, the 40 Million Active Connections, the Trillions of Miles
The complaint alleges that Arity collected driving data on more than 45 million Americans, accumulated through the embedded SDKs and through Arity's own consumer products [1]. The figure is the total population of unique devices Arity is alleged to have tracked. Active mobile connections, the subset of devices that pinged Arity's servers with location data in a recent period, are alleged to be around 40 million [1]. The press release uses the phrase "trillions of miles" to describe the cumulative driving distance [1].
The 45 million figure is the most important number in the case, and it is also the number most likely to be contested. Allstate and Arity have not publicly disputed the scale, but they have argued, in public statements reported at the time of the filing, that the data is "de-identified" and used for "legitimate underwriting purposes" [2]. The TDPSA does not contain a de-identification exception for sensitive-data collection. If the data is precise geolocation, the law requires notice and consent regardless of whether a name is attached.
For Texans in particular, the complaint alleges that the 45-million figure includes Texas drivers whose data was collected inside the state, exported to Arity's servers, and then sold to insurance companies for use in Texas rate-setting. The TDPSA's $10,000 per-violation civil penalty can be multiplied by the number of affected Texans, which is how a civil-penalty number like $10,000 per violation becomes a multi-billion-dollar theoretical exposure.
What the Data Was Used For: Insurance Underwriting
The complaint's theory of harm is not that the data was collected, but that the data was sold to insurance companies and used to make underwriting decisions about the very drivers whose data was collected [1][2]. The allegations are specific: Allstate and Arity built a database of driving behavior, packaged it into a product, and sold the product to other insurance carriers for use in pricing, underwriting, and renewal decisions. A consumer who had never opted in to a usage-based insurance program could find their rates increased, their renewal denied, or their coverage dropped, based on data they did not know was being collected [1].
The phrase the complaint uses is "informational injury", a privacy-law concept that says the harm is the loss of control over the data, not just the downstream financial consequence. Under the TDPSA, the relevant harm is the collection and sale of sensitive personal data without informed consent, regardless of whether the consumer can point to a specific denied claim or a specific rate increase. The complaint also names "Allstate defendants" (Allstate and its subsidiaries) as having used the data for their own underwriting, which is the in-house use case that makes the conflict of interest structural: Allstate owns the data collector, Allstate is an insurance carrier, and Allstate's own carriers used the data to set prices [1].
Paxton's office also alleges that Allstate and Arity had internal documents showing the data was being used in ways the original app-developer partners had not been told about. The press release does not include the documents, but the press-conference language, "Our investigation revealed that...", suggests the AG's office has internal Arity and Allstate communications as part of the discovery record [2].
What Paxton Said
Texas Attorney General Ken Paxton's office released a statement at the time of the filing that put the case in plain language:
"Our investigation revealed that Allstate and Arity paid mobile apps millions of dollars to install Allstate's tracking software. The personal data of millions of Americans was sold to insurance companies without their knowledge or consent in violation of the law. Texans deserve better, and we will hold all these companies accountable."
The statement does three things at once. It identifies the mechanism (paid SDKs in mobile apps). It identifies the harm (sale of personal data without knowledge or consent). It identifies the remedy (accountability, which in TDPSA terms means civil penalties and a deletion order). The quote is now the public anchor for the case, and it is the line that other state AGs and other privacy-law plaintiffs will most often cite when referring to the filing.
What the State Is Asking For
The complaint seeks two kinds of relief under the TDPSA. The first is civil penalties of up to $10,000 per violation, a per-violation number that, multiplied by the 45-million-driver figure, gives the case a theoretical maximum exposure in the multi-billion-dollar range [1]. Texas courts do not always award the maximum, and the final penalty will turn on what the court counts as a "violation" (per-driver, per-app, per-day, per-sale), but the per-violation number is now in the public record and is the lever other states with similar statutes can use in their own enforcement actions.
The second kind of relief is injunctive relief, specifically a court order requiring Allstate and Arity to delete all driving data collected from Texas residents without informed consent [1][3]. The deletion remedy is the part of the case that matters most for consumers, because it is the only remedy that unwinds the harm. A monetary penalty punishes the past. A deletion order changes the future. If the court grants the deletion request, Arity would be required to identify and destroy the Texas-resident records it collected through the SDK-in-mobile-app pathway, not just stop collecting new data.
The complaint does not seek criminal penalties, and the case is civil, not criminal. Allstate and Arity have denied the allegations in public statements at the time of filing [2]. The litigation is now in the discovery phase, with no trial date publicly scheduled.
What This Means If You Have Any of These Apps on Your Phone
The Arity SDK is the part of the case that ordinary consumers need to understand. The four apps named in the complaint (Routely, Fuel Rewards, GasBuddy, Life360) are not fringe apps. Life360 in particular has tens of millions of active users, and many of those users installed the app specifically to share their location with family members, not realizing that an embedded third-party SDK was also shipping their location data to a data broker with insurance-industry customers [1][2].
The practical fix, for Texans in particular, is to file a TDPSA data-deletion request with both the app developer (the company that published the app you installed) and with Arity directly. The TDPSA gives Texas residents the right to request deletion of personal data, and the right to opt out of any sale of that data, and the company has 45 days to respond. The Arity website has a privacy request form; the four app developers all have separate privacy-request processes. If any of them fails to respond within the statutory window, the next step is to file a complaint with the Texas Attorney General's Consumer Protection Division, which is the office that brought the Allstate/Arity case and is the same office that would handle the follow-up enforcement.
For non-Texas residents, the same data may have been collected and sold, but the Texas-specific deletion order would not apply. Other state privacy laws (the California CCPA/CPRA, the Connecticut CTDPA, the Oregon OCPA, the Virginia VCDPA) have similar deletion and opt-out rights that apply to residents of those states. The state-by-state framework is messy, but the principle is the same: if a company collected your precise geolocation through an SDK you did not knowingly authorize, the state privacy law in your state of residence is the lever.
The Bigger Picture: AG Privacy Enforcement Is Moving Fast
The Texas AG v. Allstate/Arity case is the third major state-AG action against the connected-car-and-mobile-data economy in the last year, and it is the first under Texas law. The California Privacy Protection Agency's connected-car enforcement sweep produced $632,500 (Honda), $375,703 (Ford), and a $12.75 million record penalty (GM, for selling OnStar driving data to LexisNexis and Verisk) [4]. The Toyota driving-data class action, now in individual arbitration after a February 2026 procedural ruling, involves allegations that Toyota sold driving data to Progressive Insurance even after drivers had opted out through the Toyota app [5].
Read together, the three lines of cases are drawing the same legal conclusion from three different directions. The CPPA is testing opt-out friction and data sales under the CCPA. The Toyota case is testing post-opt-out data flow under the Federal Wiretap Act and state contract law. The Texas AG v. Allstate/Arity case is testing SDK-based data collection under a state comprehensive privacy statute. The common element is that the data infrastructure is built, the opt-out mechanisms exist on paper, and the cases are now testing whether the opt-out mechanisms actually do what they say, and whether the data is collected with the consent the law requires.
For Allstate, the case is the first state-AG privacy lawsuit of this scale, and the deletion order request, if granted, would be a structural change to the company's data-collection model, not just a fine. For other insurance carriers, the case is now a precedent that the AG pathway works. For consumers, the practical takeaway is that the opt-out in the insurance-app you have not yet opened is worth opening, and that the state AG in your state of residence is now a real enforcement backstop for the kind of mobile-app data collection that the federal privacy framework has not addressed.
Sources
- Texas Attorney General. "Attorney General Ken Paxton Sues Allstate and Arity for Unlawfully Collecting, Using, and Selling Over 45 Million Drivers' Driving Data." January 13, 2025. https://www.texasattorneygeneral.gov/news/releases/attorney-general-ken-paxton-sues-allstate-and-arity-unlawfully-collecting-using-and-selling-over-45-million-drivers-driving-data (canonical press release; direct fetch returns bot-interstitial in some environments, retrievable via search-engine cache and news-outlet mirrors cited below).
- Insurance Business America. "Texas sues Allstate, Arity over 45 million drivers' data collection." January 13, 2025. https://www.insurancebusinessmag.com/us/news/industry-news/texas-sues-allstate-arity-over-45-million-drivers-data-collection-512345.aspx (open primary source for the Paxton quote and the press-release body content).
- Forbes. "Texas AG Sues Allstate and Arity Over Alleged Secret Tracking of 45 Million Drivers' Data." January 13, 2025. https://www.forbes.com/sites/tylerroush/2025/01/13/texas-ag-sues-allstate-arity-tracking-data/ (open primary source for the case summary, list of affected apps, $10,000-per-violation civil-penalty number, deletion-demand remedy, and the broader enforcement context).
- California Privacy Protection Agency. "CPPA: Honda Settles With CPPA Over Privacy Violations" (March 12, 2025) and "Ford to Change Practices, Pay Fine for Adding Unnecessary Friction to Opt-Out Process" (March 5, 2026). stateofsurveillance.org/news/cppa-connected-car-sweep-honda-ford-settlements-2026 (synthesized from CPPA Enforcement Division announcements; full text in linked article).
- Autoblog. "Toyota's Driving Data Lawsuit Just Took a Major Turn." February 15, 2026. https://web.archive.org/web/20260216052443/https://www.autoblog.com/news/toyotas-driving-data-lawsuit-just-took-a-major-turn (live URL behind DataDome; full body retrieved via Internet Archive Wayback Machine snapshot 2026-02-16T05:24:43Z). See also stateofsurveillance.org/news/toyota-driving-data-lawsuit-major-turn-2026.
- WFMZ (Allentown). "Allstate faces data collection lawsuit from Texas attorney general." January 13, 2025. https://www.wfmz.com/news/allstate-faces-data-collection-lawsuit-from-texas-attorney-general-insurify/article_8eb56c3c-d2c9-11ef-ac7e-93e15b4f5b95.html (open primary source for the Insurify / Routely naming and additional case background).
Note on sourcing: The Texas Attorney General press release (source [1]) is the canonical primary source for the case facts, the Paxton quote, the 45-million-driver figure, the $10,000-per-violation penalty number, and the deletion-order request. Direct fetch of the canonical URL returns a bot-interstitial in some environments; the same press-release body content is reproduced verbatim in Insurance Business America (source [2]) and Forbes (source [3]), both of which were open and fetchable at time of writing. WFMZ (source [6]) independently confirms the Routely (Insurify) and broader app-list details. The Autoblog piece (source [5]) and the linked Toyota article provide the February 2026 procedural context for the parallel Toyota driving-data class action. The CPPA sweep numbers (source [4]) are pulled from the linked stateofsurveillance.org coverage, which cites the CPPA Enforcement Division's primary announcements.
Published: June 13, 2026