Last updated: 2026-10-02
On 2026-08-28 Judge Richard Seeborg of the Northern District of California denied Google's renewed motion for judgment as a matter of law in Rodriguez v. Google LLC, No. 3:20-cv-04688-RS, and on 2026-09-21 Google filed its notice of appeal to the Ninth Circuit. The plaintiffs are Google account holders who turned off Web & App Activity (WAA), a Google account setting, or its supplemental sub-setting (sWAA). They sued over app activity data Google collected through Firebase and Google Mobile Ads, Google's software development kits (SDKs) that third-party developers build into their apps. The jury's verdict of $425,651,947 in actual damages is the basis of the final judgment of 2026-03-02, which adds interest; Google's appeal is from that judgment.
What did the court rule on 2026-08-28?
The court denied both post-trial motions: Google's Rule 50(b) motion on the privacy claims and the plaintiffs' Rule 59 motion for a new trial on the California Comprehensive Computer Data Access and Fraud Act (CDAFA) claim, which the jury had decided for Google. Google argued that its disclosures told users what would happen with sWAA off. From the order:
Perhaps the jury could have adopted that reading of Google's disclosures, but it evidently did not. [...] Google can poke holes in all that evidence, but the decision to credit it or not is the province of the jury. Google took a shot at trial, and it lost.
The evidence cited for that passage includes a Google-commissioned survey in which participants expected that "turning off [the sWAA] toggle [would] stop their activity from being saved", and an exhibit (PX-003) in which Google employees described the disclosures as giving users "a false sense of security that their data is not being stored at Google, when it fact [sic] it is" and called them "very deceptive". The court also rejected Google's argument that the California Uniform Trade Secrets Act displaces the privacy claims, holding that the anonymized app data "is thus not a trade secret nor, frankly, even remotely close to one" (page 5).
On the offensiveness element of the privacy claims, the court quoted its January 2026 ruling: "Google's decision to collect sWAA-off data was highly offensive because it misled users about its plan to do so". It distinguished Hammerling v. Google, another privacy case against Google, because "the plaintiffs there did not attempt to stop Google's collection of its data" (page 6).
The same day, a separate order granted class counsel one third of the common fund. The court-authorized class notice puts that fund, the verdict plus interest, at $440,345,685.40 as of 2026-03-02. Counsel's third, in the fee order's words, "totaled $146,781,895.13 as of final judgment (accounting for post-judgment interest)".
The fee order says that "each of the 98 million class members will walk away with less than $5". The verdict form gives "estimated class sizes" of 54,923,146 for the Android class and 59,565,930 for the non-Android class (page 2), which together exceed 98 million. How the fee order arrives at 98 million is not stated in the documents read for this post.
Class counsel also asked for $12,422,374.42 in litigation costs. Plaintiffs' motion of 2026-09-17 states that the fee order "did not address" that request and asks the court to enter an amended final judgment.
Rodriguez v. Google timeline: from filing to appeal
| Date | Event | Docket |
|---|---|---|
| 2020-07-14 | Complaint filed, N.D. Cal. | Docket |
| 2024-01-03 | Two classes certified (Android and non-Android users with WAA or sWAA off, from 2016-07-01) | Dkt. 352 |
| 2025-01-07 | Google's motion for summary judgment denied | Dkt. 445 |
| 2025-09-03 | Jury verdict, $425,651,947 (form filed 2025-09-04) | Dkt. 670 |
| 2026-01-30 | Plaintiffs' requests for an injunction and $2.36B disgorgement denied; Google's decertification motion denied | Dkt. 721 |
| 2026-03-02 | Final judgment entered | Dkt. 725 |
| 2026-08-28 | Rule 50(b) and Rule 59 motions denied; fee award granted | Dkt. 1009, Dkt. 1010 |
| 2026-09-17 | Plaintiffs ask the court to rule on $12,422,374.42 in litigation costs and enter an amended final judgment | Dkt. 1014 |
| 2026-09-21 | Google's notice of appeal from the final judgment and the 2026-08-28 order | Dkt. 1017 |
| 2026-09-22 | Fee objector Gregory R. Bronner (objection at Dkt. 974) files a notice of appeal from the fee order (Dkt. 1010) | Dkt. 1021 |
| 2026-09-24 | Ninth Circuit docketing notice for Google's appeal, No. 26-6237; opening brief due 2026-12-14, answering brief 2027-01-13 | Dkt. 1022 |
Table source: the district court docket on CourtListener, checked 2026-10-02. Later entries, among them Dkt. 1025, an "Order on Motion for Miscellaneous Relief", had no text on CourtListener that day, so what they decide is not established here.
What did the jury find in Rodriguez v. Google?
The verdict form records that the jury found for the classes on invasion of privacy under the California Constitution and on intrusion upon seclusion, rejected Google's consent defense on both, and found for Google on CDAFA. It awarded $247,154,157 to the Android class and $178,497,790 to the non-Android class, declined to award disgorgement of Google's profits (an advisory answer, because the court treated disgorgement as an equitable remedy for itself to decide), and answered "No" on malice, oppression or fraud. The January 2026 order records that the jury "declined to award punitive or nominal damages." The final judgment fixes the damages period as July 1, 2016 through September 23, 2024 and adds pre-judgment interest from the verdict date.
The three claims tried were CDAFA, invasion of privacy under the California Constitution and intrusion upon seclusion, all outside the California Invasion of Privacy Act (CIPA). CIPA pen register claims over apps become an Attorney General action in 2027; the SB 690 post covers that change.
What did the Firebase and Google Mobile Ads SDKs send to Google, per the court record?
The class certification order defines each class by users whose "activity on a non-Google-branded mobile app was still transmitted to Google [...] because of the Firebase Software Development Kit ("SDK") and/or Google Mobile Ads SDK." The same order records Google's position: it "admits that it collects this data but, for sWAA-off users, it does so only for 'basic record-keeping' of its advertising services and to store and analyze data for the third-party app developers."
The summary judgment order of 2025-01-07 describes in the most detail how the SDKs collect the data:
- Google Analytics for Firebase (GA4F) "works by automatically sending to Google a user's ad interactions and certain identifiers regardless of a user's (s)WAA settings", and "GMA logs similar ad-related interactions."
- GA4F "is integrated in 60% of the top apps", a figure the order takes from the report of plaintiffs' expert Jonathan E. Hochman.
- For attribution and conversion tracking, Google collects the Android advertising ID (ADID) or the iOS IDFA through its SDKs, and attribution tracking lets Google "log the fact that it has served an ad alongside a device identifier for accounting purposes".
- Google can also save the GAIA ID through GA4F; the GAIA ID "uniquely identifies a Google account holder".
- The data, "per Google, consists only of non-personally identifiable information and is unrelated (or, at least, not directly related) to any profit-making objectives".
- Google "insists" that for sWAA-off users it runs a "consent check", logs the data in a "pseudonymous space" that holds no GAIA IDs, and encrypts the retrieved device IDs.
- Google's example, quoted in a footnote, is an
in_app_purchaseconversion event, of which "it is just the fact that the event occurred that is logged."
The January 2026 order describes the commercial use argued at trial: plaintiffs' damages expert tied sWAA-off data to conversion tracking, starting from Google's U.S. revenues from App Promo, AdMob and Ad Manager. The court found that profit estimate unsupported and denied disgorgement.
This post relies on the verdict form, the final judgment and the court's orders (class certification, summary judgment, the January 2026 post-trial order, the 2026-08-28 orders), which summarise expert reports, trial testimony and exhibits. The orders name the SDKs, identifiers and event types and list no network hosts or request fields. The trial transcript and the sealed exhibits are outside this account, so what the jury heard beyond the orders' summaries is not established here.
How would Firebase and Google Mobile Ads SDK presence and traffic be documented in an app?
Google's setup guides require the Google Mobile Ads SDK app ID in a com.google.android.gms.ads.APPLICATION_ID meta-data entry in the Android manifest and in a GADApplicationIdentifier key in the iOS Info.plist. Firebase Analytics on Android ships the com.google.android.gms.measurement package, and its AppMeasurementService runs only when declared in AndroidManifest.xml, so the manifest entry is a static marker. Static analysis establishes that the SDK is in the binary; what it sent takes a network capture on a test device.
Google's list of automatically collected events states that apps using the Google Analytics for Firebase SDK collect events such as session_start and screen_view with no additional code, attach app_version, firebase_screen_id and firebase_screen_class to every event, and log ad_impression for "Publisher events coming from AdMob via the Google Mobile Ads SDK". Firebase's Cloud Functions source code on GitHub names the Analytics service app-measurement.com. A capture records each request with its timestamp, host, path and payload, so it shows which of these events and identifiers were sent from the device, in what order, and before or after any consent prompt.
A test of the Rodriguez question on one app captures it twice with the same signed-in test account, once with sWAA on and once with it off, and compares what the SDKs sent in each run. The result covers that app, that build and that account. A capture covers the device side only; storage after receipt, including the "pseudonymous space" described in the summary judgment order, takes place on Google's servers.
What a CITT scan shows for these SDKs
When I scan an app, the static pass lists the SDKs found in the binary, with the file and line for each finding, and the dynamic pass records the traffic on test devices: which host received what, and whether it was sent before or after consent. How a scan checks an app and where a scan stops are on the methodology page; the public app index lists the apps scanned so far.
I run these scans and captures for lawyers and for researchers working with lawyers. Sign up for a CanITrustThat (CITT) account to run your own research, or let us run an investigation for you.