Short answer: no. The CIA did not create, fund or run Pokémon Go. But the claim has a real root, and the story that grew out of that root is far more interesting than the conspiracy theory. It is also still going.
Here is the whole thing, checked.
The claim
That Pokémon Go was a CIA operation: a global surveillance program dressed up as a monster-catching game, and that its 2016 launch got hundreds of millions of people to map the world for an intelligence agency without knowing it.
The part that is true
2001. John Hanke co-founds Keyhole, a 3D earth-mapping startup, with Brian McClendon and others. Before this, Hanke spent four years in the US Foreign Service, in Washington and Myanmar.
February 2003. In-Q-Tel, the CIA’s venture capital arm, invests in Keyhole. The deal is announced on June 25, 2003. The customer is NIMA, now the NGA. From In-Q-Tel’s own press release: “Within two weeks of In-Q-Tel’s engagement with Keyhole, we implemented the technology to support our mission within the Pentagon.” It was used for operations in Iraq.
2004. Google buys Keyhole for roughly $35 million in stock. Keyhole becomes Google Earth.
2010. Hanke starts an AR gaming unit inside Google: Niantic Labs. In 2012 it ships Ingress, a game whose entire mechanic is players walking to real-world landmarks.
2015. Niantic spins out of Google with $30 million from Google, Nintendo and The Pokémon Company.
2016. Pokémon Go launches.
So yes: CIA venture money is in the founder’s origin story. That part is not a rumor.
The part that is false
In-Q-Tel never invested in Niantic, and never invested in Pokémon Go. No US intelligence agency funded, commissioned or ran the game. The money behind it was Google, Nintendo and The Pokémon Company.
Two acquisitions and fifteen years sit between the In-Q-Tel check and the launch. “CIA money once touched a company the same founder ran in 2003” is not “the CIA made Pokémon Go.”
The twist nobody posts
The intelligence angle points the other way.
Iran banned the game. China cited geographic information security. Russia called it a CIA tool. Egypt and Kuwait restricted play near government and military sites. Belarus claimed in 2024 that it had been used to map military assets.
And Foreign Policy reported in November 2024 that in 2016, US intelligence was worried Pokémon Go might be a foreign collection vector, most of all a Chinese one. There is no public evidence that any intelligence agency, American or otherwise, ran the game. Everybody suspected everybody.
The part that should actually worry you
Forget 2016. Look at what happened while nobody was watching.
What the model was trained on. Niantic built a Large Geospatial Model from player-submitted 3D scans of real places. This matters and gets misreported constantly, so be precise: normal gameplay did not feed it. Niantic’s own words: “Merely walking around playing our games does not train an AI model.” The training data came from an optional feature where players visited a specific public location and chose to scan it, usually for in-game rewards. By late 2024 that meant about 10 million scanned locations, roughly a million fresh scans a week, and more than 50 million neural networks with over 150 trillion parameters between them.
That is still an enormous, voluntarily-built, ground-level map of the physical world. It is just a map built by people who opted in, not by people catching Pidgeys.
March 12, 2025. Niantic announces the sale of its games division, Pokémon Go included, to Scopely for $3.5 billion. The deal closes on May 29, 2025. Scopely is owned by Savvy Games Group, which is owned by Saudi Arabia’s Public Investment Fund. Over 400 employees and the live player base move with it.
What is left. The deal spins out Niantic Spatial, a separately capitalized company led by Hanke, holding the geospatial technology and team. Since the sale, current Pokémon Go play no longer feeds it. The models were trained on the scans that came before.
December 16, 2025. Niantic Spatial announces a partnership with Vantor, the defense and intelligence imagery firm formerly known as Maxar Intelligence and a long-standing supplier to the NGA and the US military. The two combine ground-level and aerial visual positioning so that drones, ground vehicles and AR headsets can locate themselves without GPS, in environments where satellite signals are jammed, spoofed or absent. Field testing was set for early 2026.
The quote in that announcement comes from Niantic Spatial’s CTO, Brian McClendon. Co-founder of Keyhole. The circle is not a conspiracy. It is the same twenty people who have been doing this work since 2001.
June 2026. The Dutch newspaper Trouw connects it publicly. Niantic Spatial’s response: sharing Pokémon Go player data “is not part of the agreement” with Vantor. It also confirms that voluntary ground scans were used to train its AI models, and argues that “the resultant models are a product of training rather than a direct copy, and Vantor does not have access to that underlying data.”
What that actually proves, and what it does not
It does not prove Pokémon Go was a surveillance operation. It does not prove player scans were handed to a defense contractor. On the published evidence, they were not: Vantor gets capability, not files.
What it does show is the shape of the modern data problem, and it is not the one the conspiracy theory describes.
Raw data stays home. The model walks out the front door. You can consent to a scan of a mural on your street in exchange for a rare spawn, and the file never leaves the company, and the thing learned from it still ends up inside a positioning stack for autonomous systems in GPS-denied environments, at a company you never heard of, under an owner who was not in the room when you tapped agree.
Nobody lied to you. The consent was real. The scans were optional. The terms in force when you opted into AR scanning permitted it. And the outcome is still a place you never agreed to go, because consent is a snapshot and a data asset is a lifetime.
The lesson
You never needed a CIA plot. You needed a game good enough that millions of people volunteered to photograph the physical world, a company structure that could be split in two, and a model that outlives the game, the owner and the privacy notice.
The CIA did not make Pokémon Go. Pokémon Go made something the intelligence world wanted anyway, and then it was sold.
What to actually do about it
The general rule that comes out of this: the question is never only “who has my data today.” It is “what can be learned from my data, and where can that go once it is learned.” A file can be deleted. A trained model cannot be un-trained. That is worth folding into your threat model as its own category of risk.
Practically, for anything that scans the physical world:
- Treat optional camera and scanning features in apps as permanent contributions, not favors. They are the only part of most games that produces a durable, resellable asset.
- Assume any dataset survives the company. Acquisitions rewrite who holds it and what they may do with it. Your original privacy notice does not travel with your intent.
- Check location permissions on a schedule, not on install. “While using the app” is the ceiling almost every app deserves, and it is worth knowing how Wi-Fi and Bluetooth locate you even when you think location is off.