Docs/Concepts/Data collection

Data collection

In short

This page lists the data the SDK handles, so you can complete Apple's App Store privacy details and Google Play's Data safety form. The SDK uses no data for advertising or tracking. With proofUploadUrl unset (the default), no location leaves the device through the SDK.

What the SDK handles

Data Leaves the device Purpose Linked to identity Tracking
Precise location Only if you set proofUploadUrl (proofs uploaded) App functionality (location proofs) No¹ No
Coarse location Only if you set proofUploadUrl App functionality (country-level proofs) No¹ No
Device ID (device fingerprint) Yes: license activation, and bound into proofs App functionality, anti-fraud No¹ No
Product interaction (usage counters) Yes, unless telemetryEnabled = false Analytics: aggregate counters, no location No No
Product interaction (daily usage record) Yes, always: one record per device per day Billing (active-device count), no location No No

¹ The device fingerprint is a pseudonymous per-install value, not an account identity, and the SDK does not link this data to a user identity. If your app associates proofs with a user account, classify the data accordingly on your own form.

The daily usage record is new in 3.0 and cannot be turned off. See Metrics and usage reporting for what each report contains.

iOS: privacy manifest

The xcframework bundles a PrivacyInfo.xcprivacy privacy manifest. Xcode adds it to your app's privacy report at build time, so no action is needed beyond reviewing it alongside your own disclosures. It declares:

  • Collected data types. Precise location, coarse location and device ID, each for App Functionality. Product interaction, for Analytics (the usage counters) and Other (the daily usage record, used for billing). Every type is declared as not linked to the user and not used for tracking.
  • Tracking. None, and no tracking domains.
  • Required-reason APIs. System boot time, for the SDK's anchored license clock, and UserDefaults, for a one-time device-ID migration.

When you upgrade from 2.x, re-check your App Store privacy details so they include product interaction for the Other purpose.

Android: Data safety form

Android has no privacy manifest inside the library, so the table above is the statement to use for your app's Play Console Data safety form. The SDK's permissions merge into your manifest automatically. See Prerequisites for the permission list.

Where to go next