Data collection
This page lists the data the SDK handles, so you can complete Apple's App Store privacy details and Google Play's Data safety form. The SDK uses no data for advertising or tracking. With proofUploadUrl unset (the default), no location leaves the device through the SDK.
What the SDK handles
| Data | Leaves the device | Purpose | Linked to identity | Tracking |
|---|---|---|---|---|
| Precise location | Only if you set proofUploadUrl (proofs uploaded) |
App functionality (location proofs) | No¹ | No |
| Coarse location | Only if you set proofUploadUrl |
App functionality (country-level proofs) | No¹ | No |
| Device ID (device fingerprint) | Yes: license activation, and bound into proofs | App functionality, anti-fraud | No¹ | No |
| Product interaction (usage counters) | Yes, unless telemetryEnabled = false |
Analytics: aggregate counters, no location | No | No |
| Product interaction (daily usage record) | Yes, always: one record per device per day | Billing (active-device count), no location | No | No |
¹ The device fingerprint is a pseudonymous per-install value, not an account identity, and the SDK does not link this data to a user identity. If your app associates proofs with a user account, classify the data accordingly on your own form.
The daily usage record is new in 3.0 and cannot be turned off. See Metrics and usage reporting for what each report contains.
iOS: privacy manifest
The xcframework bundles a PrivacyInfo.xcprivacy privacy manifest. Xcode adds it to your app's privacy report at build time, so no action is needed beyond reviewing it alongside your own disclosures. It declares:
- Collected data types. Precise location, coarse location and device ID, each for App Functionality. Product interaction, for Analytics (the usage counters) and Other (the daily usage record, used for billing). Every type is declared as not linked to the user and not used for tracking.
- Tracking. None, and no tracking domains.
- Required-reason APIs. System boot time, for the SDK's anchored license clock, and
UserDefaults, for a one-time device-ID migration.
When you upgrade from 2.x, re-check your App Store privacy details so they include product interaction for the Other purpose.
Android: Data safety form
Android has no privacy manifest inside the library, so the table above is the statement to use for your app's Play Console Data safety form. The SDK's permissions merge into your manifest automatically. See Prerequisites for the permission list.
Where to go next
- Metrics and usage reporting. What the counters and the daily record contain.
- Gateway routing. Which hosts the SDK contacts, and how to route them through one domain.