Privacy
55 post(s)
-
Apple Ads: a subtle Terms change that could hint at third-party inventory (Mobile Dev Memo)
Eric Seufert spots updated Apple Advertising Terms language that appears to grant Apple latitude to place Apple Ads beyond Apple-owned surfaces. If true, it raises a big follow-on question: what does attribution look like when Apple Ads is not just on Apple inventory?
-
Google Play policy update (July 15, 2026): phone verification via READ_CALL_LOG is out, and app registration is now a hard requirement
Google’s July 15 policy announcement has two practical ‘don’t get removed’ items: (1) you can no longer justify READ_CALL_LOG for account verification via phone call, and (2) you must register your Play apps in Play Console (including apps you distribute outside Play, if you want installs on certified devices). It also clarifies that User Data rules apply to third-party AI integrations.
-
Email open tracking in Europe: why the pixel now needs consent (Courier)
France (CNIL) and Italy (Garante) are treating open-tracking pixels like cookies. Practical implication: keep sending emails, but only fire the pixel when the recipient has opted in.
-
Google Play Terms: subscriptions can be charged 48 hours early (and Google finally spells out background data)
Android Authority highlights Google Play’s updated Terms of Service (effective July 29, 2026), including a new ‘System Services’ section, clearer background mobile data language, and a change that allows subscription renewals to be charged up to 48 hours before the next billing period.
-
Google Play: age verification bills turn into product work (Play Age Signals API, Texas SB 2420)
Google Play outlines how Texas’ SB 2420 and similar laws change developer obligations, introducing the Play Age Signals API (beta) plus new Play Console workflows for ‘significant changes’ and parental approval status.
-
A quick reality check on App Store privacy labels and ATT: the numbers are still huge (42matters)
42matters keeps a rolling snapshot of App Store privacy label declarations. The useful part is not the exact percentages, it’s the gut-check: how many apps still declare tracking, background location access, and analytics-linked data at scale.
-
Apple is moving Sign in with Apple and Hide My Email to private.icloud.com (June 2026)
Apple will issue new Sign in with Apple relay addresses and iCloud+ Hide My Email addresses on private.icloud.com. Here’s what to update so logins, email validation, and deliverability don’t break silently.
-
Sign in with Apple + Hide My Email: new relay domain private.icloud.com (Apple Developer)
Apple is unifying Sign in with Apple and iCloud+ Hide My Email relay domains under private.icloud.com. Existing relay addresses keep working, but your validation, allowlists, and ESP filtering rules need to accept the new domain to avoid silent deliverability bugs.
-
Google consent changes (June 2026) make call attribution a measurement trap
A credited summary of Invoca’s breakdown of Google’s June 2026 consent rule change: Ads attribution hinges on ad_storage, which can erase call conversion signals and mis-train Smart Bidding.
-
IDFA in 2026: where it still works, and what you need when it doesn’t
Branch’s refresher on IDFA post-ATT, with a pragmatic message: use deterministic IDFA when you have consent, but plan measurement around SKAdNetwork coverage and a unified view across both.
-
Apple Developer: Texas App Store age assurance (Declared Age Range + PermissionKit Significant Change)
A credited summary of Apple’s June 2026 update: new Apple Accounts in Texas now fall under SB 2420 age assurance rules, which adds declared age ranges, parent/guardian consent for minors, and a ‘significant change’ consent flow apps need to implement.
-
Texas age assurance on iOS (SB 2420): what Apple’s June 3 update means for consent, significant changes, and server notifications
Apple says new Apple Accounts in Texas are now subject to SB 2420 age assurance requirements, including parent/guardian consent for downloads, IAP, and significant app changes. If you ship to Texas, this is now funnel plumbing: eligibility, consent, and revocation handling.
-
Google: June 2026 Android Drop (safety signals, faster sharing, and AI helpers in everyday surfaces)
A credited summary of Google’s June 2026 Android feature drop. The growth takeaway: platform-level safety and sharing features become funnel surfaces, they change user expectations and can quietly affect support load and reviews.
-
iOS attribution in 2026: what ATT actually broke (and what still works)
A credited summary of Attriqs’ practical guide to attribution after ATT: why click-level truth is gone for most iOS users, how to think about SKAN vs AdAttributionKit, and the resilient stack (first-party + server-side + incrementality).
-
Google outlines Android’s 2026 security and privacy roadmap (banking scam calls, threat detection, theft protections)
Google’s Android Security and Privacy team previews 2026 platform protections: verified financial calls to stop spoofed bank scams, expanded on-device threat detection, tighter Advanced Protection, and stronger device theft defenses.
-
June 2026 consent change: Google Signals stops being your ‘backdoor’ privacy switch
A credited summary of PPC Land’s explainer on Google’s June 15, 2026 consent change: ad_storage becomes the sole authority for Ads data collection, so ‘Signals off’ is no longer a substitute for a real CMP.
-
App Store Marketing Weekly – Week 18 (2026)
This week’s theme: the lock screen is a product surface. Push, permissions, and platform policy now change retention and conversion as much as creatives do, because they shape what users see (and what they fear) before they ever open the app.
-
Apple releases: iOS 26.4.2 + iOS 18.7.8 (notifications database fix)
Apple’s April 22 releases (iOS 26.4.2 and iOS 18.7.8) are a reminder that platform ‘bugfix’ updates can have direct privacy implications. In this case, it appears to close a hole where deleted notifications could persist in the on-device notification database.
-
EFF: push notifications can leak more than you think (lock screen, cloud routing, device databases)
EFF breaks down two privacy leak points for push notifications: what platforms can see in transit (content/metadata), and what can persist on-device (including recovered ‘deleted’ notifications). For app teams, the takeaway is simple: treat notifications as a public surface and design for minimised content.
-
Apple fixed a bug where deleted notifications could be retained on-device (iOS 26.4.2)
A credited summary of Apple’s April 22, 2026 security note for iOS 26.4.2: notifications marked for deletion could be unexpectedly retained on the device. Practical takeaway for app teams: treat notifications as a privacy and trust surface, and keep lock screen content minimal.
-
TechCrunch: Apple fixes iPhone bug that retained ‘deleted’ notification content
A credited summary of TechCrunch’s April 2026 report: iOS cached notification content in a way that could retain messages marked for deletion. Apple shipped a fix, which is a good reminder for app teams that lock-screen copy is part of your privacy model.
-
App Store Marketing Weekly – Week 17 (2026)
This week’s theme: workflow and permissions are quietly converging. Toolchain gates (TestFlight/Xcode) and platform hardening (local network, background audio, CT defaults) are now part of conversion and retention, because they change what ships and what breaks.
-
Android 17 Beta 4: the ‘boring’ changes that become support tickets
Android 17 Beta 4 is the last scheduled beta, and the headline for app teams is not one feature, it is a bundle of default-tightening changes: local network access blocked by default (new ACCESS_LOCAL_NETWORK permission), background audio hardening, certificate transparency on by default, plus new memory limits and profiling triggers for anomalies.
-
EFF: Push notifications can betray your privacy (and what to do about it)
EFF’s practical point is simple: notifications leak in two places, in transit (Apple/Google push infrastructure) and at rest (what your OS stores locally). Their advice is to reduce preview content, tighten per-app and OS-wide settings, and treat notification copy like sensitive data.
-
Google Play policy announcement (April 15, 2026): contacts access, account transfers, and tighter location defaults
A skimmable summary of Google Play’s April 15, 2026 policy announcement, focused on what will trip releases: contacts access expectations, account transfer workflow, and location permission scope.
-
Android Developers: Play is pushing contact picker, location button, and a real account transfer flow
Google’s Android Developers blog frames the April 2026 Play policy changes as ‘clearer choice’ plus business protection. The practical bits: move invites/sharing off READ_CONTACTS and onto Contact Picker/Sharesheet, use the location button for one-off precise location, and plan for an official account ownership transfer workflow with a cooldown.
-
Google Play policy update (Apr 15, 2026): contacts access, account transfers, location, health data
Google Play’s April 15 policy announcement adds a new Contacts Permissions policy, formalises developer account transfers, and tightens expectations around location and sensitive health data. Here’s what changes, what’s just clarified, and what to sanity-check this week.
-
Play policies are turning into product work (contacts picker, location button, and account transfers)
A credited summary of the Android Developers Blog post on updated Play policies, focused on the concrete implementation changes that reduce review risk and user friction.
-
Updated Play policies: Contact Picker, location button, and account transfer workflow (Android Developers Blog)
A skimmable summary of Google’s Android Developers Blog post tying Play policy changes to concrete platform features (Contact Picker, location button) plus the new account transfer workflow.
-
Google Play policy announcement (Apr 15, 2026): Contacts access, account transfer, and tighter location expectations
A quick summary of Google Play’s April 15 policy announcement, including a new Contacts Permissions policy, a new Account Transfer policy, and updated guidance around location permissions and the Android location button.
-
Mobile growth after privacy: stop chasing perfect attribution, build a signal system
Mobile Growth Association’s thesis: privacy didn’t remove data, it redistributed it. Winning teams integrate platform signals, cohorts, and incrementality tests into a single decision system.
-
Apple updated the Developer Program License Agreement (again). If you ship privacy-sensitive features, skim the diffs
Apple’s March 30, 2026 update to the Apple Developer Program License Agreement adds more explicit requirements around specific frameworks (including privacy expectations). It’s the kind of ‘legal’ change that becomes a product/fire-drill if you only notice it during a release.
-
Location SDK panic is usually a configuration story, not a magic data leak
OneSignal clarifies how location works in its mobile SDK: it is off by default, requires explicit developer enablement, and still depends on OS-level user permission. Useful framing for privacy reviews and stakeholder questions.
-
Android 17 is making location permissions more ‘in-the-moment’ (and harder to over-collect by accident)
Android 17 introduces a new ‘location button’ for one-time precise location, stronger transparency indicators, improved coarse location in low-density areas, and a redesigned runtime permission dialog. This is privacy work, but it also reduces friction in the moments where users actually want location to work.
-
Android 17 Beta 3: photo picker customization and privacy defaults that will show up as UX friction (if you ignore them)
Android 17 reaches platform stability in Beta 3. Buried in the release is a practical UX change: you can now customize the photo picker’s layout to match your app, while keeping the privacy-preserving picker model. At the same time, defaults like certificate transparency and local network protections keep tightening.
-
Apple: App Store Connect Analytics adds IAP + subscription metrics (cohorts, benchmarks, exports)
Apple refreshed App Store Connect Analytics with 100+ new monetization metrics, cohort analysis, peer benchmarks, and new exportable subscription reports.
-
Android 17’s Contact Picker: a privacy-first replacement for broad contacts permission
Android’s new Contact Picker lets apps request only the specific contact fields a user selects, helping teams avoid READ_CONTACTS for common invite/share flows.
-
Moburst: Mobile attribution in 2026 (what marketers actually need to know)
A practical snapshot of the 2026 measurement reality: iOS attribution is now AdAttributionKit-first with volume thresholds, Android still has deterministic signal (for now), and the only stable answer is a layered stack (platform postbacks + MMP SSOT + first-party + incrementality).
-
Airbridge: why ‘installs’ are not ROI, and what an MMP is actually for in 2026
Airbridge argues that the core measurement problem is trust (not data), and lays out why independent attribution plus cohort revenue is still the only sane way to make budget decisions under SKAdNetwork and signal loss.
-
Maryland’s ‘App Store Accountability Act’ idea: why blanket age verification at the store layer is risky
R Street argues Maryland HB1179 would push app stores toward broad age verification and parental consent gates, creating privacy/security risk and likely constitutional problems.
-
Feroot: CCPA for mobile apps (SDK tracking risks and the compliance gap)
A sharp reminder that ‘we passed App Store review’ is not a privacy program. Regulators increasingly expect publishers to actively govern SDK data flows, propagate opt-outs into SDK configs, and detect drift when vendors change runtime behavior.
-
App Store Connect Analytics got better in 2026, but it still won’t answer your monetization ‘why’
A credited summary of FunnelFox’s breakdown of what App Store analytics is good for (visibility, installs, high-level subs) versus what remains structurally hidden post-ATT: attribution, creative-level revenue, and the steps between install and subscription.
-
SKAdNetwork 4.0: three postbacks, lockWindow, and what to change in your measurement plan
A credited summary of Airbridge’s SKAN 4.0 explainer: multiple conversion windows, earlier postbacks via lockWindow, and new coarse conversion values (plus the trade-offs).
-
Google’s upcoming Android developer verification: why it matters for distribution
A credited summary of AdGuard’s explainer on Google’s planned developer verification scheme, and what it could change for independent distribution, alternative stores, and friction in the Android install path.
-
Apple updates age assurance tools (Declared Age Range API) for Brazil, AU/SG, Utah and Louisiana
Apple is tightening how 18+ apps are downloaded in some regions, and expanding developer signals for age assurance and significant updates.
-
Subscription growth in 2026: why install-level attribution is lying to you
Airbridge argues that subscription + AI apps should optimize channels by retention and LTV, not installs or trials, and explains where platform dashboards mislead post-ATT/SKAN.
-
Google Play’s 2025 safety numbers: 1.75M blocked apps, 80k banned dev accounts, and ‘policy-by-default’ tooling
A credited summary of Google Play ecosystem safety reporting: how pre-review checks, developer verification, AI-assisted review, and integrity signals are becoming part of shipping, not just compliance.
-
Adjust’s Mobile App Trends 2026: why integrated measurement is becoming the new baseline
A credited summary of Adjust’s Mobile App Trends 2026 report announcement: installs up, sessions up, ATT opt-ins creeping higher, and the practical shift to cross-platform (web+app) measurement.
-
Privacy Pulse: the US demand map for VPNs, password managers, authenticators & private browsers (iOS vs Android)
APPlyzer snapshot of US privacy-intent demand and the apps that capture it across iOS and Google Play.
-
Mobile analytics + consent in 2026: patterns (and anti-patterns) that keep you compliant and trusted
A practical summary of Sachith Dassanayake’s guide to privacy, consent flows, and analytics initialization in mobile apps — with a checklist you can ship.
-
Choosing a push platform in 2026: treat delivery, consent, and experimentation as one system
SashiDo’s 2026 guide is essentially a retention-team buyer checklist: reliable delivery and token hygiene, deep segmentation, journey automation with caps, and experimentation/holdouts that let you prove impact without drowning users in notifications.
-
Apple pauses Texas age assurance rollout (SB2420) after injunction, but keeps the tooling in sandbox
Apple says it will pause its previously announced Texas age assurance implementation plans after a court injunction, while leaving the Declared Age Range API + related tools available for sandbox testing.
-
Apple updated the App Review Guidelines (Nov 2025): what app marketers should actually watch
Apple clarified rules around creator apps and age-gating, brand misuse in app names/icons, HTML5 ‘mini apps’, loan APR limits, and disclosing when you share personal data with third-party AI.
-
Google Privacy Sandbox update: Chrome is retiring several APIs (and doubling down on interoperable attribution)
Google’s Oct 2025 update retires multiple Privacy Sandbox technologies and shifts focus toward an interoperable attribution standard, plus CHIPS/FedCM and anti-fraud tooling.
-
Apple: Texas SB2420 age assurance requirements (what changes for accounts, consent, and your app)
Apple outlines how Texas’ SB2420 will affect under-18 accounts (Family Sharing + parental consent) and the developer-side capabilities expected for age categories and ‘significant change’ consent flows.