If you're a mobile developer, you probably use a Mobile Measurement Partner (MMP) for attribution and deep linking. AppsFlyer, Branch, Adjust.
You installed their SDK, set up your links, and moved on. The attribution works. The deep links work. You don't think about it.
But have you actually read their privacy policies? I did. Here's what I found.
From AppsFlyer's privacy policy: AppsFlyer collects "name, email, contact details or any other personal content that you provide", along with "browser type, operating system, device type, IP address" and detailed usage data including "pages you visited, where you clicked, searches performed."
They also track email engagement: "whether you receive, opened or clicked on any links in an email."
And they do it through a broad set of tracking technologies: "cookies and other similar technologies (e.g. HTML5 Local Storage, LSO, web beacons, JavaScript, etc.)"
That's a lot of data for an attribution provider. But the collection isn't the problem. The sharing is.
AppsFlyer shares your users' data with:
Ad networks -- their policy explicitly states they use "third-party marketing and advertising networks" to help market their products, including "remarketing ads across the Internet by Google."
Resellers, agents, and partners -- data goes to "AppsFlyer resellers, agents, partners or service providers acting on our behalf."
Aggregate data publishing -- they may "publish general aggregate and unidentifiable information relating to use of its Marketing Platforms."
International transfers -- your data gets transferred "to countries where we and/or our service providers operate" using Standard Contractual Clauses.
Your app's user data flows from your app, through AppsFlyer's servers, to ad networks and marketing partners. Your users didn't consent to that. You probably didn't either, you consented to attribution, not to becoming a data source for Google remarketing campaigns.
AppsFlyer's policy includes an interesting California-specific statement: "We do not 'Sell'... your personal information which we have collected."
Note the quotes around "Sell." Under California law (CCPA), "sell" has a specific legal definition that excludes certain types of data sharing. Sharing data with ad networks for remarketing may not count as "selling" under CCPA, even though your users' data still ends up in the hands of ad networks. The legal definition protects AppsFlyer. It doesn't protect your users.
"We will only retain your Personal Information for as long as necessary to pursue the purpose of the collection." And for marketing data specifically: "when we use your information for direct marketing purposes, we will retain your data until you opt-out."
Translation: forever, unless your users actively find and use the opt-out.
Branch goes deep on device identifiers. From their privacy policy:
Advertising IDs: GAID, IDFA, IDFV, Android ID, RIDA
IP addresses and full device fingerprints
A "Branch Cookie ID" -- their own cross-session tracking identifier
Device specs down to "CPU type, connection type, locale"
Branch is more transparent about what they DON'T collect: "We do not collect or store information such as names, email addresses, physical addresses, or SSNs."
But look at who gets the data they DO collect.
Branch shares your users' data with:
Ad networks -- they share data with "ad networks or vendors used by our Clients." This means the ad network ecosystem gets your device-level attribution data.
A list of sub-processors -- Branch maintains a list of vendors that process customer personal data on their behalf. That's a lot of hands touching your users' data.
Limit Ad Tracking pass-through -- a user's Limit Ad Tracking preference is "passed through from Branch to ad networks, and the ad network can then decide whether or not to target the user." Read that carefully: Branch tells the ad network your user wants to opt out, and then the ad network decides whether to respect it.
And then there's this:
"De-identified and/or aggregated data" -- Branch explicitly states they may share this "for any purpose"and "may also disclose such data to any other parties, including business partners, Clients, and/or others."
"Any other parties" and "any purpose." That's not buried in legal fine print. That's their stated policy for de-identified data. And "de-identified" is doing a lot of heavy lifting in that sentence -- research has repeatedly shown that de-identified data can often be re-identified, especially when combined with other datasets.
Branch markets itself as privacy-forward. Their blog talks about avoiding fingerprinting and using "securely shared, privacy-preserving aggregated data." They're a member of the Network Advertising Initiative (NAI).
But membership in an industry self-regulatory body doesn't change what the privacy policy says. And the privacy policy says "any other parties, for any purpose."
In 2021, Adjust was acquired by AppLovin one of the largest mobile ad networks in the world. Adjust had an estimated ARR near $150M at the time.
Think about what this means: your attribution provider, the company that sees every install, every in-app event, every conversion in your app, is now a wholly-owned subsidiary of a company that makes money selling ads.
The conflict of interest is structural, not incidental. AppLovin bought Adjust because attribution data is strategically valuable for an ad network. As Mobile Dev Memo analyzed, Adjust gives AppLovin visibility into "which networks, and which source apps, drive conversions for their clients", competitive intelligence that directly benefits AppLovin's own advertising business.
The same analysis raised the possibility that if "Applovin's owned-and-operated properties store data in a proprietary data warehouse, and Applovin's wholly-owned Adjust property has access to that data", then the line between attribution data and ad targeting data effectively disappears.
In 2021, Apple temporarily banned apps using the Adjust SDK for fingerprinting practices -- collecting device data to uniquely identify users in violation of Apple's App Tracking Transparency (ATT) policy. Apple has been explicit: fingerprinting contravenes ATT policy, regardless of whether you call it "probabilistic matching."
In 2025, the SEC opened a formal investigation into AppLovin's data collection practices. The probe, led by the SEC's Cyber and Emerging Technologies unit, focuses on whether AppLovin systematically violated platform partners' service agreements.
According to a short seller report by Muddy Waters, AppLovin allegedly collected third-party platform identifiers from Meta, Google, Snap, TikTok, Reddit, and Shopify to construct what they call "Persistent Identity Graphs" (PIGs), unified digital profiles stitched together from data obtained across platforms.
The report states: "Code reveals AppLovin's collection of Facebook, Google, Snap, Reddit, as well as other platforms' IDs."
This allegedly violates Meta's terms ("the collecting or storage of any data obtained from any Ad" is prohibited) and Apple's policy (apps cannot "derive data from a device for the purpose of uniquely identifying it").
AppLovin's stock dropped 20% on the day the report was published. The SEC investigation is ongoing.
If you use Adjust, your attribution data flows to a company that:
Operates one of the largest mobile ad networks in the world
Had its SDK banned by Apple for fingerprinting
Is under SEC investigation for data collection practices
Allegedly builds cross-platform identity graphs from data collected across Meta, Google, Snap, and more
You're paying for attribution, you might also be fueling an ad network's targeting machine.
Every traditional MMP follows the same model:
Your app installs their SDK
The SDK collects device identifiers, IP addresses, and behavioral data
That data flows to the MMP's servers (usually in the US)
The MMP shares data with ad networks, partners, and "de-identified" aggregators
You pay for the privilege
Your App Users
|
v
MMP SDK (collects device IDs, IP, behavior)
|
v
MMP Servers (US-based)
|
+---> Ad Networks (remarketing, retargeting)
+---> "Business Partners"
+---> "De-identified" aggregators
+---> "Any other parties, for any purpose"
This is the business model. Attribution is the product you buy. Data is the product they sell.
If your app has EU users, you need a legal basis for every data flow. Did your privacy policy disclose that your MMP shares device-level data with ad networks? Did your users consent to that specific flow?
Under GDPR, consent must be specific, informed, and freely given. "We use analytics tools" in your privacy policy doesn't cover "we send your device ID to an ad network owned by AppLovin so they can build cross-platform identity graphs." If your consent flow doesn't specifically cover your MMP's data sharing, you have a compliance gap.
The fines are not theoretical. GDPR enforcement has resulted in penalties exceeding 4 billion euros since 2018, with increasing focus on adtech data flows.
Your users downloaded your app, not AppsFlyer's. They don't know their install event, device ID, and behavior data are being processed by a third party and shared with ad networks. When users discover this, it erodes trust in your app, not in the MMP they've never heard of.
You're running a closed-source SDK in your app. You can't audit what it actually sends because the code is proprietary. You trust the privacy policy, but the privacy policy says "any other parties, for any purpose."
If Apple or Google changes their privacy enforcement (as Apple did with ATT), you're dependent on your MMP to comply. If they don't, as happened when Apple banned the Adjust SDK, your app is the one at risk.
Traditional MMPs charge $15,000-$50,000+ per year. You're paying for attribution. But you're also paying with your users' data, which the MMP monetizes through ad network partnerships, data aggregation, and cross-platform identity building. You're the customer and the product.
AppsFlyer (MMP) | Branch (MMP) | Adjust (MMP) | Grovs (not an MMP) | |
|---|---|---|---|---|
Data shared with ad networks | Yes | Yes | Parent company IS an ad network | No. Not partnered with any. |
Data shared with "partners" | Yes -- resellers, agents, partners | Yes -- "any other parties, any purpose" | AppLovin ecosystem | No partners. No sharing. |
Cross-network attribution | Yes (that's the product) | Yes | Yes | No. First-party only. |
Attribution method | Probabilistic (fingerprinting) | Probabilistic | Probabilistic | Deterministic only |
SDK source code | Closed | Closed | Closed | Open source (MIT) |
Data location | US servers | US servers | US/AppLovin infra | EU-hosted |
Owner | Public adtech company | Venture-backed | AppLovin (ad network) | Independent, bootstrapped |
SEC investigation | No | No | Parent company, yes | No |
Annual cost (100K MAU) | $15,000+ | "Contact sales" | "Contact sales" | $2160/year |
The reason MMPs share your data is structural. They're called "Mobile Measurement Partners" because they sit between you and the ad networks. That's the whole business, they partner with Facebook, Google, TikTok, and dozens of other ad networks, and your users' data flows through those partnerships. The data sharing isn't a bug. It's the service.
So the fix isn't finding a better MMP. It's asking whether you need one at all.
Most apps need deep linking, install attribution, campaign analytics, and revenue tracking. MMPs do that, but they also distribute your install data to ad networks. Grovs does the same thing, including cross-network attribution via custom links, with first-party deterministic data that stays yours. EU-hosted, open-source, no black boxes.
That's what we built with Grovs. It's not an MMP. It's a first-party attribution and deep linking platform. The data flow looks like this:
Your App Users
|
v
Grovs SDK (collects device ID, IP)
|
v
Grovs Cloud (EU-hosted, your data only)
|
v
Your Dashboard (only you see this data)
|
+---> Ad Networks? No. We're not partnered with any.
+---> Business Partners? No. We don't have any.
+---> Data brokers? No.
+---> "Any other parties"? No.
Your data never leaves the loop between your app and your dashboard. There's nowhere else for it to go. We're not partnered with ad networks. We don't do cross-network attribution. We don't do probabilistic matching. We don't need to, and neither do most apps.
We make money from your subscription, no ad network to feed, no venture investors pushing us to monetize data, no parent company that sells ads. We're an independent, bootstrapped company. Your data has zero value to us beyond making your dashboard work.
Grovs gives you everything most apps actually use an MMP for, without the data sharing:
Deep linking with deferred deep links (iOS, Android, web). Links survive the install flow.
Deterministic attribution -- first-party, no fingerprinting, no probabilistic guessing. Know exactly where every install came from.
Revenue tracking (IAP, subscriptions, MRR, LTV, churn) -- included in all plans, not gated behind enterprise pricing.
Campaign analytics (real-time dashboards, campaign comparison, referral tracking)
Push notifications (APNs, FCM)
All EU-hosted. All first-party. Starting at $1.99 per 1,000 MAU with a free tier up to 10,000 MAU. No "contact sales." No opaque enterprise pricing. 20M+ daily active users run through Grovs in production today.
The entire attribution engine is open source on GitHub. MIT licensed. You can read every line, audit every data flow, and confirm there is no third-party data sharing anywhere in the codebase. If you don't want to trust anyone, you can self-host the entire platform for free.
More articles you might find useful