WarpLink
Trust and reliability

Apple Privacy Rules and Install Matching

How WarpLink's install matching relates to Apple's tracking and fingerprinting rules, what the iOS SDK sends, and routing-only mode if a reviewer objects.

WarpLink's deferred match is first-party: it connects your own link to your own app, shares nothing with another company, and is not tracking under Apple's definition. Apple's fingerprinting guidance is a separate rule that App Review applies to each app, and routing-only mode turns off the address, language, and time zone match for teams whose reviewer or policy objects.

What the iOS SDK reads and sends

On first launch the iOS SDK sends four device values in the attribution request:

  • The device language.
  • The time zone, as an offset in minutes and as an IANA zone name.
  • The vendor identifier (IDFV), which iOS scopes to apps from your own developer account.
  • A reinstall marker, one true or false value kept in the Keychain.

The SDK reads no advertising identifier (no IDFA) and shows no App Tracking Transparency prompt. Its privacy manifest declares NSPrivacyTracking as false, lists no tracking domains, and lists two collected fields, the vendor identifier and the reinstall marker, each unlinked, not used for tracking, and collected for app functionality. The full field list and what we store from each request are on the SDK data flow page.

What a deferred match is

A deferred match finds which of your links a person tapped before they installed your app. It runs inside one customer's own setup.

  • Your link, your app. The tap is on a link in your organization. The first launch is your app.
  • One window. The first launch has to come within the link's match window, 6 hours by default and 24 at most.
  • The key. When the link is tapped, the server stores a pending entry under a keyed hash of the request address, the language, and the time zone. At first launch, the SDK's request produces the same hash if it comes from the same network in the same window. The entry expires with the window.
  • The result. The match returns the link's destination or deep link, so your app opens the right screen.

We create no device identifier in this process, and nothing is shared with any other company. We do not use the match for advertising measurement or to build a profile of a person. The hash is keyed with a secret that only the server holds, so it cannot be recomputed outside our systems. After the match, the install record keeps the same hash as its match record, under the retention rules in the privacy policy.

Apple's definitions

Apple's words, from the page User Privacy and Data Use (read 2026-10-10).

On tracking, Apple says:

Tracking refers to the act of linking user or device data collected from your app with user or device data collected from other companies’ apps, websites, or offline properties for targeted advertising or advertising measurement purposes. Tracking also refers to sharing user or device data with data brokers.

On fingerprinting, Apple's question and answer read:

Can I fingerprint or use signals from the device to try to identify the device or a user?

No. Per the Apple Developer Program License Agreement, you may not derive data from a device for the purpose of uniquely identifying it. Examples of user or device data include, but are not limited to: properties of a user's web browser and its configuration, the user's device and its configuration, the user's location, or the user's network connection. Apps that are found to be engaging in this practice, or that reference SDKs (including but not limited to Ad Networks, Attribution services, and Analytics) that are, may be rejected from the App Store.

Our assessment

This is our reading of Apple's rules. App Review decides for each app.

  • Tracking. The match links a tap on your link to a launch of your app, both inside your own setup. The match runs only inside your own organization, serves only to open the right screen, and feeds no advertising measurement or profile. By Apple's definition above, it is not tracking, which is why the SDK needs no ATT prompt.
  • Fingerprinting. Apple's rule is about deriving data from a device to identify it. The match is built to pick one pending tap, not to identify a device. The pending entry lives for the match window, at most 24 hours, and answers one tap. The hash is keyed with a secret that only our servers hold, so it cannot be recomputed outside our systems. After a match, the install record keeps that hash under the retention rules in the privacy policy. We use it to pick one pending tap from your own links, not to recognize a device across apps, sessions, or companies.

The inputs include a network connection property and a device setting, the kinds of signal Apple lists in its examples. We state that plainly. A reviewer can apply the fingerprinting rule to any SDK that reads such signals, and we cannot promise an outcome for your submission.

If your reviewer or policy says no

Routing-only mode turns off probabilistic matching for one app. The setting is per app, and you can change it at any time.

DefaultRouting-only mode
Deep links, redirects, store fallbacksWorkWork
Android Play Install Referrer matchUsedUsed
iOS vendor identifier repeat checkUsedUsed
Match from address, language, and time zoneUsedStops
Pending entry stored at tap timeA keyed hash, for the match windowNone

A first install on iOS carries no deterministic signal, so it is not matched in this mode, and the SDK receives matched: false like any other miss. You do not need an SDK change or an app release.

To turn it on, open Apps, choose your app, then Settings, then Install matching, and switch Probabilistic matching off. The same setting is the probabilistic_matching field of PATCH /v1/apps/{id}. The steps and the details of what stops are in Routing-only mode.

App Store privacy answers

Use the lists on the SDK data flow page when you complete your app's privacy questions. For the iOS SDK, the manifest declares these two types, both not linked to the user's identity, not used for tracking, and collected for app functionality:

Data typeField
Device IDThe vendor identifier (IDFV)
Other data typesThe reinstall marker

Your own app may collect more than the SDK does, so answer for the whole app. With routing-only mode on, the match stops using the address, language, and time zone. The two manifest entries stay, because the vendor identifier repeat check and the reinstall marker still run.

On this page