Data safety

Play Data safety answers

Your answers for the AdHedge SDK in Play Console's Data safety form.

Does the SDK collect or share user data?

Yes.

Data types

Play categoryCollectedSharedEphemeralRequiredPurposes
Device or other IDsYesNoNoYesFraud prevention, security, and compliance; Analytics
App activity: in-app actionsYesNoNoYesFraud prevention, security, and compliance; Analytics
App info and performance: diagnosticsYesNoNoYesFraud prevention, security, and compliance; Analytics
Device or other IDs: Advertising ID (blocking mode with AppsFlyer or Adjust only)YesNoYesYesAdvertising or marketing; Analytics
Location: approximate locationYesNoNoYesFraud prevention, security, and compliance; Analytics

Fields the SDK sends

App and install, Install facts and Device checks are sent once per install. A field is empty when the Android version can't provide it. None of these need a permission. Behavior is the one group that is not sent once per install: it is batched, and its own table says when each field is sent.

App and install

FieldWhat it isAndroid source
Install IDA random ID the SDK creates once. Built from no device identifier.UUID in SharedPreferences
Play App Set IDScoped to your developer account. Our server hashes it on receipt and never stores it raw.AppSetIdClient
Package nameYour app's package.Context.getPackageName
Signing certificate hashSHA-256 of your app's signing certificate.PackageInfo.signingInfo
First install timeWhen your app was first installed on the device.PackageInfo.firstInstallTime
Last update timeWhen your app was last updated.PackageInfo.lastUpdateTime
App version codeThe running build.PackageInfo.getLongVersionCode
SDK versionThe AdHedge SDK version.SDK constant
Android API levelThe device's Android version.Build.VERSION.SDK_INT
Config versionWhich SDK settings were in effect.SDK config
Existing-user flagWhether your app was installed before the SDK.Install and update times
Request hashSHA-256 of these fields. Ties them to the Play Integrity token.Computed by the SDK

Install facts

FieldWhat it isAndroid source
Installer packageThe app store or package that installed your app. Empty for a sideload.installingPackageName
Package that started the installAndroid 11 and up.initiatingPackageName
Install source typeStore, local file, downloaded file or other. Android 13 and up.packageSource
Play Install Referrer stringExactly as Play returns it, up to 1,024 bytes. Holds the ad click ID when Play has one. The only free-text field.installReferrer
Referrer click timeWhen the store listing was opened from a click.referrerClickTimestampSeconds
Install start timeWhen the Play download began.installBeginTimestampSeconds
App version at installYour app version when it was first installed.installVersion
Referrer availabilityWhether Play could return a referrer.InstallReferrerClient response
Debuggable build flagWhether this build is debuggable.FLAG_DEBUGGABLE
USB debugging settingWhether USB debugging is on. Read-only.Settings.Global.ADB_ENABLED
Test-keys buildWhether the system image is signed with test keys.Build.TAGS
Work profileWhether the app runs in a managed work profile. Android 11 and up.isManagedProfile

Device checks

FieldWhat it isAndroid source
Emulator build markersWhich of 8 fixed build-string patterns match.Build.*
Root markersWhich of 4 fixed file-path and system-property checks match. No app lookups.File and property checks
Network transport typeWi-Fi, cellular, Ethernet, other or none. No SSID, BSSID or IP address.NetworkCapabilities
VPN activeWhether traffic goes through a VPN.TRANSPORT_VPN
Proxy setWhether a system HTTP proxy is set.http.proxyHost
Battery levelPercent, 0 to 100.ACTION_BATTERY_CHANGED
Charging stateWhether the device is charging.ACTION_BATTERY_CHANGED
Time since bootMilliseconds since the device started.SystemClock.elapsedRealtime
Sensor countHow many sensors the device reports. No sensor readings.SensorManager.getSensorList
SIM stateAbsent, ready, unknown or other. No number, carrier or country.TelephonyManager.getSimState
Phone typeNone, GSM, CDMA, SIP or other.TelephonyManager.getPhoneType

Play purpose for every field in this table: Fraud prevention, security, and compliance. Why each group is collected:

Why these are diagnostics under App info and performance: every one is a point-in-time value about the device's state at one install, none is a persistent identifier, and none is joined across apps. The Play App Set ID is hashed on receipt, and the install record as a whole is still declared under Device or other IDs, because Google treats a server-side device record as a device identifier whatever fields compose it.

How long they are kept: these signals 90 days, the install and its country 13 months. The IP address is kept 30 days and the network prefix 13 months, and the full address is never stored past that.

Behavior

This is the App activity group. It is the only group not sent with the install record: events are batched on the device, at most 20 of them, held at most 7 days, and posted on the SDK's background thread. Kept 90 days, like the rest of the signals. The collector runs only while tier 4 is on in the app's SDK config.

FieldWhat it isAndroid sourceSentKept
Taps in a sessionHow many touches the session had, as a number. No coordinates, no view, no content.Window.Callback, ACTION_DOWN countPer session90 days
Session lengthHow long the session lasted, in milliseconds. Tap interval variance is derived on our side from these pairs.ActivityLifecycleCallbacksPer session90 days
First-touch delayMilliseconds from process start to the first touch after install.SystemClock.elapsedRealtimeOnce90 days
Next-day returnThat the app was opened again on the day after the install day. One flag. No session count.Install day + 1, on deviceOnce90 days
Event timeThe device clock when the event happened. Our server also records when it arrived.System.currentTimeMillisPer event90 days
Conversion adapter resultWhich adapter fired the conversion and whether the vendor SDK accepted the call.Adapter return valuePer fire90 days
Late referrerThe Play Install Referrer fields above, when Play returned them after the install record was already sent.InstallReferrerClientAt most once90 days

Play purposes for this table: Fraud prevention, security, and compliance; Analytics. Why it is collected: a racked device that installs, opens once and never touches the screen looks identical to a real install in every network report. Counts and durations separate the two. Touch coordinates, view IDs, screen names and text input are never read, so the events carry nothing that could identify a person or reconstruct what they did.

How taps are counted: the SDK registers one Application.ActivityLifecycleCallbacks and wraps each Activity's Window.Callback. No listener is attached to your views, and no accessibility service is used. On the dispatch path the wrapper increments an int when the action is ACTION_DOWN and calls through to the callback that was there before, with no allocation and no I/O. A measured per-event figure on reference devices is not published yet. Mechanism and cost in full: docs.

Seen by our server

The SDK doesn't send these. Our server reads them from each request.

FieldWhat it isKept
IP addressThe address each request comes from.30 days
Network prefixThe IP address with its host part removed.13 months
Network operatorThe network the request came from and whether it is a hosting provider. Derived from the IP address.13 months
CountryDerived from the IP address and stored with the install.13 months

Purposes

Fraud prevention, security, and compliance. Analytics. The advertising ID row adds Advertising or marketing. Never personalization.

Shared

No. AdHedge processes the data on your behalf as a service provider, and Google does not count that as sharing. We don't sell it, link it across apps, or join it to personal data. The advertising ID goes only to your own AppsFlyer or Adjust account, on your instruction, and is never stored or joined to install data.

Handling

Never collected

Permissions: INTERNET and ACCESS_NETWORK_STATE only.

Play Integrity

One token per install, under a Cloud project linked to your app. No tracking across apps.