Skip to Content
DocumentationPrivacy & Compliance

Privacy & Compliance

AttributeHQ is designed with privacy in mind, supporting GDPR, ATT, and data minimization principles.

Data Collection

What We Collect

DataPurposePlatformStorage
IP addressFingerprinting, geolocationAllServer-side (anonymized)
User-AgentFingerprinting, device typeAllServer-side
Screen resolutionFingerprintingAllSent on install only
TimezoneFingerprintingAllSent on install only
LanguageFingerprintingAllSent on install only
IDFADeterministic attributioniOSWith ATT permission
GAIDDeterministic attributionAndroidIf not opted out
Install ReferrerDeterministic attributionAndroidOne-time read
Custom eventsAnalyticsAllEncrypted at rest

What We Don’t Collect

  • Browser history or bookmarks
  • Contacts or phone numbers
  • Photos or media
  • Location (GPS/fine location)
  • SMS or call logs
  • Cookies from other domains
  • Form inputs or passwords
  • DOM content

IP Anonymization

IP addresses are anonymized during fingerprint matching:

  • IPv4: Last octet zeroed (e.g., 192.168.1.42192.168.1.0)
  • IPv6: Last 80 bits zeroed

The original IP is used only for the initial fingerprint hash calculation, then discarded. The hash is one-way (SHA-256) and cannot be reversed.

ATT (iOS 14+)

On iOS 14+, the SDK requests App Tracking Transparency permission before accessing the IDFA. If the user denies:

  • No IDFA is collected
  • Attribution falls back to fingerprint matching
  • SKAdNetwork still provides privacy-preserving attribution

Data Retention

Data TypeRetentionStorage
Click records7 daysDynamoDB (TTL auto-delete)
Event data90 daysClickHouse
Raw events90 days hot, 2 years archiveS3 → S3 Glacier
Attribution resultsIndefinitePostgreSQL
SDK localStorageUntil cleared by userClient-side

GDPR Compliance

  • Lawful basis: Legitimate interest (attribution for business analytics)
  • Data minimization: Only data necessary for attribution is collected
  • Purpose limitation: Data used solely for attribution and analytics
  • Storage limitation: Automatic TTL-based cleanup
  • Data subject rights: Users can clear localStorage to remove client-side data
  • Encryption: All data transmitted over HTTPS, encrypted at rest in AWS

No Third-Party Sharing

AttributeHQ does not sell or share user data with third parties. Postbacks to ad networks contain only the device ID and attribution metadata — no personal information.

Self-Hosted Option

For maximum data control, AttributeHQ can be self-hosted on your own AWS infrastructure. All data stays within your AWS account and VPC.