What the SDK sends
- The app and device: bundle id, version, build UUID, OS name and version, device model
(for example
iPhone16,1), and the SDK’s name and version. - Sessions: a random session id, start and end, outcome.
- Failures: crash reports, hangs, terminations without a crash report, and the handled errors your code records, with their stacks.
- Performance: app start and screen load times, MetricKit reports, and network requests: method, URL without the query string or fragment, host, status code and duration.
- What your code adds: logs, breadcrumbs, spans, attributes, feature flags and the user hash.
What stays on the phone
- Request and response bodies, query strings and URL fragments.
- Advertising and vendor identifiers: the SDK never reads the IDFA or the IDFV.
- Emails and names: the SDK never collects them on its own. Do not put them in logs or attributes either.
The user hash
setUser(idHash:) identifies the user with a value you compute, such as a SHA-256 of your
own user id. Apsio never sees the id itself. See Users and attributes.
The installation id
To count users, not only sessions, the SDK keeps a random id per install of your app:- generated on first launch and reset when the app is reinstalled;
- never derived from the IDFV, the IDFA or any other device identifier, and never shared with other apps, so it is not tracking under App Tracking Transparency;
- on by default. Turn it off with
ApsioOptions(installationId: false); release health then shows crash-free sessions only.
Consent
Apsio.setConsent(false) stops collection and deletes what is waiting to be sent;
setConsent(true) resumes it. The choice is kept across launches. If your app must ask
before anything is collected, call start only after the user agrees. See
Privacy and consent in the iOS SDK.
App Store privacy labels
Each module of the iOS SDK ships a privacy manifest (PrivacyInfo.xcprivacy). It declares
crash data, performance data, other diagnostic data and a device ID, none of them linked to
the user or used for tracking, for app functionality and analytics. The SDK uses no
required-reason API.
In your App Store privacy label:
- declare crash data, performance data and other diagnostic data;
- if you keep the installation id on, declare a device ID used for analytics, not linked to the user and not used for tracking;
- if you call
setUser, the data is linked to a user: declare a user ID and mark the data as linked.