> ## Documentation Index
> Fetch the complete documentation index at: https://docs.apsio.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy and consent

> What the SDK sends, what stays on the phone, the installation id, consent and App Store privacy labels.

What leaves the phone is decided on the phone: the SDK leaves out what Apsio does not need
before anything is sent.

## What the SDK sends

* **The app and device:** bundle id, version, build UUID, OS name and version, device model
  (for example `iPhone16,1`), and the SDK's name and version.
* **Sessions:** a random session id, start and end, outcome.
* **Failures:** crash reports, hangs, terminations without a crash report, and the handled
  errors your code records, with their stacks.
* **Performance:** app start and screen load times, MetricKit reports, and network requests:
  method, URL without the query string or fragment, host, status code and duration.
* **What your code adds:** logs, breadcrumbs, spans, attributes, feature flags and the user
  hash.

## What stays on the phone

* Request and response bodies, query strings and URL fragments.
* Advertising and vendor identifiers: the SDK never reads the IDFA or the IDFV.
* Emails and names: the SDK never collects them on its own. Do not put them in logs or
  attributes either.

Apsio does not store the IP address a request comes from.

## The user hash

`setUser(idHash:)` identifies the user with a value you compute, such as a SHA-256 of your
own user id. Apsio never sees the id itself. See [Users and attributes](/sdks/ios#users-and-attributes).

## The installation id

To count users, not only sessions, the SDK keeps a random id per install of your app:

* generated on first launch and reset when the app is reinstalled;
* never derived from the IDFV, the IDFA or any other device identifier, and never shared with
  other apps, so it is not tracking under App Tracking Transparency;
* on by default. Turn it off with `ApsioOptions(installationId: false)`; release health then
  shows crash-free sessions only.

## Consent

`Apsio.setConsent(false)` stops collection and deletes what is waiting to be sent;
`setConsent(true)` resumes it. The choice is kept across launches. If your app must ask
before anything is collected, call `start` only after the user agrees. See
[Privacy and consent in the iOS SDK](/sdks/ios#privacy-and-consent).

## App Store privacy labels

Each module of the iOS SDK ships a privacy manifest (`PrivacyInfo.xcprivacy`). It declares
crash data, performance data, other diagnostic data and a device ID, none of them linked to
the user or used for tracking, for app functionality and analytics. The SDK uses no
required-reason API.

In your App Store privacy label:

* declare crash data, performance data and other diagnostic data;
* if you keep the installation id on, declare a device ID used for analytics, not linked to
  the user and not used for tracking;
* if you call `setUser`, the data is linked to a user: declare a user ID and mark the data as
  linked.

## Remote limits

The [remote configuration](/remote-configuration) can narrow what devices collect without a
release, and never widen it. See [Privacy and security](/privacy-and-security) for where data
is stored and who can read it.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.