---
title: "iOS Tracking - ATT, Privacy Manifests, Safari | EdgeAngel"
description: "iOS Tracking experts: App Tracking Transparency, sequencing with the CMP, Privacy Manifests, Link Tracking Protection. We adapt your collection to Apple."
url: https://edgeangel.co/en/data-foundations/ios-tracking
lang: en
---

> Site index for agents, read it before exploring further : https://edgeangel.co/llms.txt
> Canonical HTML page, which also carries the diagrams and visuals : https://edgeangel.co/en/data-foundations/ios-tracking

[Other tools](https://edgeangel.co/en/data-foundations/app-tracking#approche-c4)

# iOS Tracking experts

## Keep measuring on iOS, within the framework set by Apple.

ATT, Privacy Manifests, SKAdNetwork, Link Tracking Protection: we adapt your collection and your attribution to Apple's rules, in the app and on Safari.

[Book a discovery call](https://edgeangel.co/en/data-foundations/ios-tracking#contact)

-   Learn more about: [our mobile app tracking agency and iOS Tracking](https://edgeangel.co/en/data-foundations/app-tracking)
-   Learn more about: [our tracking and analytics agency, web measurement under Safari](https://edgeangel.co/en/data-foundations/web-tracking)

[Scroll to the content](https://edgeangel.co/en/data-foundations/ios-tracking#expertise)

EdgeAngel iOS Tracking expertise

## Hold Apple's framework, keep the first-party data, measure in hybrid

01

### App Tracking Transparency audit and compliance

The ATT prompt, what it covers, and everything the app has to declare around it.

-   **ATT framework implementation**: the four statuses, the purpose string, the call at the right moment of the app, and the status re-read at each launch
-   **Sequencing with the CMP**: Apple's prompt and the GDPR consent collection in [Didomi](https://edgeangel.co/en/data-foundations/didomi) or your CMP, in the order the App Store accepts, without asking again after a refusal
-   **Explanation screen**: what Apple allows before the prompt, transparent and without incentive, and what it forbids, gating a feature behind consent
-   **Privacy Manifests and third-party SDKs**: the app's privacy file, the reasons for accessing sensitive APIs, the declared tracking domains, and the inventory of SDKs that carry one
-   **App Store listing**: the App privacy details aligned with the actual collection, at each version

02

### First-party data strategy

The data you collect yourself replaces the identifier Apple took away.

-   **Own identifiers**: the IDFV for your apps, the pseudonymous user ID after login, set in the tagging plan and never shared in clear
-   **Email and account collection**: the journeys that give a reason to sign in, measured and improved
-   **CRM activation**: Customer Match, Meta audiences and enhanced conversions fed from your hashed data, with consent
-   **Warehouse**: first-party data gathered in BigQuery with [our Modern Data Stack offer](https://edgeangel.co/en/data-foundations/modern-data-stack), the source of audiences and reports

03

### Hybrid measurement and modelling

What is consented is measured, what is not is modelled or aggregated, and both are read together.

-   **Google Consent Mode on iOS**: consent signals passed to Firebase and Google Ads, modelled conversions for users who decline
-   **SKAdNetwork and AdAttributionKit**: Apple's aggregated attribution for install campaigns, detailed on [the SKAdNetwork page](https://edgeangel.co/en/data-foundations/skadnetwork)
-   **gbraid and wbraid parameters**: measuring Google Ads clicks from and to an iOS app without GCLID, and Private Click Measurement for web clicks
-   **Server-side collection**: [sGTM for Apps](https://edgeangel.co/en/data-foundations/gtm-sgtm) and web server-side tagging, to control what goes to each destination
-   **MMP**: [Adjust](https://edgeangel.co/en/data-foundations/adjust) or AppsFlyer to bring consented attribution, Apple postbacks and modelling into a single report

The tool

## Tracking on iOS, our reading

Since **26 April 2021 and iOS 14.5**, an app that wants to link its users' data with other companies' data, for advertising or its measurement, must ask through the **App Tracking Transparency** prompt. Without authorisation, the IDFA advertising identifier is all zeros. Since iOS 17, the tracking domains declared in the app's **Privacy Manifest** are blocked until the user accepts, and since 1 May 2024 the App Store rejects an app whose listed SDKs lack their manifest.

On the Safari side, **Intelligent Tracking Prevention** has blocked third-party cookies since March 2020 and caps script-written storage at 7 days; **Link Tracking Protection** strips tracking parameters from links in Mail, Messages and Private Browsing since iOS 17; Safari 26 denies known tracking scripts the APIs used for fingerprinting since September 2025. On **16 September 2026**, Apple announced an alternative ATT prompt in the European Union with iOS 27.2, mandatory in France: the form changes, the scope of tracking subject to permission stays the same.

Updated September 2026

### What Apple's framework does very well: a stable rule, and a lot that stays measurable

The rule fits in one sentence: linking a user's data with another company's requires their permission, once, and the app lives with the answer. It has not moved since 2021, and that is what makes it possible to build on. **What stays measurable without authorisation is wider than people say**: events and conversions in Firebase and Google Analytics, the IDFV identifier for your own apps, the aggregated attribution of SKAdNetwork and AdAttributionKit, the web click through Private Click Measurement. Apple documents it in black and white, and the work starts there.

### What ATT really is: an Apple permission, next to GDPR consent

The ATT prompt is not consent in the sense of the GDPR or the TCF framework, and Didomi like the other CMPs writes it: a European app carries both, Apple's prompt and the consent banner. The order matters. Apple refuses that you ask again after a refusal, and that you gate a feature behind acceptance; it allows an explanation screen before the prompt, provided it is transparent. **The sequencing between the CMP and the prompt is therefore a compliance and an experience decision at once**, which we take with your product and legal teams, and which we QA on a test build. The European prompt of iOS 27.2 reopens the subject in 2026: we follow its rollout.

[Didomi, the CMP in the app](https://edgeangel.co/en/data-foundations/didomi)

### Where the framework stops, and what we build instead

What disappeared is the identifier shared across companies, and with it device-level attribution for users who decline. Nothing replaces it identically, and that is not the goal. **What we build instead rests on four sources**: the first-party data of your accounts and your CRM, the ad platforms' modelling fed by Consent Mode and the gbraid and wbraid parameters, Apple's aggregated attribution read in the MMP, and a warehouse that brings it all together. To arbitrate a budget between two channels, an incrementality test decides, and our Advanced Media Measurement offer runs it.

[Our Advanced Media Measurement offer](https://edgeangel.co/en/marketing-activation/advanced-media-measurement)

Sources : [User privacy and data use, App Store, Apple](https://developer.apple.com/app-store/user-privacy-and-data-use/) · [Tracking prevention in WebKit, the policy and its mechanisms](https://webkit.org/tracking-prevention/)

Our expert notes : [Apple's Link Tracking Protection on iOS 17 and Safari 17](https://edgeangel.co/en/notes/ios-17-et-safari-17-link-tracking-protection-dapple-quels-impacts-sur-le-tracking) · [Google Ads, the wbraid and gbraid parameters](https://edgeangel.co/en/notes/google-ads-nouveaux-paramtres-wbraid-et-gbraid-pour-le-suivi-des-conversions) · [AdAttributionKit, ad campaign tracking on iOS 18](https://edgeangel.co/en/notes/adattributionkit-linnovation-dans-le-suivi-des-campagnes-publicitaires-sur-ios-18)

## Frequently asked questions about iOS tracking

### What is App Tracking Transparency (ATT)?

Apple's framework, mandatory since iOS 14.5 in April 2021, which requires an app to ask permission before linking the user's data with other companies' data, for advertising or its measurement. Without authorisation, the IDFA advertising identifier is all zeros and, since iOS 17, the declared tracking domains are blocked.

### How do you measure conversions if the user declines tracking?

By combining what remains: the app's events in Firebase or Piano, which ATT does not touch; the aggregated attribution of SKAdNetwork and AdAttributionKit for installs; the modelled conversions of Google Ads and Meta, fed by Consent Mode and the gbraid and wbraid parameters; and your first-party data, accounts and CRM. The MMP and the warehouse bring them together.

### What is the impact of iOS 17 on link tracking?

Link Tracking Protection strips known tracking parameters from links opened from Mail, Messages and Safari Private Browsing, and can extend to all browsing through a setting. Click attribution loses identifiers; UTM parameters and server-side tracking remain, and Private Click Measurement, now Web AdAttributionKit, measures the click without cookies.

### Is the ATT prompt enough as GDPR consent?

No. ATT is an Apple permission on linking data across companies; GDPR consent covers processing purposes, and it is collected in a CMP. An app in Europe carries both, sequenced in an order the App Store accepts, without asking again after an ATT refusal. The QA verifies that no event subject to consent leaves before it.

### What does the alternative ATT prompt announced for Europe change?

Apple announced it on 16 September 2026 for iOS 27.2, mandatory in France, Germany, Italy, Poland and Romania: a full-page sheet, a richer purpose text, and the possibility to ask again one year after the answer. The scope of tracking subject to permission does not change. We update the prompt and its QA as soon as it ships.

Contact

## You leave your details, we get back to you within 24 hours.

A first call to understand your context, and tell you what is feasible and under which conditions.

1.  Contact details
2.  Defining your need
3.  Then we schedule a call

Your details are used to reply to you on this topic. [Data protection policy](https://edgeangel.co/en/a-propos/politique-de-protection-des-donnes)

Or call us directly: [+33 1 84 16 42 20](tel:+33184164220)

Paul Schmitt

Consulting Director

"Our goal is to make your data actionable to generate concrete value, quickly."

[The team](https://edgeangel.co/en/a-propos/agence)

```json
{"@context":"https://schema.org","@type":"Organization","name":"EdgeAngel","url":"https://edgeangel.co","logo":"https://edgeangel.co/assets/brand/edgeangel-logo.svg","sameAs":["https://www.linkedin.com/company/edgeangel"],"contactPoint":{"@type":"ContactPoint","email":"hello@edgeangel.co","telephone":"+33 1 84 16 42 20","contactType":"customer service"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://edgeangel.co/en"},{"@type":"ListItem","position":2,"name":"Data Foundations","item":"https://edgeangel.co/en/data-foundations"},{"@type":"ListItem","position":3,"name":"App Tracking","item":"https://edgeangel.co/en/data-foundations/app-tracking"},{"@type":"ListItem","position":4,"name":"iOS Tracking","item":"https://edgeangel.co/en/data-foundations/ios-tracking"}]}
{"@context":"https://schema.org","@type":"Service","name":"iOS Tracking - ATT, Privacy Manifests, Safari | EdgeAngel","description":"iOS Tracking experts: App Tracking Transparency, sequencing with the CMP, Privacy Manifests, Link Tracking Protection. We adapt your collection to Apple.","provider":{"@type":"Organization","name":"EdgeAngel","url":"https://edgeangel.co"},"areaServed":"France","url":"https://edgeangel.co/en/data-foundations/ios-tracking"}
{"@context":"https://schema.org","@type":"FAQPage","mainEntity":[{"@type":"Question","name":"What is App Tracking Transparency (ATT)?","acceptedAnswer":{"@type":"Answer","text":"Apple's framework, mandatory since iOS 14.5 in April 2021, which requires an app to ask permission before linking the user's data with other companies' data, for advertising or its measurement. Without authorisation, the IDFA advertising identifier is all zeros and, since iOS 17, the declared tracking domains are blocked."}},{"@type":"Question","name":"How do you measure conversions if the user declines tracking?","acceptedAnswer":{"@type":"Answer","text":"By combining what remains: the app's events in Firebase or Piano, which ATT does not touch; the aggregated attribution of SKAdNetwork and AdAttributionKit for installs; the modelled conversions of Google Ads and Meta, fed by Consent Mode and the gbraid and wbraid parameters; and your first-party data, accounts and CRM. The MMP and the warehouse bring them together."}},{"@type":"Question","name":"What is the impact of iOS 17 on link tracking?","acceptedAnswer":{"@type":"Answer","text":"Link Tracking Protection strips known tracking parameters from links opened from Mail, Messages and Safari Private Browsing, and can extend to all browsing through a setting. Click attribution loses identifiers; UTM parameters and server-side tracking remain, and Private Click Measurement, now Web AdAttributionKit, measures the click without cookies."}},{"@type":"Question","name":"Is the ATT prompt enough as GDPR consent?","acceptedAnswer":{"@type":"Answer","text":"No. ATT is an Apple permission on linking data across companies; GDPR consent covers processing purposes, and it is collected in a CMP. An app in Europe carries both, sequenced in an order the App Store accepts, without asking again after an ATT refusal. The QA verifies that no event subject to consent leaves before it."}},{"@type":"Question","name":"What does the alternative ATT prompt announced for Europe change?","acceptedAnswer":{"@type":"Answer","text":"Apple announced it on 16 September 2026 for iOS 27.2, mandatory in France, Germany, Italy, Poland and Romania: a full-page sheet, a richer purpose text, and the possibility to ask again one year after the answer. The scope of tracking subject to permission does not change. We update the prompt and its QA as soon as it ships."}}]}
```
