Policies

Data Collection & Store Submission

Use this page to complete Apple's App Privacy questionnaire and Google Play's Data Safety form before you submit an app that embeds the Koah SDK. It states what the SDK collects and maps each item to both stores.

What Koah collects

The SDK is contextual: it does not read the advertising identifier (IDFA / Android Advertising ID), build a cross-app or cross-site profile, or track users across apps and websites. What it sends:

DataWhat it isPurposeLinked to user?Used for tracking?
Device & app contextDevice type, manufacturer, model and marketing name (e.g. "iPhone", "Pixel 8" — never the user-assigned device name), OS name + version, app name / bundle ID / version / build, locale, emulator flag, a "location services enabled" boolean (a flag — not coordinates), user agent, and mobile radio technology (e.g. LTE, 5G). Flutter sends a smaller set: no location flag or radio technologyAd format selection, diagnostics, invalid-traffic filteringNoNo
IP address & approximate locationThe SDK reports the IP address of the device's active network interface (the Wi-Fi LAN address; on cellular, the carrier-assigned address, which can be a public IP; React Native reports the Wi-Fi address only). Koah's servers also see the public IP of the connection, as any HTTP service does. Koah resolves the request IP to an approximate location — country, region and city — with an IP-geolocation database hosted on Koah's own servers; the IP is not sent to a third-party lookup service. The SDK never reads GPS or precise coordinatesAd selection and geographic targeting, invalid-traffic filtering, aggregate reportingNoNo
Pseudonymous client IDA random per-install identifier ({uuid}--{publisherId}) generated on-device and sent as the X-Koah-State request header. Not the IDFA/AAID; not tied to a real-world identityStable session & attributionNoNo
Ad context textThe conversation / article / feed text you pass into KoahAdContextMatching a relevant adNoNo
Ad interaction & quality eventsImpressions, views, clicks (with the tap position within the ad and the ad's on-screen frame), poll votes, and user-submitted ad reports (a reason code, no free text) — each identified only by a server-issued queryExternalIdMeasurement, billing, ad qualityNoNo
Age (optional)Sent only if your app calls setAge / setAgeRange. An exact age is sent as a single-value range (age…age); a bucket is sent as its bounds. SDK versions 1.0 and later ignore any age under 13 — the setter is a no-op and an under-13 value persisted by an earlier version is discarded on upgradeDemographic targetingNoNo
Gender (optional)Sent only if your app calls setGender (male / female)Demographic targetingNoNo
Household income bracket (optional)Sent only if your app calls setIncomeBracket — an annual household income bucket in thousands of USD (0-50 … 200+)Demographic targetingNoNo

Age, gender and income bracket are the visitor attributes; the SDKs that support each are listed there.

Where the data goes

Everything above is stored in app-private on-device storage and sent to Koah's servers (app.koah.ai in production). Two things reach other hosts:

  • Ad creative. Ad images and advertiser icons load directly from the advertiser's or its CDN's host, and tapping an ad opens the advertiser's page in a browser (Chrome Custom Tabs, SFSafariViewController, or the in-app browser on React Native). Those hosts see the device's IP address and user agent, as with any web content.
  • Demand partners. To fill a request from programmatic demand, Koah's servers may pass request signals such as the user agent and device / OS type to its demand partners.

The SDK fires no third-party tracking pixels or viewability beacons and embeds no third-party analytics or crash-reporting SDKs.

Apple — App Privacy (nutrition labels)

In App Store Connect → App Privacy, declare the following for the Koah SDK. All are not linked to the user and not used for tracking.

Apple data typeMaps toPurposesNotes
Identifiers → Device IDPseudonymous client IDThird-Party Advertising, Analytics, Product PersonalizationDeclared in the bundled privacy manifest
Usage Data → Product InteractionImpressions, views, clicks, poll votes, reportsThird-Party Advertising, Analytics, Product PersonalizationDeclared in the bundled privacy manifest
Location → Coarse LocationApproximate location derived from the IP addressThird-Party Advertising, Analytics, App FunctionalityDeclared in the bundled privacy manifest
Diagnostics → Other Diagnostic DataDevice / OS / app contextApp Functionality, AnalyticsDeclared in the bundled privacy manifest; used for compatibility & invalid-traffic filtering
User Content (conditional)Ad context textThird-Party AdvertisingOnly if you pass user-authored text into KoahAdContext
Other Data Types (conditional)Age, genderThird-Party AdvertisingOnly if you call setAge / setAgeRange / setGender; not in the bundled manifest
Financial Info → Other Financial Info (conditional)Household income bracketThird-Party AdvertisingOnly if you call setIncomeBracket; not in the bundled manifest

Apple has no "IP address" data type: per its guidance you declare the data types derived from how the IP is used — here Coarse Location and Other Diagnostic Data.

Google — Play Data Safety

In the Play Console → Data safety form, declare the following. For every row: collected = Yes, not processed ephemerally, and not required to use your app.

Play data typeMaps toPurposes
Device or other IDsPseudonymous client IDAdvertising or marketing; Analytics; Fraud prevention, security, and compliance
App activity → App interactionsImpressions, views, clicks, poll votes, reportsAdvertising or marketing; Analytics
Location → Approximate locationApproximate location derived from the IP addressAdvertising or marketing; Analytics; Fraud prevention, security, and compliance
App info and performance → DiagnosticsDevice / OS / app contextApp functionality; Analytics; Fraud prevention, security, and compliance
App activity → Other user-generated content (conditional)Ad context text, if user-authoredAdvertising or marketing
Personal info → Other info (conditional)Age, gender — only if you call those settersAdvertising or marketing
Financial info → Other financial info (conditional)Household income bracket — only if you call setIncomeBracketAdvertising or marketing

The form also asks whether each type is shared. Koah processes this data as your service provider; see Where the data goes for the third-party hosts involved and answer per Google's definition of sharing.

You must also declare the com.google.android.gms.permission.AD_ID permission status. Koah does not use the Advertising ID, so if Koah is your only ads SDK you can declare that your app does not use it.

App Tracking Transparency & IDFA

You are the data controller for your users. In the EEA / UK, obtain a lawful basis (typically consent) before you initialize Koah, and gate the configure / init call behind your consent management platform (CMP). Users can request data deletion via support@koahlabs.com.

US state privacy (CCPA / CPRA and similar)

Where US state privacy laws apply, you are the business and Koah acts as a service provider / processor for the ad request. Serving ads may qualify as "sharing" for cross-context behavioral advertising under CPRA. Provide the required notice and honor consumer opt-out choices (including a "Do Not Sell or Share" mechanism) through your own consent/privacy controls, and gate Koah initialization accordingly.

Children's privacy (COPPA)

Mobile SDK versions 1.0 and later enforce the last point in code: setAge / setAgeRange ignore any age or age range that starts under 13 (including the under-13 bucket), and an under-13 value persisted by an earlier version is discarded on upgrade. Nothing is stored or sent, and no error is thrown. The JavaScript SDK does not enforce this.

Privacy manifest by SDK

Apple's PrivacyInfo.xcprivacy declares the data types Koah collects:

  • iOS — bundled automatically in the KoahAds Swift package / XCFramework.
  • React Native — bundled automatically as a CocoaPods resource bundle; picked up on pod install (RN CLI and Expo prebuild). It declares the same data types as the iOS manifest and no required-reason APIs, because the package ships no native code.
  • Flutter — koah_flutter's iOS plugin does not yet bundle a manifest. Its plugin dependencies (flutter_secure_storage, device_info_plus, package_info_plus) already ship manifests for the required-reason APIs they use; add the manifest below to your app's iOS target to also declare the data types Koah collects.

If you vendor the SDK manually (or are on Flutter), add this manifest to your app target:

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>NSPrivacyTracking</key>
    <false/>
    <key>NSPrivacyCollectedDataTypes</key>
    <array>
        <dict>
            <key>NSPrivacyCollectedDataType</key>
            <string>NSPrivacyCollectedDataTypeDeviceID</string>
            <key>NSPrivacyCollectedDataTypeLinked</key>
            <false/>
            <key>NSPrivacyCollectedDataTypeTracking</key>
            <false/>
            <key>NSPrivacyCollectedDataTypePurposes</key>
            <array>
                <string>NSPrivacyCollectedDataTypePurposeThirdPartyAdvertising</string>
                <string>NSPrivacyCollectedDataTypePurposeAnalytics</string>
                <string>NSPrivacyCollectedDataTypePurposeProductPersonalization</string>
            </array>
        </dict>
        <dict>
            <key>NSPrivacyCollectedDataType</key>
            <string>NSPrivacyCollectedDataTypeProductInteraction</string>
            <key>NSPrivacyCollectedDataTypeLinked</key>
            <false/>
            <key>NSPrivacyCollectedDataTypeTracking</key>
            <false/>
            <key>NSPrivacyCollectedDataTypePurposes</key>
            <array>
                <string>NSPrivacyCollectedDataTypePurposeThirdPartyAdvertising</string>
                <string>NSPrivacyCollectedDataTypePurposeAnalytics</string>
                <string>NSPrivacyCollectedDataTypePurposeProductPersonalization</string>
            </array>
        </dict>
        <dict>
            <key>NSPrivacyCollectedDataType</key>
            <string>NSPrivacyCollectedDataTypeCoarseLocation</string>
            <key>NSPrivacyCollectedDataTypeLinked</key>
            <false/>
            <key>NSPrivacyCollectedDataTypeTracking</key>
            <false/>
            <key>NSPrivacyCollectedDataTypePurposes</key>
            <array>
                <string>NSPrivacyCollectedDataTypePurposeThirdPartyAdvertising</string>
                <string>NSPrivacyCollectedDataTypePurposeAnalytics</string>
                <string>NSPrivacyCollectedDataTypePurposeAppFunctionality</string>
            </array>
        </dict>
        <dict>
            <key>NSPrivacyCollectedDataType</key>
            <string>NSPrivacyCollectedDataTypeOtherDiagnosticData</string>
            <key>NSPrivacyCollectedDataTypeLinked</key>
            <false/>
            <key>NSPrivacyCollectedDataTypeTracking</key>
            <false/>
            <key>NSPrivacyCollectedDataTypePurposes</key>
            <array>
                <string>NSPrivacyCollectedDataTypePurposeAppFunctionality</string>
                <string>NSPrivacyCollectedDataTypePurposeAnalytics</string>
            </array>
        </dict>
    </array>
    <key>NSPrivacyAccessedAPITypes</key>
    <array>
        <dict>
            <key>NSPrivacyAccessedAPIType</key>
            <string>NSPrivacyAccessedAPICategoryUserDefaults</string>
            <key>NSPrivacyAccessedAPITypeReasons</key>
            <array>
                <string>CA92.1</string>
            </array>
        </dict>
        <dict>
            <key>NSPrivacyAccessedAPIType</key>
            <string>NSPrivacyAccessedAPICategorySystemBootTime</string>
            <key>NSPrivacyAccessedAPITypeReasons</key>
            <array>
                <string>35F9.1</string>
            </array>
        </dict>
    </array>
</dict>
</plist>

Questions about data handling? Contact support@koahlabs.com.

Was this helpful?