Skip to main content
Intempt
Browse legal and privacy documents

Apple App Privacy Guidance

Last Modified: September 26, 2026

Apple asks every App Store developer to disclose what their app collects, including what third-party SDKs collect on their behalf. This page sets out what the Intempt iOS SDK collects by default, so your team can answer Apple's privacy questions accurately. Your answers depend on how you configure the SDK and what you send it, so check them with the people who implemented it before you submit.

1. You decide what is sent

Intempt only processes the data your app sends. Most collection is off until you turn it on: screen views, taps, control changes, screen exits, raw touches, app open and background events, and install and upgrade events all default to off. The one event sent by default is a session start. Anything else reaches Intempt because you called the SDK or enabled a feature.

Intempt is not an advertising network or a data broker, and we do not sell or share your data for cross-context behavioral advertising. We process it on your instructions as your processor under our Data Processing Addendum.

2. No tracking, as Apple defines it

The SDK's privacy manifest declares NSPrivacyTracking as false and lists no tracking domains. The SDK does not read the advertising identifier (IDFA), so it never triggers an App Tracking Transparency prompt on your behalf. It does not read the identifier for vendors (IDFV) or carrier information either. If your own app links Intempt data with third-party data for advertising, that is tracking under Apple's rules and your answers must say so.

3. Location

The SDK never reads the device's location services. By default, Intempt derives country, region and city from the IP address of each request on our servers. You can turn that off by initializing the SDK with useIPAddressForGeolocation: false. Precise location is not collected, and our Acceptable Use Policy does not allow you to send it without our written approval.

4. Retention

You choose how long Intempt holds your data. Event retention and user profile retention are set separately, so an events-only source can be held for a shorter period than a source that also carries user profiles. Every level sits within the maximum set out in our Data Processing Addendum.

5. What the SDK collects by default

Mapped to the data types in Apple's App Store Connect questionnaire. This reflects the SDK with no optional features turned on and no custom data sent.

Apple data typeCollected by default?Detail
Contact InfoNoOnly if you send it, for example an email address as a user attribute.
Health and FitnessNoNot collected. Health data is prohibited without a separate written agreement.
Financial InfoNoNot collected. Payment card data is prohibited.
LocationCoarse onlyCountry, region and city derived on our servers from the request IP. Off with useIPAddressForGeolocation: false.
Sensitive InfoNoNot collected, and prohibited by our Acceptable Use Policy without written approval.
ContactsNoThe SDK never reads the address book.
User ContentNoAutocapture never reads text typed into fields, and skips secure text entry entirely.
Browsing HistoryNoNot collected on iOS.
Search HistoryNoOnly if you send search events yourself.
Identifiers: User IDYesA random Intempt profile ID generated on first launch, plus your own user ID if you call identify.
Identifiers: Device IDYesThe same random profile ID, which is scoped to the app install. Not the IDFA and not the IDFV.
PurchasesNoOnly if you send product or order events.
Usage Data: Product InteractionYesSession start and end. Screen views and taps only if you turn on autocapture.
DiagnosticsNoThe SDK has no crash reporter and sends no performance data.
Other DataDevice factsDevice model, OS version, device type, and your app's name, version and bundle ID, sent once per session.

In the SDK's privacy manifest, each collected type is declared as linked to the user, not used for tracking, and used for analytics. If you use Intempt to message users through journeys or push, add Developer's Advertising or Marketing and App Functionality as purposes in your own answers.

6. Push notifications

If you pass the SDK an APNs device token, it is sent as an attribute on that user's profile so you can send push messages to the device. Opens and receipts are only recorded when you call the SDK's push tracking methods.

7. Required reason APIs

The SDK's privacy manifest declares two required reason APIs:

  • User defaults (CA92.1): to store the SDK's own identifiers and settings, readable only by your app.
  • Disk space (E174.1): to check free space before writing queued events to the device.

8. Opting users out

Call optOut() to stop collection for a user, optIn() to resume, and hasOptedOut() to check the current state. Opt-out applies to every event the SDK sends, including automatic ones. To delete data you already hold, submit an erasure request from the Privacy Center in the console or through the API. See our GDPR and CCPA pages for how those requests work.

9. Where the data lives

Intempt hosts customer data in the United States only. See Data Residency for how international transfers are handled.

Questions: privacy@intempt.com | Intempt Technologies LLC, 1101 W 34th St #595, Austin, TX 78705