What's Inside the Report
- 57 SDKs carrying App Store Terms of Service Violation Risk, transmitting precise location off-device without declaring it in their privacy manifest, across iOS and Android
- 33 SDKs carrying FTC Section 5 Violation Risk, collecting or transmitting precise location without disclosing it in their privacy policy, or publishing no privacy policy at all
- Apps and developers at risk, including how many apps and developers are affected by each risk type, broken down by platform
- Country-level breakdowns showing where at-risk app publishers are registered
- Genre-level breakdowns of at-risk apps
Learn more → Explore Pixalate’s Ad SDK Trust Index 1.0
Pixalate's Methodology: Ad SDK Trust Index 1.0
The SDK Trust Index is a quarterly reference of mobile advertising and analytics SDKs ranked by observable risk against two distinct compliance regimes: the FTC Act, Section 5, and the published guidelines of the Apple App Store and Google Play. Each SDK in the Index is evaluated on three precise-location signals — privacy policy declaration, manifest file declaration, and code-level collection (with associated transmission behavior) — and assigned two outputs: FTC Section 5 Violation Risk (Critical Risk Detected or Not Detected) and App Store ToS Violation Risk (Critical Risk Detected or Not Detected).
The Index covers SDKs distributed on Android and iOS. The same SDK package is rated separately on each operating system because the disclosure surfaces, manifest formats, and runtime permission models differ between the two platforms. An SDK can carry different ratings on iOS than on Android.
Learn more → Read the methodology behind Pixalate's Ad SDK Trust Index 1.0
Why SDK behavior matters
An SDK that collects regulated data and transmits it to third parties without matching disclosure exposes three parties at once: the publisher embedding the SDK, the SDK vendor itself, and the end users whose data is being collected. Publishers and SDK vendors may face direct enforcement risk as well as app store terms-and-conditions violation risk.
Three-Layer Audit
Each SDK is evaluated across three sources: (1) its public privacy policy, reviewed manually for location disclosure language; (2) its bundled manifest file — Apple's PrivacyInfo.xcprivacy or the Android merged manifest — examined for declared location capabilities; and (3) its compiled source code, analyzed for precise location collection and off-device transmission. The gap between what the code does and what each disclosure surface says is the basis for both risk indicators.
FTC Section 5 Risk
Reflects exposure under the FTC Act's prohibition on unfair or deceptive acts or practices. Driven primarily by inconsistency between the SDK vendor's privacy policy (the consumer-facing surface) and the SDK's actual data behavior in code. An undisclosed collection or undisclosed off-device transmission constitutes deception. FTC Section 5 Violation Risk is rated Critical Risk Detected when either condition is present, and Not Detected otherwise.
App Store ToS Violation Risk
Reflects exposure under the published guidelines of the Apple App Store and Google Play. Driven primarily by inconsistency between the SDK's manifest-file declarations (the platform-facing surface — Apple's PrivacyInfo.xcprivacy, Android's merged manifest, and the host app's Data Safety form) and the SDK's actual data behavior. App Store ToS Violation Risk is rated Critical Risk Detected when code analysis confirms precise location data is packaged into network-bound payloads (ad requests, event uploads) that can leave the SDK without matching manifest declaration, and Not Detected otherwise.
Why Both Matter
An SDK can carry serious FTC exposure with minimal app-store exposure (manifest declares the collection but the consumer-facing privacy policy does not). It can carry serious app-store exposure with minimal FTC exposure (privacy policy admits the collection but the manifest hides it from the platform). The dual rating surfaces both patterns separately so the right remediation reaches the right surface.
Learn more → Consent-blind location transmission in Google Mobile Ads SDK ≤ v20.6.0
See also:
About Pixalate
Pixalate is a global platform specializing in privacy compliance, ad fraud prevention, and digital ad supply chain data intelligence. Founded in 2012 and recognized by UNICEF as a “key innovator” for children’s online privacy, Pixalate is trusted by regulators, data researchers, advertisers, publishers, ad tech platforms, and financial analysts across the Connected TV (CTV), mobile app, and website ecosystems. Pixalate is accredited by the MRC for the detection and filtration of Sophisticated Invalid Traffic (SIVT).