What the Index measures?
01
Scope.
The Index covers 698 mobile advertising and analytics SDKs and data brokers distributed across iOS and
Android, evaluated on precise location collection, transmission, and disclosure behavior.
02
Method.
Pixalate triangulates three independent sources for every SDK: static analysis of the compiled SDK source
code, extraction of platform-facing privacy manifests (Apple PrivacyInfo.xcprivacy and the Android merged
manifest), and automated plus human-verified review of the vendor's published privacy policy. The
underlying evidence is published for public inspection alongside every rating.
03
Output.
Each SDK receives two independent risk indicators — an FTC Section 5 Violation Risk flag and an App Store
Compliance Risk flag. Each surface is rated as either Critical Risk Detected or Not
Detected. The dual-flag model exists because an SDK can carry serious FTC exposure with minimal
app-store exposure, or the inverse, and each surface has its own remediation path.
Why Should You Care?
01
App developers carry the liability, but lack the tool to manage it.
Play Console documentation states that "it is your responsibility to ensure that any SDKs you are
using" comply with Play policies. Apple's App Store Review Guidelines impose the same duty for iOS.
Yet neither store offers a public, independent SDK rating tool to help developers meet that obligation.
02
Existing indexes rate by popularity, not by safety.
Google's SDK Index displays self-declared checkmarks for SDKs that have committed not to violate Play
policies — a signal developers may reasonably read as compliance assurance, but which does not validate
code-level behavior. Google's index covers Android only. Apple's Privacy Nutrition Labels rely entirely on
developer self-disclosure. Commercial scale databases such as 42matters and AppFigures rank SDKs by
adoption footprint.
03
The regulatory pressure is real.
The FTC has brought Section 5 actions against X-Mode/Outlogic, InMarket, Gravy
Analytics/Venntel, Mobilewalla, and earlier Goldenshores and InMobi. The 2020
HyperBeard action and 2024 Tilting Point settlement extended liability to app publishers for
the data conduct of the third-party SDKs they ship.