Pixalate — SDK Trust Index
Ad SDK Trust Index 1.0 / Q2 2026 Edition

The first independent rating of 698 mobile advertising and analytics SDKs

A free, public reference database that rates ad SDKs and data brokers on whether their code behavior matches their privacy disclosures — built for app developers managing FTC Section 5 liability and app store delisting risk. Every rating is backed by source code analysis, privacy manifest evaluations, and privacy policy reviews.

Hero Image
698
Ad & Analytics SDKs Rated and Ranked
10%
Of rated SDKs flagged with Critical Risk Detected
89K
Apps reached by SDKs with Critical Risk Detected
26K
App developers with Critical Risk Detected SDKs installed on their apps

An SDK's source code, its privacy manifest, and its privacy policy should tell the same story.

THE THESIS

Popularity has been mistaken for safety for too long. Every gap between what an SDK does and what it discloses is FTC Section 5 or app store liability that publishers inherit the moment they embed the SDK.

What the Index measures?
01

Scope.

The Index covers 698 mobile advertising and analytics SDKs and data brokers distributed across iOS and Android, evaluated on precise location collection, transmission, and disclosure behavior.

02

Method.

Pixalate triangulates three independent sources for every SDK: static analysis of the compiled SDK source code, extraction of platform-facing privacy manifests (Apple PrivacyInfo.xcprivacy and the Android merged manifest), and automated plus human-verified review of the vendor's published privacy policy. The underlying evidence is published for public inspection alongside every rating.

03

Output.

Each SDK receives two independent risk indicators — an FTC Section 5 Violation Risk flag and an App Store Compliance Risk flag. Each surface is rated as either Critical Risk Detected or Not Detected. The dual-flag model exists because an SDK can carry serious FTC exposure with minimal app-store exposure, or the inverse, and each surface has its own remediation path.

Why Should You Care?
01

App developers carry the liability, but lack the tool to manage it.

Play Console documentation states that "it is your responsibility to ensure that any SDKs you are using" comply with Play policies. Apple's App Store Review Guidelines impose the same duty for iOS. Yet neither store offers a public, independent SDK rating tool to help developers meet that obligation.

02

Existing indexes rate by popularity, not by safety.

Google's SDK Index displays self-declared checkmarks for SDKs that have committed not to violate Play policies — a signal developers may reasonably read as compliance assurance, but which does not validate code-level behavior. Google's index covers Android only. Apple's Privacy Nutrition Labels rely entirely on developer self-disclosure. Commercial scale databases such as 42matters and AppFigures rank SDKs by adoption footprint.

03

The regulatory pressure is real.

The FTC has brought Section 5 actions against X-Mode/Outlogic, InMarket, Gravy Analytics/Venntel, Mobilewalla, and earlier Goldenshores and InMobi. The 2020 HyperBeard action and 2024 Tilting Point settlement extended liability to app publishers for the data conduct of the third-party SDKs they ship.

Who Uses SDK Trust Index?

For App Developers

App developers carry the FTC and app store liability for every SDK they ship — but they cannot audit closed-source code themselves. The Index surfaces discrepancies between what an SDK declares and what its code actually does, before integration ships.

  • Vet an SDK's risk rating before it lands in production
  • Audit inherited risk in your existing SDK stack
  • Document due diligence with source code and manifest evidence

For SSPs & DSPs

Supply-side and demand-side platforms inherit liability from the SDKs embedded in the inventory they transact. The Index functions as a pre-auction and pre-buy due diligence layer for identifying high-risk SDK configurations entering the marketplace.

  • Filter high-risk SDK exposure from inventory pools
  • Identify FTC and app store risk in supply-path SDKs
  • Protect brand-safe deal IDs from undisclosed data leakage

For Regulators

Regulators and enforcement bodies need independent, systematic evidence of non-compliance patterns across an SDK's full app network. The Index publishes the underlying source code, privacy manifest, and privacy policy evidence for every rating — built to be cited.

  • Independent code-level evidence, updated continuously
  • Full attribution chain from SDK to publisher network
  • Child-directed app exposure tracked at SDK granularity

Where Google rates by popularity, Pixalate rates by evidence.

Category Pixalate Ad SDK Trust Index Google SDK Index
Scope
# of SDKs Rated 720 279
iOS Coverage
Privacy & Security
SDK Location Permission Access Risk (Privacy Manifest File Analysis)
Days Since Last SDK Update
SDK Location Transmission Off-Device Risk
SDK Privacy Policy Analysis
Popularity & Reach
SDK App Reach
SDK User Reach
SDK Reach on Child-Directed Apps
Top Apps With SDK Installed
SDK Version SOV
SDK Retention
SDK API Level

Three layers. One question: does this SDK do what it says it does?

LAYER 01

Code

Static analysis of the SDK's compiled code. Detects whether precise location is processed, and whether network communications transmit those coordinates off-device.

SOURCE: SDK SOURCE CODE ANALYSIS
LAYER 02

Privacy Manifest

What the SDK formally declares to platforms — Apple's PrivacyInfo.xcprivacy on iOS, the merged AndroidManifest.xml on Google Play. The app-store-facing disclosure surface.

SOURCE: MANIFEST FILE EXTRACTION
LAYER 03

Privacy Policy

What the SDK vendor tells the public. Whether a policy exists, and whether it discloses location collection. The consumer-facing disclosure surface.

SOURCE: AUTOMATED & MANUAL POLICY REVIEW

Audit before a regulator does.

The SDK Index is free and open to the public. Searchable by SDK name. Ranked by estimated user reach. Updated quarterly. Code snippets and privacy manifest evidence published alongside each rating.