SDK Trust Index — Code Analysis Evidence Dashboard | Pixalate
Pixalate · SDK Trust Index

SDK Trust Index

Code Analysis Evidence Dashboard

Pixalate's SDK Trust Index analyzes mobile SDK source code to identify exactly where and how each SDK collects and transmits device location. Each entry below shows the code paths Pixalate detected — annotated with plain-English steps, function names, and the network endpoints data is sent to. Generated from periodic static analysis of public SDK distributions.

Disclaimer: Pixalate's Trust SDK Index Ratings reflect Pixalate's opinions and proprietary research findings, and are not intended to impugn the standing or reputation of any entity, person, or SDK. Classification of an SDK within a particular risk tier does not indicate that the operator, its SDK(s), or any associated practices are in violation of any laws or regulations, including COPPA, FTC Section 5, or any other global privacy framework. See full disclaimer below.
Blue (Collection) — code that collects a precise location value via API or permission function calls.
Amber (Payload) — code where a location value is assembled into a network payload.
Red (Data Transmission) — code that connects to an off-device network and can transmit data for downstream use or sale.
Not Detected · Verified — the SDK contains code that resembles location handling, but byte-level verification established it never executes in the rated version (for example, a value that is always null). The code is displayed for completeness with a "Never executes" marker on each inert step.
Historical version line — behavior documented for an earlier, superseded version line of an SDK; the entry states the version range and when the behavior was removed.
A complete SDK trace typically reads BlueAmberRed.

Disclaimer: Pixalate’s SDK Trust Index Ratings (“SDK Index”) reflect Pixalate’s opinions that Pixalate believes may be useful to developers, regulators, platforms, advertisers, researchers, and others in the digital media industry. Any data shared is grounded in Pixalate’s proprietary technology and analytics, which Pixalate is continuously evaluating and updating. Any references to outside sources should not be construed as endorsements, affiliations, or associations with any third-parties. Pixalate is sharing this data not to impugn the standing or reputation of any entity, person or SDK, but, instead, to report research findings and trends pertaining to the period studied.

It is important to note however, that classification of a software development kit operator (“SDK operator”) within a particular risk tier does not mean that the SDK operator, its SDK(s), or any associated practices are in violation of any laws or regulations, including the Children’s Online Privacy Protection Act (COPPA) or any other global privacy framework. Further, the SDK(s) of an SDK operator(s) that appear(s) to present elevated risk signals does not mean that such SDK, or its operator, is failing to comply with applicable FTC Rules.

Pixalate’s determinations are based on a proprietary methodology that incorporates a combination of signals and automated processes. Additionally, with respect to SDK operators that appear to have characteristics that, in Pixalate’s opinion, may trigger related privacy law or regulatory compliance obligations and/or risk, such assertions reflect Pixalate’s opinions i.e., they are neither facts nor guarantees. While Pixalate endeavors to apply rigorous standards in compiling this SDK Index, no assurances or guarantees can be, or are, made as to the accuracy or completeness of any classification. This SDK Index, including all content set forth herein–constitutes Pixalate “Materials” under Pixalate’s Terms of Use, and is licensed subject to–and conditioned expressly upon–compliance with each of the applicable terms and conditions of such Pixalate Terms of Use.

Methodology note: The code-analysis evidence presented in this index is derived from static analysis of each SDK as distributed in the version analyzed. Static analysis identifies code paths present in the software; it does not execute the software and therefore does not confirm whether, when, or how frequently any given code path runs at runtime, nor whether its execution depends on end-user permission, consent, host-application configuration, or geographic region. SDK behavior may also differ in other or later versions.

Apple and the Apple logo are trademarks of Apple Inc; Google, Google Ad Exchange, the brand “Google Play,” its logos, and other Google logos are trademarks of Google LLC. These companies are not affiliated with, nor do they endorse or sponsor, any products, data, content, reports, materials or services associated with Pixalate. Any other brand logos, names, or trademarks not explicitly mentioned herein – but otherwise mentioned, displayed, or used in any of Pixalate’s materials, including this report – are the property of their respective owners.