Ravensight

AnalyticsPrivacyLaunch

The privacy label is a download decision

Apple's labels cost tracking apps twice the downloads they cost everyone else. A small studio can make its label the reason to be picked over a clone.

A raven perched on an upright phone whose screen shows a privacy card with a shield and three rows of green checkmarks, in front of a crowd of identical grey phones fading into the dark.

Every app on the App Store carries a privacy label: a card on the store page listing what the app collects, whether it is linked to the person, and whether it is used to track them. It was introduced as a disclosure. It behaves like a price tag.

The number that should worry a game in a crowded category

Bian, Ma and Tang measured what the labels did to the top 10,000 apps by 2020 downloads, using a comparison that is hard to argue with: each iOS app against its own Android version, where no label appeared. After the labels went up, an iOS app lost 14 percent of its weekly downloads and 15 percent of its revenue relative to its Android twin.

The average hides the distribution. Apps that collect data in order to track users lost 2.2 times as much as apps that do not. Apps in the bottom quartile of data-collection intensity showed no statistically significant drop at all. And the effect was weaker for popular, mature apps that people cannot easily replace.

Read that last finding from the other side. The label hurts most where the product is easy to substitute. A game in a genre with fifty lookalikes is the most substitutable product on the store. A player choosing between two match-three puzzles, or two idle games with the same screenshots, pays nothing to switch and sees one visible difference on the page. A major social app can carry a heavy label and keep its downloads because there is no replacement for it. Your game is not in that position, and the study says the light label is worth real downloads precisely because of it.

The prompt most players refuse

The second half of Apple's privacy regime is the tracking permission prompt. If an app wants to track in Apple's sense, it has to ask, and the player can say no. In the second quarter of 2025, among users who were shown the prompt, 35 percent said yes industry-wide. Games vary by genre: sports titles reach 50 percent, hyper casual 43, action 40, and board games 30.

That is the ceiling for anything built on the prompt. Attribution that depends on a consented advertising identifier measures a third of your players and, in the quieter genres, less. The other two thirds are not only unmeasured. They have been asked, by their operating system, whether this game wants to follow them across other apps, and they have said no. The prompt itself is a reminder that there is something to be worried about.

How much that worry costs is harder to pin down. A consent-tool vendor's own April 2023 survey of 269 games reported that 40 percent of players say they would delete a game over privacy concerns, and that 90 percent of the games sampled collected personal data without consent. A vendor that sells consent tools has an interest in both numbers, so treat them as a direction rather than a measurement. The direction matches the download study.

What tracking actually means on the store

The way out is not a cleverer label. It is to stop doing the thing the label is for, and that turns out to be a narrow thing.

Apple's definition is specific. Tracking means linking data collected from your app about a user or device with third-party data for targeted advertising or advertising measurement, or sharing it with a data broker. Two triggers: combining your data with someone else's for advertising, and selling it on. Everything else is not tracking, however much data it involves.

The same page defines the other two words on the label. Data is not linked to you when direct identifiers are stripped before collection and you never try to link it to a person afterwards. Data is not collected at all when it is processed only on the device, or used transiently to serve a request and then discarded.

So first-party analytics on a per-install identifier, held by you, never combined with another app's data, never handed to an ad network or a broker, is not tracking. It does not need the prompt, because the prompt exists for the two triggers, and you have pulled neither. The lightest quartile in the download study lost nothing for a plain reason: those apps had little to disclose, and the label said so.

What a light label looks like for a game

For a game that sends gameplay events to its own analytics and nothing else, the App Store form has two rows worth filling in.

Data typeLinked to youUsed to track youPurpose
Identifiers: Device IDNoNoAnalytics
Usage Data: Product InteractionNoNoAnalytics

Diagnostics is a third row only if you send crash events. The Google Play Data safety form takes the same answers in its own words: device or other IDs and app interactions, collected, not shared, not used for advertising, encrypted in transit, with a deletion path.

For a game that runs no ads, that label earns a sentence on the store page, and it is the sentence a player comparing two games will remember: No ads, no tracking, no account needed. A game with ads drops the first clause and keeps the other two, which still say more than most store pages do. The row-by-row reasons, the privacy manifest values and the Play form answers are in the docs, written so you can copy them into the form rather than reason it out under deadline.

How Ravensight is built so the light label is the true one

A label is only an advantage if it is true, and a studio cannot promise what its SDK does not do. So here is what the Ravensight SDK does, stated plainly, in the release this post ships with.

  • The device id is random and per install: 32 hex characters plus the OS name,

generated on first run and saved. It is not derived from hardware, an account, or anything the operating system knows about the person.

  • No advertising identifier is read anywhere. Not on iOS, not on Android, not

in the SDK, not on the server.

  • There is no third-party SDK inside your game. The Godot SDK is three

GDScript files that talk to the ingestion API over HTTPS, and nothing else is embedded.

  • Event rows carry no IP address, no user agent and no location, and they

expire after 90 days. A per-device first-seen record (game, device id, first day seen) is kept so retention counts stay correct past that window.

  • No names, no emails, no player accounts. The SDK has no field for them.
  • Nothing is sold, shared with an ad network, or handed to a data broker.
  • The AI analyst sends player feedback text and the results of its own

read-only tools to the model provider under contract, because that is what it reasons over. It never sends screenshots.

  • For studios that show their own consent screen, the SDK has an opt-out

switch that stops sending, and a reset call that discards the device id and starts a new one. Wire both to your settings screen.

  • No tracking permission prompt is required, because nothing above meets the

definition.

That is the whole list. Nothing in it is a plan; all of it is in the release.

What you give up

Be clear about the trade. Without a consented advertising identifier you cannot do cross-app attribution, so you will not know which ad on which network brought a particular install. You cannot retarget players who left. You cannot build lookalike audiences from the ones who stayed.

For a small studio these are smaller losses than they sound, because the prompt already took most of them. Attribution on a 35 percent opt-in measures the consenting third and models the rest; retargeting and lookalikes work on the same minority. What remains is the measurement that actually changes a game: retention cohorts, where a level loses people, which step of the first five minutes they abandon and how long the survivors spend there, what a playtest persona got stuck on, and what happened to new players in the seventy two hours after a trailer, a stream or a launch post. None of that needs an identifier that follows a person out of your game. Marketing memory measures touchpoint lift from your own telemetry with a stated method, and the sales ledger attributes revenue by storefront and period from the reports the stores already give you. That is the attribution a studio can do honestly, and it does not require asking anyone's permission to be followed.

The checklist for this week

  1. Open your build's dependency list and remove anything that reads an

advertising identifier or talks to an ad network. If a plugin cannot tell you what it collects, that is the answer.

  1. Fill in the App Store and Google Play forms from the two tables in the

docs: Device ID and Product Interaction, not linked, not used to track, purpose Analytics.

  1. Do not add the tracking permission prompt. Nothing in a game built this way

meets the definition, and the prompt costs you the two thirds who say no.

  1. Put the sentence on the store page where a player comparing two games will

read it: no ads, no tracking, no account needed, or the last two if your game runs ads.

  1. If you show a consent or settings screen, wire the SDK's opt-out and reset

calls to it, so the promise on the page is one the player can act on.

The research says the label is a download decision. For a studio in a crowded category, it is one of the few decisions you get to make alone, for free, before launch day.

Sources

  • Bian, Ma and Tang, "The Supply and Demand for Data Privacy: Evidence from

Mobile Apps", LSE Financial Markets Group discussion paper 881, July 2023. fmg.ac.uk

  • Adjust, "ATT opt-in rates 2025", Q2 2025 figures among users shown the

prompt. adjust.com

  • Usercentrics, mobile games report, April 2023, a consent-tool vendor's own

survey of 269 games. usercentrics.com

  • Apple, "App privacy details", the definitions of tracking, linked data and

collected data. developer.apple.com

Questions people ask

Does an analytics SDK require the App Tracking Transparency prompt?
Not by itself. Apple defines tracking as linking data collected from your app about a user or device with third-party data for targeted advertising or advertising measurement, or sharing it with a data broker. An analytics SDK that reports gameplay to your own backend on a per-install identifier, and never combines that data with other apps' data or passes it to an ad network, does none of that, so no prompt is required. The prompt becomes mandatory the moment an SDK reads the advertising identifier for attribution or hands data to an ad network, which is why the choice of SDK decides the answer.
What privacy label does a Godot game with Ravensight need?
Two rows on the App Store form. Identifiers, Device ID, and Usage Data, Product Interaction, each marked Data Not Linked to You and Data Not Used to Track You, with Analytics as the purpose. Add Diagnostics only if you send crash events. On Google Play the equivalent is Device or other IDs and App interactions, collected, not shared, not used for advertising, encrypted in transit, with the SDK's reset call as the deletion path. The docs carry the same tables with the privacy manifest values so you can copy them into the forms.
Does Ravensight use the IDFA or Android advertising ID?
No. The SDK never reads either identifier, and nothing on the server asks for one. The only identifier is a random per-install id, 32 hex characters plus the OS name, generated on first run and saved locally. It is not derived from hardware, an account or the advertising identifier, it is never combined with data from other apps, and a reset call discards it and generates a new one.
Can a player opt out of analytics in my game?
Yes, if you wire it. The SDK has an opt-out switch that stops events from being sent, and a reset call that discards the saved device id and starts a new one, so a studio that shows its own consent or settings screen can connect both to it. Whether to show that screen is your decision. Nothing the SDK collects requires the tracking permission prompt, so the switch is there for studios that want to offer the choice rather than because the platform demands it.