Back to all articles

Privacy Policy Clause for AppLovin MAX (2026) - Copy-Paste Text

By Support URL Generator Team · Published

Advertisement

AppLovin MAX sends user data to AppLovin Corporation. The SDK transfers device identifiers, IP address and ad-interaction data to AppLovin, which uses them to run its AXON ad engine and match ads across apps — a third-party transfer that App Store review, Google Play and the GDPR all require you to disclose. Generate a full privacy policy with this clause built in →

Does AppLovin MAX need a privacy policy disclosure?

Yes. AppLovin MAX is an ad mediation SDK that also connects your app to AppLovin's own exchange (ALX) and its AXON bidding engine. When an ad is requested, the AppLovin SDK collects your device advertising identifier (IDFA on iOS, Android Advertising ID / Amazon Advertising ID on Android), the vendor ID (IDFV), your IP address, country, time zone and locale, device make, model and OS, and data about the ads you see and interact with. Advertisers may also share transaction or "event" data for e-commerce optimization.

AppLovin acts as an independent data controller and its own privacy policy states that each advertising partner is an independent controller of your data. AXON predicts a user's projected value across apps and bids in real time, which means impressions from your app feed a cross-app model. That is "tracking" under Apple's App Tracking Transparency framework and Guideline 5.1.2, so AppLovin requires an ATT prompt before it can read the IDFA. Independent researchers have reported that the SDK also collects a wide set of device signals that can re-identify a device even when the IDFA is unavailable, so disclose broadly.

What data does AppLovin MAX collect?

Data typePurposeLinked to the user?Used for tracking?
Advertising identifiers (IDFA, GAID, Amazon Ad ID), IDFVAd matching, bidding, measurement, frequency cappingYesYes
IP address, country, time zone, locale (approximate location)Ad delivery, geo targeting, fraud preventionYesYes
Ad-interaction and advertising data (impressions, clicks, ads seen)Ad performance, AXON model trainingYesYes
Device make, model, OS, and technical signalsAd rendering, compatibility, device recognitionYesYes
App performance and install dataOptimization and fraud preventionYesNo
Advertiser-supplied event / transaction data (if configured)E-commerce and value optimizationYesYes

The exact list depends on your configuration. Enabling revenue reporting, passing a user identifier, running the AppLovin Exchange, or turning on specific mediated networks all expand what you must disclose.

Copy-paste privacy policy clause for AppLovin MAX

We use AppLovin MAX, an advertising and mediation service provided by
AppLovin Corporation, to display and optimize ads in this app. When an ad
is requested or shown, the AppLovin SDK collects and transmits to
AppLovin your device advertising identifier (IDFA on iOS, Advertising ID
on Android), vendor identifier, IP address, coarse location, device
information, and data about the ads you see and interact with. AppLovin
acts as an independent data controller and uses this data to select,
mediate, bid on and measure ads, including through its AXON engine, which
may involve building profiles used across applications. This processing
constitutes cross-app tracking. In the European Economic Area, the United
Kingdom and Switzerland we request your consent before AppLovin loads
personalized ads, and for users in applicable US states we set a "do not
sell or share" signal. Learn more at
https://www.applovin.com/privacy/.

Adapt it: name your company, list the mediated networks you enable, and remove the e-commerce sentence if you do not pass advertiser events. This text is a starting point, not legal advice; you remain responsible for its accuracy.

App Store "App Privacy" label answers

In App Store Connect, declare for the AppLovin SDK:

  • Identifiers > Device ID — purpose Third-Party Advertising; Linked to the user; Used to Track You.
  • Identifiers > User ID — only if you set one; Linked; Used to Track You.
  • Usage Data > Product Interaction and Usage Data > Advertising Data — Third-Party Advertising; Linked; Used to Track You.
  • Diagnostics > Performance Data and Crash Data — App Functionality and Analytics.
  • Location > Coarse Location — derived from IP; Third-Party Advertising.
  • Purchases > Purchase History — only if you pass revenue or advertiser transaction events.

Because AppLovin accesses the IDFA, answer "Yes" to the tracking question and present an ATT prompt. The AppLovin SDK is on Apple's list of commonly used third-party SDKs and ships a signed privacy manifest (from v12.0); stay on a current version for Guideline 5.1.2.

Google Play Data Safety answers

  • Device or other IDs — Collected: Yes. Shared: Yes. Purpose: Advertising or marketing, Analytics, Fraud prevention. Not processed ephemerally.
  • Location > Approximate location — Collected: Yes. Shared: Yes. Purpose: Advertising or marketing.
  • App activity > App interactions — Collected: Yes. Shared: Yes. Purpose: Advertising or marketing, Analytics.
  • App info and performance > Diagnostics and Crash logs — Collected: Yes. Shared: Yes.
  • Financial info > Purchase history — only if you pass revenue or advertiser events. Shared: Yes.

Data sharing is "Yes": AppLovin receives the data as an independent controller. Users can request deletion through AppLovin's privacy request form; describe that route in your policy.

AppLovin MAX-specific gotchas

  • AXON makes this cross-app tracking. Impressions feed a model that predicts value and bids across apps, so treat every integration as tracking and obtain consent, regardless of whether you also run the AppLovin Exchange.
  • IDFA denial does not stop collection. Independent research indicates the SDK still gathers many device signals that can re-identify a device; keep the disclosure and the "Used to Track You" label even when ATT is denied.
  • Set consent and privacy flags before the first ad request. Use the "Has User Consent" flag for GDPR regions and the "Do Not Sell" flag for US multi-state laws; the SDK does not infer them.
  • No child-directed use. AppLovin removed its age-restricted-user API; you may not use the SDK in apps directed to children or with users below the age of consent.
  • Mediation multiplies obligations. Every mediated network needs its own disclosure and consent; Meta Audience Network additionally needs its Limited Data Use flag set through the adapter.
  • AppLovin owns other SDKs. Adjust and (historically) MoPub demand flow through AppLovin; if your policy lists corporate groups or recipients, reflect that.

Related

See the sibling clause guides for Google AdMob, Meta Audience Network, Unity Ads, and ironSource (LevelPlay). For a Firebase and Google Analytics policy, see the Firebase privacy policy generator, and build the whole document with the privacy policy page generator.

Advertisement

Need a Support URL for Your App?

Generate a compliant, professional support page in under a minute. Our easy-to-use generator creates everything you need for App Store and Google Play submissions.