Back to all articles

Privacy Policy Clause for Branch (2026) - Copy-Paste Text + Store Label Mapping

By Support URL Generator Team · Published

Advertisement

Branch sends user data to Branch Metrics, Inc. Device identifiers, IP address and link-click and install data leave the device and are processed on Branch's servers to power deep links and attribution — a third-party data transfer that App Store review, Google Play and the GDPR all require you to disclose. Generate a full privacy policy with this clause built in →

Does Branch need a privacy policy disclosure?

Yes. Branch is a deep-linking and mobile-attribution SDK. When a user taps a Branch link or opens your app, the SDK sends Branch the advertising identifier (IDFA with App Tracking Transparency consent, or the Android Advertising ID), the IDFV, the device IP address (public and, in some SDK versions, local), a Branch-generated identity and device ID, cookie or match data, install and open events, the link-click parameters, and device metadata. Branch uses this to route the user to the right in-app content and to attribute the install or action to the link.

When Branch links are used for marketing attribution, the SDK connects in-app data to advertising activity across other apps and companies, which is "tracking" under Apple's App Tracking Transparency and Guideline 5.1.2 — show an ATT prompt before the SDK collects the IDFA. Branch acts as your data processor. On iOS it also reads SKAdNetwork and AdAttributionKit data.

What data does Branch collect?

Data typePurposeLinked to the user?Used for tracking?
Device identifiers (IDFA with ATT consent, IDFV, Android Advertising ID, Branch identity and device ID, developer ID, cookie / match ID)Deep linking, attribution, device matchingYesYes, when used for attribution
IP addressDevice matching, coarse geo, fraud detectionYesYes, when used for attribution
Install, open, and link-click eventsDeep linking and attributionYesYes, when used for attribution
Link and campaign parameters, referring link URLDeep linking, attributionYesYes, when used for attribution
In-app events you send (custom events, purchases, if configured)Attribution and analyticsYesYes, when used for attribution
Device metadata (model, OS version, language, screen, browser user agent)Matching, compatibilityYesNo

The exact list depends on your configuration. Sending purchase or custom events, enabling Branch's Journeys web-to-app product, or passing a developer identity all expand what you must disclose. Branch's SDK exposes privacy controls (disableTracking, per-user "do not process" flags, and DMA / consent parameters); if you use them, adjust the table.

Copy-paste privacy policy clause for Branch

Deep linking and attribution. We use Branch, a service provided by
Branch Metrics, Inc., to power deep links and to measure how our
marketing links perform. When you tap a Branch link or use our app, the
Branch SDK collects device identifiers (including the advertising
identifier where you have granted permission), your IP address, install
and link-click events, and technical device attributes, and transmits
them to Branch. Branch processes this data as our service provider to
route you to the correct in-app content and to attribute installs and
actions to the referring link. Where we use Branch links for advertising
measurement, this processing constitutes cross-app tracking and we
request your consent before collecting the advertising identifier.
Branch deletes matching data after a period of user inactivity and
honors erasure requests. Learn more at https://branch.io/policies/privacy-policy/.

Adapt this: drop the advertising sentence if you only use Branch for organic deep links, and add purchase events if you send them. You are responsible for ensuring the wording matches your build; this text is a starting point, not legal advice.

App Store "App Privacy" label answers

For a standard Branch integration, declare in App Store Connect:

  • Identifiers > Device ID — purpose "App Functionality" (deep linking) and, if used for attribution, "Analytics" / "Third-Party Advertising". Linked to the user: Yes. Used to Track You: Yes when used for attribution.
  • Identifiers > User ID — only if you set a developer identity.
  • Usage Data > Product Interaction and Advertising Data — purpose "Analytics" and "Third-Party Advertising". Linked: Yes. Used to Track You: Yes when used for attribution.
  • Browsing History — Branch's Google Play guidance lists "Web browsing history" for link-level page views; declare the closest Apple bucket if your Journeys web SDK is active.
  • Purchases > Purchase History — only if you send commerce events.

Branch ships an Apple privacy manifest listing its data types and tracking domains; add those domains to your app's manifest and make sure ATT gates the IDFA.

Google Play Data Safety answers

Following Branch's own Data Safety guidance, declare:

  • Device or other IDs — Collected: Yes. Shared: Yes. Purpose: App functionality, Analytics, Advertising or marketing, Personalization. Not processed ephemerally. Users can turn this off.
  • App activity > App interactions ("Page views and taps in app") — Collected: Yes. Shared: Yes.
  • App activity > Web browsing history — Collected: Yes (link-level). Shared: Yes.
  • Other data (engagement metrics, device metadata) — Collected: Yes. Shared: Yes.
  • Branch states it does not collect location, contacts, messages, files, financial or health data, or crash logs by default.

Users can request deletion: Branch honors erasure requests and its SDK has a per-user opt-out that stops engagement-data processing. Branch also deletes identifiable matching data after 30 days of inactivity (90 days for some attribution products) and keeps identifiable usage logs no more than 14 days. Mention deletion in your policy.

Branch-specific gotchas

  • "Tracking" depends on how you use the links. Pure organic deep linking can be App Functionality, but the moment a Branch link carries a paid campaign, the same data becomes cross-app tracking and needs ATT plus "Used to Track You" labels.
  • Probabilistic matching and fingerprinting. Branch uses probabilistic (IP plus device-model) matching where deterministic identifiers are missing; Apple rejects apps that fingerprint regardless of ATT consent, so keep probabilistic matching off for iOS paid attribution unless legal has cleared it.
  • Consent must be passed to the SDK. Branch keeps collecting until you call disableTracking or set the per-user "do not process" flag and the DMA consent parameters for the EEA.
  • Local IP collection surprised many teams. Some SDK versions read the device's local network IP; check your version and disclose or disable it.
  • Retention is short but not zero. Aggregated reporting is kept up to 24 months; state a retention period in your policy that matches your Branch dashboard settings.
  • Developer responsibility. You, not Branch, answer the store forms — verify the data types against your actual SDK build and enabled products.

Related

See the sibling clauses for AppsFlyer, Adjust, Firebase Authentication and Sign in with Apple. For the full document use the privacy policy page generator, and for Firebase services read the Firebase privacy policy generator guide.

Advertisement

Need a Support URL for Your App?

Generate a compliant, professional support page in under a minute. Our easy-to-use generator creates everything you need for App Store and Google Play submissions.