Back to all articles

Privacy Policy Clause for Mixpanel (2026) - Copy-Paste Text + Store Label Mapping

By Support URL Generator Team · Published

Advertisement

Mixpanel sends user data to Mixpanel, Inc. Event data, a Mixpanel-generated distinct ID, device attributes and an IP-derived city all leave the device and are stored on Mixpanel's servers, so this is a third-party transfer you must disclose in your privacy policy under the GDPR, the App Store rules and Google Play. Generate a full privacy policy with this clause built in →

Does Mixpanel need a privacy policy disclosure?

Yes. Mixpanel is a product-analytics SDK: it records the events, screen views and user properties you instrument, attaches a distinct ID plus automatic device and session properties, and uploads them to Mixpanel for reporting, funnels and retention analysis. That data leaves the device and is processed by a company that is not you, which is the definition of a third-party disclosure obligation.

Mixpanel states that it acts as a data processor on behalf of its customers and that it does not engage in "tracking" as defined by Apple — it does not combine your data with other sources, does not do targeted advertising, and is not a data broker. So a default Mixpanel setup normally does not trigger an App Tracking Transparency prompt, but you still must disclose the collection. If you push advertising IDs or cross-app identifiers into Mixpanel yourself, that changes.

What data does Mixpanel collect?

Data typePurposeLinked to the user?Used for tracking?
Distinct ID and a unique event ID (Mixpanel-generated alphanumeric identifiers)Attribute events to a device or userYesNo
Device attributes (device model, OS, OS version, app release/version)Analytics, segmentationYesNo
Usage / product-interaction data (events, screen views, session info, time in app, when the app was opened and for how long)Analytics, funnels, retentionYesNo
Coarse location (city, region, country derived from IP)Geographic reportingYesNo
Any user properties or event properties you set (name, email, plan, etc.)Whatever you instrumentYesNo

Mixpanel says it does not collect granular or real-time geolocation by default and prohibits it in its standard terms, and by default does not collect contact info, health, financial data, contacts, user content, browsing/search history, purchases or diagnostics. The real list depends entirely on your configuration: you can disable IP collection and geolocation in the SDK, and everything under "user properties" is data you chose to send.

Copy-paste privacy policy clause for Mixpanel

Analytics. We use Mixpanel, a product-analytics service provided by
Mixpanel, Inc., to understand how people use our app. Mixpanel collects a
Mixpanel-generated distinct identifier, the in-app events and screen
views we instrument, session and usage data (including when and how long
the app is used), device and operating-system attributes, and a coarse
location (city, region, country) derived from an IP address. We also send
Mixpanel the account properties needed for our analysis, such as a user
identifier. Mixpanel processes this data solely as our processor under
its terms of service and does not sell it or use it for its own
advertising. See https://mixpanel.com/legal/privacy-policy/ for details.

Adapt this: list the specific user properties you set, remove the coarse-location sentence if you disable IP and geolocation in the SDK, and name your EU or US data-residency choice if you configured one. This is a template, not legal advice — you are responsible for making it match your implementation.

App Store "App Privacy" label answers

For a default Mixpanel integration, declare in App Store Connect:

  • Identifiers > User ID — if you call identify with your own account ID. Purpose "Analytics", Linked to the user, not used to track.
  • Identifiers > Device ID — the distinct ID. Purpose "Analytics", Linked to the user, not used to track.
  • Usage Data > Product Interaction — purpose "Analytics", Linked to the user, not used to track.
  • Diagnostics > Other Diagnostic Data — only if you record performance or error events.
  • IP-derived city: Apple has no coarse-location category, so as long as you do not use Core Location this is generally not declared as Location.

Because Mixpanel does not meet Apple's definition of tracking, mark everything "not used to track you" unless you deliberately feed it advertising identifiers or share its data with a data broker or ad network.

Google Play Data Safety answers

In the Play Console Data Safety form, a standard Mixpanel setup means:

  • Device or other IDs — Collected: Yes. Shared: No. Purpose: Analytics. Not processed ephemerally.
  • App activity > App interactions and Other actions — Collected: Yes. Shared: No. Purpose: Analytics.
  • App info and performance > Diagnostics — Collected: Yes if you instrument performance events. Shared: No.
  • Personal info > Name / Email address / User IDs — Collected: Yes only if you send those as user properties. Shared: No. Purpose: Analytics, Account management.
  • Location > Approximate location — Collected: Yes if IP-based geolocation is left enabled. Shared: No. Purpose: Analytics.

Mark data as not "processed ephemerally" (Mixpanel stores events; the default retention is five years if you set nothing). Users can request deletion; Mixpanel exposes a data-deletion API and a compliance email, and you should point users to your own deletion request flow.

Mixpanel-specific gotchas

  • Legacy autotrack sent form and element text. Older Mixpanel web/mobile autotrack could capture input labels and page text; make sure autocapture is configured and sensitive fields are masked.
  • Default retention is 5 years. If you never set a retention period, Mixpanel keeps event data for five years — state a shorter period in your policy and configure it.
  • User properties are permanent-ish. people.set writes a profile that persists until explicitly deleted; sending an email or full name there creates a directly identifying record.
  • EU residency is opt-in. Data goes to US servers unless you create the project on Mixpanel's EU (or India) residency endpoint and point the SDK at it.
  • Disable geolocation explicitly if you need to. IP-to-city lookup runs by default; call the SDK option to stop IP collection if your legal basis does not cover location.
  • Session Replay is a separate, higher-risk feature. If you enable Mixpanel Session Replay you are recording screen content and must disclose it and mask personal data.

Related

See the sibling clauses for Google Analytics for Firebase, Amplitude, PostHog and Segment. Build the whole document with the privacy policy page generator, and if your app also uses Firebase see the Firebase privacy policy generator guide.

Advertisement

Need a Support URL for Your App?

Generate a compliant, professional support page in under a minute. Our easy-to-use generator creates everything you need for App Store and Google Play submissions.