Back to all articles

Privacy Policy Clause for Superwall (2026) - Copy-Paste Text + Store Label Mapping

By Support URL Generator Team · Published

Advertisement

Superwall sends user data to Superwall, Inc. By default the SDK reports every paywall event plus device and session attributes to Superwall's servers, which is a third-party transfer you must disclose. Generate a full privacy policy with this clause built in →

Does Superwall need a privacy policy disclosure?

Superwall is a paywall management and A/B-testing tool. The SDK renders remotely configured paywalls and, unless you turn data collection down, sends every event you register plus a set of device and session attributes to Superwall so it can power dashboard analytics and experiment results. It also derives an approximate location (country, region, city) from the device IP address, even though the SDK never asks for location permission.

That is a transfer of personal data to a third-party processor, so disclose it. Superwall states it does not identify users by email and does not track purchase history for advertising, so on its own Superwall is "App Functionality" plus "Analytics", not "tracking" under Apple's ATT rules or Guideline 5.1.2 — as long as you do not feed it advertising identifiers or attach personal data to its user attributes.

What data does Superwall collect?

Data typePurposeLinked to the user?Used for tracking?
Device identifiers: vendor ID (IDFV), your app user ID and aliases, bundle IDAttribute events to a device or user, deduplicateApp user ID linked if you set a real one; IDFV pseudonymousNo
IP-derived approximate location (country, region, city, timezone)Paywall targeting, analyticsLinked to the deviceNo
Device and app attributes (OS version, device model, locale, language, currency, timezone, interface style, network type, low-power mode, SDK and app version)App functionality, targeting, analyticsLinked to the deviceNo
Paywall and lifecycle events (paywall open / close / decline, transaction events, app install / open, session start)Analytics, experiment resultsLinked to the device or userNo
Subscription status / entitlement stateGate paywalls, analyticsLinkedNo
A/B experiment and holdout group assignmentRun experimentsLinked to the deviceNo

The exact list depends on your configuration: the isExternalDataCollectionEnabled setting, which events and custom properties you register, whether you set a real app user ID, and whether you pass any identifiers.

Copy-paste privacy policy clause for Superwall

Paywall analytics and experiments (Superwall)

This app uses Superwall, provided by Superwall, Inc., to display and test
in-app purchase paywalls. The Superwall SDK sends the following to
Superwall's servers: a device identifier (identifierForVendor) and any
app user ID or alias we set, your IP address (from which Superwall derives
an approximate country, region, and city), device and app attributes such
as operating system version, device model, locale, currency, timezone,
and network type, your subscription status, the A/B test group you are
assigned to, and events describing which paywalls you saw and whether you
subscribed, dismissed, or declined them. Superwall processes this data on
our behalf to render paywalls, produce analytics, and measure
experiments. Superwall does not use it for advertising. Superwall acts as
our data processor. See Superwall's privacy policy at
https://superwall.com/privacy/.

Adapt this: if you set isExternalDataCollectionEnabled to .none or .superwallOnly, narrow the event description accordingly; if you pass custom user attributes, list the meaningful ones.

App Store "App Privacy" label answers

In App Store Connect, declare the following for Superwall:

  • Identifiers > Device ID (and User ID if you set one) — purposes "App Functionality" and "Analytics". Linked to the user: Device ID pseudonymous; User ID yes. Used to track you: No.
  • Usage Data > Product Interaction — purposes "Analytics" and "App Functionality". Linked: Yes. Used to track you: No.
  • Purchases > Purchase History (subscription state) — purposes "App Functionality" and "Analytics". Linked: Yes. Used to track you: No.
  • Diagnostics > Other Diagnostic Data — paywall load times and performance. Purpose "Analytics".
  • Location > Coarse Location — Superwall derives approximate location from IP. Purpose "Analytics". Linked: Yes. Used to track you: No. (See uncertain note below.)

Superwall's own guidance says the minimum is the "Purchases" category with "Analytics" and "App Functionality". Superwall ships a privacy manifest declaring no tracking.

Google Play Data Safety answers

For the Play Console Data safety form:

  • Device or other IDs — Collected: Yes. Shared: No (Superwall is a service provider processing on your behalf). Purposes: Analytics, App functionality.
  • App activity > App interactions — Collected: Yes. Shared: No. Purpose: Analytics.
  • App info and performance > Other app performance data — Collected: Yes. Shared: No. Purpose: Analytics.
  • Financial info > Purchase history — Collected: Yes. Shared: No. Purposes: App functionality, Analytics.
  • Location > Approximate location — Collected: Yes if you count IP-derived city. Shared: No. Purpose: Analytics.
  • Data is not processed ephemerally. Users can request deletion; you can delete a user's Superwall data through Superwall's reset / delete APIs or support.

Superwall-specific gotchas

  • Send-everything is the default. With isExternalDataCollectionEnabled at .all, every event and custom property you register is forwarded to Superwall — including any PII you attach. Set it to .none or .superwallOnly, or keep PII out of Superwall.
  • Location without a permission prompt. Superwall stores approximate geo from the IP address even though the SDK never triggers a location dialog — you still have to disclose it.
  • Custom user attributes. Anything passed to identify() or setUserAttributes() goes to Superwall; do not send emails or names unless your policy says so.
  • Keep it consistent with RevenueCat / StoreKit. Subscription state is shared with Superwall; align both SDKs' disclosures (see the RevenueCat clause).
  • Holdout groups. Experiments mean some users never see a paywall; some regimes expect you to mention that you run A/B tests.
  • You own the accuracy of your store labels; Superwall's guidance is informational, not legal advice.

Related

See the sibling clauses for RevenueCat, Stripe, Supabase, and Google Sign-In. Build the full document with the privacy policy page generator, and see the Firebase privacy policy guide if your app also uses Firebase.

Advertisement

Need a Support URL for Your App?

Generate a compliant, professional support page in under a minute. Our easy-to-use generator creates everything you need for App Store and Google Play submissions.