Mobile Privacy

What Apple's Tracking Prompt Actually Blocks (and What It Doesn't)

August 11, 2026 9 min read Haven Team

Since iOS 14.5, opening a new app has meant seeing a system prompt asking whether it can "track you across apps and websites." Most people tap "Ask App Not to Track" and move on, treating it as a general privacy switch. It isn't one. App Tracking Transparency draws a specific, narrow line, and understanding exactly where that line sits matters more than the prompt itself.


App Tracking Transparency, or ATT, shipped with iOS 14.5 in April 2021. Before it existed, every iOS device carried an Identifier for Advertisers, IDFA, a persistent per-device value that advertising networks used to stitch your activity together across unrelated apps. Install a game, browse a shopping app, scroll a news feed, and the same IDFA let an ad network recognize you were the same person in all three, without needing your name or account details.

What the Framework Actually Does

ATT requires any app that wants to access the IDFA, or that wants to link data it collects with data from other companies for advertising or measurement purposes, to first call the AppTrackingTransparency framework and show the system permission prompt. If you decline, the app receives an IDFA of all zeros instead of a real identifier, which makes device-level cross-app matching through that channel useless.

This is a meaningful, specific mechanism: it governs "tracking" as Apple defines the term in its App Store guidelines, which is data linked across apps or websites owned by different companies, or shared with data brokers, for advertising or ad measurement. That definition is doing a lot of work, and it's the reason the prompt has a much smaller effect than most users assume.

The definitional boundary

Apple's "tracking" means linking your data with a third party's data for advertising purposes. It does not restrict an app from collecting extensive data about you for its own first-party use, and it does not restrict Apple's own data collection at all.

What Falls Outside the Prompt

A retail app can still build a detailed profile of everything you browse and buy inside that one app, use it to target you with ads inside that same app, and share aggregate (not individually linked) insights with partners, all without triggering the ATT prompt. First-party data collection and first-party advertising are untouched by the framework. So is fingerprinting-style tracking that doesn't rely on the IDFA at all, an app can still infer a lot about device and usage patterns from signals ATT was never designed to cover, though Apple's App Store review process separately restricts some of these techniques.

Apple's own advertising business, which serves ads inside the App Store and Apple News, is also outside ATT's consent flow. Apple's position is that this isn't cross-app tracking in the sense the framework targets, since it uses data collected within Apple's own properties rather than linking data from unrelated third-party apps. Critics, including advertising industry groups and antitrust regulators in the European Union, have argued this is a double standard: Apple requires competitors to ask permission for a practice it doesn't apply the same consent requirement to for itself. That argument has been the basis of regulatory scrutiny of ATT's implementation in multiple jurisdictions.

The Industry Built Around the Gap

Losing reliable IDFA access reshaped mobile advertising rather than shrinking it. Companies that depended heavily on cross-app identity matching moved toward probabilistic matching instead: inferring that two events likely belong to the same person from signals like IP address, device model, and timing, without a persistent identifier confirming it. Meta told investors the change would cost billions of dollars in lost ad revenue, which is a rough measure of how much the industry had been relying on deterministic IDFA matching before ATT closed it off. Probabilistic matching is generally less precise, but it isn't nothing, and it isn't something a user consent prompt addresses, because it doesn't request the kind of access ATT governs in the first place.

Apple's own answer to advertisers' measurement needs is SKAdNetwork, a privacy-preserving attribution API that lets an ad network learn whether an install came from its campaign without learning which specific user installed it. It's a real architectural alternative to IDFA-based tracking, not just a fallback, but adoption and data granularity limitations mean many advertisers still lean on probabilistic methods alongside it.

The regulatory scrutiny has followed the same double-standard argument. Competition authorities in the European Union and elsewhere have examined whether ATT amounts to self-preferencing under antitrust law. Third-party developers must ask permission for a form of advertising that Apple's own ad business isn't subject to the same consent requirement for. That's a live legal question in multiple jurisdictions, and the outcome doesn't change what the framework does today, but it's a useful reminder that a privacy mechanism and a competitive one can be the same piece of code viewed from two different angles.

Covered by ATT consent Not covered by ATT consent
Reading the device IDFA for cross-app ad matching Data an app collects about you for its own first-party use
Sharing your data with a third-party ad network or broker Apple's own advertising inside the App Store and Apple News
Explicit third-party identity linking for ad measurement Probabilistic matching based on IP, device model, and timing

How This Compares to Android

Android's equivalent identifier, the Google Advertising ID, has historically defaulted to on with an opt-out buried in system settings rather than a mandatory consent prompt at first use, though Google has been moving toward letting users reset or limit the identifier more directly and is separately restructuring ad targeting through its Privacy Sandbox initiative. The practical difference for most users has been default state: iOS shifted to an ask-first model, Android has largely stayed opt-out. Neither platform's mechanism reaches the broader cross-device tracking techniques that don't rely on an advertising identifier at all, or the first-party data collection that remains the far larger category of what apps actually gather about you. For a fuller map of what an operating system's permission dialogs do and don't reach, see our piece on mobile app permissions.

What the Prompt Is Actually Good For

None of this makes ATT meaningless. It closed a real, specific channel that the advertising industry had relied on for a decade, and declining the prompt genuinely does prevent that one form of cross-app identity linking. The mistake is treating the prompt as a general privacy control that governs how much an app knows about you. It governs one narrow question: can this app tie what it learns about you to what a different company learns about you, for advertising. Everything an app collects and does with that data inside its own walls is a separate question entirely, one the operating system's permission prompts were never built to answer.

The broader lesson generalizes past ATT specifically. Platform-level privacy controls tend to be precise mechanisms with narrow, well-defined scope, not blanket assurances, and reading the actual boundary of what a control covers is usually more useful than reading the marketing description of it.

Try Haven free for 15 days

Encrypted email and chat in one app. No credit card required.

Get Started →