How device fingerprinting works
Fingerprinting collects several dozen device and browser attributes which together produce a
high-probability identification. A typical signal set:
IP address, device type, manufacturer
OS plus version, browser version
Language, time zone
Screen resolution, colour depth
Installed fonts (canvas fingerprint)
WebGL and audio fingerprint
The hash of that combination is the fingerprint. If the attribute set is distinctive enough, the
device is identified with high probability.
Why fingerprinting is used in mobile attribution
Before iOS 14.5 (2021), the advertising ecosystem leaned on IDFA, Apple’s deterministic identifier.
After ATT (App Tracking Transparency) arrived, most people stopped granting tracking permission and
IDFA became unavailable for more than 75% of the iOS audience.
In those conditions, MMPs (mobile measurement partners — AppsFlyer, Adjust, Branch) built
probabilistic attribution models. Formally Apple prohibits device fingerprinting, but MMPs use
privacy-aggregate models that work without binding to a particular device.
Limitations and risks
| Limitation | Consequence |
|---|---|
| Unstable IP addresses on mobile networks | False matches behind NAT and CGNAT |
| Widespread VPN use | Lower accuracy |
| OS changes on update | Identification lost after an update |
| Apple’s prohibition | Risk of rejection from the App Store |
| GDPR and CCPA | User consent required |
Important: fingerprinting is not a reliable foundation for long-term personalization. For that,
use deterministic identifiers — a signed-in user, an email address — combined with first-party
data.
Alternatives in a cookieless environment
- A signed-in user — the most reliable identifier, independent of the device
- SKAdNetwork (Apple) — aggregated attribution with no device-level binding
- Privacy Sandbox (Android) — Google’s Topics API and Attribution Reporting API
- First-party data matching — an email match between the ad platform and the CRM