How device fingerprinting works

Fingerprinting collects several dozen device and browser attributes which together produce a
high-probability identification. A typical signal set:

IP address, device type, manufacturer
OS plus version, browser version
Language, time zone
Screen resolution, colour depth
Installed fonts (canvas fingerprint)
WebGL and audio fingerprint

The hash of that combination is the fingerprint. If the attribute set is distinctive enough, the
device is identified with high probability.

Why fingerprinting is used in mobile attribution

Before iOS 14.5 (2021), the advertising ecosystem leaned on IDFA, Apple’s deterministic identifier.
After ATT (App Tracking Transparency) arrived, most people stopped granting tracking permission and
IDFA became unavailable for more than 75% of the iOS audience.

In those conditions, MMPs (mobile measurement partners — AppsFlyer, Adjust, Branch) built
probabilistic attribution models. Formally Apple prohibits device fingerprinting, but MMPs use
privacy-aggregate models that work without binding to a particular device.

Limitations and risks

Limitation Consequence
Unstable IP addresses on mobile networks False matches behind NAT and CGNAT
Widespread VPN use Lower accuracy
OS changes on update Identification lost after an update
Apple’s prohibition Risk of rejection from the App Store
GDPR and CCPA User consent required

Important: fingerprinting is not a reliable foundation for long-term personalization. For that,
use deterministic identifiers — a signed-in user, an email address — combined with first-party
data.

Alternatives in a cookieless environment

  • A signed-in user — the most reliable identifier, independent of the device
  • SKAdNetwork (Apple) — aggregated attribution with no device-level binding
  • Privacy Sandbox (Android) — Google’s Topics API and Attribution Reporting API
  • First-party data matching — an email match between the ad platform and the CRM