Privacy architecture

Mobile analytics you can defend in a privacy review.

AppMetricsKit minimizes the personal data needed for analytics while still showing onboarding, retention, paywall, and subscription performance.

Pseudonymous by design

The SDK does not require an account identifier. When one is configured, it is hashed on device before AppMetricsKit receives it.

PII guardrails at ingest

The SDKs and ingest pipeline help detect risky keys and common email, phone, location, advertising ID, name, and payment card patterns.

Customer-controlled retention

Teams can choose a retention window within their plan limit and start app or organization data deletion from the product.

Example audit scoreSample
94OUT OF 100

The in-app privacy audit computes a real app-specific score after events and payload rules exist.

Open privacy audit
Kept out of event storage

Remove risky values before storing analytics events.

The SDKs drop configured keys and common personal data patterns on device. If ingest detects another risky payload key, it removes that key before storing the event and records a finding with a short redacted sample.

Read the full privacy policy
Email addresses
Phone numbers
Raw names
Advertising IDs
Raw account IDs
Precise GPS
Payment card data