Mobile In-App Tracking and Advertising

Carnegie Mellon University Data Privacy Day 2017

How do I manage app permissions? How does in-app In recent versions of iOS and in (6.x), tracking work? applications must ask the user for permission before using sensitive resources. These permissions can also be managed after the app has • • • been installed. However, in Android Lollipop (5.x), all permissions Similar to online tracking, are automatically granted once you install the app. mobile applications are able to record information about you, which is typically used to serve targeted ads. To

learn more about you, mobile applications often use resources from your phone’s operating system, such as your location,

photos, and contacts list.

Android and iOS operating systems also have built-in advertising platforms used by apps to provide you with targeted ads. Each device is iOS (6+) By app: Settings → App name associated with an By resource: Settings → Privacy advertising ID, which is used to place you in a Android By app: Settings → Apps → App name targeting group. These Marshmallow (6.x) → App permissions advertising IDs are By resource: Settings → Apps → Tap associated with information the gear icon in the upper-right corner → App permissions such as your Apple or account profile Android Lollipop To view app permission in the Google (including your age and (5.x) Play store, search for the app and look gender), downloads to your for the “Permissions” section in the device, and activities in app description apps. To view permissions of apps installed on the device: Settings → Apps → Tap on app name image: http://media02.hongkiat.com/android-app-permissions/app-permissions.jpg How can I control in-app tracking?

How it works How to do it Reset advertising This control works much like deleting iOS: Settings → Privacy → Advertising → identifiers cookies in a browser — the device is Reset Advertising Identifier harder to associate with past activity, Android: Google settings → Ads → Reset but tracking can start anew using the advertising ID new advertising identifier. Limit use of If you turn on this setting, apps are iOS: Settings → Privacy → Advertising identifiers not permitted to use the advertising → Limit Ad Tracking identifier to serve consumers targeted Android: Google Settings → Ads → ads. Although this tool will limit the Enable “Opt Out of Interest-Based Ads” use of tracking data for targeting ads,

companies may still be able to monitor your app usage for other purposes, such as research, measurement, and fraud prevention. Enable Do Not DNT is a setting in your browser that Chrome (only Android): In the Chrome Track (DNT) sends a signal to that you browser, tap the menu icon (three dots to wish not to be tracked. However, the right of the address bar) → Settings → many websites see this signal as an Privacy → “Do Not Track” → Toggle “Off” opt-out of targeted advertising and to “On” not necessarily tracking. (iOS): Settings → Safari → Enable “Do Not Track” Clear browser Clearing your browser cookies will Chrome (Android & iOS): In the Chrome cookies remove any cookies, including browser, tap the menu icon (three dots to advertising and tracking cookies, that the right of the address bar) → Settings → had been previously set on your Privacy → Clear browsing data → Change browser. Without these cookies, third- “Clear data from the” to “beginning of parties will not be able to link you to time” (if necessary)→ Make sure “Cookies your previous online activity. Note and site data” is checked → Tap “Clear that these cookies will be set again Data” when you browse. Safari (iOS): Settings → Safari → Clear History and Data Install a content Similar to tracker blocking browser iOS: Install and configure a content blocker (iOS extensions, content blockers are apps blocking app to your preferences. Popular only) which can be used to block different apps include: tracking technologies on Safari, • Focus including ad, analytics, and social • Purify trackers. • 1Blocker • Sanitize • Adguard