App Tracking Transparency (ATT) is Apple's privacy framework that requires iOS apps to ask users for permission before tracking them across other companies' apps and websites. Without permission, the app cannot access the device's advertising identifier (IDFA).
How does App Tracking Transparency work?
Since iOS 14.5, released in April 2021, iOS shows a system prompt whenever an app wants to track a user across other companies' apps and websites. The user picks "Ask App Not to Track" or "Allow". If they decline, the IDFA stays locked, and Apple's rules also forbid tracking them through other identifiers.
Users can also switch off tracking requests globally in iOS settings, in which case the prompt never appears.
What does ATT mean for advertisers?
ATT hit platforms like Meta especially hard, since much of their advertising runs inside their own apps. When an iPhone user who declined ATT taps an ad in the Instagram app, Meta has a harder time connecting the later conversion to that click. The result:
- Fewer attributed conversions from iOS traffic
- More signal loss and weaker optimisation
- Greater reliance on modelled data
Platforms responded with server-side interfaces like the Conversions API. There, the quality of the customer data you send matters most, reflected in your Event Match Quality score.
Together with Intelligent Tracking Prevention in Safari, ATT makes up Apple's side of the tracking restrictions.
Example
A user sees your ad in the Instagram app on their iPhone, has declined ATT and later buys on your website. The browser pixel fires, but Meta can only partly link the event to the ad click. If you also send a server event with a hashed email address, Meta can match the buyer to their account.
App Tracking Transparency with LeadSignal
LeadSignal cannot change ATT, but it can soften the impact. With the visitor's consent, the script picks up email, phone and name from forms automatically and sends them SHA-256 hashed through the Meta Conversions API, the TikTok Events API or the LinkedIn Conversions API. Pixel and server event are deduplicated via an event ID. To improve your match rates, read our article on Meta Event Match Quality.