Overview
AppsFlyer is a mobile attribution and marketing analytics platform that connects web-based touchpoints — landing pages, ad clicks, and campaign URLs — to mobile app installs and in-app events, providing full-funnel measurement across paid, organic, and owned channels. Its web SDK is deployed on landing pages, web-to-app conversion flows, and mobile web properties.
What This Script Does
Web SDK and Attribution Capture
The AppsFlyer Web SDK loads from appsflyer-sdk.com or via a first-party domain configured by the operator. On page load, it:
- Captures attribution parameters from the referring URL: UTM parameters (
utm_source,utm_medium,utm_campaign,utm_term,utm_content), AppsFlyer click IDs (af_click_id), and ad network-specific click parameters - Identifies the user's device, browser, OS, and approximate geolocation (via IP address)
- Sets a first-party attribution cookie to persist the click attribution through the web-to-app transition
- Fires a page view event to AppsFlyer's collection servers at
impression-us-east-1.appsflyer.comorimpression-us-west-1.appsflyer.com
OneLink Deep Linking AppsFlyer's OneLink feature handles smart redirect links that route users to the appropriate destination based on device type:
- iOS users → App Store listing or direct app deep link
- Android users → Google Play listing or direct app deep link
- Desktop users → web fallback page
OneLink intercepts clicks via a redirect at {brand}.onelink.me or a custom domain, capturing the device and attribution context before forwarding the user. This enables attribution to be maintained through the app store install and first app launch.
Conversion Events The Web SDK fires conversion events at key funnel points — typically when a user reaches a landing page from a paid campaign, submits a lead form, or initiates a web-to-app flow. Events sent include:
- Event name (e.g., "af_complete_registration", "af_purchase", custom event names)
- Conversion value (optional revenue parameter)
- Attribution context (the campaign, ad set, and ad that drove the conversion)
Cookies set:
af_id(first-party, varies — typically 90 days to 1 year) — AppsFlyer visitor identifier for web-to-app attribution persistenceafUserId(first-party, varies) — AppsFlyer user identifier for conversion matching- Attribution parameter storage in
localStorageto survive browser restarts
Domains contacted: appsflyer-sdk.com, impression-us-east-1.appsflyer.com, impression-us-west-1.appsflyer.com, t.appsflyer.com, {brand}.onelink.me
Data collected per session: IP address, User-Agent, device type, OS version, browser, language, referrer URL, full landing page URL and query parameters, UTM parameters, ad network click IDs, screen dimensions, timestamp.
Consent & Compliance
GDPR/ePrivacy: AppsFlyer performs cross-device attribution tracking that links web behavior to mobile app activity. The attribution cookies (af_id, afUserId) and the IP-based device fingerprinting used for probabilistic attribution require explicit opt-in consent under GDPR Article 7 and the ePrivacy Directive. Probabilistic matching using IP address and device signals without cookies constitutes processing personal data even without a cookie.
CCPA/CPRA: AppsFlyer's attribution data — linking ad clicks to app installs and in-app purchases — constitutes personal information that may be shared with ad network partners for attribution reporting, qualifying as sharing personal information under CCPA. Opt-out requests via Global Privacy Control (GPC) must be honored.
EU-US Data Transfers: AppsFlyer Ltd. (Israeli entity) processes data subject to Israeli data protection law. Data transferred to AppsFlyer's US servers is covered by Standard Contractual Clauses. Israel has an EU adequacy decision for data transfers.
IAB TCF: AppsFlyer is registered as an IAB TCF vendor. Attribution tracking maps to IAB TCF Purposes 1, 2, and 7.
Consent category: Analytics and Marketing (mobile attribution and campaign measurement).
Should You Block This Without Consent?
Yes. AppsFlyer tracks users across the web-to-app funnel for advertising attribution and campaign measurement. Both the attribution cookies and the probabilistic fingerprinting (IP + device signals) require consent under GDPR and ePrivacy. Block the AppsFlyer Web SDK until analytics or marketing consent is granted. For sites targeting EU users, ensure the SDK initialization is deferred until after consent is obtained, and configure AppsFlyer's privacy-preserving mode for non-consenting users.
Is AppsFlyer GDPR compliant?
AppsFlyer typically loads marketing and analytics trackers, which are not strictly necessary for your site to work. Under the GDPR and the ePrivacy Directive, non-essential cookies and trackers must stay blocked until a visitor gives clear opt-in consent. So AppsFlyer can be fully GDPR compliant, but only if your site holds its scripts until consent is granted and lets visitors decline just as easily. Compliance depends on how your site loads AppsFlyer, not on AppsFlyer itself.
Consent Categories
Also Known As
Industries
Tracked Domains (3)
appsflyer.comMarketingappsflyer.com is a marketing domain operated by AppsFlyer, used to serve ads, build audiences, and measure ad conversions.
cdn-sdk.appsflyer.comMarketingcdn-sdk.appsflyer.com is a marketing domain operated by AppsFlyer, used to serve ads, build audiences, and measure ad conversions.
onelink.meMarketingonelink.me is a marketing domain operated by AppsFlyer, used to serve ads, build audiences, and measure ad conversions.
Frequently Asked Questions
Related Vendors
Manage consent for AppsFlyer
ConsentStack automatically detects and manages AppsFlyer trackers so your site stays compliant with global privacy regulations.