Privacy
Install Trust SDK privacy policy
Last updated October 8, 2026. This covers the Install Trust Android SDK and the AdHedge service behind it. For this website, see site privacy.
Who is who
An app's developer chooses to include the Install Trust SDK. The developer decides what the app collects and is responsible for telling its users. AdHedge processes install-verification data on the developer's behalf, as a service provider.
What the SDK sends
Facts about the app and its install, including the Play install referrer. The device's build values and hardware figures, and checks of its environment. A random install ID the SDK creates and, when the app already includes Google's App Set library, the Play App Set ID. A Play Integrity token. For a new install, touch counts and session timing. Our server also sees the IP address each request comes from and derives a country and a network from it.
Every field, its Android source and how long it is kept: data safety.
What it never reads
Android ID, advertising ID, IMEI, serial number, MAC address. Phone number or phone state. Accounts, contacts, calendar, SMS, call logs. Location. The list of installed apps. Touch coordinates, screen contents, text input. The SDK declares no runtime permission.
The full list, with its one caveat, is under Never collected.
What the data is used for
Verifying installs, reporting the result to that app's developer, and running and improving the verification. In Play's terms: fraud prevention, security and compliance, and analytics.
AdHedge does not sell the data. It is not used for advertising or marketing. It is not combined across apps into a device identity, and it is not joined to advertising identifiers or personal information.
Who receives it
AdHedge, and the infrastructure providers that host the service and carry its traffic. The app's developer sees the results in the AdHedge console.
The Play Integrity token is produced by Google Play on the device, under a Google Cloud project linked to the app. AdHedge has Google decode it, keeps the decoded answer and does not keep the token.
Retention and deletion
How long each kind of data is kept is under Handling on the data safety page.
A developer asks for an install's data to be deleted, with its install ID, through the contact form on this site. An app's user asks the app's developer, who holds the link between a user and an install.
Security
Everything the SDK sends goes over TLS. The SDK has no plaintext transport.
Children
The SDK does not know a user's age. It asks for no account or contact information. A developer whose app is for children decides whether the SDK fits the rules for that app.
Changes
When this policy changes, the date at the top of this page changes with it.
Contact
AdHedge provides the SDK and runs its service. Reach us through the contact form on this site.