What the SDK sends
Once, on the first launch after install, the SDK sends one install report to TrueOrigin over HTTPS, then asks for the result until it is decided. The report holds:
The SDK does not read the advertising ID or the Android ID, and asks for no permission
beyond
INTERNET and the install referrer library’s BIND_GET_INSTALL_REFERRER_SERVICE.
It reads no location, contacts, files or clipboard. The full list is in section 5.2 of our
privacy policy.
Answers for the form
For the SDK’s data:
TrueOrigin processes the data on your behalf, as your service provider. It also uses it
for a few purposes of its own: security, measuring its matching accuracy, and statistics
that identify no person or app (section 5.7 of the
privacy policy). Whether that makes sending it to
TrueOrigin sharing in Play’s sense is part of your decision.
Deletion
TrueOrigin keeps an install’s data while your app uses TrueOrigin, and deletes it when you delete the app in the dashboard. When a user asks you to delete their data, we help: write to hello@trueorigin.dev with the install ID (TrueOrigin.installId).
Purchases reach TrueOrigin from RevenueCat’s servers, not from the TrueOrigin SDK: declare
them as RevenueCat’s own documentation says. revenueCatAttributes() puts the install ID,
and once matched the campaign, into RevenueCat’s subscriber attributes, which the
RevenueCat SDK sends.