Data & privacy
Use this page to complete your privacy policy and your App Store App Privacy details.
Data collected
Section titled “Data collected”| Category | Data | When |
|---|---|---|
| Device | Model (hardware identifier), OS version, screen size and density | Session start |
| App | Bundle id, version and build number | Session start |
| Identifiers | Random device id generated by the SDK (not the IDFA or IDFV); session id; the user identifier you pass to identify() |
Every event |
| Usage | Screens, taps (accessibility id, label, text), view-controller lifecycle | Continuously |
| Diagnostics | Crash stack traces and thread info; your trace logs | On event |
| Network | URL, method, status, duration, request/response headers and bodies | Each call through an instrumented URLSession |
| Device integrity | Jailbreak, simulator and debugger-tamper flags | Once per launch |
| Location | Last known location — only if your app already holds a location permission | Once per launch |
| Dependencies | Your app’s library list and versions | Once per app version |
The SDK uses its own random identifier and never reads the IDFA (advertising id), so it adds no App Tracking Transparency requirement of its own. It never requests a location permission — it only reads a cached location when your app has already been granted one.
Remote storage commands
Section titled “Remote storage commands”From the dashboard, authorized team members can send commands to a device during an active session. The SDK polls for them every 30 seconds while the app is in the foreground:
- Capture storage — upload a snapshot of the app’s
UserDefaultssuites. - Set — write a value to a
UserDefaultskey. - Clear — remove a key or clear a suite (clearing everything with
*is refused).
The SDK’s own suite and known-sensitive suites (Apple security, Firebase, Google) are excluded, and you can exclude more with Cimka.denyStorageSuites(_:).
Controls
Section titled “Controls”| Control | Where | Effect |
|---|---|---|
| Masked properties | Dashboard → application settings | Header names and JSON keys replaced with [MASKED] in network logs |
| Always-removed headers | Built in | Authorization, cimkaApiKey, cimkaAppId are never logged |
maskSensitiveInputs |
cimka_config.json |
Text-field text logged as *** (default on); secure fields always masked |
cimkaMasked |
Your code | Exclude a view from click tracking (UIKit) |
denyStorageSuites(_:) |
Your code | Exclude UserDefaults suites from remote storage commands |
| Log type switches | Dashboard | Disable click, screen, crash, network, trace, lifecycle, session, device audit or dependency logs |
| SDK kill switch | Dashboard | Disable the SDK entirely without an app update |
clearUser() |
Your code | Stop attaching the user identifier |
Screen names and click labels are stored as-is — don’t put personal data in them.
Transport security
Section titled “Transport security”Every request is sent over HTTPS (when baseUrl uses https) and signed with HMAC-SHA256 using your license key, with a timestamp and a one-time nonce, so requests can’t be forged or replayed.