Privacy Policy
Last updated 23 September 2026
TrueOrigin tells app publishers which ad or link led to an install of their iOS app. This policy explains which personal data we process to do that, and for what purposes. It also covers our website and our dashboard.
1. Who we are
TrueOrigin is operated by KI Koehler International Ltd., Archiepiskopou Makariou III, 59, MOUYIAS TOWER, 3rd floor, Flat/Office 301, 6017 Larnaca, Cyprus, registration number HE482364 ("we", "us").
For privacy questions and requests, write to hello@trueorigin.dev. We have not appointed a data protection officer, because the law does not require one for us.
2. Our two roles
- Our own services. For our website trueorigin.dev, our dashboard app.trueorigin.dev and our contact with customers and prospects, we decide how personal data is used. We are the controller (Sections 3 and 4).
- Our customers' apps. App publishers ("customers") use TrueOrigin through tracking links on appdownload.link and through the TrueOrigin SDK in their apps. For that data, the app publisher is the controller and we process it on its behalf as a processor (Section 5). If you tapped an ad or installed an app that uses TrueOrigin, the app's privacy policy applies, and the app publisher is your first contact. We describe the processing here so you can see exactly what happens.
3. Our website trueorigin.dev
Visiting the site. Our hosting provider Vercel processes your IP address, browser
details, the page requested and the time, to deliver the site and protect it from
attacks. The site sets no cookies and uses no analytics or advertising tools. Its fonts
are served from our own domain.
Legal basis: our legitimate interest in a working, secure website (Article 6(1)(f)
GDPR).
Our documentation docs.trueorigin.dev. Mintlify hosts our documentation and
processes your IP address, browser details, the page requested and the time, to deliver
the pages and protect them from attacks. We have turned off Mintlify's analytics and
page feedback.
Legal basis: our legitimate interest in working, secure documentation (Article 6(1)(f)
GDPR).
Early access form. When you request access, we store your email address, the app
you named, your monthly ad spend range, the ad platforms you selected, your note, your
browser's user agent, and the address of the page you sent the form from, including its
parameters (for example campaign tags). We may get a notification email with these
details. We use them to reply to you and to set up your access; we do not send
newsletters.
Legal basis: steps you asked for before a contract (Article 6(1)(b) GDPR).
Retention: until your early access is settled; we delete a request earlier if you
ask. If you become a customer, Section 4 applies.
Booking a call. "Book a call" opens our booking page at Cal.com. When you book,
Cal.com stores your name, email address, the time you chose and anything you add to
the booking, and processes your IP address and browser details to deliver the page. We
use this to hold the call and to follow up on it.
Legal basis: steps you asked for before a contract (Article 6(1)(b) GDPR).
Retention: as long as the conversation continues; we delete a booking earlier if you
ask. If you become a customer, Section 4 applies.
Email. When you write to us, we use your message and contact details to answer
you. We keep correspondence as long as the conversation continues and as long as
commercial and tax law require.
Legal basis: Article 6(1)(b) or (f) GDPR, depending on the topic.
4. Our dashboard app.trueorigin.dev
Account. Your email address and password. The password is stored hashed by our authentication provider Supabase; we never see it. Supabase also records sign-in and confirmation times, and the IP address and browser of each sign-in, for security.
Organization. The organization's name (by default derived from your email domain), its members' email addresses and roles, and invitations: the invited email address, who invited it, and the expiry date. Invitations expire after 30 days. When an owner removes a member, the membership is deleted.
Apps and settings. App details, tracking links, the time zone and currency you choose, ad spend you import, and your connections:
- RevenueCat: a webhook credential, stored hashed.
- Meta and TikTok: the pixel or dataset ID, the access token (stored encrypted) and an optional test event code. If you connect an ad account through Meta or TikTok login, we receive an access token and read the ad accounts, pixels, campaigns, spend and delivery figures you grant us access to. We use this only to show your spend and return on ad spend, and to send the conversions you enable. We do not use it for any other purpose, and we do not share it.
- Test events: when you press "Send test event", your browser's IP address and user agent are sent to Meta or TikTok as the test tap and kept in the delivery log.
Adding an app. Your search term and a country code are sent from our server to Apple's App Store search. Your browser loads app icons directly from Apple's servers, so Apple sees your IP address.
Cookies and local storage. Sign-in cookies set by Supabase (needed to keep you
signed in), a cookie to_app that remembers the app you last opened (one year), and a
local-storage entry per app that remembers whether you hid the setup checklist. When you
create an app or rotate its SDK key, the new key is also kept in your browser's local
storage so the setup checklist can fill it into the install code; it is removed the next
time that browser opens the app's Overview after the SDK has reported an install. The dashboard uses no analytics or advertising cookies.
Legal basis: performance of our contract with you or your company (Article 6(1)(b)
GDPR), and our legitimate interest in running the dashboard securely (Article 6(1)(f)
GDPR).
Retention: as long as the account exists. When an account ends, we delete its data
within 30 days, unless the law requires us to keep it. To close your account, write to
hello@trueorigin.dev.
5. Data we process for our customers
This section is about the people who tap a customer's tracking link or install a customer's app ("end users"). We process their data on behalf of the app publisher, to tell the publisher which ad or link led to an install.
5.1 Tapping a tracking link
A tracking link looks like appdownload.link/{app}/{campaign}. When you open one, a
short page loads and forwards you to the App Store, or on other devices to a page the
publisher chose. We record:
- From the request: IP address, user agent, the request headers except cookies
(for example language and referrer), the full link including its parameters
(campaign and ad identifiers, and click IDs the ad network adds, such as
fbclid,ttclidorgclid), and the time. - Derived from the IP address by Cloudflare: country, region, city, postal code, approximate coordinates, time zone, network operator (ASN and name) and connection details.
- Read by a script on the page: screen and window size, pixel density, color depth and range, orientation; time zone, languages, clock and calendar format, number format; number of processor cores, device memory, touch points, platform and browser vendor; display and accessibility settings (dark mode, reduced motion, increased contrast, reduced transparency, inverted or forced colors, text size, pointer type); and whether cookies are enabled, the page runs as a web app, the browser is automated, a PDF viewer is available, the referring page, and whether the page is visible.
The page sets no cookies and stores nothing on your device.
5.2 Opening an app that contains the TrueOrigin SDK
On the app's first launch, the SDK sends one install report:
- Network: your IP address as our server sees it, and the data derived from it as in 5.1; connection type (Wi-Fi or cellular), whether a VPN is active, IPv4/IPv6 availability, Low Data Mode and whether the connection is marked as expensive.
- Device: hardware model, iOS version and kernel release, screen size and scale.
- Settings: time zone, preferred languages, clock and calendar format, dark mode, reduce motion, increase contrast, reduce transparency, invert colors and text size.
- App: bundle ID, app version and build, SDK version, the date the app's data folder was created, and from Apple's StoreKit: the original purchase date, the original app version, the environment (production, sandbox or Xcode) and the transaction ID of the app download.
- A random install ID that the SDK creates, and the time of the first launch.
The SDK keeps the install ID and the attribution result in the app's own storage on your device; they are deleted with the app. The SDK does not access the advertising identifier (IDFA), the vendor identifier (IDFV), your contacts, precise location or the clipboard.
5.3 Purchases
If the app publisher connects RevenueCat, we receive RevenueCat's notifications about purchases in the app: event type, product, price, currency, store, country, transaction IDs and times, the RevenueCat user IDs and aliases, and every subscriber attribute the publisher has set, including the TrueOrigin install ID. Depending on the publisher's setup, user IDs and attributes can contain an email address, a name or device identifiers. We keep each notification as received.
5.4 Matching
We compare the install report with recent taps on the same app's tracking links, using time, network, device and settings data, and calculate how likely each tap is to have led to the install. The result is matched, ambiguous or unmatched. We store the result, the taps considered and their scores. Installs are never compared with taps on another app's links.
The result tells the publisher which ad or link brought an install. It is not used to make any decision about you.
5.5 Sending the result back to the app
The SDK receives the result: whether the install was matched and, if so, the campaign, ad, click IDs and link parameters of the tap. The app may pass it to its own tools, such as RevenueCat or its analytics, under the publisher's privacy policy.
5.6 Conversions sent to Meta and TikTok
If the publisher connects Meta or TikTok, and an install is matched to a tap on that network's ad, we send that network the events the publisher has enabled (install, trial, subscription, purchase). Each event contains: the event name and time, the install ID (plain in the event ID, hashed as external ID), the IP address and user agent of the tap, the network's click ID, the link with its parameters (and, for TikTok, the referrer), and for purchases the value, currency and product ID. The network uses these events to measure and optimize the publisher's ads, under its own privacy policy. Ambiguous and unmatched installs are never sent.
5.7 Our role and our own purposes
For all of Section 5 we act on the publisher's instructions, and the publisher decides the legal basis. We also use this data, as controller, for three purposes of our own:
- keeping the service secure and preventing abuse;
- measuring and improving the accuracy of our matching, for example by re-running it on stored data to measure how often it matches wrongly; and
- statistics that identify no person, app or publisher, such as our published error rates.
Legal basis: our legitimate interest in a secure and accurate service (Article 6(1)(f) GDPR). You can object to this at any time (Section 9).
5.8 Retention
We keep this data while the app uses TrueOrigin. It is deleted when the publisher deletes the app in the dashboard, or within 30 days after the publisher's account ends. Taps we could not process, for example malformed ones, are kept apart without a link to an app, for troubleshooting only.
5.9 Your rights for this data
Please contact the app publisher first. You can also write to us; we will pass your request to the publisher and help answer it. We usually do not know who an end user is, so to find your data we may need details such as when you tapped the link.
6. Service providers
These providers process personal data for us, bound by data processing agreements:
| Provider | Purpose | Where data is processed |
|---|---|---|
| Cloudflare | Click pages, install endpoint, queues, DNS and network protection | Worldwide network |
| Railway | Hosting our backend | Netherlands |
| Supabase | Database, dashboard sign-in and its emails | United Kingdom (London) |
| Vercel | Hosting trueorigin.dev and app.trueorigin.dev | United Kingdom (London); content delivery worldwide |
| Google Workspace | Worldwide | |
| Cal.com | Booking calls from trueorigin.dev | United States |
| Mintlify | Hosting docs.trueorigin.dev | United States; content delivery worldwide |
| Resend | Sending emails | United States |
| PostHog | Error tracking | United States |
Other recipients. Meta and TikTok receive the conversions a publisher enables (Section 5.6), as recipients the publisher chooses, under their own terms. Apple receives App Store searches and icon requests from the dashboard (Section 4). We disclose data to authorities only where the law requires it.
7. Transfers outside the EEA
Some providers are based in the United States or process data worldwide. The United Kingdom has an adequacy decision of the European Commission. For other countries without one, we rely on the European Commission's Standard Contractual Clauses, or on the provider's certification under the EU-U.S. Data Privacy Framework. You can ask us for a copy of the safeguards.
8. Security
Data travels encrypted (TLS). Ad network access tokens are stored encrypted, and app API keys and webhook credentials are stored only as hashes. Access to the database is limited to our backend and the people who operate TrueOrigin.
9. Your rights
Under the GDPR you have the right to access your data, to have it corrected or deleted, to restrict its processing, to receive it in a portable format, and to object to processing based on our legitimate interests. Where processing relies on your consent, you can withdraw it at any time. Write to hello@trueorigin.dev; we answer within one month.
You can also complain to a supervisory authority, in particular in the country where you live or work. Ours is the Commissioner for Personal Data Protection, 1 Iasonos Street, 1082 Nicosia, Cyprus (dataprotection.gov.cy).
10. Other points
No sale, no automated decisions. We do not sell personal data. We make no decisions based solely on automated processing that have legal or similarly significant effects on you.
United States. For end-user data we act as a service provider (processor) of the app publisher, under US state privacy laws such as California's. We do not sell personal information, and we do not share it for cross-context behavioral advertising on our own account; conversions reach Meta and TikTok only on the publisher's instruction.
Children. Our services are for businesses and are not directed at children. Our customers may not use TrueOrigin in apps directed at children.
Changes. We update this policy when our processing changes. The date at the top shows the current version. We tell customers about material changes by email or in the dashboard.