Skip to content
AdsAnalyzer

What is mobile attribution, and how does it work?

You spend money on ads, and installs appear. Mobile attribution is the work of connecting the two: deciding which ad, creator or link caused each install, so you can tell what your money bought.

It sounds like it should be simple. It is not, because the ad and the install happen in two different places, owned by different companies. Someone sees an ad inside Instagram. They tap it, land on the App Store, download your app, and open it an hour later. Your app has no idea any of that happened. Instagram has no idea the install followed. Something has to join the two halves.

The two halves of every match

Every attribution system, ours included, works on the same shape of problem:

  1. The click, recorded when the person taps an ad or a link. It happens on the network’s side, or on a tracking link you own.
  2. The install, recorded when the app runs for the first time and an SDK inside it reports in.

Attribution is deciding which click, if any, belongs to which install. What differs between platforms and networks is the evidence available to make that decision.

Android: the install referrer

Google Play gives you an exact answer. When someone reaches the Play Store through a link that carries a referrer parameter, the Play Store keeps that value and hands it to the app on first launch, through the Install Referrer API. If your tracking link put a click ID in there, the app reads it back and the match is certain — no guessing, no permission prompt.

The same API returns two timestamps: when the ad was clicked and when the download began. Those are useful beyond attribution, because a “click” recorded after the download started cannot have caused it. That pattern is a well-known fraud technique, and the timestamps expose it.

iOS: exact where Apple allows it

Apple gives no equivalent of the install referrer. What it gives instead:

  • Apple Search Ads, through the AdServices framework. The app fetches a token at first launch and the server exchanges it with Apple, which returns the campaign that drove the install. Exact, and no permission needed. The token expires 24 hours after it is created, so it has to be sent promptly.
  • The advertising ID (IDFA), but only when the user allowed tracking in both the app where the ad ran and in yours. Most people decline, so this covers a minority of installs.
  • SKAdNetwork and AdAttributionKit, Apple’s own privacy-preserving measurement. Apple tells the ad network — and you, if the app lists your endpoint — how many installs a campaign produced and a coarse measure of the revenue that followed. Per campaign, not per person, and delayed by a day or more.

That combination is why honest iOS reporting has two layers: exact numbers for the installs you can name, and per-campaign totals from Apple for the rest.

What about guessing?

There is a fourth technique, usually called probabilistic matching or fingerprinting: comparing the IP address, device model and timing of a click with those of an install and calling it a match if they look close enough.

We do not do it, for two reasons. It is against Apple’s rules — Apple says you may not derive data from a device in order to identify it, and apps that include SDKs doing so can be rejected from the App Store. And it is a guess: mobile carriers put thousands of phones behind one IP address, and iCloud Private Relay and VPNs hide it entirely. A number that is confidently wrong is worse than an honest gap.

Windows: how long a click counts

A click does not credit an install forever. Every attribution tool applies a window — commonly seven days for clicks — and an install that arrives after it counts as organic. Shorter windows under-credit ads that people act on slowly; longer ones let a campaign claim installs it had nothing to do with.

When several clicks precede one install, the industry convention is that the last one wins, with earlier ones recorded as assists.

What you actually get

With those signals in place, the questions you can answer are:

  • Which campaigns, creators and links produced installs, and at what cost.
  • Whether those users came back on day 1, 7 and 30.
  • What they paid, and whether the campaign earned back its spend.

The first of those is attribution. The rest is why anyone bothers with it.

Next: how CPI and ROAS are calculated, and what iOS still measures after the tracking prompt.

Measure this for your own app

Add the SDK, connect your ad accounts, and see where your installs really come from.