Reference document for completing the Data safety section and the Advertising ID declaration in Play Console.
Important: this is not resolved by code alone. Manifest changes make the collection explicit and consistent, but the flag is only raised when the form in Play Console is updated with what is below.
Public repository. This document describes what data categories each SDK collects. Do not add API keys, tokens, DSNs, Play Console account IDs, credentials, or real user identifiers here.
1. The report
Version code 6: Policy declaration - Data safety section: Device or other identifiers data type: Device or other identifiers (some common examples include advertising ID, Android ID, IMEI, BSSID, MAC address)
Translation: the Play scan detected that the app accesses device identifiers, but the version code 6 Data Safety declaration does not declare the Device or other identifiers data type.
2. Root cause
The app integrates eight analytics, attribution, monitoring, and ad SDKs. Several of them read the
Advertising ID (GAID) and/or generate persistent installation identifiers, and several inject
com.google.android.gms.permission.AD_ID into the final manifest via manifest merge —
meaning the permission was already in the published APK even if it did not appear in
app/src/main/AndroidManifest.xml. Play detects this and compares it against the form.
This is not a false positive: the app does collect device identifiers.
3. Code changes already applied
None of these alter runtime behavior. They are for traceability and consistency:
AD_IDdeclared explicitly inapp/src/main/AndroidManifest.xml. Play requires this permission in apps targeting Android 13+ that access the advertising ID (without it, the GAID returns as zeros). It came via merge fromfirebase-analyticsandaf-android-sdk; now it is visible, commented, and auditable against this document.Removed the
com.facebook.sdk.AdvertisingIdCollectionEnabledmeta-data. That key does not exist in the Meta SDK — the valid ones areAutoInitEnabled,AutoLogAppEventsEnabled,AdvertiserIDCollectionEnabled,CodelessDebugLogEnabledandMonitorEnabled(constants ofFacebookSdk). It was a no-op attruethat visually contradictedAdvertiserIDCollectionEnabledatfalse, and made the manifest read as if Meta would collect the ad ID when it does not.
Effective behavior after the change: the Meta SDK continues without collecting the Advertising ID. The GAID is still used by Firebase Analytics and AppsFlyer, as before.
4. What to complete in Play Console
4.1 App content → Advertising ID
| Field | Response |
|---|---|
| Does your app use the advertising ID? | Yes |
| Purpose of use | Analytics and Advertising or marketing (installation attribution) |
This declaration is independent of the Data Safety declaration and is also mandatory when targeting Android 13+. If missing, Play blocks publication separately.
4.2 Data safety → Data types to declare
The report names a single type, but if Device identifiers was undeclared it is very likely that the other three are also missing. It is convenient to review all of them in the same pass to avoid rebouncing.
a) Device or other identifiers — the one that triggered the report
| Form question | Response |
|---|---|
| Is this data collected? | Yes |
| Is this data shared with third parties? | Yes (see note below) |
| Is this data processed ephemerally? | No |
| Is collection optional? | Mandatory — the app offers no opt-in or opt-out | Purposes | Analytics · Advertising or marketing · App functionality · Fraud prevention, security and compliance |
What falls here concretely: GAID, Android ID (AppsFlyer fallback), AppsFlyer ID, Firebase App Instance ID, Firebase Installation ID, Mixpanel distinct_id, Amplitude device ID, New Relic device UUID, and Sentry installation ID.
Note on "shared": Play does not consider sharing sending to a provider that processes data on your behalf. Purely analytics SDKs (Firebase, Amplitude, Mixpanel, Sentry, New Relic) usually fall under this category. Meta, on the other hand, uses data for its own advertising purposes, and AppsFlyer distributes attribution data to ad networks. That is why the safe answer is Yes. Confirm this against the DPAs you have signed with each provider.
b) App information and performance → Crash logs
| Question | Response |
|---|---|
| Is this collected? | Yes — Firebase Crashlytics, Sentry, New Relic |
| Is this shared? | Yes | Is collection optional? | Mandatory |
| Purposes | Analytics · App functionality |
c) App information and performance → Diagnostics
| Question | Response |
|---|---|
| Is this collected? | Yes — Firebase Performance Monitoring, New Relic, Sentry (tracesSampleRate = 1.0) |
| Is this shared? | Yes | Is collection optional? | Mandatory |
| Purposes | Analytics · App functionality |
d) App activity → App interactions
| Question | Response |
|---|---|
| Is this collected? | Yes — AnalyticsEvents events (app_open, screen_view, webview_load_*, navigation_back, webview_error) |
| Is this shared? | Yes | Is collection optional? | Mandatory |
| Purposes | Analytics · Advertising or marketing |
e) Location → Approximate location — evaluate
The app does not request location permissions. However, Firebase Analytics and other SDKs derive an approximate geolocation from the IP on the server side. Google documents approximate location derived from IP within what Google Analytics reports.
Suggested criterion: declare it as collected with Analytics purpose. This is the conservative option and has no cost; under-declaring is exactly what generated this report.
5. SDK inventory
Source: gradle/libs.versions.toml and app/build.gradle.kts.
| SDK | Where it initializes | Identifiers it touches | Other data |
|---|---|---|---|
| Firebase Analytics | MainActivity.onCreate() |
App Instance ID, GAID | Interactions, approximate location via IP, device info |
| Firebase Crashlytics | Auto (plugin) + MainActivity |
Crashlytics Installation UUID | Stack traces, device state |
| Firebase Performance | MainViewModel (traces webview_page_load) |
Installation ID, IP | Load metrics, url attribution |
| AppsFlyer | MainActivity.setupTracking() |
GAID, Android ID (fallback), AppsFlyer ID, IP | Events, install referrer |
| Install Referrer | Transitive via AppsFlyer | — | Play Store referrer |
| Meta SDK + Audience Network | MainActivity.getFacebookLogger() |
Ad ID disabled by manifest | Manual app events |
| Amplitude | MainActivity.setupTracking() |
Device ID (UUID) | Events (offline = true, useBatch = true) |
| Mixpanel | MainActivity.setupTracking() |
distinct_id, device info |
Events (trackAutomaticEvents = false) |
| New Relic | MainActivity.onCreate() |
Device UUID | Crashes, network, performance |
| Sentry | SaltoInicialApp.onCreate() |
Installation ID | Errors, breadcrumbs, sessions, traces |
6. Open points to review
None of these are part of the current report, but all three could generate the next one:
URLs sent to analytics.
MainViewModel.onPageStarted/onPageFinished/onErrorsends the URL of each visited page to the five analytics providers, andFirebasePerformancestores it as a trace attribute. These are all URLs withinsaltoinicial.com.ar, so they fit better as App interactions rather than Web browsing history — that category is meant for general-purpose browsers. If the WebView ever allows navigation outside the own domain, the classification needs review.No consent mechanism. All SDKs start in
onCreate()without asking the user anything. That is why collection is declared as Mandatory. If the app targets EU/EEA users, this also needs a CMP compatible with the Consent Management Platform requirement of Play, which is a separate topic from this report.Audience Network initializes without showing ads.
AudienceNetworkAds.initialize()runs inMainActivity.kt, but there is noAdView,NativeAdorInterstitialAdin the project. A third-party ad SDK is being loaded with its associated data surface without using it. If there is no plan to monetize with Audience Network, removing it reduces what needs to be declared and the APK size.
7. Maintenance
When adding, removing, or reconfiguring any third-party SDK, update this document and review the declaration in Play Console before publishing. The gap between what the app does and what the form declares is exactly what Play penalizes.
8. Sources
- Provide information for Google Play's Data safety section — Play Console Help
- Advertising ID — Play Console Help
- Behavior changes: Apps targeting Android 13 or higher — Android Developers
- Firebase: Prepare for Google Play's Data safety section
- AppsFlyer: About device identifiers
- AppsFlyer: Bulletin — The Android SDK adds the AD_ID permission
- Meta: Getting Started with App Events for Android
