Compliant with GDPR, CCPA, COPPA, LGPD, PECR, PDPA, PIPEDA, and more.
This guide is for mobile app publishers. It sets up the UniConsent app SDK with the ad, analytics and attribution SDKs most apps use, so that each SDK gets the consent signal it needs in Europe and in the other regions where you have users.
Time needed: about 1 to 2 hours: about 10 minutes for Step 1, 20 to 30 minutes to add the SDK in Step 2, 5 to 15 minutes for each SDK in Step 4, and about 30 minutes to test and check in Steps 6 and 7. Changes you publish in the dashboard reach the app the next time it loads the consent screen.
Who does what: Steps 1 and 3 are done in your UniConsent dashboard. Steps 2, 4 and 5 change your app's code, so your app developer will do those. Steps 6 and 7 are done on a test device.
In your dashboard, create an app project and copy its App ID. The app project uses IAB TCF in Europe: Google requires a Google-certified CMP that uses IAB TCF for ads served in the EEA, the UK and Switzerland, and UniConsent is a Google-certified CMP, Gold tier.
Then turn on the policies for your other regions: CCPA and US State Privacy for the US, and IAB TCF Canada for Canada. Turn on IAB GPP as well, so ad SDKs receive the US and Canada choices.
Add the UniConsent SDK for your platform: Android, iOS, Flutter, React Native. Start it with your App ID when the app launches, before your ad and analytics SDKs, and let it show the consent screen when consent is needed. Each SDK guide shows how.
| Region | What users see | What your SDKs receive |
|---|---|---|
| Europe | The IAB TCF consent screen at first launch | The IAB TCF choice, and Google Consent Mode for Firebase |
| Canada | The IAB TCF Canada consent screen at first launch | The IAB GPP Canada section after the user's choice |
| United States | No screen at launch: US privacy is opt-out. Users opt out from the privacy settings in your app (Step 5). | The US Privacy string and the IAB GPP US sections. When ad tracking is turned off on the device, this counts as an opt-out. |
| Everywhere else | No consent screen | Ads and analytics run as usual |
Europe covers the European Union, Norway, Iceland and Liechtenstein, the United Kingdom, Switzerland, and Albania, Andorra, Belarus, Bosnia and Herzegovina, Kosovo, Moldova, Monaco, Montenegro, North Macedonia, San Marino, Serbia and Ukraine.
In the United Kingdom, the UK GDPR and the ICO's guidance require consent before non-essential storage and tracking, in apps as on websites, so keep the UK in your Europe region.
If you turn off the policy for a region, users from that region are treated as if no CMP were installed: no consent screen appears, and no SDK is held back.
In the US, California is covered by CCPA / CPRA, and Virginia, Colorado, Utah, Connecticut, Florida, Montana, Oregon, Texas, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island by US State Privacy. Users can opt out of the sale and sharing of their data and of targeted advertising, and the choice is passed to ad SDKs in IAB GPP and, for California, the US Privacy string. See US State Privacy Setup.
Ad SDKs and Firebase read the user's choice themselves, from the standard IAB keys the UniConsent SDK stores on the device, so you do not need to hold them back yourself. Start requesting ads once the user's choice is known.
| SDK | How | Guide |
|---|---|---|
| Google Mobile Ads (AdMob, Ad Manager) | Reads the IAB TCF and IAB GPP keys automatically. | Your platform guide: Android, iOS, Flutter, React Native |
| Mediation and other ad networks (for example AppLovin MAX, Unity LevelPlay) | Most read the IAB keys. Check each network's documentation: some also need the US choice through their own setting. | |
| Firebase Analytics | The UniConsent SDK sends the user's choice to Firebase automatically. Set the default consent to off in your app settings, as your platform guide shows. | Your platform guide |
| Attribution (Adjust, AppsFlyer, Branch, Airbridge) | The UniConsent SDK passes the choice to supported attribution SDKs. | App attribution partners |
| App Tracking Transparency (iOS) | Show the ATT prompt after the UniConsent choice. When tracking is not allowed, UniConsent treats it as a US opt-out. | iOS with ATT |
| Web pages inside your app (WebViews) | Pass the user's choice to the web page, so the website's CMP does not ask again. | "Sync Consent to WebView" in your platform guide |
Users must be able to change their choice at any time, and US users opt out from here. Add a Privacy Settings item to your app's settings screen that opens the UniConsent screen. Your platform guide shows how to open a specific screen, for example the settings: Android, iOS, Flutter, React Native.
Set a test region in your app to see the screens of another region, then repeat with CA (Canada), CAQC (Quebec), USCA (California), USTX (Texas) and N (outside these regions):
// for testing only: remove it in release builds
UniConsent.getInstance().setTestRegion("EU");
The UniConsent demo apps have a test region picker. Remove the test region before you release your app.
Do each check on a fresh install, or after clearing the app's data, so that earlier choices do not carry over.
EU, open the app. The consent screen appears at first launch, and ads load only after the choice.USCA, open the app. No consent screen appears, and ads load.The UniConsent SDK stores the choice in the app's standard storage (SharedPreferences on Android, NSUserDefaults on iOS), where ad SDKs read it. Your developer can check these keys, or read them with the SDK's methods, for example getGPPString() and getUSPrivacyString():
IABTCF_TCString IAB TCF choice (Europe)
IABGPP_HDR_GppString IAB GPP string (US and Canada)
IABUSPrivacy_String US Privacy string (California)
Contact us: support@uniconsent.com