Privacy and consent
The SofAds SDK follows the consent your app collects, reads a TV's advertising ID only when that is allowed, and reads none at all in apps made for children. This page explains what it does and when, so you can describe it correctly in your consent screen and privacy policy. It is not legal advice; have your own texts reviewed.
Consent and TCF
Pass what your app knows at start-up, and call SofAds.setConsent() whenever it changes. The change is merged into the current state and applies from the next request.
// From your consent tool (IAB TCF v2):
SofAds.init({ appId: "sof_YOUR_APP_ID", consent: { gdpr: 1, tcf: "CP_your_tcf_string" } });
// Or your own consent screen, without TCF:
SofAds.setConsent({ ads: false, analytics: true });| Your app passes | What the SDK does |
|---|---|
gdpr: 1 and a TCF string | Sends an advertising ID only when the string gives consent for TCF purpose 1 (store and/or access information on a device). The string itself goes with every ad request, so demand partners read the rest of your users' choices from it. |
ads: true or ads: false | Your own answer wins over TCF: with false, no advertising ID is sent at all. |
analytics: false | Cookieless mode: no install ID is created, stored or sent for analytics. |
gpp, gpp_sid, us_privacy | Passed on to the ad server and demand partners as given. |
| Nothing about GDPR | The ad server decides from the user's location whether GDPR applies. |
Every field is in the SDK reference. For a "Reset advertising ID" button in your privacy settings, call SofAds.resetAdvertisingId(): it replaces the SofAds install ID with a new one. The TV's own advertising ID is reset in the TV's settings.
Google PAL and the TCF API
Google's Programmatic Access Library (PAL), which only runs where SofAds enables Google demand, reads consent from the page's TCF API (__tcfapi). If your app has its own consent tool with that API, PAL uses it. If it doesn't, the SDK provides a minimal __tcfapi that only ever passes on a TCF string your app gave it:
- with a string, PAL sees exactly that string;
- without one, it reports whether GDPR applies and no consent, so PAL shows only limited ads;
- it never reports consent by default.
The SDK also tells PAL to use limited ads whenever there is no advertising consent or Limit Ad Tracking is on.
Made for children
Each app answers "Is this app made for children?" in the dashboard. Apps that answer yes, and apps that haven't answered yet, are treated as made for children:
- No device IDs. The SDK reads no TV advertising ID and sends no
ifa, ID type or Limit Ad Tracking value, and never sends its install ID as an advertising ID. The ad server ignores any device ID an older SDK might still send, and empties every device macro sent to partners. - No signal providers. Google PAL and any other provider are switched off for the app.
- Child-safe demand only. Only SofAds' own reviewed campaigns and partners marked child-safe may fill. Requests to partners are marked as directed at children (
coppa=1), with the IP address shortened. - What stays. The install ID is still used inside SofAds for frequency caps, user and session counts, and your registered test devices. It never reaches advertisers or partners.
An unanswered app is protected until you answer: see Made for children not answered.
Which IDs the SDK uses, per platform
| Platform | Advertising ID the SDK may read | How |
|---|---|---|
| Samsung Tizen | TIFA (Tizen Identifier for Advertising), with Limit Ad Tracking | webapis.adinfo, with the adinfo privilege in config.xml. See Tizen setup. |
| LG webOS | LGUDID | LG's device ID service, only when your consent setup allows advertising IDs, because LG requires the user's agreement. See webOS setup. |
| Whale TV | WAID | Only through the getter your app passes (whale: { getAdId }); Whale has no public API for it yet. See Whale TV setup. |
| Titan OS | The Titan SDK's advertising ID | Product.WhaleAdID from the Titan SDK's device info. Never the hardware device ID or MAC address. See Titan OS setup. |
| Any platform | The SofAds install ID | A random ID the SDK creates for your app on that TV, stored in the app's local storage. Used where no TV advertising ID is available or allowed. |
When an ID is read and sent
- At start-up, only when allowed. The SDK reads the TV's advertising ID after its start-up configuration says device IDs may be used and the app isn't made for children. Without that configuration, it reads none.
- Only with advertising consent. An advertising ID goes into an ad request only when your consent setup allows it (see consent). Without consent, the request carries no advertising ID at all.
- Fallback. Where no TV advertising ID is available, the SDK sends its own install ID as a publisher-provided ID, together with the TV's Limit Ad Tracking setting where there is one.
- Raw and labeled. IDs are sent as they are, never hashed or relabeled, with their type (
tifa,lgudid,waid,ppid), so partners know what they get. - Limit Ad Tracking. When it is on, the ID is passed with that flag, and only non-personalized (contextual) demand may use it.
- Never on a landing page. Device IDs, IP addresses and the app are never filled into an advertiser's landing URL.
Analytics (users, sessions, test devices) always key on the install ID, never on the TV's advertising ID, and run cookieless without analytics consent.
Privacy policy lines per platform
Your app's privacy policy has to say that it shows ads and what data that involves. Copy the base lines and the lines for your platform, and adapt them to your app. They match the SofAds privacy policy, which is itself still a draft, so treat them as a template.
Every app:
This app shows ads from SofAds. To choose, show and measure ads, the app sends SofAds information about the app and the TV (platform, manufacturer, model, operating system version, screen size and language), your IP address, your consent choices and an advertising identifier where your choices allow it. Where no TV advertising identifier is available or allowed, SofAds uses a random install ID stored by this app, which you can reset in the app's privacy settings. SofAds privacy policy: https://sofads.com/privacy/
Samsung Tizen:
On Samsung TVs, the advertising identifier is the Tizen Identifier for Advertising (TIFA), sent together with your Limit Ad Tracking setting. You can reset TIFA and switch on Limit Ad Tracking in the TV's privacy settings; with Limit Ad Tracking on, only non-personalized ads are shown.
Samsung Tizen with Google demand (PAL):
On Samsung TVs, some ads come from Google. For those ads, the app loads Google's Programmatic Access Library (PAL) from Google's servers. PAL sends Google information about the TV, the app and ad playback (start, end, clicks or scans, and remote interactions such as skipping) and may store an identifier on the TV. PAL reads your consent choices and shows only limited ads without advertising consent or with Limit Ad Tracking on. How Google uses this information: https://policies.google.com/technologies/partner-sites
LG webOS:
On LG TVs, and only after you agree, the advertising identifier is the LG Unique Device ID (LGUDID). Without your agreement the app uses its own resettable install ID instead.
Whale TV:
On Whale TV, the advertising identifier is the Whale advertising ID (WAID), when the app can read it. You can reset or limit it in the TV's settings.
Titan OS:
On Titan OS TVs, the advertising identifier is the advertising ID provided by the Titan SDK. The app never sends the TV's hardware device ID or MAC address to SofAds.
Sources
Checked on October 8, 2026. When a source and this page disagree, the source wins.
- IAB Europe: Transparency and Consent Framework (TCF)
- IAB Tech Lab: TCF v2 consent string and the __tcfapi CMP API
- Google PAL: ConsentSettings
- FTC: Children's Online Privacy Protection Rule (COPPA)
- Samsung Developers: Tizen Identifier for Advertising (TIFA)
- LG webOS TV Developer: Device unique ID (LGUDID)
Keep reading
- SDK reference: consent: every consent field.
- Release checklist: consent and privacy lines before you submit.
- SofAds privacy policy: what SofAds itself does with the data.