Quick Answer
Douglas Leith’s October 4 preprint alleges that Apple’s App Store sent searches, viewed apps, ad activity, and button clicks with user- and device-linked identifiers to Apple servers without a consent prompt. Apple’s disclosures describe several App Store data uses for advertising and fraud prevention. The study is unreviewed and tested one older jailbroken iPhone, so users should review Apple Advertising settings and limit sensitive App Store activity where practical.
Key Takeaways
- The October 4, 2026 preprint examined App Store traffic captured during February and March 2026.
- The researcher alleges that App Store searches, app views, ads viewed, and clicks were transmitted with linked identifiers.
- The study also alleges that ad selection used information related to sexuality, religious beliefs, and health.
- Apple says its advertising platform does not know or make available sexual orientation, religious beliefs, or political affiliations to advertisers.
- Users can turn off Personalized Ads in Settings, although Apple says the setting does not reduce the number of ads shown.
What does the Apple App Store tracking study allege?
The Apple App Store tracking study alleges that routine activity inside the App Store was sent to Apple servers alongside identifiers linked to the user and device, without a separate consent prompt. Douglas Leith posted the single-author preprint, titled “Poor Privacy Practices Of The Apple App Store: Cookies, Advertising and Tracking Of Users,” to arXiv on October 4, 2026. The preprint describes captured App Store traffic involving searches, apps viewed, ads viewed, and buttons clicked.
The central privacy question is not whether the App Store needs some data to function. App marketplaces need information to return search results, process downloads, detect fraud, and show relevant listings. The preprint instead questions the scope of App Store telemetry, the identifiers attached to it, and whether users receive a meaningful opportunity to understand or control the tracking described in the research.
Apple App Store tracking is especially notable because the App Store is part of iOS rather than an optional third-party service. Users can choose not to install many apps, but downloading software, updating existing apps, and searching for apps generally require use of Apple’s marketplace. The practical response is to treat App Store searches as potentially sensitive activity, particularly when searching for health, religious, dating, or other personal-interest apps.
What did the App Store testing setup measure?
The App Store study measured encrypted traffic from a jailbroken iPhone 8 running iOS 16.7.11, using a mitmdump proxy to inspect communications. The reported traffic captures took place during February and March 2026. An independent review of the methodology notes that the research relied on one primary test device and a modified operating environment, which limits how broadly the findings can be applied to current iPhones and current iOS versions. The methodology review also identifies the study as an unreviewed preprint.
The preprint alleges that Apple servers stored multiple cookies and advertisements with tracking identifiers on the tested handset. Cookies are small pieces of stored data that can help a service recognize a device or preserve information between sessions. Identifiers can support legitimate functions, but they can also allow separate actions to be connected into a more detailed activity record.
The Apple App Store study does not establish that every iPhone, every iOS version, or every App Store user receives identical tracking behavior. A jailbroken iPhone 8 on iOS 16.7.11 is not representative of all current Apple hardware, and a preprint has not completed peer review. The most sensible interpretation is that the paper raises specific, testable allegations about App Store data handling rather than providing a final regulatory or scientific conclusion.
What sensitive ad targeting did the study identify?
The App Store preprint alleges that App Store ad selection used special-category information related to sexuality, religious beliefs, and health. The researcher’s reported observations are the author’s findings from the tested device and traffic captures, not a determination by the Federal Trade Commission, a court, or another regulator. That distinction matters because the evidence has not yet been independently validated through peer review or an official investigation.
Special-category information can be sensitive because an app search may reveal a personal concern even when a user does not directly state it in a profile. A search for a medical condition, a faith-related app, or a dating service can suggest information that many users would prefer not to connect with advertising. The potential harm is not limited to a single ad because repeated activity signals can create a broader picture of interests over time.
Apple states that its advertising platform does not know or make available a person’s sexual orientation, religious beliefs, or political affiliations to advertisers. Apple’s advertising disclosure also says that App Store search terms, pages viewed, browsing activity, ad interactions, and certain download or purchase information can be used for ad selection or fraud prevention under specified conditions. The apparent tension between the preprint’s interpretation and Apple’s policy language requires further independent examination.
Users should not assume that an ad displayed after an App Store search proves that a single search directly determined the ad. Advertising systems can use multiple signals, and the study’s interpretation remains disputed. Still, people handling sensitive subjects may want to avoid unnecessary App Store browsing tied to those subjects until the claims receive broader verification.
How does Apple describe App Store advertising data?
Apple’s advertising documentation says App Store activity can contribute to advertising and fraud-prevention processes under specified conditions. The disclosed activity includes search terms, pages viewed, browsing activity, interactions with ads, and some download or purchase information. Apple’s documentation matters because it confirms that App Store behavior can have advertising relevance, even though Apple describes limits on how that information is used and shared.
Apple also says that advertisers do not receive certain sensitive personal categories from its advertising platform, including sexual orientation, religious beliefs, and political affiliations. The company’s statement addresses what is made available to advertisers, while the preprint focuses on traffic observed between an App Store client and Apple servers. Those are related but not identical questions, because internal processing, ad selection, and advertiser-facing reporting can operate differently.
Apple’s broader privacy approach also distinguishes platform advertising from third-party tracking. Third-party apps generally need App Tracking Transparency permission before tracking users across other companies’ apps and websites or accessing the device advertising identifier. Apple’s developer documentation describes those App Tracking Transparency requirements. The App Store privacy question is different because the allegations concern Apple’s own first-party service activity.
Users who are already reviewing how apps use permissions may also want to understand application access controls on Apple devices. Privacy controls work differently depending on whether data collection comes from an app, an operating system service, or a platform marketplace.
Does App Tracking Transparency cover Apple’s own App Store activity?
App Tracking Transparency does not function as a general consent prompt for every form of data processing performed by Apple’s own services. Apple says third-party apps must request permission when they track users across other companies’ apps and websites or access the device advertising identifier. The framework is designed around cross-company tracking, which means a user should not expect the standard App Tracking Transparency prompt to appear for every App Store data use described in Apple’s own privacy materials.
The Apple App Store tracking study therefore raises a narrower but important question: how clearly should first-party platform data practices be presented to users when those practices involve advertising-related signals? The absence of an App Tracking Transparency prompt does not, by itself, establish a policy violation. It does mean that users need to rely on Apple’s disclosures, account settings, and platform-level privacy choices rather than a prompt that appears at the moment of App Store use.
Apple’s distinction between first-party services and third-party apps can be difficult to recognize during ordinary use. A user may see a permission request from a downloaded app but not associate App Store searches with advertising settings elsewhere in iOS. The practical response is to review platform controls directly instead of assuming that declining tracking requests in apps applies to Apple’s own services.
Similar privacy choices arise across other consumer AI and social platforms. People who manage conversational data may want to review how to delete saved chat history, because deleting content, limiting ad personalization, and denying cross-app tracking are separate controls with different effects.
How can users turn off Personalized Ads on iPhone?
iPhone users can turn off Personalized Ads by opening Settings, selecting Privacy & Security, selecting Apple Advertising, and turning off Personalized Ads. Apple says this setting does not reduce the number of ads shown. Instead, the setting is intended to reduce the use of personal information for ad personalization, so users may still see App Store advertisements that are less tailored to their activity.
- Open the Settings app on the iPhone.
- Select Privacy & Security.
- Select Apple Advertising.
- Turn off Personalized Ads.
Apple Advertising settings provide a practical privacy control, but the setting is not a complete opt-out from advertising or from every data-processing purpose described in Apple’s disclosures. Apple says some App Store information may be used for fraud prevention, which is a separate function from personalized advertising. Users should therefore read the setting description carefully and avoid assuming that one switch removes all data collection connected to App Store use.
Privacy settings also cannot undo information already provided through a search, download, or purchase. The most cautious approach is to turn off Personalized Ads before conducting searches that reveal sensitive interests. Users who want fewer AI features in everyday apps can apply the same setting-by-setting approach when deciding how to limit Meta AI across supported services.
What are the main limits of the Apple App Store study?
The Apple App Store study has 4 important limits: it is a preprint, it has one author, it has not been peer reviewed, and its main setup used one jailbroken iPhone 8 running iOS 16.7.11. These limits do not disprove the reported observations, but they mean the findings should not be treated as proof that every current iPhone behaves in the same way.
| Study element | What the research supports | What it does not establish |
|---|---|---|
| Traffic captures | Observed App Store traffic on the tested handset during February and March 2026 | Identical behavior across all iPhones, accounts, regions, or iOS versions |
| Identifiers and cookies | The author alleges that Apple servers stored identifiers and cookies on the tested device | That every identifier had the same purpose or was used in every session |
| Sensitive ad selection | The author reports observing selection tied to sexuality, religion, and health-related information | A regulator’s finding or a confirmed Apple policy violation |
| Apple disclosures | Apple says certain App Store behavior can be used for advertising or fraud prevention | That Apple agrees with every interpretation in the preprint |
The study also examines a technical environment that differs from normal consumer use. Jailbreaking changes an iPhone’s security model and is not recommended for typical users because it can weaken device protections and complicate support. Users should not jailbreak an iPhone to try to reproduce the research. Stop and contact Apple Support if a device has already been modified and begins showing security or stability problems.
What should iPhone users do after the App Store tracking allegations?
iPhone users should review Personalized Ads, avoid unnecessary sensitive searches in the App Store, and wait for additional independent examination before drawing broad conclusions. Turning off Personalized Ads is the direct step Apple provides, but users should understand that the setting does not remove ads or necessarily prevent all processing associated with security and fraud prevention.
Users should also keep App Store privacy concerns separate from malware or account-security concerns. The preprint discusses alleged platform tracking behavior, not a claim that the App Store has been hacked. If an iPhone displays suspicious purchase prompts, asks for Apple Account credentials through an unexpected message, or directs a user to install software outside the App Store, treat that as a separate security issue. Recent fake iPhone preorder scams show why unexpected links and credential requests deserve caution.
The most important practical limit is that privacy settings reduce some forms of personalization but do not make online activity completely private. Users with heightened privacy needs should consider what a search term reveals before entering it into any platform service. People dealing with a safety-sensitive health, relationship, or identity issue may want to use trusted professional resources and avoid leaving sensitive activity on a shared device or account.
Apple has not, in the materials cited here, publicly accepted the preprint’s conclusions. The appropriate next step is continued scrutiny of the methodology, Apple’s disclosures, and any response from Apple or relevant regulators. Consumers can take available privacy steps now without treating an unreviewed study as a final finding.
FAQ
Does the Apple App Store tracking study prove Apple violated privacy law?
No, the Apple App Store tracking study does not prove Apple violated privacy law. The paper is an unreviewed, single-author preprint, and its findings are not a determination by a court or regulator.
What App Store activity did the study say Apple received?
The study alleges that Apple received App Store searches, apps viewed, ads viewed, and buttons clicked alongside identifiers linked to the user and device. The reported captures came from testing conducted during February and March 2026.
Can I stop personalized App Store ads on my iPhone?
Yes, iPhone users can turn off Personalized Ads at Settings > Privacy & Security > Apple Advertising. Apple says the setting does not reduce the number of ads shown.
Does App Tracking Transparency stop Apple from using App Store data?
No, App Tracking Transparency is designed for third-party tracking across other companies’ apps and websites or access to the device advertising identifier. Apple’s App Store data practices are addressed through Apple’s disclosures and platform settings instead.
Should I avoid using the App Store after this study?
No, users do not need to stop using the App Store based on an unreviewed preprint. Users concerned about sensitive searches should turn off Personalized Ads and limit unnecessary App Store activity involving personal subjects.