All terms

Mobile Attribution: How App Installs Get Credited to Ad Campaigns

Mobile attribution is the process of matching app installs and in-app events to the ad campaigns that drove them. Learn how device-level attribution works, what changed after iOS 14.5, and why attribution data can be misleading even when it's technically accurate.

Jay Ma
6 min read
Mobile attribution definition: how app installs are credited to ad campaigns
On this page

Mobile attribution is the process of connecting app installs and in-app events back to the ad campaigns or other marketing touchpoints that drove them. When a user sees an ad for a mobile game, clicks it, and installs the game, mobile attribution is how the game developer knows which campaign, ad network, and creative was responsible for that install.

Attribution data drives every optimization decision in mobile paid acquisition: which channels to scale, which creatives to keep running, which audience segments are converting, and which aren't. When attribution is inaccurate, budget flows toward the wrong campaigns.

How Device-Level Attribution Works

The traditional mobile attribution flow has three steps.

First, a user clicks an ad. The ad network records the click and generates a unique click identifier. This click ID is appended to the destination URL (the app store link or deep link).

Second, the user installs and opens the app. The app's attribution SDK fires a request to the MMP (AppsFlyer, Adjust, Branch, Singular), passing along the click ID or the device's advertising identifier (IDFA on iOS, GAID on Android).

Third, the attribution platform matches the install to the click. If the click ID matches, the install is attributed to that campaign via deterministic attribution. If there's no click ID (for example, the user saw an ad impression but didn't click, or cleared their clipboard), the platform may fall back to probabilistic attribution — matching based on IP address, device fingerprint, or timestamp — which is less accurate.

The matched attribution data is sent back to the ad network, which uses it to optimize delivery toward users similar to those who converted.

What iOS 14.5 Changed

Before April 2021, iOS attribution worked as described above. The IDFA was available by default, and cross-app tracking was a standard part of the mobile ad ecosystem. Attribution platforms could match users across apps and sessions with high accuracy.

iOS 14.5 introduced the App Tracking Transparency (ATT) framework. Now, apps must request explicit permission before accessing the IDFA. Users who decline (typically 55-75% of users in most markets, leaving 25-45% opt-in) cannot be tracked at the device level.

For opted-in users, deterministic attribution still works. For opted-out users, Apple introduced SKAdNetwork (SKAN), a privacy-preserving attribution framework that provides:

  • Aggregated conversion data instead of user-level data
  • A delay of 24-72 hours before conversion signals arrive
  • Limited conversion value cardinality (a 6-bit conversion value in SKAN 3, expanded to 64 coarse values + 64 fine values per postback in SKAN 4)
  • No user-level signals — only campaign-level aggregate data

This created a split attribution landscape: device-level data for opted-in users (rich, accurate, individual), SKAN aggregate data for opted-out users (delayed, coarse, campaign-level). Most attribution platforms now blend these two streams to produce modeled attribution estimates for opted-out users.

The Attribution Accuracy Problem

Even before iOS 14.5, mobile attribution was not perfectly accurate. Several systemic issues affect attribution quality:

Last-click dominance. Most attribution models credit the last click before install. If a user saw a Facebook ad, then a Google ad, then searched the app store organically and installed — the organic search gets credit unless a click ID from the last ad click was carried through. Many conversions driven by multi-touch journeys are attributed to whichever channel happened to touch the user last.

Install fraud. Click injection (fraud apps fire fake clicks just before a real install to steal attribution credit), click flooding (sending massive numbers of fake clicks hoping some match to real installs), and SDK spoofing (faking SDK traffic) inflate install numbers on fraudulent publishers while stealing credit from legitimate sources. Attribution platforms have fraud protection systems, but determined fraud operations adapt faster than fraud detection improves.

View-through attribution windows. Most platforms let advertisers claim attribution credit for users who saw an ad impression (without clicking) and then installed within a specified window (often 24 hours to 7 days). View-through attribution significantly inflates conversion counts, especially on social platforms where ad impressions are frequent and organic installs are high.

SKAdNetwork modeling uncertainty. SKAN's conversion values are coarse and delayed. Attribution platforms model what happened from limited signals. Models introduce uncertainty that's invisible in standard reporting — a campaign that shows 500 attributed installs via SKAN modeling may actually have driven anywhere from 380 to 680 real installs.

What Attribution Data Is Good For

Despite these limitations, attribution data is essential for direction-setting. It tells you which channels and campaigns are performing relative to each other within the same attribution framework. Even if the absolute numbers are off, the relative performance comparison across campaigns on the same platform is usually directionally accurate.

Attribution data is least reliable for cross-channel comparison. Comparing Google UAC attributed installs against Meta attributed installs against organic installs is an apples-to-oranges comparison: each channel uses different attribution windows, different credit rules, and different fraud protection levels.

Incrementality testing is the complement to attribution for cross-channel comparisons. Attribution tells you where credit is flowing; incrementality tells you where growth is actually being caused.

X-Ray tracks post-install behavioral data (retention, events, revenue) at the cohort level, which lets you validate attribution accuracy by comparing the behavioral quality of users attributed to different campaigns. Campaigns attributing low-quality users (high churn, low LTV) may be inflating install counts through fraud or measurement artifacts.

How to Validate Attribution Accuracy

Attribution data can be internally consistent (the numbers add up) while still being inaccurate (the wrong campaigns are getting credit). A few validation approaches give you a sense of how reliable your attribution actually is.

Behavioral quality check. Pull cohort retention and LTV data for users attributed to each channel and each publisher. If users attributed to a specific network have significantly lower Day-7 retention than the organic baseline, the attribution may be capturing fraudulent installs or installs from users who had no genuine intent. High install volume paired with poor behavioral quality is the clearest indicator of attribution fraud, not just measurement error.

Attribution baseline test. Pause one paid channel for 3 to 5 days and observe how organic installs change. If organic installs barely shift when a paid channel goes dark, that channel was likely taking credit for installs that would have happened without it. Fingerprinting-based attribution and click flooding can both cause this pattern: the install happens organically, but a prior click or device fingerprint match causes the MMP to attribute it to a campaign.

Holdout incrementality check. Reserve 15 to 20% of a campaign's target audience as a holdout group that sees no ads. After the campaign window, compare conversion rates between the holdout and exposed groups. Any conversions in the holdout represent organic intent that would have converted without the campaign. The difference between holdout conversion rate and exposed conversion rate is the true incremental lift, which is almost always lower than what the MMP attributes to the campaign.

None of these tests eliminate attribution uncertainty. Mobile attribution has structural limitations that cannot be fully resolved while privacy constraints exist and fraud remains economically incentivized. The goal is calibrated confidence: understanding where your attribution is reliable enough to inform budget decisions and where it is too noisy to be the primary signal.

Frequently asked questions

  • What is mobile attribution?

    Mobile attribution is the process of identifying which marketing touchpoint (ad, campaign, or channel) was responsible for a user installing an app or completing an in-app event like a purchase. An attribution platform matches the user who clicked an ad with the same user who later installed the app, then credits the ad campaign.

  • How does mobile attribution work?

    When a user clicks an ad, the ad platform generates a unique click ID. When the user later installs the app and opens it for the first time, the app's SDK sends the click ID (or device fingerprint data) to the attribution platform, which matches it to the original click. The install is then credited to that campaign. On iOS post-14.5, this process is limited by ATT and replaced in part by Apple's SKAdNetwork (SKAN) for non-opted-in users.

  • What changed with iOS 14.5 for mobile attribution?

    iOS 14.5 introduced the App Tracking Transparency (ATT) framework, which requires users to explicitly opt in before their device ID (IDFA) can be used for cross-app tracking. Opt-in rates average 25-45% depending on how well the permission prompt is timed and framed. For non-opted-in users, Apple's SKAdNetwork (SKAN) provides aggregated, delayed, privacy-preserving attribution data instead of device-level signals.

  • What is SKAdNetwork (SKAN) in mobile attribution?

    SKAdNetwork (SKAN) is Apple's privacy-preserving attribution framework for iOS users who have not opted into ATT tracking. Instead of user-level click IDs, SKAN delivers aggregated postbacks containing campaign identifiers, conversion values, and install counts without linking to individual users. Attribution platforms build probabilistic models on SKAN data to estimate campaign performance for the opted-out user segment.

  • What is the IDFA and how is it used in attribution?

    The IDFA (Identifier for Advertisers) is a unique anonymous identifier assigned to iOS devices. Attribution platforms use it to match a user who clicked an ad with the same user who later installed an app, enabling deterministic attribution. Since iOS 14.5, accessing the IDFA requires explicit opt-in consent via ATT, limiting its availability to the 25-45% of users who accept the tracking prompt.

  • What is probabilistic attribution and when is it used?

    Probabilistic attribution estimates which campaign drove an install when deterministic methods (click IDs, device IDs) are unavailable. It uses device signals like IP address, device type, OS version, and timestamp to find statistical matches between ad clicks and app installs. It is less accurate than deterministic matching but fills gaps created by iOS privacy restrictions and cookieless environments.

Jay Ma

Co-founder

Co-founder of Hellyeah. Writes about building durable growth loops that compound over time.

Find the next growth opportunity.

Tell us what you are promoting, where you are spending and what result you need. We will review the fit and come prepared for the growth audit.