One number, every app¶
Nothing in this market works without a value that means the same thing in a weather app and a dating app. The advertising identifier is that value. It is the reason a coordinate from one application and a coordinate from another can be laid on the same timeline, and it is the single design decision that turns a heap of unrelated records into a person’s week.
A privacy improvement, faithfully delivered¶
Before the identifier there were hardware serials, permanent and unchangeable, which is worse on almost every count a privacy engineer would name. Apple introduced the identifier for advertisers in 2012 with an opt-out. Google shipped the Android equivalent in 2013 with a reset button. In 2016 iOS 10 zeroed the value outright for users who opted out, and by 2021 Android 12 could do the same while iOS 14.5 replaced the setting with a per-app prompt. Each step is a real improvement on the serial it replaced, and the history netzpolitik.org set out in September 2024 reads as a decade of incremental good faith.
None of it touched the join. A resettable identifier still identifies until it is reset, and the reset is a thing a person does, occasionally, on one device, against a trade that can knit the record together again from the sessions that follow, which makes the reset a nuisance to the market rather than a defence against it. The improvements moved the burden rather than the capability, and they moved it to the far end of edge 1, where the person with the handset holds the only control anybody has bothered to build.
Handsets without an advertising identifier at all, such as those running GrapheneOS, show that the value is a design choice rather than a technical necessity. It is not a choice the two companies that make it have any reason to revisit.
The auction that broadcasts¶
The identifier travels because the advertising auction sends it everywhere at once. An app with a slot to sell emits a bid request carrying the identifier, the position, the network address and the device model, and the request goes to hundreds of firms in the milliseconds before the screen finishes drawing. One German demand-side platform put its own traffic at 1.8 billion bid requests a day.
Losing costs a bidder nothing, and a loser keeps what it saw. That is the mechanism in one line: participation in the auction is indistinguishable from collection, and no rule in the protocol separates the two. Firms that bid without much intention of winning are simply reading the feed at commercial rates. Fan-out of that width settles the provenance question too. Once a record has been broadcast to several hundred recipients, no later holder can reliably establish where it came from, even in good faith, and the refusal to name sources becomes a formality rather than a defence.

Advertising intelligence, so named¶
Researchers at the University of Washington coined the term ADINT in 2017 for the use of advertising infrastructure as an intelligence channel, and the industry that grew around it did not stay theoretical. netzpolitik.org’s account of the sector names the Israeli firm Rayzone, whose promotional video follows a man called Stefan from his flat to his office to his preferred coffee, and which says it operates in eighty countries; Patternz, assembling profiles from apps including 9gag and Kik; Anomaly Six, claiming real-time reach over billions of devices; and Venntel, which sold location data to American federal agencies. A Norwegian journalist who asked what Venntel data held about him received 75,406 location points.
These firms are not unusually sinister. They buy the ordinary product. Nothing in the pipeline has to be subverted, no access has to be gained, and no law has to be broken at the point of collection, because the collection was already sold as advertising and the identifier was already designed to survive the trip.
Pseudonymity, and the second dataset¶
Every defence along the chain leans on the same fact: the records carry no name. This is true, and it holds for exactly as long as there is one dataset. The Norwegian case netzpolitik.org and NRK reported in May 2025 shows the failure mode precisely. A man had installed Grindr briefly, privately, to work something out about himself. Grindr’s own coordinates in the file were too coarse to place him. The precise pings came from a messaging app carrying the same advertising identifier, and led to his front door. Two apps, neither of which knew his name, one of which he had chosen carefully, the other of which he had not thought about at all.
Grindr’s privacy chief noted that the company cannot control what happens when bad actors combine advertising identifiers with data from elsewhere. The sentence is accurate. It is also a description of the design, since combining identifiers with data from elsewhere is what the identifier exists to permit.
The party that defines the identifier need not be the party that does the joining. Apple and Google issue the join key, and the joining happens downstream, among firms the person has never dealt with and mostly could not name.
The clerk’s brief¶
From the clerks, for the Patrician’s eyes
Compiled August 2026, newest first, with settled items absorbed into the state of the join at the foot of the file. The machinery recorded here sits upstream of everything else in the section.
May 2025: One app’s caution undone by another’s¶
On 25 May 2025 netzpolitik.org and NRK traced a Norwegian man to his door using a messaging app’s precise pings joined to a dating app’s coarse ones through a shared advertising identifier. He had installed the dating app briefly and privately. The clerks note that his caution was real and irrelevant. The identifier belongs to the handset rather than to the application, and the careless app supplies the precision for the careful one.
January 2025: The applications get named¶
On 15 January 2025 a second file named around 40,000 apps behind 380 million records and 47 million advertising identifiers across 137 countries, from a single summer day, games and weather and shopping and dating alike. Bavaria’s data protection commissioner called it contrary to everything the average user of an app would expect, being trackable for months afterwards, and said his office would use its investigative powers. The clerks note that expectation is not a control.
September 2024: The identifier’s own history¶
On 3 September 2024 netzpolitik.org retraced the advertising identifier from permanent hardware serials through opt-outs, resets, zeroing and per-app prompts. The clerks record a decade of genuine improvements to the control surface, none of which altered the property that makes the market possible, and file the observation that a privacy feature which relocates effort onto the user is a feature the industry can live with indefinitely.
July 2024: The trade acquires a name¶
On 19 July 2024 netzpolitik.org named the sector selling advertising-derived intelligence to states, seven years after researchers coined a term for it. The clerks note that the arrangement had a marketing category and a customer base well before it had a scandal, which is the usual order of events and rarely the one the participants describe afterwards.
The state of the join¶
The identifier remains resettable, remains shared across every app on the handset, and remains the axis on which unrelated records are stacked. The auction still broadcasts it to hundreds of recipients per slot, so participation and collection stay indistinguishable and provenance stays unrecoverable. Each privacy improvement since 2012 has been genuine and has left the join intact, moving the work to the person holding the phone. The clerks hold that one shared number makes each application’s privacy settings depend on how every other application on the handset behaves, an arrangement nobody using the device chose and few would recognise.