Third-Party SDKs

SWAVE · Last updated: 2026-08-03

This page lists every third-party software development kit (SDK) and service embedded in the SWAVE app that can receive data, what each one is for, and what it collects. It is the supporting detail behind our Privacy Policy , the Google Play Data safety declaration, and the App Store privacy labels.

1. Advertising

Ads are shown only to users without an active subscription. See Privacy Policy §5 for how to limit ad personalization.

SDK Purpose Data collected
TopOn AnyThink Technology Ad mediation — decides which ad network fills a slot, and reports rewarded-video completion to our server Advertising identifier (GAID / IDFA), device model, OS version, language, screen size, network type, IP address, ad request and impression events, and the SWAVE user ID plus episode ID attached to a rewarded unlock
Google Mobile Ads (AdMob) Google Ad network behind the TopOn mediation layer — actually serves and measures the ads. Integrated as the TopOn AdMob adapter plus Google's own ads SDK. Advertising identifier (GAID / IDFA), device and network information, IP address, ad interaction and measurement events
Pangle Bytedance Pte. Ltd. Ad network behind the TopOn mediation layer — competes to fill a slot and serves the ad it wins. Integrated as the TopOn Pangle adapter plus Pangle's own SDK. Advertising identifier (GAID / IDFA), device and network information, IP address, ad interaction and measurement events
Unity Ads Unity Technologies Ad network behind the TopOn mediation layer — competes to fill a slot and serves the ad it wins. Integrated as the TopOn Unity Ads adapter plus Unity's own ads SDK. Advertising identifier (GAID / IDFA), device and network information, IP address, ad interaction and measurement events
Google Advertising ID / App Set ID Google Supplies the resettable identifiers the ad SDKs above use for frequency capping and measurement Advertising ID (GAID), App Set ID
App Tracking Transparency Apple (iOS only) Asks your permission before any tracking identifier is used on iOS Collects nothing itself. It records your yes/no answer, which controls IDFA access.

2. Accounts & Backend

SDK / service Purpose Data collected
Supabase Supabase Inc. Authentication, and the database holding your profile, favorites, watch progress, unlocks and subscription status. Also sends account emails such as password resets. Email address, display name and avatar (if set), user ID, favorites, watch progress, episode unlocks, subscription status, IP address of API requests
Google Sign-In Google Optional "Continue with Google" sign-in Your Google account email address, name, profile picture URL and account identifier — only if you choose this sign-in method
Sign in with Apple Apple (iOS) Optional "Continue with Apple" sign-in An Apple-issued user identifier and an email address (which may be Apple's private relay address) — only if you choose this sign-in method
SWAVE backend operated by us Validates purchase receipts, signs short-lived playback addresses, grants rewarded unlocks, deletes accounts Your account ID and access token, the episode being requested, purchase receipts, and standard server-log data such as IP address and timestamp

3. Analytics

We use one product-analytics service to understand how people move through the app — which screens are opened, which episodes get played and finished, and where the purchase flow is abandoned — so we can improve our content and the experience. It is not used for advertising, and no advertising identifier is sent to it.

SDK / service Purpose Data collected
PostHog PostHog Inc. (US cloud) Product analytics — measures how users navigate the app so we can improve our content and the experience. Our server additionally reports a completed purchase to it once a receipt has been validated. Device and app information (device model, OS version, app version, language, network type, IP address); app usage and interaction events — screens viewed, dramas opened from the home page, episodes played and completed, a per-episode watch summary (seconds watched and completion percentage), favorites added or removed, paywall views, purchase funnel steps (initiated / failed / completed) and the sign-up or sign-in method used; and a pseudonymous user identifier (your SWAVE account ID) plus whether you were a subscriber at the time. No advertising identifier (GAID / IDFA) is collected, and session recording / session replay is not enabled. If you are not signed in, events are recorded anonymously and are not linked to any account. Your email address, display name and account contents are never sent.

4. Attribution

We use one marketing-attribution service to work out which advertising campaign a new install came from, and which campaigns go on to produce subscriptions and ad revenue. On iOS it can use the advertising identifier only if you answered "Allow" to the App Tracking Transparency prompt described in §1. See our Privacy Policy §5 for how to limit ad personalization.

SDK / service Purpose Data collected
Adjust Adjust GmbH Marketing attribution — measures which advertising campaign led to an install, and which campaigns produce subscriptions and ad revenue, so we can spend our marketing budget where it works. Advertising identifier (GAID on Android, IDFA on iOS, only where you have allowed tracking); device and app information (device model, OS version, app version, language, IP address); Google Play install referrer; and conversion events — sign-up, paywall view, rewarded-video completion, first completed episode, subscription purchases (including the amount paid), and ad impression revenue. Adjust may share attribution data with the advertising network that delivered the ad you clicked.

5. Purchases

SDK Purpose Data collected
Google Play Billing Google (Android) Sells and renews subscriptions on Android; sends renewal and cancellation notifications to our server Purchase token, product ID, order ID, subscription state. Payment details stay with Google — we never see them.
StoreKit / In-App Purchase Apple (iOS) Sells and renews subscriptions on iOS; sends server notifications to our server Signed transaction, product ID, original transaction ID, subscription state. Payment details stay with Apple.

6. Media, Content & Platform

Component Purpose Data collected
Huawei Cloud OBS + CDN Huawei Cloud Stores and delivers video, subtitles and cover images over signed, short-lived HTTPS addresses IP address, user agent, and the media file requested — the standard access log of any HTTP request. No account data is sent.
Video player Flutter (ExoPlayer on Android, AVPlayer on iOS) Plays the HLS video streams Nothing beyond the media requests described above; runs on-device
WebView Google (Android System WebView) / Apple (WKWebView) Renders this document and the other in-app legal pages, from files bundled inside the app Nothing. These pages are local files and make no network requests.
Image cache cached_network_image Downloads and caches cover art on the device Nothing beyond the image request itself (IP address, as with any HTTP request)
On-device storage shared_preferences Remembers your session, subtitle language preference, first-launch consent, and ad frequency counters Stored on your device only. Removed when you uninstall the app.

7. Android Install Attribution

Library Purpose Data collected
Google Play Install Referrer Google Can report which link or campaign led to the install Install referrer string, install and click timestamps
Galaxy Store Install Referrer Samsung The same, for installs from the Samsung Galaxy Store Install referrer string, install timestamp

8. Not Present

For the avoidance of doubt, apart from the PostHog product analytics described in §3 and the Adjust attribution SDK described in §4, the SWAVE app contains no other analytics or attribution SDK : there is no Firebase, no Google Analytics, no Singular, no AppsFlyer, and no crash-reporting SDK. There is also no Meta (Facebook) SDK : the Facebook login library was removed from the build, and SWAVE offers no Facebook sign-in. We do not access your contacts, photo library, camera, microphone, precise GPS location, calendar, or health data.

9. Provider Privacy Policies

10. Contact

Questions about any component on this page? Contact us at blueming333@gmail.com .