Description
Hi team,
A NowSecure dynamic scan reports Missing Privacy Tracking Declaration (flagged as App Store Blocker) in our iOS app. It found these domains that are not declared under NSPrivacyTrackingDomains in any privacy manifest:
firebase-settings.crashlytics.com
firebaselogging-pa.googleapis.com
reports.crashlytics.com
update.crashlytics.com
www.firebase.com
www.googleadservices.com
Our own code doesn't call any of these. They all come from the Firebase SDK.
Environment: latest Firebase iOS SDK, Xcode 26.6, SPM, Analytics + Crashlytics + App Distribution, Release build.
Could you please confirm:
Are any of these domains considered tracking under Apple's definition? If not, is it expected that they aren't listed in NSPrivacyTrackingDomains?
www.googleadservices.com in particular: which Firebase component calls it, and can it be disabled if we don't use ads or conversion tracking?
Any official guidance we can share with our security reviewers and use for App Store compliance?
Related: #16440
Thanks,
Murali Sai
Reproducing the issue
No response
Firebase SDK Version
12.19.1
Xcode Version
26.6
Installation Method
Swift Package Manager
Firebase Product(s)
Crashlytics
Targeted Platforms
iOS
Relevant Log Output
If using Swift Package Manager, the project's Package.resolved
Expand Package.resolved snippet
Replace this line with the contents of your Package.resolved.
If using CocoaPods, the project's Podfile.lock
Expand Podfile.lock snippet
Replace this line with the contents of your Podfile.lock!
Description
Hi team,
A NowSecure dynamic scan reports Missing Privacy Tracking Declaration (flagged as App Store Blocker) in our iOS app. It found these domains that are not declared under NSPrivacyTrackingDomains in any privacy manifest:
firebase-settings.crashlytics.com
firebaselogging-pa.googleapis.com
reports.crashlytics.com
update.crashlytics.com
www.firebase.com
www.googleadservices.com
Our own code doesn't call any of these. They all come from the Firebase SDK.
Environment: latest Firebase iOS SDK, Xcode 26.6, SPM, Analytics + Crashlytics + App Distribution, Release build.
Could you please confirm:
Are any of these domains considered tracking under Apple's definition? If not, is it expected that they aren't listed in NSPrivacyTrackingDomains?
www.googleadservices.com in particular: which Firebase component calls it, and can it be disabled if we don't use ads or conversion tracking?
Any official guidance we can share with our security reviewers and use for App Store compliance?
Related: #16440
Thanks,
Murali Sai
Reproducing the issue
No response
Firebase SDK Version
12.19.1
Xcode Version
26.6
Installation Method
Swift Package Manager
Firebase Product(s)
Crashlytics
Targeted Platforms
iOS
Relevant Log Output
If using Swift Package Manager, the project's Package.resolved
Expand
Package.resolvedsnippetReplace this line with the contents of your Package.resolved.If using CocoaPods, the project's Podfile.lock
Expand
Podfile.locksnippetReplace this line with the contents of your Podfile.lock!