Privacy

Device ID

Also called device identifier.

Device ID is an identifier meant to represent a physical device rather than a logged-in person. Mobile advertising IDs are the common example.

How it is measured

On phones, the system supplies an advertising ID that the user can reset or deny. Apps also generate their own install ID. On the web, there is no real device ID, only what a script builds or stores.

See it in an SDK's request payload. Check whether the value survives an app reinstall and whether it zeroes out when the user opts out.

Worked example

A puzzle app logs 90,000 installs. After a platform prompt asks for tracking permission, 24 percent allow it. For the other 76 percent, the advertising ID arrives as zeros, so attribution there depends on aggregate methods.

The team now reports installs by campaign for only a quarter of users and models the rest.

How it differs

A device ID points to hardware or an install. A client ID points to a browser profile. The device ID excludes web storage; the client ID excludes the app.

Common errors

Treating it as non-personal. Ignoring user resets. Expecting it after a permission denial. Combining it with email in one table. Assuming it is stable forever.

In practice

Inventory the SDKs in your app and what ID each reads. Honor denial. Update your notice.

See also

Client ID, User ID, Fingerprinting

Sources

Count this on a real site.

Watch my website