← 资料库索引 ← 个人博客 原始链接 ↗ 🔍
个人博客

Android 广告 ID 与 App Set ID 的隐私区别 原文标题:Android advertising ID and App Set ID privacy | PTKD Journal

发表时间:2026-05-24采集时间:2026-10-09 10:28:11来源:ptkd.com原文语言:en状态:完整

内容概要总结

PTKD Journal 的一篇文章,讲清 Android 两个面向 App 的标识符——广告 ID(advertising ID,即 GAID)与 App Set ID——用途与隐私边界,并说明用错其中一个既是隐私问题也是政策问题。

核心结论:广告 ID 用于广告与广告衡量,可由用户重置、删除并退出,target Android 13 或更高且使用它的 App 必须在 manifest 声明 AD_ID 权限,否则收到的广告 ID 会被替换为全零,破坏广告归因;App Set ID 用于非广告用途(分析、反欺诈),作用域限于你自己的 App 集合,明确不用于跨开发者追踪。二者不可互换。

文章给出两者对照表(用途、作用域、用户控制、跨开发者追踪、权限),并强调必须尊重用户重置与退出:不得把重置后的广告 ID 重新关联(bridging)到其旧值或其他标识符。作者还提醒不要用设备特征自建持久设备标识来绕过规则(那属于被限制的指纹识别),并要在 Data safety 表单中准确声明标识符使用。文中反复建议用提交前扫描工具(如 PTKD.com,读取编译后的 APK/AAB 对照 OWASP MASVS,列出所用 SDK 与标识符)来核对声明与实际使用是否一致。文末附 FAQ 与相关阅读。

翻译内容

原文内容(English)

⚠ 说明:为与原文结构对齐,补回了「继续阅读」章节中的 2 个图片占位符。

Android 为你提供两个用途迥异的设备标识符,用错其中一个既是隐私问题,也是政策问题。广告 ID 用于广告、可由用户重置,且现在需要一项权限;而 App Set ID 用于分析、反欺诈等非广告用途,作用域限于你自己的 App。把它们搞混、用广告 ID 做分析、或无视用户的重置,都违反 Google Play 的规则和用户的预期。以下是每个标识符的用途、AD_ID 权限与用户控制,以及如何尊重地使用它们。

简短回答

Android 有两个主要的、面向 App 的标识符:广告 ID——一个可由用户重置、删除、可退出(opt out)的、用于广告的标识符;以及 App Set ID——作用域限于你自己的一组 App,用于分析、反欺诈等非广告用途。根据 Google 的文档,target Android 13 或更高、使用广告 ID 的 App 必须声明 AD_ID 权限,否则该 ID 会被替换为全零,并且你必须尊重用户的重置与退出。广告 ID 只用于广告,App Set ID 用于非广告用例,绝不重新关联重置后的广告 ID,并在你的 Data safety 表单中声明你的用途。这两个标识符不可互换。

你应该知道的要点

  • 广告 ID 用于广告:可由用户重置、可退出。
  • App Set ID 用于非广告:分析与反欺诈,作用域限于你的 App。
  • AD_ID 权限是必需的:在 Android 13+ 上使用广告 ID 必须声明,否则会被置零。
  • 尊重用户控制:不要重新关联重置后的广告 ID。
  • 声明你的用途:在 Data safety 表单中。

广告 ID 与 App Set ID 有什么区别?

它们服务于不同目的,作用域也不同。下表对二者作了对比。

方面广告 IDApp Set ID
用途广告与广告衡量非广告:分析、反欺诈
作用域设备级、跨 App 共享作用域限于你自己的一组 App
用户控制可重置、可删除、可退出并非以同样方式面向用户;随时间重置
跨开发者追踪可能,受政策约束不用于跨开发者追踪
权限Android 13+ 需要 AD_ID无需特殊权限

广告 ID 是用户可控的、设备级的广告标识符,只应用于广告相关目的。App Set ID 是按开发者的,用于分析、反欺诈等需要稳定标识符但又不属于广告的用例,并且明确不用于跨不同开发者追踪用户。为用途选择正确的标识符是第一条规则:如果你的用途是分析或反欺诈,不要仅仅因为广告 ID 用起来熟悉就伸手去用它——在这些场景下 App Set ID 才是合适的。

那 AD_ID 权限与用户控制呢?

两者都反映出广告 ID 是隐私敏感的。target Android 13 或更高、使用 Google 广告 ID 的 App 必须在 manifest 中声明 AD_ID normal 权限;没有它,你的 App 收到的广告 ID 会被替换为一串零,破坏广告归因。在用户一侧,广告 ID 可重置、可删除:用户可以重置它来切断与过去活动的关联、退出个性化广告,或完全删除它,此后 App 会收到全零。你必须尊重这些控制,这意味着不得试图把重置后的广告 ID 重新关联到其之前的值或其他标识符——这有时被称为 bridging——因为这违背了用户的选择并违反政策。因此,使用广告 ID 既附带一项声明要求,也附带一项尊重用户重置与退出的义务。

如何尊重地使用这些标识符?

让标识符与用途匹配,声明它,并尊重用户的选择。广告 ID 只用于广告与广告衡量;如果你 target Android 13 或更高就声明 AD_ID 权限;绝不把重置后的广告 ID 重新关联到过往数据。对于分析或反欺诈等非广告需求,使用 App Set ID 而不是广告 ID,因为这正是它的用途,且它不是用于跨开发者追踪的。避免从设备特征自建持久设备标识来绕过这些规则,因为那属于指纹识别,是被限制的。在你的 Data safety 表单中准确声明你对这些标识符的使用,因为它们属于你的数据实践的一部分。这一原则与 iOS 的做法相呼应:由用户控制的标识符,按其预期用途使用,附有同意与披露,而不是隐蔽的持久追踪。

需要注意什么

第一个陷阱是把广告 ID 用于分析等非广告目的,而 App Set ID 才是正确的标识符;要让标识符与用途匹配。第二个是在 Android 13 或更高上遗漏 AD_ID 权限,这会使广告 ID 被置零。第三个是重新关联或 bridging 重置后的广告 ID,这违背用户的选择与政策。像 PTKD.com(https://ptkd.com)这样的提交前扫描,会读取编译后的 APK 或 AAB 并对照 OWASP MASVS,列出你的 App 所使用的 SDK 与标识符,帮助你看出某个 SDK 是否在使用广告 ID,从而使你的声明与使用相符。这些是你在 App 中做出的标识符选择。

要点回顾

  • Android 的广告 ID 用于广告,可由用户重置、可退出;而 App Set ID 用于分析、反欺诈等非广告用途,作用域限于你自己的 App。
  • target Android 13 或更高的 App 必须声明 AD_ID 权限才能使用广告 ID,否则它会被替换为全零,并且你必须尊重用户的重置与退出。
  • 按预期用途使用每个标识符,绝不重新关联重置后的广告 ID,避免用指纹识别作为变通,并在 Data safety 表单中声明你的用途。
  • 使用像 PTKD.com 这样的提交前扫描,看清你的 App 使用了哪些标识符与 SDK,使你的使用与披露保持一致。

常见问题(FAQ)

广告 ID 与 App Set ID 有什么区别?

广告 ID 是用于广告与广告衡量的设备级标识符,用户可重置、删除并退出,target Android 13 或更高的 App 需要 AD_ID 权限才能使用。App Set ID 的作用域限于你自己的一组 App,用于分析、反欺诈等非广告用例,不用于跨不同开发者追踪用户。按预期用途使用各自,二者不可互换。

我需要 AD_ID 权限吗?

需要。如果你的 App target Android 13 或更高并使用 Google 广告 ID,你必须在 manifest 中声明 AD_ID normal 权限。没有它,你的 App 收到的广告 ID 会被替换为一串零,破坏广告归因。使用广告 ID 的 SDK 也可能需要它。因此,如果你确实把广告 ID 用于广告,就声明 AD_ID;而如果你的 App 根本不使用广告 ID,就不要申请它。

广告 ID 有哪些用户控制?

广告 ID 可重置、可删除,用户还可以退出个性化广告。用户可以重置它来切断与过去活动的关联,或完全删除它,此后你的 App 会收到全零。你必须尊重这些控制,这意味着不得把重置后的广告 ID 重新关联或 bridging 到其之前的值或其他标识符,因为这违背用户的选择并违反政策。尊重重置与退出,是使用广告 ID 的一部分。

我能用广告 ID 做分析吗?

不能。分析、反欺诈等非广告目的应使用 App Set ID。广告 ID 用于广告与广告衡量,用它做分析是在把一个用户为广告目的控制的标识符挪作他用。App Set ID 是专为你自己的 App 范围内稳定的非广告用例而设计的。并且不要从设备特征自建持久设备标识来绕过规则,因为那属于被限制的指纹识别。

如何确认我的 App 使用了哪些标识符?

扫描构建产物。像 PTKD.com 这样的提交前扫描会读取编译后的 APK 或 AAB 并对照 OWASP MASVS,列出你的 App 所使用的 SDK 与标识符,帮助你看出某个 SDK 是否在使用广告 ID,以及你是否需要 AD_ID 权限,从而使你的声明与使用相符。有了这种可见性,你就能为每个用途使用正确的标识符、只在需要时声明 AD_ID,并让 Data safety 表单保持准确。

继续阅读

A 2026 view of device characteristics being combined into a fingerprint to track a user, contrasted with the required-reason APIs and consent mechanisms that restrict it
A 2026 view of device characteristics being combined into a fingerprint to track a user, contrasted with the required-reason APIs and consent mechanisms that restrict it
  • Journal · Privacy —— 设备指纹与移动隐私:指纹识别通过设备特征来识别设备,绕开用户控制,Apple 和 Google 都对它加以限制。本文说明它是什么以及如何不越界。8 分钟阅读
  • Journal · Privacy —— Google Play 的账号与数据删除要求:如果你的 App 允许创建账号,Google Play 要求既能在 App 内删除,也能通过网页链接删除,且删除账号必须删除数据。本文说明如何合规。8 分钟阅读
  • Journal · Privacy —— Android 剪贴板隐私:须知:自 Android 12 起,系统会标记读取剪贴板的 App,剪贴板中常含密码或验证码。只在用户操作时读取。本文说明如何尊重地处理。7 分钟阅读
A 2026 view of an Android input method editor processing keystrokes in an app's field, with password input types and disabled personalized learning marking sensitive input
A 2026 view of an Android input method editor processing keystrokes in an app's field, with password input types and disabled personalized learning marking sensitive input
  • Journal · Privacy —— Android 自定义键盘与输入法安全:键盘是一个能看到用户在你们字段中输入内容的 App。本文说明如何标记敏感输入,使第三方键盘小心处理,以及如果你自建键盘时的义务。8 分钟阅读

几分钟内扫描你的 App

上传 APK、AAB 或 IPA。PTKD 返回一份与 OWASP 对齐的报告,附可直接复制粘贴的修复方案。

Android gives you two device identifiers with very different purposes, and using the wrong one is both a privacy problem and a policy problem. The advertising ID is for advertising, is user-resettable, and now requires a permission, while the App Set ID is for non-advertising uses like analytics and fraud prevention and is scoped to your own apps. Mixing them up, using the advertising ID for analytics, or ignoring a user's reset, breaks Google Play's rules and user expectations. Here is what each identifier is for, the AD_ID permission and user controls, and how to use them respectfully.

Short answer

Android has two main app-facing identifiers: the advertising ID, a user-resettable, deletable identifier for advertising that users can opt out of, and the App Set ID, scoped to your own set of apps and intended for non-advertising uses like analytics and fraud prevention. Per Google's documentation, apps targeting Android 13 or higher that use the advertising ID must declare the AD_ID permission, or the ID is replaced with zeros, and you must respect user resets and opt-outs. Use the advertising ID only for advertising, the App Set ID for non-ad use cases, never reconnect a reset advertising ID, and declare your use in your Data safety form. The two identifiers are not interchangeable.

What you should know

  • Advertising ID is for ads: user-resettable and opt-out-able.
  • App Set ID is for non-ads: analytics and fraud, scoped to your apps.
  • AD_ID permission is required: for advertising ID on Android 13+, or it is zeroed.
  • Respect user controls: do not reconnect a reset advertising ID.
  • Declare your use: in the Data safety form.

What is the difference between the advertising ID and App Set ID?

They serve different purposes and have different scopes. The table contrasts them.

AspectAdvertising IDApp Set ID
PurposeAdvertising and ad measurementNon-advertising: analytics, fraud prevention
ScopeDevice-wide, shared across appsScoped to your own set of apps
User controlResettable, deletable, opt-outNot user-facing in the same way; resets over time
Cross-developer trackingPossible, governed by policyNot for tracking across developers
PermissionAD_ID required on Android 13+No special permission

The advertising ID is the device-wide identifier for advertising that the user controls, and is the one to use only for ad-related purposes. The App Set ID is per-developer, intended for use cases like analytics and fraud prevention that need a stable identifier without being for advertising, and is explicitly not meant to track users across different developers. Choosing the right one for the purpose is the first rule: do not reach for the advertising ID just because it is familiar if your use is analytics or fraud, where the App Set ID is appropriate.

What about the AD_ID permission and user controls?

Both reflect that the advertising ID is privacy-sensitive. Apps targeting Android 13 or higher that use the Google advertising ID must declare the AD_ID normal permission in the manifest; without it, the advertising ID your app receives is replaced with a string of zeros, breaking ad attribution. On the user side, the advertising ID is resettable and deletable: a user can reset it to break the link to past activity, opt out of personalized ads, or delete it entirely, after which the app receives zeros. You must respect these controls, which means not attempting to reconnect a reset advertising ID to its previous value or to other identifiers, sometimes called bridging, since that defeats the user's choice and violates policy. So using the advertising ID comes with both a declaration requirement and an obligation to honor the user's resets and opt-outs.

How do you use these identifiers respectfully?

Match the identifier to the purpose, declare it, and honor user choices. Use the advertising ID only for advertising and ad measurement, declare the AD_ID permission if you target Android 13 or higher, and never reconnect a reset advertising ID to past data. For non-advertising needs like analytics or fraud prevention, use the App Set ID rather than the advertising ID, since that is what it is for and it is not for cross-developer tracking. Avoid building your own persistent device identifier from device characteristics to work around these, since that is fingerprinting, which is restricted. Declare your use of these identifiers accurately in your Data safety form, since they are part of your data practices. The principle mirrors the iOS approach: identifiers the user controls, used for their intended purpose, with consent and disclosure, not covert persistent tracking.

What to watch out for

The first trap is using the advertising ID for non-advertising purposes like analytics, when the App Set ID is the right identifier; match the identifier to the use. The second is omitting the AD_ID permission on Android 13 or higher, which zeros out the advertising ID. The third is reconnecting or bridging a reset advertising ID, which violates the user's choice and policy. A pre-submission scan such as PTKD.com (https://ptkd.com) reads the compiled APK or AAB against OWASP MASVS and surfaces the SDKs and identifiers your app uses, which helps you see whether an SDK is using the advertising ID, so your declarations and usage match. The identifier choices you make in the app.

What to take away

  • Android's advertising ID is for advertising and is user-resettable and opt-out-able, while the App Set ID is for non-advertising uses like analytics and fraud, scoped to your own apps.
  • Apps targeting Android 13 or higher must declare the AD_ID permission to use the advertising ID, or it is replaced with zeros, and you must respect user resets and opt-outs.
  • Use each identifier for its intended purpose, never reconnect a reset advertising ID, avoid fingerprinting as a workaround, and declare your use in the Data safety form.
  • Use a pre-submission scan such as PTKD.com to see which identifiers and SDKs your app uses so your usage and disclosures align.

Frequently asked questions

What is the difference between the advertising ID and App Set ID?

The advertising ID is a device-wide identifier for advertising and ad measurement that the user can reset, delete, and opt out of, and that apps targeting Android 13 or higher need the AD_ID permission to use. The App Set ID is scoped to your own set of apps and is intended for non-advertising use cases like analytics and fraud prevention, and is not meant to track users across different developers. Use each for its intended purpose; they are not interchangeable.

Do I need the AD_ID permission?

Yes, if your app targets Android 13 or higher and uses the Google advertising ID, you must declare the AD_ID normal permission in your manifest. Without it, the advertising ID your app receives is replaced with a string of zeros, which breaks ad attribution. SDKs that use the advertising ID can also require it. So declare AD_ID if you genuinely use the advertising ID for advertising, and do not request it if your app does not use the advertising ID at all.

What user controls apply to the advertising ID?

The advertising ID is resettable and deletable, and the user can opt out of personalized ads. A user can reset it to break the link to past activity, or delete it entirely, after which your app receives zeros. You must respect these controls, which means not reconnecting or bridging a reset advertising ID to its previous value or to other identifiers, since that defeats the user's choice and violates policy. Honoring resets and opt-outs is part of using the advertising ID.

Can I use the advertising ID for analytics?

No, use the App Set ID for non-advertising purposes like analytics and fraud prevention. The advertising ID is for advertising and ad measurement, and using it for analytics misuses an identifier the user controls for ad purposes. The App Set ID is purpose-built for stable, non-ad use cases scoped to your own apps. And do not build your own persistent device identifier from device characteristics to work around the rules, since that is fingerprinting, which is restricted.

How do I confirm which identifiers my app uses?

Scan the build. A pre-submission scan such as PTKD.com reads the compiled APK or AAB against OWASP MASVS and surfaces the SDKs and identifiers your app uses, which helps you see whether an SDK is using the advertising ID and whether you need the AD_ID permission, so your declarations and usage match. With that visibility, you can use the right identifier for each purpose, declare AD_ID only when needed, and keep your Data safety form accurate.

Keep reading

A 2026 view of device characteristics being combined into a fingerprint to track a user, contrasted with the required-reason APIs and consent mechanisms that restrict it
A 2026 view of device characteristics being combined into a fingerprint to track a user, contrasted with the required-reason APIs and consent mechanisms that restrict it

Journal · PrivacyDevice fingerprinting and mobile privacyFingerprinting identifies a device by its traits, working around user controls, and Apple and Google restrict it. Here is what it is and how to stay on the right side.8 min read

Journal · PrivacyGoogle Play's account and data deletion requirementIf your app allows account creation, Google Play requires deletion both in-app and via a web link, and deleting the account must delete the data. Here is how to comply.8 min read

Journal · PrivacyAndroid clipboard privacy: what to knowSince Android 12 the system flags apps that read the clipboard, which often holds passwords or codes. Read it only on user action. Here is how to handle it respectfully.7 min read

A 2026 view of an Android input method editor processing keystrokes in an app's field, with password input types and disabled personalized learning marking sensitive input
A 2026 view of an Android input method editor processing keystrokes in an app's field, with password input types and disabled personalized learning marking sensitive input

Journal · PrivacyAndroid custom keyboard and input method securityThe keyboard is an app that sees what users type in your fields. Here is how to mark sensitive input so a third-party keyboard treats it carefully, and the duty if you build one.8 min read

Scan your app in minutes

Upload an APK, AAB, or IPA. PTKD returns an OWASP-aligned report with copy-paste fixes.

放大预览