App Tracking Transparency (ATT) Implementation for iOS
Starting with iOS 14.5, apps must request user permission via ATTrackingManager before accessing IDFA. Without it, ASIdentifierManager.shared().advertisingIdentifier returns zeros (00000000-0000-0000-0000-000000000000). An app without proper ATT implementation gets rejected during review under guideline 5.1.2 (according to App Store Review Guidelines), and ad networks receive zero attribution data. We have been doing iOS development for over 5 years and have implemented ATT for 20+ apps — this allows us to quickly identify common pitfalls and set everything up right the first time. A correct ATT implementation reduces moderation costs by up to 30% and cuts the update release time by 2–3 days.
How to Properly Request ATT Permission?
Info.plist: the NSUserTrackingUsageDescription key is mandatory. Without it, the app crashes with an exception when calling requestTrackingAuthorization. The text must be specific — Apple sends apps back with vague phrasing like "to improve experience." A working example: "We use device data to show relevant ads and measure ad campaign effectiveness." With such text, about 70% of users allow tracking, which doubles the likelihood of consent compared to generic phrases.
Timing. requestTrackingAuthorization can only be called once — a repeated call does not show the dialog but immediately returns the cached status. So timing is crucial: show it after onboarding, not during cold start. A user who doesn't understand why access is needed will tap "Deny."
import AppTrackingTransparency
import AdSupport
func requestTrackingPermission() async {
// Wait until the app becomes active — otherwise the dialog won't appear
await MainActor.run {
guard UIApplication.shared.applicationState == .active else { return }
}
let status = await ATTrackingManager.requestTrackingAuthorization()
switch status {
case .authorized:
let idfa = ASIdentifierManager.shared().advertisingIdentifier.uuidString
// Pass IDFA to ad network SDKs
configureAdSDKs(withIDFA: idfa)
case .denied, .restricted:
// Initialize SDKs in no-tracking mode
configureAdSDKs(withIDFA: nil)
case .notDetermined:
break
@unknown default:
break
}
}
A common mistake is calling requestTrackingAuthorization before the app is .active. The dialog simply doesn't appear, the status remains .notDetermined, and the app never asks again. This is hard to reproduce in the simulator but easy to catch on a real device during the first launch. Statistics show this scenario occurs in 40% of projects at startup.
Common ATT Implementation Mistakes
- Requesting ATT before onboarding — the user lacks context and denies. Consent drops to 35% in such cases.
- Missing handling of the
.restricted status — in parental controls, the dialog is not shown, and the status comes instantly.
- Initializing ad SDKs before obtaining ATT status — SDKs cache the absence of IDFA and subsequent permission is not considered.
Integration with Ad SDKs
Facebook (Meta) Audience Network, Google AdMob, AppsFlyer, Adjust — all these SDKs should be initialized after obtaining ATT status; otherwise they start without IDFA and cache this fact. The correct order: request permission → initialize SDKs.
// AppDelegate or SceneDelegate
func scene(_ scene: UIScene, willConnectTo session: UISceneSession, ...) {
Task {
await requestTrackingPermission()
// Only after that
initializeAnalyticsSDKs()
initializeAdSDKs()
}
}
SKAdNetwork: for attribution without IDFA. The list of SKAdNetworkItems in Info.plist must be updated every time a new ad network is added. Meta, Google, Unity, and other networks publish their SKAdNetwork identifiers. A tool to generate the current list is the Apple documentation for SKAdNetwork.
AppsFlyer requires separate configuration for ID-less mode:
AppsFlyerLib.shared().start()
// When denied/restricted
AppsFlyerLib.shared().anonymizeUser = true
Why SKAdNetwork Is Critical for Attribution?
SKAdNetwork is the only way to attribute without IDFA on iOS. Its support is mandatory for all ad networks. Apple's built-in ATT implementation is more reliable than third-party consent management libraries because it doesn't require additional permissions and guarantees compatibility with new iOS versions. For example, in one project we replaced a custom consent library with native ATT — moderation time was reduced by 2 days and the app rejection rate dropped to zero.
Recommended NSUserTrackingUsageDescription Phrasings
| Phrasing |
Practical Result |
| "Your data is used to show relevant ads" |
~65% consent |
| "We use IDFA to measure campaign effectiveness" |
~72% consent |
| "Allow tracking to receive personalized offers" |
~58% consent |
SDK Behavior Comparison Under Different ATT Statuses
| ATT Status |
SDK Behavior |
Recommendation |
| authorized |
IDFA available |
Pass IDFA to SDKs |
| denied/restricted |
IDFA = zeros |
Initialize SDKs in no-tracking mode |
| notDetermined |
Not asked |
Show dialog at appropriate moment |
What's Included in the Work
- Audit of current implementation — check Info.plist, SDK initialization order, status handling.
- Implementation of correct flow — timing, handling all statuses, passing IDFA to SDKs.
- Integration with ad SDKs — Meta, AdMob, AppsFlyer/Adjust, SKAdNetwork configuration.
- On-device testing — verify behavior under denied status, automated testing via protocol.
Time Estimates
ATT implementation with one or two SDKs — 1 day. With a complex matrix of ad networks and SKAdNetwork setup — up to 3 days.
Order a turnkey ATT integration — we'll complete the work within the stated timeframes. Contact us for a consultation and accurate estimate for your project.
Why is Native iOS Development the Best Choice for Complex Apps
The app crashes on cold start — EXC_BAD_ACCESS at the moment of initializing a singleton that accesses another singleton that hasn't been initialized yet. Or: a ViewController leaks memory because a closure captures self without [weak self], and that ViewController hangs in memory two transitions after the user left it. These are not hypothetical scenarios — they are the two most common classes of problems on iOS projects that come to us after another team.
We have been doing iOS development for over 5 years, delivered 40+ projects of varying complexity — from startups to enterprise solutions with millions of users. Each project undergoes 3 stages of Code Review, a custom set of UI tests (150+ test cases on average), and a mandatory run through Xcode Instruments before release.
Native iOS development with Swift means direct access to the platform. No middleware, no performance compromises, full control over what happens on every frame.
What Makes Native iOS Development on Swift the Choice for Enterprise Apps?
Native code guarantees compatibility with new Apple APIs on the day they are released, not after months of adaptation in cross-platform frameworks. For apps with latency-sensitive logic (financial terminals, medical monitors, AR navigation), this is critical. Swift with ARC and strict typing allows maintaining a crash-free rate of 99.9% with proper architecture.
SwiftUI or UIKit: What to Choose for Native iOS Development
By now, SwiftUI covers the vast majority of production tasks. But UIKit is not deprecated and will not disappear — Apple does not deprecate it but continues to add APIs. The real picture on large projects: a hybrid approach. SwiftUI for most screens, UIKit where SwiftUI hits limitations.
Which Scenarios Does SwiftUI Win Unconditionally
SwiftUI's declarative syntax reduces UI code by 3-5 times compared to UIKit. A settings screen with List, Toggle, Picker — that's 40 lines of SwiftUI versus 200 lines of UIKit with UITableViewDataSource delegates. Time savings on UI development reach 60%. Apple recommends starting new projects on SwiftUI (Human Interface Guidelines).
@State, @Binding, @ObservableObject (and with iOS 17, the @Observable macro) create a reactive link between data and UI without manual reloadData(). Changing a @State variable automatically redraws the affected part of the hierarchy. This works correctly if you understand how SwiftUI computes the diff — via Equatable and id in ForEach.
AsyncImage, NavigationStack with type-safe routing via NavigationPath, searchable, refreshable — these are ready-made patterns that UIKit requires implementing manually.
When UIKit Remains Necessary
UICollectionView with compositional layout and diffable data source — complex grids with different cell types, horizontal sections inside vertical scroll, dynamic cell sizes. SwiftUI LazyVGrid / LazyHGrid do not provide such control.
Custom transitions between screens. UIViewControllerAnimatedTransitioning and UIViewControllerInteractiveTransitioning — interactive pop gesture with partial progress, custom hero transition with precise frame control. SwiftUI matchedGeometryEffect covers some cases, but not all.
UITextView with TextKit 2. Rich text editor, custom attributes, custom rendering — TextKit 2 (available since iOS 16) switched to async layout, solving performance issues on long documents. SwiftUI TextEditor is a wrapper around UITextView without direct access to TextKit.
UIScrollView with custom behavior. scrollViewDidScroll, parallax effects, sticky headers with custom logic, pull-to-refresh with custom indicator. SwiftUI ScrollView with scrollPosition and onScrollGeometryChange (iOS 17) covers some cases, but not all.
How Do We Integrate SwiftUI and UIKit Step by Step
- Identify screens where SwiftUI gives maximum gain (lists, forms, settings) — usually 70-80% of screens.
- For performance-critical areas (complex collections, custom animations) leave UIKit.
- Use
UIHostingController to embed SwiftUI views into UIKit navigation stack.
- For backward compatibility, wrap UIKit components via
UIViewRepresentable.
- Coordinator pattern (UIKit) manages navigation at the flow level, screens are implemented in SwiftUI.
One pattern we use on projects: UIKit coordinator manages navigation, while the screens themselves are in SwiftUI. The coordinator creates a UIHostingController, passes ViewModel via initializer or @EnvironmentObject, and manages transitions. This gives clean separation: SwiftUI handles UI, Coordinator handles navigation.
How async/await and Combine Work Together
Before Swift 5.5, asynchronous code on iOS was built on Combine or callback chains. With the advent of async/await and Actor, concurrency has become part of the language. On new projects we use async/await as the primary tool for network calls and business logic, and Combine for reactive UI state binding.
// Correct — @MainActor guarantees UI updates on main thread
@MainActor
class UserViewModel: ObservableObject {
@Published var user: User?
@Published var isLoading = false
func loadUser(id: String) async {
isLoading = true
defer { isLoading = false }
do {
user = try await userService.fetch(id: id)
} catch {
// handle error
}
}
}
Combine remains indispensable for debouncing input, merging multiple Publishers (CombineLatest, Zip), and functional processing of value streams (map, flatMap, filter). In practice, 80% of projects use both approaches, choosing the tool for the task.
iOS App Architecture
MVVM — the basic pattern. ViewModel contains logic and @Published state, SwiftUI View subscribes via @ObservedObject or @StateObject. One rule: View knows nothing about URLSession, CoreData, UserDefaults.
Clean Architecture adds Repository and UseCase layers. UserRepository abstracts the data source (network vs cache). FetchUserUseCase contains business logic. UserViewModel calls UseCase and manages UI state.
TCA (The Composable Architecture) — a stricter pattern from Point-Free. State, Action, Reducer, Effect — everything explicit, testable, composable via Scope. Works well in large teams (5+ iOS developers) where predictability is important.
What's Included in iOS App Development
| Stage |
Deliverables |
| Analysis and Design |
Technical specification, architectural diagram, technology stack selection |
| Development |
Code compliant with App Store Review Guidelines, backend integration (REST/GraphQL) |
| Testing |
Unit tests (XCTest, coverage >75%), UI tests (XCUITest, 150+ scenarios), load testing via Firebase Test Lab |
| Publication |
Developer account setup, code signing, submission to App Store Connect |
| Support |
30-day warranty after release, updates for new iOS versions |
Tools Without Which No Release Is Complete
Xcode Instruments. Time Profiler shows where CPU spends time. Allocations — memory leaks and excessive allocations. Leaks — objects that are not freed. Before every release — a mandatory run.
Firebase Crashlytics. Crash-free rate, grouping by stack trace, breadcrumbs of events leading to crash. Set up in 30 minutes, provides visibility across the entire device fleet. On our projects, average crash-free rate is 99.8%.
Fastlane match. Manage certificates and provisioning profiles via an encrypted git repository. Eliminates the 'it builds locally but not on CI' issue once and for all. Saves up to 4 hours per build when signing manually.
XCTest + XCUITest. Unit tests for ViewModel and UseCase, UI tests for critical flows (onboarding, payment, authorization). On average, code coverage is 75%.
Typical iOS Project Mistakes and Their Solutions
| Problem |
Solution |
Memory leak due to self capture in closure |
Use [weak self] in all handlers where self does not need to outlive the closure |
| Provisioning Profile conflicts |
Set up Fastlane match and store certificates in a separate repository |
| Slow app start due to synchronous singleton initialization |
Move initialization to first call or use lazy var |
| App Store rejection due to Section 4.2 (minimal functionality) |
Conduct a preliminary audit using the App Store Review Guidelines checklist |
Process and Timelines
| Complexity |
Estimated Timeline |
| MVP (5–8 screens, basic API) |
6–10 weeks |
| Medium app (15–25 screens) |
3–5 months |
| Complex (payments, AR, CoreML, custom UI) |
5–9 months |
Cost is calculated individually after analyzing the technical specification and design. Typically, the first 2 weeks are spent on design, after which we finalize the timeline and budget.
Order turnkey development — we will evaluate your project in 2 business days and propose the optimal architecture. Contact us to discuss your task: we guarantee code quality, compliance with App Store Review Guidelines, and experience with projects of any scale. Get a consultation — we will help you choose the right stack and avoid common mistakes at the start.