Referral programs in mobile apps bring up to 30% of new users, but their implementation is technically harder than it seems. The main problem is attribution: you need to link an app install to a specific referrer, even if days pass between clicking the link and the first launch. Without correct deferred deep linking, the program loses its meaning—money simply goes nowhere. With over 20 projects, we have accumulated experience that guarantees transparent attribution and protection against fraud.
How Deferred Deep Linking Works
A normal deep link does not work if the app is not installed: the user lands in the App Store and the link is lost. A deferred deep link "remembers" the referral parameter and passes it on first launch. This is the foundation of correct attribution.
Tools: Branch.io, AppsFlyer OneLink, Adjust. Branch is the most versatile, supporting iOS, Android, and Web, and offers a free tier. Here's an example of handling a link on first launch in Swift:
// iOS — Branch SDK
Branch.getInstance().initSession(launchOptions: launchOptions) { params, error in
if let referrerID = params?["referrer_id"] as? String {
// First launch with referral parameter
ServerAPI.attributeInstall(referrerID: referrerID, newUserID: currentUser.id)
}
}
Branch tracks clicks via fingerprinting (IP + User-Agent + time) and matches the install within a 2-hour window. Accuracy is ~85-95% — sufficient for business metrics. More details: deferred deep linking.
Why Real-Time Attribution Monitoring Matters
Without monitoring, you won't know about problems until the budget disappears. Real-time dashboards from Branch or AppsFlyer show click-to-install conversion rates, the number of suspicious events, and the effectiveness of each channel. We configure alerts for anomalies — for example, a sudden spike in installs without clicks may indicate an attack.
How to Protect a Referral Program from Fraud
Anti-fraud is not an option but a necessity. Otherwise, the program becomes a budget leak. We implement multi-layered protection:
- Device uniqueness check (device_id) — one bonus per device.
- Monthly referral cap (e.g., 30).
- Minimum referrer account age (7 days) — to eliminate fakes.
- Integration with anti-fraud services (Branch Fraud Protection, Adjust Fraud Prevention) — they analyze behavioral patterns and emulation.
Additional anti-fraud mechanisms: device fingerprinting, rate limiting (no more than 5 referrals per day from the same IP), canary links (hidden markers to detect bots). Bonus credits are awarded only after confirming the referee's activity — for example, first purchase or 7 days of use. Early awarding leads to garbage traffic.
Comparison of Attribution Tools
| Tool |
Deferred deep linking |
Anti-fraud |
Platform support |
Price |
| Branch.io |
+ |
+ |
iOS, Android, Web |
Freemium |
| AppsFlyer |
+ (OneLink) |
+ |
iOS, Android, Web |
Enterprise |
| Adjust |
+ |
+ |
iOS, Android, Web |
Enterprise |
For startups, Branch.io is the best solution: 2x cheaper than AppsFlyer for volumes up to 100k events. For large projects with deep analytics, choose AppsFlyer or Adjust.
Process and Timeline
| Stage |
Duration |
Result |
| Analysis and design |
1-2 days |
Architecture, tool selection, rules |
| SDK and server logic integration |
3-5 days |
Working deferred deep links, attribution API |
| UI development |
2-3 days |
Referral screen, balance, history |
| Testing and anti-fraud |
2-4 days |
Scenario testing, attack simulation |
| Launch and monitoring |
1 day |
Deploy to App Store and Google Play |
Basic integration takes 3-5 days; a comprehensive solution with anti-fraud and analytics starts from 2 weeks. Cost is calculated individually.
What's Included in the Implementation
We don't just connect an SDK. The project includes:
- Integration of Branch SDK (iOS and Android) with deferred deep linking configuration.
- Server-side attribution logic: tracking referrals, verifying award conditions, anti-fraud.
- Development of app screens: balance display, award history, "Share" button.
- Configuration of link parameters (UGC tags, dynamic parameters).
- Documentation and training for the client's team.
All solutions comply with App Store Review Guidelines (Section 4.2, 5.1) and Google Play Console. We guarantee your program will pass moderation.
Typical Implementation Mistakes
- Missing deferred deep linking — links don't work without the installed app.
- Awarding bonuses without activity checks — encourages fraud.
- Using outdated SDKs (Firebase Dynamic Links) — they are deprecated.
- Ignoring anti-fraud — budget leaks on fake referrals.
Avoiding these is easy: we have accounted for all pitfalls in our standard methodology.
Get a consultation on your project — we'll discuss the mechanics, tools, and timelines. Contact us, and we'll prepare a custom proposal.
Mobile App Monetization: IAP, Subscriptions, and Ad Mediation
An app with poorly implemented purchases loses money not because users don't want to pay, but because a StoreKit transaction hangs, Receipt Validation fails with an error, or restore purchases doesn't work — and the user writes to support or leaves a 1-star review. Our experience (over 7 years in mobile development) shows that proper monetization increases LTV by 30–60% within the first three months after implementation. Get a consultation on monetizing your app — we'll analyze the current model and find growth points.
Why StoreKit 2 is the Best Choice for IAP?
StoreKit 2 (iOS 15+) is a modern API with async/await and device-side verified transactions without a server. Transaction.currentEntitlements returns all active purchases. Key change compared to StoreKit 1: JWS signature verification on device via VerificationResult<Transaction> — no need to send receipt to server for basic validation.
But server-side validation is still needed for consumable purchases and fraud prevention. App Store Server API replaces the old /verifyReceipt endpoint. Webhooks via App Store Server Notifications v2 provide real-time events: SUBSCRIBED, DID_RENEW, EXPIRED, REFUND — without polling.
A typical mistake: not handling paymentQueue(_:updatedTransactions:) in the background for unfinished transactions. User bought a consumable, app crashed before finishTransaction — purchase remains in queue, restores on next launch and requires reprocessing on server. Without server idempotency — double crediting.
How Not to Lose Revenue on Subscriptions?
The subscription model requires tracking states: trial → active → grace period → expired → refunded. RevenueCat is the de facto standard for managing subscriptions in production. It abstracts StoreKit and Google Play Billing, providing a unified API, webhooks, cohort analytics, and A/B testing of paywalls.
Alternatives to RevenueCat include custom implementations with Adapty or Qonversion. Fully custom only if data must not leave the infrastructure or there is non-standard logic. We guarantee that webhook setup and subscription lifecycle event handling is done without losses — verified on projects with over 500k DAU.
Google Play Billing Library 6+ requires handling PurchasesUpdatedListener and explicitly calling acknowledgePurchase() or consumePurchase() within 3 days — otherwise Google automatically cancels the purchase and refunds. The average cost of such an error is a significant loss per user per month (based on our project data).
Ad Mediation: Boosting CPM via Bidding
Showing ads from a single source means losing revenue. Mediation (waterfall or bidding) requests ads from multiple networks and displays the best bid. Google AdMob is the foundation for banner, interstitial, rewarded ads. Mediation via AdMob Mediation or MAX (AppLovin) is the second de facto standard. MAX uses In-App Bidding — a real-time auction without waterfall. In practice, MAX yields significantly higher CPM than classic waterfall (depending on geo and audience). For example, for rewarded video in the US, the improvement can be substantial. With 100,000 rewarded video impressions per day, switching from waterfall to In-App Bidding can generate additional daily revenue.
ironSource (Unity Ads) has a strong position in the gaming segment, especially rewarded video. Mintegral covers the Asian audience well.
Setting up mediation requires ATT (App Tracking Transparency) on iOS 14+. Without requestTrackingAuthorization, ad CPM drops by 3-5 times for non-consenting users. SKAdNetwork and Privacy Manifest (iOS 17) are mandatory requirements; without them, review fails.
| Network |
Ad Type |
Feature |
| AdMob |
banner, interstitial, rewarded |
Wide network, easy start |
| MAX (AppLovin) |
rewarded, interstitial |
In-App Bidding, high fill rate |
| ironSource |
rewarded video |
Best for games |
| Mintegral |
rewarded, native |
Asia, programmatic |
How We Implement Monetization: Step-by-Step Process
- Current model audit — analysis of funnel, paywall, price tiers, and identification of bottlenecks.
- Model design — choose type (subscription, consumable, non-consumable) and optimize price points.
- IAP integration — set up StoreKit 2 / Google Billing 6, receipt validation, webhooks.
- Ad mediation — connect 3-6 networks, configure waterfall or In-App Bidding, test fill rate.
- Analytics and cohorts — integrate RevenueCat, Amplitude, or Firebase for LTV tracking.
- A/B testing of paywall — use Remote Config for experiments without a release.
- Launch and monitoring — 2 weeks of free support after launch, bug fixes by 24-hour SLA.
How to Design a Freemium Model and Paywall?
Freemium works when the boundary between free and paid is properly drawn. Too strict a paywall at the start — users delete. Too generous a free tier — no incentive to pay.
A technically sound pattern: server-side feature flags (Remote Config in Firebase or LaunchDarkly) control access to features. This allows A/B testing of paywall without a release, changing trial conditions, and running promotions.
Implementation at the code level: EntitlementManager — a single point for checking access to features, aware of subscription status, flags, and promos. No scattered isPremium checks throughout the code. Experience shows this approach reduces paywall-related bugs by 80% (confirmed on 30+ projects).
Checklist of Typical Monetization Mistakes
- Missing handling of
unfinished transactions — revenue loss of 5-10%.
- No server-side idempotency for consumable processing — double crediting.
- Forgot to call
acknowledgePurchase() on Android — purchase cancelled after 3 days.
- Not handling
REFUND and DID_RENEW events — incorrect subscription status.
- Paywall without A/B testing — leaving 20-40% of monetization potential.
- Ads from a single source (e.g., AdMob without mediation) — CPM 15-30% lower.
Scope of Monetization Work
- Current model audit — analysis of funnel, paywall, price tiers.
- IAP integration — StoreKit 2 / Google Billing 6, receipt validation, webhooks.
- Ad mediation — configure MAX / AdMob, connect 3-6 networks, test fill rate.
- Analytics setup — RevenueCat, Amplitude / Firebase, cohort analysis.
- Documentation — description of entitlements, restoration procedure, review checklist.
- Team training — analysis of typical mistakes, support recommendations.
- Guarantee — 2 weeks free support after launch, bug fixes by 24-hour SLA.
Estimated Timelines
| Stage |
Duration |
| Basic IAP (one store) |
1–2 weeks |
| Subscription system + RevenueCat + paywall |
3–5 weeks |
| Ad mediation (MAX + 3 networks) |
1–2 weeks |
| Full cycle (IAP + ads + analytics) |
4–8 weeks |
Cost is calculated individually. We have been working in this field for over 8 years and have implemented monetization in over 40 projects — many of which passed App Store Review without a single rejection. Contact us for an audit or order a consultation — we'll tell you what growth points exist in your app.