Referral programs in mobile apps bring up to 30% of new users, but their implementation is technically harder than it seems. The main problem is attribution: you need to link an app install to a specific referrer, even if days pass between clicking the link and the first launch. Without correct deferred deep linking, the program loses its meaning—money simply goes nowhere. With over 20 projects, we have accumulated experience that guarantees transparent attribution and protection against fraud.
How Deferred Deep Linking Works
A normal deep link does not work if the app is not installed: the user lands in the App Store and the link is lost. A deferred deep link "remembers" the referral parameter and passes it on first launch. This is the foundation of correct attribution.
Tools: Branch.io, AppsFlyer OneLink, Adjust. Branch is the most versatile, supporting iOS, Android, and Web, and offers a free tier. Here's an example of handling a link on first launch in Swift:
// iOS — Branch SDK Branch.getInstance().initSession(launchOptions: launchOptions) { params, error in if let referrerID = params?["referrer_id"] as? String { // First launch with referral parameter ServerAPI.attributeInstall(referrerID: referrerID, newUserID: currentUser.id) } } Branch tracks clicks via fingerprinting (IP + User-Agent + time) and matches the install within a 2-hour window. Accuracy is ~85-95% — sufficient for business metrics. More details: deferred deep linking.
Why Real-Time Attribution Monitoring Matters
Without monitoring, you won't know about problems until the budget disappears. Real-time dashboards from Branch or AppsFlyer show click-to-install conversion rates, the number of suspicious events, and the effectiveness of each channel. We configure alerts for anomalies — for example, a sudden spike in installs without clicks may indicate an attack.
How to Protect a Referral Program from Fraud
Anti-fraud is not an option but a necessity. Otherwise, the program becomes a budget leak. We implement multi-layered protection:
- Device uniqueness check (device_id) — one bonus per device.
- Monthly referral cap (e.g., 30).
- Minimum referrer account age (7 days) — to eliminate fakes.
- Integration with anti-fraud services (Branch Fraud Protection, Adjust Fraud Prevention) — they analyze behavioral patterns and emulation.
Additional anti-fraud mechanisms: device fingerprinting, rate limiting (no more than 5 referrals per day from the same IP), canary links (hidden markers to detect bots). Bonus credits are awarded only after confirming the referee's activity — for example, first purchase or 7 days of use. Early awarding leads to garbage traffic.
Comparison of Attribution Tools
| Tool | Deferred deep linking | Anti-fraud | Platform support | Price |
|---|---|---|---|---|
| Branch.io | + | + | iOS, Android, Web | Freemium |
| AppsFlyer | + (OneLink) | + | iOS, Android, Web | Enterprise |
| Adjust | + | + | iOS, Android, Web | Enterprise |
For startups, Branch.io is the best solution: 2x cheaper than AppsFlyer for volumes up to 100k events. For large projects with deep analytics, choose AppsFlyer or Adjust.
Process and Timeline
| Stage | Duration | Result |
|---|---|---|
| Analysis and design | 1-2 days | Architecture, tool selection, rules |
| SDK and server logic integration | 3-5 days | Working deferred deep links, attribution API |
| UI development | 2-3 days | Referral screen, balance, history |
| Testing and anti-fraud | 2-4 days | Scenario testing, attack simulation |
| Launch and monitoring | 1 day | Deploy to App Store and Google Play |
Basic integration takes 3-5 days; a comprehensive solution with anti-fraud and analytics starts from 2 weeks. Cost is calculated individually.
What's Included in the Implementation
We don't just connect an SDK. The project includes:
- Integration of Branch SDK (iOS and Android) with deferred deep linking configuration.
- Server-side attribution logic: tracking referrals, verifying award conditions, anti-fraud.
- Development of app screens: balance display, award history, "Share" button.
- Configuration of link parameters (UGC tags, dynamic parameters).
- Documentation and training for the client's team.
All solutions comply with App Store Review Guidelines (Section 4.2, 5.1) and Google Play Console. We guarantee your program will pass moderation.
Typical Implementation Mistakes
- Missing deferred deep linking — links don't work without the installed app.
- Awarding bonuses without activity checks — encourages fraud.
- Using outdated SDKs (Firebase Dynamic Links) — they are deprecated.
- Ignoring anti-fraud — budget leaks on fake referrals.
Avoiding these is easy: we have accounted for all pitfalls in our standard methodology.
Get a consultation on your project — we'll discuss the mechanics, tools, and timelines. Contact us, and we'll prepare a custom proposal.







