What Are GAID and IDFA? Mobile Ad IDs Explained

Key takeaways

  • GAID and IDFA are resettable device IDs meant only for advertising: GAID on Android through Google Play services, IDFA on iPhone and iPad.
  • On iOS 14.5 and later, the IDFA is all zeros unless the user allows tracking. On Android it is available by default, but users can reset or delete it.
  • Both stores restrict how ad IDs may be combined with other identifiers and personal data, so read the policies before you build on them.

What are GAID and IDFA?

GAID and IDFA are mobile advertising IDs: device identifiers that apps can read and that exist only for advertising and ad measurement. GAID, the Google Advertising ID, is provided on Android by Google Play services, and Google calls it simply the advertising ID. IDFA, the Identifier for Advertisers, is Apple’s equivalent on iPhone and iPad. Unlike a hardware serial number, users can control both, and when access is not allowed the ID is returned as a string of zeros.

Both look like a standard UUID, for example 00000000-0000-0000-0000-000000000000, which is exactly the value an app receives when the ID is unavailable.

GAID vs IDFA at a glance

GAID (Android)IDFA (iOS and iPadOS)
Provided byGoogle Play servicesApple, through the AdSupport framework
Default accessAvailable to apps that declare the AD_ID permission, unless the user deleted the IDAll zeros until the user grants tracking permission
How the user controls itReset or delete it in Android settingsAllow or deny tracking per app, or turn off tracking requests entirely
Value when unavailableA string of zerosAll zeros
Measurement without itGoogle Play Install Referrer, click IDsSKAdNetwork and AdAttributionKit, click IDs

IDFA and App Tracking Transparency

Apple’s developer documentation describes the IDFA as an alphanumeric string that is unique to each device and used only for advertising, and lists uses such as frequency capping, attribution, conversion events, counting unique users, ad fraud detection, and debugging.

Since iOS 14.5 and iPadOS 14.5, an app must request permission through the App Tracking Transparency (ATT) framework before it can read the IDFA. According to Apple, the identifier returns all zeros when:

  • the app has not asked for tracking permission,
  • the user declined,
  • a profile or configuration restricts access,
  • or the app runs in Simulator, on a Mac, or as an iPhone or iPad app in visionOS.

Users can change their choice at any time in the Tracking section of their Privacy settings. Apple therefore recommends not storing the IDFA and reading it fresh, checking the current authorization status.

ATT is about more than the ID. Apple defines tracking as linking user or device data collected from your app with data collected from other companies’ apps, websites, or offline properties for targeted advertising or advertising measurement, or sharing it with data brokers. Its user privacy guidance adds that, under the Apple Developer Program License Agreement, apps may not derive data from a device to uniquely identify it, which rules out fingerprinting as a replacement for the IDFA.

GAID and the Android 13 AD_ID permission

Google’s Play Console Help describes the advertising ID as “a unique, user-resettable, and user-deletable ID for advertising, provided by Google Play services.” Three changes matter for anyone using it today:

  • Users can delete it. When a user deletes the advertising ID in Android settings, it is removed, and any app trying to read it receives a string of zeros. Google rolled this out from late 2021, on all devices that support Google Play from April 1, 2022.
  • Apps need a permission. Apps that target Android 13 (API level 33) or later must declare com.google.android.gms.permission.AD_ID in their manifest. Without it, Google’s API reference says the returned value is all zeros. Some SDKs, such as Google’s Mobile Ads SDK, already declare it and it is merged into your app.
  • Opt-out must be respected. If the user has opted out of ads personalization, Google’s Ads policy forbids using the ID for profiles or personalized ads, while still allowing contextual advertising, frequency capping, conversion tracking, reporting, and security and fraud detection.

For analytics and fraud prevention that are not about ads, Google points developers to a separate identifier, the App Set ID, which must not be used for ads personalization or measurement.

What about Privacy Sandbox on Android? Google had been building privacy-preserving advertising APIs for Android. On October 17, 2025, it announced it would retire most of them, including Topics, Protected Audience, Protected App Signals, the Attribution Reporting API, and SDK Runtime, citing ecosystem feedback and low adoption. That announcement did not mention the advertising ID, which remains part of Google Play services and its policies today.

How MMPs and ad networks use ad IDs

Ad IDs let different companies recognize the same device without knowing who the user is:

  1. An ad network shows an ad inside an app and records the click together with the device’s ad ID, where it is available.
  2. The user installs the advertised app. The measurement SDK in that app reads the same ad ID on first open.
  3. The MMP matches the two and credits the install to the network, then reports later in-app events the same way.

Ad IDs also power frequency capping, retargeting, and fraud checks such as spotting one device claiming many installs. Where the ID is all zeros, measurement falls back to other methods: the Play Install Referrer on Android, Apple’s SKAdNetwork and AdAttributionKit on iOS, and click IDs passed through server-to-server tracking. What is an MMP? explains each of these in more detail.

Privacy rules for advertising IDs

  • No linking to persistent IDs. Google’s Ads policy says the advertising ID may not be connected to persistent device identifiers, such as SSAID, MAC address, or IMEI, for any advertising purpose.
  • Personal data only with consent. Google allows connecting it to personally identifiable information only with the user’s explicit consent.
  • A reset is a reset. After a reset, the new ID must not be linked to the old one or to data derived from it without explicit consent.
  • Ask first on iOS. No IDFA and no tracking without ATT permission.
  • Disclose it. Both stores expect your privacy policy and store privacy labels to describe how you collect and use the ID.
  • Local law still applies. In the EU, for example, the GDPR counts online identifiers as personal data when they can identify a person. Store rules are a minimum, not the whole picture.

Both stores also have stricter rules for apps aimed at children. This article is general information, not legal advice.

Getting app users without ad IDs on Sharklio

Sharklio has no SDK and does not rely on GAID or IDFA. In a task campaign, users install your app, reach the goal you set, such as finishing the tutorial or reaching level 5, and send proof, and you approve each completion before you pay, at a price you set per country from $0.01. That works the same on Android and iOS, with or without tracking permission. Multi-step offer campaigns, available by arrangement with our team, pay for each step your own server reports through a postback, matched by our click ID. You can create a free account and your first campaign today. For more ways to grow an app, see how to get app installs.

Frequently asked questions

What is the difference between GAID and IDFA?

GAID is Google’s advertising ID for Android, IDFA is Apple’s for iOS and iPadOS. The big practical difference is the default: on Android the ID is available unless the user deletes it, while on iOS 14.5 and later it is all zeros until the user allows tracking.

Is GAID the same as AAID?

Yes. GAID and AAID (Android Advertising ID) are both names for the advertising ID provided by Google Play services. Google’s own documentation mostly calls it the advertising ID.

Why is my IDFA all zeros?

Because the app has not asked for tracking permission, the user declined, a device profile restricts it, or the app is running in Simulator.

Can users reset their advertising ID?

On Android, users can reset or delete the advertising ID in settings. On iOS, users control access per app through tracking permission, and can turn off tracking requests for all apps.

Do I need the AD_ID permission?

If your app targets Android 13 or later and reads the advertising ID, yes. Without it, the ID is returned as zeros. Check whether an SDK you use already adds it.

Did Google remove the advertising ID with Privacy Sandbox?

No. Google’s October 2025 update retired most Privacy Sandbox APIs, including those on Android, and did not announce any change to the advertising ID.