Trust Signals: Data Collection and Privacy

EARLY ACCESS

This page lists the device and contextual data the Trust Signals SDKs collect and transmit to Futurae infrastructure, and describes how that data is protected.

All fields are optional. A field is omitted from an observation when the required permission is missing, or when the data source is unavailable on the device.

Data collected by the Mobile Sensor SDK

Data collectedPlatform
Latitude, longitude, accuracy, speedAndroid, iOS
Nearby Wi-Fi access points: SSID, BSSID, timestampAndroid, iOS
Connected Wi-Fi network: SSIDAndroid, iOS
Connected Wi-Fi network: BSSID, RSSI, connected devicesAndroid only
Nearby Bluetooth LE devices: name, address, timestampAndroid, iOS
Connected Bluetooth LE peripheralsAndroid, iOS
Combined nearby BLE and Wi-Fi devicesAndroid only
Devices discovered through Bonjour on the local networkiOS only
Public IP addressAndroid, iOS
Timezone IDAndroid, iOS
Timezone display nameAndroid only
Device model, OS version, screen resolution, uptimeAndroid, iOS
ManufacturerAndroid only
OS name, screen scale and brightness, proximity sensor stateiOS only
User-assigned device name, such as “John’s iPhone”iOS only
Vendor identifier (IDFV), which persists across app reinstallsiOS only
Thermal state, low power modeiOS only
Language and regionAndroid, iOS
Connection type, VPN active, proxy hostAndroid only
Whether a phone call is activeAndroid, iOS
Debugger attachedAndroid, iOS
Developer mode enabledAndroid only
Host application versionAndroid, iOS
Host application installer sourceAndroid only
Host application build numberiOS only
Battery level and charging statusAndroid, iOS

Data collected by the Browser Sensor SDK

Which behavioral data is collected depends on the features you enable. The fingerprint feature collects its data points as a single combined object. The table lists the relevant ones, and leaves out low-level values used only as internal inputs to its computation.

Data collectedType
Mouse events: timestamps and coordinatesBehavioral
Keystroke durations (key-down / key-up pairs)Behavioral
Form input focus and blur eventsBehavioral
Window resize eventsBehavioral
Window inner dimensions and device pixel ratioBehavioral
Browser name, version and operating systemFingerprint
User-agent stringFingerprint
User-agent client hints: platform, architecture, bitness, model, platform versionFingerprint
Browser platform string, raw OS and CPU stringFingerprint
Browser vendor string and rendering-engine flavorFingerprint
Screen resolutionFingerprint
Hardware concurrency (logical CPU cores)Fingerprint
Device memory (GB)Fingerprint
Touch support: max touch points, touch event and touchstart availabilityFingerprint
Timezone, date and time locale, browser language listFingerprint
Color depth, color gamut, HDR supportFingerprint
Display and accessibility preferences: reduced motion, reduced transparency, inverted colors, forced colors, monochrome, contrastFingerprint
Browser audio volume, audio subsystem base latencyFingerprint
WebGL: version, vendor, renderer, shading language version (masked and unmasked)Fingerprint
Storage availability: cookies, local storage, session storage, IndexedDB, openDatabaseFingerprint
Installed fonts and font-rendering metricsFingerprint
Installed browser plugins, such as PDF viewers, and PDF-viewing capabilityFingerprint
Ad-blocker presenceFingerprint
Math function precision, from the output of Math functions for a fixed set of inputsFingerprint
Apple Pay availability, Privacy-Preserving Ad Click Attribution API supportFingerprint
IP address of the browser, passed on by your collection proxy in X-Forwarded-ForNetwork

Data in transit

All communication between the SDKs and the backend is encrypted over HTTPS.

Data at rest

Sensor observations and derived signal outputs are stored on Futurae cloud infrastructure with encryption at rest, for a guaranteed retention period of 24 months.

Privacy and access control

Pseudonymization recommendation. The accountId used across the Trust Signals SDKs and Signals API is defined and managed entirely by you. Futurae has no independent means of resolving it to a real-world user identity.

To limit the personal data held on Futurae infrastructure, Futurae recommends supplying a randomly generated, opaque identifier such as a UUID, in place of a username, email address, or any other value that could directly identify the end user. This gives you full control over whether sensor observations can be linked to a specific individual, with no impact on signal quality. The recommended convention is in Identifier Strategy.

Access control is strictly enforced: only authorized service components may access observation data, scoped to the tenant that collected it.

GDPR and data sovereignty

  • Futurae processes personal data as a Data Processor on behalf of the service provider, who acts as the Data Controller.
  • A Data Processing Agreement (DPA) is available on the Futurae website.

You are responsible for informing your end users about the sensor data collected by the Trust Signals SDKs, in accordance with applicable privacy regulations.