generated: '2026-08-12' method: searched source: >- https://github.com/AdColony/AdColony-Android-SDK/wiki/Privacy-Laws, https://github.com/AdColony/AdColony-iOS-SDK/wiki/Privacy-Laws, https://github.com/AdColony/AdColony-iOS-SDK/blob/master/CHANGELOG.md, https://github.com/AdColony/AdColony-Android-SDK/blob/master/CHANGELOG.md notes: >- AdColony publishes no OpenAPI, so nothing here is derived from a spec. Every entry below is asserted from AdColony's own still-served SDK documentation on its GitHub organization. AdColony's conformance surface is adtech- and privacy-regime shaped (IAB frameworks, platform attribution APIs, privacy statutes), not web-API shaped — there is no OAuth, OIDC, JSON:API, RFC 9457 or OData surface to assert, and those are recorded as not applicable rather than as failures. The company was absorbed into Digital Turbine in 2021 and these documents have not been revised since 2022-06-07, so every claim below describes the terminal state of the product. conformance: - id: iab-tcf-v2 name: IAB Transparency and Consent Framework v2.0 conforms: true evidence: >- "We've also added support for version 2.0 of the IAB Transparency and Consent Framework (TCF)." AdColonyAppOptions ingests a TCF v2.0 consent string via setPrivacyConsentString(AdColonyAppOptions.GDPR, consent), and the Android SDK additionally reads the TCF v2.0 string from SharedPreferences per the IAB storage recommendation. since: Android/iOS SDK v4.2 source: https://github.com/AdColony/AdColony-Android-SDK/wiki/Privacy-Laws - id: iab-tcf-v1.1 name: IAB Transparency and Consent Framework v1.1 conforms: true evidence: >- "AdColony supports ingestion of the IAB TCF v1.1 and TCF v2.0 versions of the consent string to our AdColonyAppOptions API." source: https://github.com/AdColony/AdColony-Android-SDK/wiki/Privacy-Laws - id: iab-us-privacy-string name: IAB CCPA US Privacy String conforms: true evidence: >- The US Privacy String may be passed via the AdColonyAppOptions API or read by the Android SDK from SharedPreferences. A non-IAB "1"/"0" opt-out value is also accepted, with the provider noting it is not IAB-compliant and may reduce fill. source: https://github.com/AdColony/AdColony-Android-SDK/wiki/Privacy-Laws - id: gdpr name: EU General Data Protection Regulation conforms: partial evidence: >- AdColony documents a publisher-facing consent-passing contract for GDPR: setPrivacyFrameworkRequired(AdColonyAppOptions.GDPR, true) to declare applicability plus setPrivacyConsentString for the consent value, propagated to downstream demand consumers. This is a documented technical mechanism for publisher compliance, not a certification or an audited attestation. source: https://github.com/AdColony/AdColony-Android-SDK/wiki/Privacy-Laws - id: ccpa name: California Consumer Privacy Act conforms: partial evidence: >- Generic privacy methods added in SDK v4.2 carry a CCPA applicability flag and an opt-out value ("1" = has not opted out of sale, "0" = opted out), propagated to downstream consumers. Documented mechanism, not a certification. source: https://github.com/AdColony/AdColony-Android-SDK/wiki/Privacy-Laws - id: iab-om-sdk name: IAB Open Measurement SDK conforms: true evidence: >- The Open Measurement SDK is bundled and versioned in both mobile SDKs; the changelogs track it from v1.3.1 (iOS 4.1.4, 2020-02-21) through v1.3.30 (iOS 4.8.0 / Android 4.7.0, 2022-03-10), including a fix for recording the 'loaded' event against the OM SDK for display ads. version: 1.3.30 source: https://github.com/AdColony/AdColony-iOS-SDK/blob/master/CHANGELOG.md - id: skadnetwork name: Apple SKAdNetwork attribution conforms: true evidence: >- "Support for SKAdnetwork attribution and upcoming iOS14 IDFA changes" (iOS 4.3.0, 2020-08-05); "SKAdNetwork view-through attribution support" (iOS 4.6.1, 2021-04-21). source: https://github.com/AdColony/AdColony-iOS-SDK/blob/master/CHANGELOG.md - id: google-designed-for-families name: Google Play Designed for Families policy conforms: true evidence: >- "Google Designed For Families (DFF) compliance changes" (Android 4.7.1, 2022-03-30). Android 4.6.5 (2021-10-21) added AD_ID permission support for Android 12. source: https://github.com/AdColony/AdColony-Android-SDK/blob/master/CHANGELOG.md not_applicable: - id: oauth2 reason: No OAuth surface. The only documented server-to-server surface is the V4VC callback, authenticated with a shared-secret MD5 hash. - id: oidc reason: No identity surface published. - id: rfc9457 reason: No HTTP API with a published error envelope is served. - id: json-api reason: No REST contract published. - id: odata reason: Not applicable to this product category. - id: fhir reason: Not a healthcare provider. - id: fapi reason: Not a financial-services provider. - id: psd2 reason: Not a payments provider. - id: scim reason: No identity/provisioning surface published. certifications: [] certifications_note: >- No SOC 2, ISO 27001, PCI DSS, HIPAA or FedRAMP attestation is published on any AdColony-controlled surface. probe-security-programs.py returned vdp=none trust=none on 2026-08-12; there is no trust center and no security.txt.