Privacy and user data
Pass a stable internal user ID that your backend can map to a user, but avoid an email address, phone number, or full name. Keep your web UID signing key and callback secret out of browser code, screenshots, and logs. Follow the platform guide for the mobile SDK API token.
Only send optional user attributes that you have a reason and permission to use. Do not assume that SDK initialization itself handles your app's consent flow. If your iOS app uses the advertising identifier, configure the required platform permissions and present your own consent flow before collecting it. Follow your applicable app store and privacy requirements for the markets where you operate.
Your reward endpoint should receive verified server callbacks over HTTPS, validate their signature or hash, and store the minimum fields needed for accounting and duplicate detection. See callbacks and testing.