In short

iOS: App Store privacy labels

The SDK ships a privacy manifest (PrivacyInfo.xcprivacy) that declares the types below, and Xcode adds it to your app's privacy report. It declares no tracking and no tracking domains. Its only required-reason API is UserDefaults (reason CA92.1: the SDK remembers which language it last reported).

Apple data typeWhat exactlyLinkedTrackingPurposeWhen
Contact Info → NameThe name the user types before their first message, or the one you pass with setUserYesNoApp FunctionalityNeeded to start a conversation
Contact Info → Email AddressOnly if the user gives one (or you pass it), so replies also reach them by emailYesNoApp FunctionalityOptional
User Content → Customer SupportThe messages the user sends, and when they were sent and readYesNoApp FunctionalityWhen the user writes
User Content → Photos or VideosPhotos the user attaches (system picker, no photo-library permission; resized, re-encoded, EXIF and location removed)YesNoApp FunctionalityOptional
User Content → Other User ContentFiles the user attaches (up to 10 MB each), with their file namesYesNoApp FunctionalityOptional
Identifiers → User IDThe user record DevReply creates for this person in your app, and your own user ID if you pass it with loginYesNoApp FunctionalityAutomatic
Identifiers → Device IDA random install token DevReply issues (kept in the Keychain), and the APNs push token if your app registers for pushYesNoApp FunctionalityAutomatic; push token only with push
Diagnostics → Other Diagnostic DataDevice model, iOS version, your app's version and build, SDK version, languageYesNoApp FunctionalityAutomatic
Other Data → Other Data TypesCustom attributes, only if you send them with setAttributesYesNoApp FunctionalityOnly if you send them

Not collected: location, contacts, health, financial info, browsing or search history, sensitive info, purchases, crash data, performance data, product interaction, advertising data, IDFA. The SDK never shows the App Tracking Transparency prompt.

Apple lets you leave out data that users give in optional, infrequent customer-support requests that aren't part of your app's main purpose. Whether that applies is your call; the manifest declares everything, to be safe.

Android: Google Play Data safety

Answer Yes to "Does your app collect or share any of the required user data types?" and add these. For each: collected, not shared (DevReply is your service provider, which Play doesn't count as sharing), not processed ephemerally, purpose App functionality.

Play data typeWhat exactlyCollectedSharedPurposeRequired or optional
Personal info → NameThe name typed before the first message, or passed with setUserYesNoApp functionalityRequired to start a conversation
Personal info → Email addressOnly if the user gives one (or you pass it)YesNoApp functionalityOptional
Personal info → User IDsThe user record DevReply creates for this person in your app, and your own user ID if you pass it with loginYesNoApp functionalityRequired (automatic)
Messages → Other in-app messagesThe messages the user sends in the chatYesNoApp functionalityRequired to use the chat
Photos and videos → PhotosPhotos the user attaches (system photo picker, no storage permission; re-encoded, EXIF removed)YesNoApp functionalityOptional
Files and docs → Files and docsFiles the user attaches, with their namesYesNoApp functionalityOptional
App info and performance → DiagnosticsDevice maker and model, Android version, your app's version and build, SDK version, languageYesNoApp functionalityRequired (automatic)
Device or other IDsA random install token DevReply issues (encrypted with an Android Keystore key), and the FCM token if your app forwards itYesNoApp functionalityRequired (automatic); FCM token only with push
Whatever your attributes containCustom attributes, only if you send them with setAttributesIf you send themNoApp functionalityYour choice

Security practices: data is encrypted in transit (Yes). Users can request that data be deleted (Yes: in your app with deleteUser, or through you, from your backend or the dashboard).

The Android SDK has no third-party dependencies (no Firebase, no analytics). It does not read the Android ID or the advertising ID. It only asks for the notification permission (Android 13+) after the user's first message, and only if your app forwards push.

Web

No store form, but your site's privacy notice should cover the same data. The web chat collects the name, optional email, messages, photos and files, and custom attributes as above. For device details it sends only the browser name and major version, the OS, and your site's hostname (or the app version you pass), plus the language. No fingerprinting, no cookies. It keeps its install token and the chat's settings in localStorage on your site, which the chat needs to work. The script is served from api.devreply.com, not a third-party CDN.

What the SDK never touches

What's on you