Reset your Android advertising ID right now. Go to Settings, Privacy, Ads, and tap “delete advertising ID.” Within a few hours, open Instagram or a mobile game and watch the same shoe ad follow you that was following you yesterday. This isn’t a bug. It’s because resetting your ad ID doesn’t do what most people think it does, and that gap between what people believe “tracking” means and what the ad industry actually means by it is the whole story.
Most privacy writing (including a lot of ours) treats “tracking” as a catch-all word for “an app doing something invasive with your data.” That’s fine for a headline, but it hides a precise, boring, technical definition that the industry itself uses, and understanding that definition is the difference between protecting yourself and just feeling like you did.
the industry’s actual definition
Under Google Play’s own developer policy, and the IAB’s Transparency and Consent Framework that underpins most of programmatic advertising, “tracking” has a specific meaning: linking data about you across apps, websites, or time, and attributing it to a persistent identity. Not collection. Linking.
An app that logs your taps inside itself, stores them on its own server, and never shares them anywhere else is “collecting” data, in this framework, not “tracking” you. An app that shares your device identifier with an ad network, which then matches that identifier against data from six other apps to build a cross-app profile, is tracking. The word “tracking,” legally and technically, describes the stitching, not the gathering.
This distinction matters because almost every privacy toggle on your phone is built around it. When Google says “ask apps not to track,” it’s asking apps not to link your GAID to anyone else’s dataset. It says nothing about what the app does with your data internally, which is why an app can honor that setting completely and still know exactly what you searched for at 2am.
the three ways matching actually happens
Deterministic matching uses a hard identifier: your Google advertising ID (GAID), an email hash, a phone number hash. Two companies compare identifiers, find a match, and merge profiles. This is what your ad ID reset is supposed to break, and it does break it, for about as long as it takes the SDKs embedded in your apps to re-sync a new profile against your other signals. Industry benchmarks from mobile measurement partners put that re-sync window at under 24 hours for apps with more than one ad SDK installed, which is most apps.
Probabilistic matching (commonly called fingerprinting) doesn’t need your identifier at all. It builds a fingerprint from your screen resolution, installed font list, battery level curve, IP address, timezone, and roughly 15 to 20 other signals, and matches that fingerprint against other sessions with 70 to 90 percent confidence depending on how unique your device configuration is. Resetting your ad ID does nothing to this. Your phone’s fingerprint didn’t change; only your ID did.
Attribution matching is the one nobody explains well. It’s why an app you’ve never opened seems to already know things about you the moment you install it. Ad networks track “install attribution” using a window, typically 7 to 30 days, that links an ad impression you saw in one app to an install you made later in a completely different app, using device and IP proximity rather than any identifier at all. This is standard, disclosed, and running on your phone right now for nearly every free app you’ve ever installed.
why the settings feel like theater
Apple’s App Tracking Transparency prompt and Android’s “delete advertising ID” option both target deterministic matching specifically, because that’s the layer regulators can actually define in a policy document. Fingerprinting and attribution windows are harder to regulate because they don’t rely on a single identifiable “tracker,” they rely on combining ordinary, individually-innocent data points. A 2023 sweep by a European data protection authority found that even after users opted out of “tracking” under GDPR-adjacent frameworks, 61 percent of tested apps continued sending device signals to third parties consistent with fingerprinting, just without the identifier attached. Technically compliant. Practically unchanged.
None of this means the opt-out settings are worthless. Deterministic matching is still the cheapest, most reliable way to build ad profiles, and breaking it does reduce ad relevance and cross-app profile completeness. But treating “ask app not to track” as a privacy switch, rather than one lock on a house with four unlocked doors, is where most people’s expectations go wrong.
what actually changes the equation
If tracking means linking, not collecting, then the fix isn’t just resetting identifiers, it’s reducing the signals available to be linked in the first place. That means fewer SDKs per phone (each additional ad or analytics SDK is another party running its own matching), consistent use of a VPN to stabilize your IP fingerprint rather than randomize it (randomizing IPs can paradoxically make fingerprints more unique, not less), and treating permissions as the real lever, since GPS, contacts, and Bluetooth scan results feed fingerprinting models far more than any advertising ID does.
The word “tracking” survives in privacy conversations because it’s emotionally accurate. Something out there does know a lot about you and follows you around. But the mechanism behind that word is not one thing you can switch off. It’s three separate systems, running in parallel, each with its own weaknesses, and only one of them cares whether you reset your ID.