Product1 publisher3 min readPublished
San Diego County accuses AppLovin of fingerprinting children past Apple and Google parental controls
San Diego County sued AppLovin, alleging fingerprinting let it track children past Apple and Google parental controls and show them adult ads. For app teams, the case tests whether a platform's child setting protects anyone once a third-party ad SDK runs inside the game.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- The complaint says AppLovin gathered children's data precise enough to show where they live and study and whether they are asleep, even with ad-tracking opt-outs turned on.
- AppLovin's ad-buyer policies, in force since 18 June, bar sexually explicit content, illegal drugs and ads aimed at children, and require its approval for alcohol ads.
- The SEC looked into AppLovin's data collection after short-seller reports and closed the probe without recommending enforcement, CFO Matt Stumpf said in August.
- The case is one of three that San Diego County's new Consumer Fairness and Public Protection Unit filed on Monday, alongside suits against Roblox and Polymaker.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint If the fingerprinting allegation holds, a parent's tracking block does not limit what an ad SDK inside a kids-rated game collects, so app teams cannot point to that setting as their safeguard.
- decision Advertisers buying through AppLovin have to settle how they identify a child user, because the network's policy says that call is solely theirs and the county says the platform setting was sidestepped.
- precedent Local prosecutors are now bringing child-safety cases against platforms on their own, so a federal probe closed without enforcement no longer settles where a company stands.
- contradiction The complaint's central claim directly contradicts Foroughi's 2025 denial that AppLovin builds device fingerprints, and the dispute now goes before a judge in San Diego.
A parent sets up an Android phone for a six-year-old and switches on Google's parental controls. The child opens a physics puzzle game. According to a screenshot in San Diego County's complaint, the game then showed an ad for a sexualised AI chatbot app [6]. Another screenshot shows ads for cannabis gummies on a device with the same controls [7].
Here's what users actually do: they flip the platform switch and consider the job finished. Here's what app teams tell themselves that switch buys: the platform's tracking block, working alongside the ad network's content rules. The county alleges that AppLovin got around the Apple and Google settings with fingerprinting and tracked children for ad targeting without parental consent [4].
AppLovin's pitch is in its policies for ad buyers: "AppLovin does not knowingly collect personal information from children or serve Advertisements to children" [9]. Those policies also make advertisers "solely responsible" for determining whether a user qualifies as a child [11]. In the county's account, what the company actually does is harvest children's data to "feed it into the company's artificial intelligence advertising engine" [5]. Pair a "knowingly" standard with an advertiser-owned child test and the network's promise depends on someone else flagging the user.
These are allegations in a complaint filed Monday in San Diego Superior Court [2]. AppLovin did not immediately respond to Bloomberg's request for comment [8]. The company has heard the fingerprinting charge before. Short sellers Fuzzy Panda and Muddy Waters accused it in 2025 of harvesting identifiers from other platforms to track users across websites and apps [12]. Chief executive Adam Foroughi wrote in March 2025 that their reports were "littered with inaccuracies" and denied creating "alternative accurate and persistent identifiers, typically called device fingerprints" [13].
The reported defendant is AppLovin [1], and the coverage does not describe the game makers whose apps carried the ads as parties. For a team running an ad SDK in a children's app, I think the nearer risk is the screenshots. They show ads in apps marked appropriate for kids [16], on devices where the parental controls were switched on [6].
The test I'd apply to an app marked for children is a 2x2. One axis asks who decides that a user is a child: the platform setting alone, or a signal the team holds and passes to every ad partner. The other asks who controls what device data leaves the phone once the tracking opt-out is on: the team's own code, or the SDK. Where both answers are someone else, the app is set up like the six-year-old's phone in the complaint. Where both are the team's, I'd expect to pay in engineering time and some ad revenue. In return, the team can tell a parent on Friday what their child was shown.
What to watch
- AppLovin's formal response to the San Diego Superior Court complaint, and whether it repeats the company's 2025 denial that it builds device fingerprints.
- Whether the county, or another plaintiff, names the game developers or advertisers whose kids-rated apps carried the ads shown in the screenshots.
- Whether Apple or Google change what their parental controls promise about third-party ad SDKs running inside children's apps.