Impersonation Risk Detection & Privacy
Impersonation Risk Detection is designed to protect your information and enable you to choose to share signals that help detect when you are at risk from active scams.
![]()
- When apps request Impersonation Risk Detection signals, information about your device use, such as the approximate number of phone calls and emails sent or received, and account use, such as your recent App Store app downloads and content purchases, will be used by Apple to generate signals.
- Neither Apple nor the app requesting Impersonation Risk Detection signals will receive the on-device information used to generate signals.
- Apple will learn the category of in-app activity you attempted when an app requests Impersonation Risk Detection signals, such as when you attempted to sign in to your account or make a payment transaction, but not which app you were using or the content of your in-app activity.
- Apple will use the signals and information about how the requesting app used the signals to help improve Impersonation Risk Detection signals.
Impersonation Risk Detection generates signals designed to help protect you from active scams.
If you enable sharing of Impersonation Risk Detection signals, when you attempt specific types of activities within an app that could put you at enhanced risk of an active scam, such as when signing in to your account or making a transaction, third-party apps can request Impersonation Risk Detection signals from Apple to help the app decide whether the actions are likely yours. You can disable this functionality at any time on your iOS device, including for individual apps, by going to Settings > Privacy & Security > Impersonation Risk Detection. You will also be able to see which apps have recently requested Impersonation Risk Detection signals and for what purposes.
If an app requests Impersonation Risk Detection signals, your device will evaluate information about your device usage patterns, such as whether you are currently sharing your screen, and the approximate number of recent emails or calls you have received, in order to generate an on-device assessment. This assessment, but not the underlying data, will be sent from your device to Apple and combined with information about your Apple Account activity, such as recent apps you have downloaded from the App Store and your recent App Store content purchases, to generate Impersonation Risk Detection signals. Apple will then send the Impersonation Risk Detection signals to the requesting app, and the requesting app will send Apple information about how the signals were used to help protect you, or if the signals were not used at all. Apple will also learn information about the in-app activity you were attempting when the app requested Impersonation Risk Detection signals, such as signing in to your account or attempting a payment transaction, but Apple will not learn which app requested the signals or the content of your in-app activity.
Apple will use the information about the in-app activity you were attempting, the Impersonation Risk Detection signals generated using your device and account information, and the feedback about how the requesting app used Impersonation Risk Detection signals, solely to provide and improve the feature.
Applicable Legal Basis for Processing Personal Data
We process your Apple Account–related personal data generally for performance of your contract with Apple, as necessary to provide the service and comply with our legal obligations. Where consent is the appropriate legal basis, we seek it in accordance with applicable local law.
Where applicable local law provides, we process the following categories of personal data as necessary for purposes of our legitimate interests or those of a third party, including information about:
- Your account, such as your recent App Store downloads
- Your device, such as the type of device, the software version and the device serial number
- Your in-app activity, such as whether you were attempting to sign in to an account in the app
These legitimate interests include:
- Helping to improve and optimise the service for you and others
- Providing you with services you request
- Preventing fraud and other malicious activity
Apple retains personal data only for as long as necessary to fulfil the purposes for which it was collected, including as described in this notice and in accordance with Apple’s Privacy Policy, or as required by law. When assessing retention periods, we first carefully examine whether it is necessary to retain the personal data collected and, if retention is required, work to retain the personal data for the shortest period permissible by law.
At all times, information collected by Apple will be treated in accordance with Apple’s Privacy Policy, which can be found at www.apple.com/uk/privacy.
2026-09-14