S.EE Blog

iOS Privacy Changes and Link Tracking: What Marketers Need to Know

Apple's privacy features have quietly changed what your click data actually means. Here's what's affected, what still works, and how to adjust your reporting.

6 min read
iOS Privacy Changes and Link Tracking
iOS Privacy Changes and Link Tracking

If your open rates jumped a few years back and never came back down, that probably wasn't your subject lines getting better. It was Apple.

A series of iOS and macOS privacy features have reshaped what marketers can actually measure, and a lot of dashboards still don't make that obvious, quietly blending reliable data with unreliable data into the same chart. If you're tracking clicks and opens without accounting for this, you might be making decisions based on numbers that don't mean what they used to, and it's worth understanding exactly which metrics are still trustworthy before you act on them.

Why this happened in the first place

Apple has spent the last several years positioning privacy as a core product differentiator, and its email and browsing tools have followed that direction closely. From Apple's perspective, a tracking pixel that silently reports back to a marketer every time someone opens an email is exactly the kind of invisible data collection its privacy features are designed to interrupt.

The changes weren't aimed specifically at link shorteners or marketers, they're part of a broader platform-level shift, but link tracking data is one of the areas that ended up affected as a side effect.

What actually changed

Apple has introduced several privacy features over recent iOS releases that affect tracking in different ways. Understanding each one separately helps explain why some metrics are more reliable than others, since lumping them all together as "Apple broke tracking" misses which specific mechanisms are actually responsible.

Mail Privacy Protection. This feature, available to anyone using Apple Mail, pre-loads remote content in emails, including the invisible tracking pixels used to measure opens, whether or not the recipient actually opens the message. It works by routing the email through Apple's own proxy servers, which fetch all remote content automatically regardless of whether a human ever looks at the message.

The practical effect is that open rates for any audience with a meaningful share of Apple Mail users become unreliable as a standalone metric, since a large share of "opens" are really just Apple's proxy pre-fetching content.

App Tracking Transparency (ATT). This requires apps to explicitly ask permission before tracking a user's activity across other apps and websites. It mainly affects in-app tracking and cross-app attribution rather than link clicks directly, but it's part of the same broader shift toward requiring consent for tracking, and it's affected how in-app browsers handle any tracking parameters embedded in shared links.

Private Relay and similar IP-masking features. For users with iCloud+ subscriptions, Private Relay routes web traffic through multiple relays operated by Apple and third parties, masking the user's real IP address from the sites they visit. This affects location and device-based analytics that rely on IP data, since the IP address seen by your tracking tools may reflect a relay server's general region rather than the visitor's actual location or ISP.

Link Tracking Protection in Messages, Mail, and Safari Private Browsing. More recent iOS versions strip known tracking parameters from links shared in Messages and Mail, and from links opened in Safari Private Browsing, before they're even opened or loaded, which specifically targets UTM-style parameters and known tracking redirect patterns. This happens client-side, on the device, before the link is ever tapped or loaded, which means the stripping occurs regardless of what tracking service is on the other end.

What this means for click tracking specifically

The good news, relatively speaking, is that click tracking on shortened links is more resilient than open tracking. A click is a real, deliberate action, someone actually tapped the link, so it doesn't suffer from the same "loaded automatically whether or not anyone looked at it" problem that affects email open pixels.

Where it does get affected is in the data layer around the click: device type, approximate location, and any UTM parameters that get stripped before the click even registers, particularly for links shared specifically through Messages or Mail.

What still works reliably

  • Raw click counts on a shortened link remain accurate, since a click requires an actual tap or visit, not passive pixel loading.
  • Conversion tracking that happens after the click, once someone lands on your site and takes an action you can measure server-side, is largely unaffected by these particular iOS changes, since it doesn't depend on a pixel or a parameter surviving the trip.
  • Click timing data stays reliable, since it's tied to the actual click event rather than inferred behavior from a pre-fetch.
  • Referrer data from non-Apple channels, like clicks coming from a social media app's in-app browser rather than Mail or Messages, is generally unaffected by these specific features.

What to treat with more caution

  • Email open rates for any list with a significant Apple Mail user base should be read as a rough signal, not a precise number, and comparing open rates before and after these features rolled out isn't a meaningful comparison at all.
  • Device and location data derived from IP address can be skewed for users on Private Relay or similar VPN-style privacy tools, sometimes showing a relay's regional location rather than the visitor's real one.
  • UTM parameters shared via Messages or Mail may get stripped before the recipient even clicks, which can create gaps in campaign attribution specifically for links shared through those channels, even though the same link would carry its parameters intact if shared through a different app.
  • Click-to-open rate calculations, since these are a ratio built on top of an already-unreliable open number, inherit the same inaccuracy.

How to adjust your approach

Lean more heavily on click-through metrics and post-click conversion data rather than opens, since clicks require deliberate action and hold up better under these privacy changes.

If you're comparing campaign performance over time, be consistent about which channels you're measuring. The impact of these changes varies depending on how much of your audience is on Apple devices specifically, which means a campaign sent to a more Apple-heavy list will show a bigger open-rate distortion than one sent to a more mixed audience.

It's also worth testing whether your link shortener's own analytics dashboard shows click data separately from opens, so you're not accidentally blending a reliable metric with an unreliable one in the same report.

For teams that still need some signal on engagement beyond raw clicks, consider tracking secondary actions that happen after the click, time on page, scroll depth, or a specific on-site event, since those depend on your own analytics setup rather than an email client's pixel-loading behavior.

A practical checklist for auditing your own reporting

  1. Identify which of your current KPIs rely on email open rate, directly or as an input to another calculated metric like click-to-open rate.
  2. Check what percentage of your audience uses Apple Mail, since the distortion scales with that share.
  3. Separate click-based metrics from open-based metrics in your reporting so stakeholders aren't comparing numbers with very different reliability.
  4. Confirm whether links shared through Messages or Mail specifically are losing UTM parameters, and adjust attribution expectations for those channels accordingly.
  5. Shift primary success metrics toward clicks and downstream conversions wherever the campaign goal allows it.

Wrapping up

None of this means tracking is broken, it means one specific category of tracking, passive pixel-based measurement, got a lot less reliable, while deliberate actions like clicks remain a solid signal. The marketers who adjust their reporting to lean on what's still accurate tend to make better decisions than the ones still treating open rate like it means what it used to, and understanding exactly which mechanism affects which metric makes that adjustment much easier to explain to a team or a client.

Thanks for reading! If you want cleaner click data you can actually trust, S.EE covers URL shortening, QR codes, link-in-bio pages, real-time analytics, and branded domains, all in one simple dashboard.

Not directly. It specifically affects open tracking by pre-loading tracking pixels automatically. Clicks still require someone to actually tap a link, so click data isn't distorted the same way.

Should I stop tracking email opens entirely?

Not necessarily, but treat open rate as a rough directional signal rather than a precise number, especially for lists with a large share of Apple Mail users, and avoid using it as the primary success metric for a campaign.

Does Private Relay affect where my click data says visitors are from?

Yes, for users with iCloud+ subscriptions using Private Relay, IP-based location data may reflect a relay server's location rather than the visitor's actual one.

Are UTM parameters completely broken by these changes?

No, but some iOS versions strip certain tracking parameters from links shared through Messages or Mail, or opened in Safari Private Browsing, before the recipient clicks or the page loads. UTM parameters in links shared or opened elsewhere aren't affected the same way.

What's the most reliable metric to focus on now?

Click-through data and what happens after the click, like conversions measured on your own site, tend to hold up better than open rates or IP-derived location and device data.

How do I know how much my own open rate data is affected?

Check what percentage of your subscriber list uses an @icloud.com, @me.com, or @mac.com address as a rough proxy, since those are strong indicators of Apple Mail usage, though plenty of Apple Mail users have addresses on other domains too.

Do these privacy changes affect Android users the same way?

No. These specific features (Mail Privacy Protection, Private Relay, Link Tracking Protection in Messages, Mail, and Safari Private Browsing) are Apple platform features. Android and non-Apple email clients aren't affected by them, though they may have their own separate privacy protections.