Measurement & Honesty · established evidence

Why the Cookie Fell: App Tracking Transparency and What Marketers Built Instead

Last reviewed 2026-07-20. Written by Chandranshu Kumar, Founder, Raveneye Global. · 9 min read

App Tracking Transparency, the iOS 14.5 change Apple shipped in April 2021, is the moment the individual-level tracking most digital advertising was built on quietly stopped working. It asked every iPhone user one plain question, whether an app could follow them across other apps and sites, and industry reports put the share who declined at roughly three in four. Third-party cookies were eroding on the same timeline. Together they broke the pixel-and-cookie machinery that let a platform claim it knew, person by person, which ad produced which sale. What marketers built instead was not a better tracker. It was a different kind of measurement: consented server-side signals a business collects and forwards with permission, and aggregate methods, marketing mix modeling and geo-experiments, that infer what advertising caused from patterns in totals rather than from surveillance of individuals. This piece traces what actually happened, separates the established events from the vendor-reported magnitudes, and reads closely what the replacements can and cannot do for a single business.

The tracking marketers relied on quietly broke

For most of the 2010s, digital advertising was measured by following people. A third-party cookie in the browser and a tracking identifier on the phone let an ad platform stitch a viewer of an ad to a later buyer, and then report, with apparent precision, which campaign earned which sale. That machinery is what a dashboard means when it shows a return on ad spend next to a specific campaign.

Apple ended the default version of that on mobile. App Tracking Transparency, introduced with iOS 14.5 in April 2021, required every app to ask explicit permission before tracking a user across other companies' apps and websites. The prompt was plain, the choice was the user's, and a large share of users declined. On the browser side, third-party cookies were being restricted by Safari and Firefox and were the subject of a long, repeatedly delayed deprecation plan in Chrome. The net effect was the same from a measurement seat: the identifiers that let a platform recognize the same person twice were disappearing.

This was not a tuning problem to be fixed with a better tag. It was the removal of the raw material, the persistent individual identifier, that person-level attribution had always assumed it would have.

What the numbers say, and who counted them

The direction of the change is not in dispute. The magnitude is where the figures get unreliable, because the most-quoted numbers come from companies with a commercial stake in the story they tell.

Industry and ad-tech reporting, summarized across marketing trade press, put the pieces at roughly this: about three quarters of iOS users opted out of cross-app tracking once prompted, the accuracy of one large platform's ad tracking was estimated to fall by around thirty to forty percent, and pixel-based revenue attribution for e-commerce dropped from capturing something like eighty to ninety-five percent of sales down to sixty to seventy percent. Read those as directional, not settled. They are drawn from vendor studies, not independent peer-reviewed research, and the vendors sit on the side of the market that benefits when the loss looks severe.

The responsible way to hold both facts at once: the event and its direction are established and dated, while the specific percentages are the least reliable part of the record and should never be repeated as if they were laboratory constants.

What marketers built, part one: consented server-side signals

The first response was to rebuild the plumbing on a lawful, consented footing. Instead of relying on a browser cookie or a device identifier set by a third party, a business collects the events it owns, a booking, a form, a purchase, on its own server, and forwards them to ad platforms through a server-side interface with the user's consent recorded.

On the major platforms this is the Conversions API and its equivalents, paired with a consent framework that decides what may be sent at all. The point is not that this restores person-by-person surveillance; it does not, and should not. The point is that the events a business is entitled to measure are counted once, at the right value, and delivered reliably, rather than being lost in a browser that now blocks the old tag. It is durable measurement infrastructure, not a workaround to keep tracking people who declined to be tracked.

What marketers built, part two: aggregate methods that never watched a person

The second response was more consequential. If you cannot follow individuals, you can still measure what advertising caused by working at the level of totals and geographies. Two methods carried this, and both were open-sourced by the largest ad platforms during exactly this period, which is itself a signal that the platforms now treat them as the credible fallback.

Marketing mix modeling

Marketing mix modeling is a statistical method that regresses a business's sales or outcome time series on its marketing time series, with transforms for carryover (adstock) and diminishing returns (saturation). It never follows a single user; it reads how totals move together over time. That is precisely why it survived the collapse of cookie- and device-level tracking, and why it is a causal-inference and forecasting method rather than a tracking method.

Both giants published their internal versions. Google open-sourced Meridian, built on geo-level Bayesian hierarchical media-mix modeling, and Meta open-sourced Robyn, built on ridge regression with a Prophet-style decomposition and automated hyperparameter search. That the two largest advertising companies released their own mix-modeling code is the clearest institutional evidence of where measurement went once individual attribution degraded.

Geo-experiments and synthetic controls

The second aggregate method is the geo-experiment. Rather than holding out individual users, an advertiser holds out matched geographic markets: run the campaign in some regions, withhold it in comparable ones, and read the difference as incremental lift. Meta's open-source GeoLift builds a synthetic control from the untreated markets to estimate what the treated markets would have done without the ads.

This sidesteps both the privacy erosion and the last-touch bias in one move, because it measures a counterfactual instead of crediting whatever touch happened to sit last on a converter's path. An independent head-to-head simulation reported GeoLift's coverage at around ninety-two to ninety-five percent, closest to the ninety-five percent target, with the lowest false-positive rate among the open-source geo-testing tools compared. Treat that comparison as industry-grade rather than peer-reviewed, since it comes from a vendor-run simulation.

Why the aggregate methods survived the collapse

The common thread is that neither method depends on recognizing the same person twice. Mix modeling reads totals; geo-experiments read regions. Privacy prompts, cookie restrictions and regulation take away individual identifiers, and both methods keep working because they never needed them.

There is a second, quieter reason they endured. Because a geo-experiment measures a genuine counterfactual, and because a mix model can be calibrated against such an experiment, these methods have a stronger claim to answering the real question, what did the spending cause, than a person-level report that credits the ad for sales that were already coming. The privacy changes did not invent that question; they just made it impossible to keep avoiding it.

The caveats at a single location's scale

A local business owner should hear the loud caveat before adopting any of this. The aggregate methods were validated at the scale of national brands with large budgets and many markets. Whether they perform as well for a single-location med spa or a home-services firm with a modest spend is an open, emerging question, not a settled one. A mix model needs enough history and enough variation to separate signal from noise; a geo-experiment needs enough comparable markets to build a credible control.

This is not a reason to retreat to the flattering platform number. It is a reason to be modest about precision, to prefer the method the available data can actually support, and to say plainly when a read is directional. It is also the argument for pooling: many similar small businesses measured on a common method recover statistical power no single one of them has alone. Any figure presented without that honesty, at any scale, is worth less than it looks.

How to read any claim that your attribution is fixed

The practical test for a buyer is short. Ask whether a reported return is a platform's account of its own work or an independent measurement of what the spend caused. Ask whether the number came from following individuals, which is now degraded and consented at best, or from an aggregate method that never needed to. Ask whether the point estimate carries a sense of its own uncertainty, or is quoted as a clean fact.

The cookie fell, and with it the pretense that individual tracking gave marketers the truth. What replaced it is less precise about persons and more honest about causes. The businesses that measure well now are not the ones clinging to the old pixel; they are the ones asking, of every dollar, what it actually changed, and accepting a directional answer over a confident wrong one.

The evidence

Key findings, with their sources

  • Apple's iOS 14.5 introduced App Tracking Transparency in April 2021, requiring apps to get explicit permission before tracking a user across other companies' apps and sites.

    established Apple, App Tracking Transparency / iOS 14.5 developer documentation, 2021; summarized in industry measurement reporting.

  • Industry-reported magnitudes of the signal loss: roughly 75% of iOS users opted out of cross-app tracking, one large platform's ad-tracking accuracy estimated to drop 30-40%, and e-commerce pixel-based revenue attribution falling from 80-95% capture to 60-70%. Directional, vendor-sourced, not peer-reviewed.

    contested Ad-tech vendor measurement reports (AppsFlyer opt-in-rate study; PubMatic ad-spend shift data), summarized in marketing-industry press, 2021-2022.

  • Across 15 large-scale randomized field experiments at Facebook (500M+ user-experiment observations, 1.6B impressions), standard observational attribution methods frequently estimated ad lift in the wrong direction or magnitude versus the randomized ground truth.

    established Gordon, Zettelmeyer, Bhargava & Chapsky, "A Comparison of Approaches to Advertising Measurement: Evidence from Big Field Experiments at Facebook", Marketing Science 38(2), 2019.

  • Marketing mix modeling regresses aggregate sales time series on marketing time series (with adstock and saturation transforms) rather than following individual users, which is why it survived the collapse of cookie- and device-level tracking.

    established Standard MMM literature, summarized in Wikipedia, "Marketing mix modeling".

  • Google (Meridian, geo-level Bayesian hierarchical media-mix modeling) and Meta (Robyn, ridge regression plus Prophet decomposition and automated hyperparameter search) both open-sourced their internal MMM methodology as individual-level tracking degraded.

    established Google, Meridian (business.google.com); Tueller et al., "Packaging Up Media Mix Modeling: An Introduction to Robyn's Open-Source Approach", arXiv:2403.14674, 2024; facebookexperimental/Robyn (GitHub).

  • Geo-experiments with synthetic controls (Meta's GeoLift) measure incremental lift without any user-level pixel; an independent simulation put GeoLift's coverage at ~92-95% (closest to the 95% target) with the lowest false-positive rate among open-source geo-testing tools compared.

    emerging facebookincubator/GeoLift (GitHub); Recast Research, "Open-Source Geo-Experiment Tools, A Head-to-Head Simulation Study".

Calibration

What is proven, what is promising, what is unproven

Evidence tierTacticsWhat the evidence says
establishedThe policy events and their direction (iOS 14.5 ATT, April 2021; cookie restriction in Safari/Firefox), that MMM is a causal-inference method rather than a tracking method, and that observational attribution diverges from randomized ground truth.Apple developer documentation; Gordon et al. 2019 (Marketing Science); standard MMM literature.
emergingHow well the aggregate replacements (MMM, geo-experiments) perform at single-location, low-budget scale, and GeoLift's specific comparative accuracy figures.Google Meridian and Meta Robyn, open-sourced but validated at national-brand scale; Recast Research vendor simulation.
contestedThe exact magnitude of the signal loss: the 75% opt-out, 30-40% accuracy drop, and 80-95% to 60-70% pixel-capture figures.Ad-tech vendor reports (AppsFlyer, PubMatic) with a commercial stake in the narrative; not independently peer-reviewed. Treat as directional.

Reference

Glossary

App Tracking Transparency (ATT)
The iOS 14.5 framework (April 2021) that requires an app to obtain explicit user permission before tracking that user across other companies' apps and websites.
A cookie set by a domain other than the one being visited, historically used to follow a user across sites for ad targeting and attribution. Restricted by Safari and Firefox and the subject of a long, repeatedly delayed Chrome deprecation plan.
Conversions API / server-side tracking
A method where a business collects the events it owns on its own server and forwards them to ad platforms with recorded consent, instead of relying on a browser tag that may be blocked.
Marketing mix modeling (MMM)
A statistical method that regresses aggregate outcomes on marketing activity over time, with carryover and saturation transforms, to infer contribution without following individual users.
Geo-experiment (geo-lift)
A test that runs a campaign in some geographic markets and withholds it in comparable ones, reading the difference (often against a synthetic control) as incremental lift, with no user-level pixel.
Multi-touch attribution
A person-level method that distributes credit for a conversion across the ad touches on a converter's path. Dependent on the individual identifiers that ATT and cookie restrictions degraded.
Incrementality
The share of outcomes an ad genuinely caused, over and above what would have happened anyway, as opposed to outcomes a platform merely observed near its own ads.

Straight answers

Frequently asked questions

What is App Tracking Transparency (iOS 14.5)?

It is the Apple framework introduced with iOS 14.5 in April 2021 that requires every app to ask for explicit permission before tracking a user across other companies' apps and websites. Industry reporting put the share of users who declined at roughly three in four, which sharply reduced the individual-level identifiers that mobile ad attribution had depended on.

Did third-party cookies actually go away?

Not entirely, and not on the timeline first announced. Safari and Firefox restricted them years ago, while Chrome's deprecation plan was repeatedly delayed and then walked back. In short, individual tracking eroded substantially, driven more by iOS App Tracking Transparency, browser restrictions and privacy regulation than by a single clean cookie switch-off.

What is marketing mix modeling, and why did it come back?

Marketing mix modeling is a statistical method that reads how a business's aggregate sales move with its marketing over time, rather than following individual users. It returned to prominence because it never needed the cookies and device identifiers that were disappearing. Both Google (Meridian) and Meta (Robyn) open-sourced their own versions during this period.

Can a single-location business use MMM or geo-experiments?

With caution. These methods were validated at the scale of national brands with large budgets and many markets. Whether they perform as well for one location on a modest budget is an open, emerging question. A mix model needs enough history and variation, and a geo-experiment needs enough comparable markets to build a credible control. The right posture is to prefer the method the available data can actually support and to label a read as directional when it is.

Is my ad spend still measurable after these changes?

Yes, but the measure changed shape. Instead of a platform's person-by-person claim about its own work, the stronger reads now come from consented server-side signals for the events you own and from aggregate methods, mix modeling and geo-experiments, that estimate what the spend actually caused. The right question to ask of any report is whether it measures cause or merely observes correlation near the ads.

Provenance

Sources

  1. Gordon, B.R., Zettelmeyer, F., Bhargava, N., Chapsky, D., "A Comparison of Approaches to Advertising Measurement: Evidence from Big Field Experiments at Facebook", Marketing Science 38(2), 193-225, 2019 (established)
  2. Apple, App Tracking Transparency / iOS 14.5 developer documentation, 2021 (established, for the dated policy event)
  3. Ad-tech vendor measurement reports (AppsFlyer opt-in-rate study; PubMatic ad-spend shift data), summarized in marketing-industry press, 2021-2022 (contested / directional, vendor-sourced point estimates)
  4. Wikipedia, "Marketing mix modeling", summarizing the standard MMM literature (established)en.wikipedia.org
  5. Google, Meridian, open-source Bayesian marketing mix model (business.google.com); Google Research geo-level Bayesian Hierarchical Media Mix Modeling lineage (established that it exists and is open-sourced)developers.google.com
  6. Tueller, N. et al., "Packaging Up Media Mix Modeling: An Introduction to Robyn's Open-Source Approach", arXiv:2403.14674, 2024; facebookexperimental/Robyn (GitHub) (established)arxiv.org
  7. facebookincubator/GeoLift (GitHub), open-source synthetic-control geo-experimentation library (established, for the method)
  8. Recast Research, "Open-Source Geo-Experiment Tools, A Head-to-Head Simulation Study" (research.getrecast.com) (emerging / industry-grade, for the comparative numbers)

Every figure above is attributed to a real, dated source and tagged with its evidence tier. Where a claim could not be verified to a primary source, it is not stated as fact.

What this means for your ad budget

The history points to one operational question the old tracking was never able to answer well and can now barely attempt: of everything you spent last month, how much actually caused a sale that would not have happened anyway? A platform dashboard reports its own work, crediting the ad for customers who were already coming. What replaces that is a standing measurement layer built on the methods this piece describes, consented server-side signals plus geo-lift and holdout experiments read against a blended efficiency figure, so your budget follows the spend that genuinely earns new customers.

service Incrementality & Measurement Retainer An experiment-led measurement layer over your paid media: geo-lift and holdout tests that measure true incremental return, reported with baselines and confidence rather than platform-graded ROAS, and reviewed by a specialist before delivery. Your ad spend stays yours, paid straight to the platforms and never marked up. See how it works

Start free with a Machine-Readiness Score, a specialist-reviewed read of where you stand across search and AI answers. No guaranteed number, and no obligation.