Music · Privacy report
iHeart icon
iHeart: Play & Listen to Music
Free · ★4.8 · iHeartMedia Management Services, Inc.

Is iHeart safe?

It leans heavily on third-party trackers.

Our take. iHeart is built with more third-party tracking code than 94% of the music we have scanned.

Privacy footprint · vs 86 musicHeavy
Trackers from other companies16 · a lot
typical music: 6
Data the app links to you8 types · some
typical music: 3 · from its own privacy label
What it collects about you

iHeart links 8 categories of your data to you.

From the developer's own App Store privacy label. These are the kinds of data iHeart ties to your identity, and it also declares it shares data to track you across other apps.

PurchasesLocationContact InfoUser ContentSearch HistoryIdentifiersUsage DataDiagnostics
Who else is inside

It carries trackers from 4 companies.

Third-party SDKs found in the app, matched to the company that publishes each. Present in the code; we do not observe what they transmit.

🇺🇸GoogleAnalytics
Firebase, AdMob and Google analytics SDKs, built to record how you use the app and serve ads.
8
SDKs
🏢Other third partiesadvertising
A third-party SDK.
4
SDKs
🇺🇸MetaAdvertising
Facebook advertising SDKs, built to link app activity to Facebook and Instagram ad profiles.
3
SDKs
🇺🇸AppLovinAdvertising
A mobile advertising and monetization network.
1
SDK
How it compares

Where it sits among music.

Every one of these apps we have scanned, on the two measures above: third-party trackers it carries (across) and data it links to you on its own label (up). Toward the top right is more invasive.

Each dot is one music app. iHeart sits to the right, carrying more third-party tracking than most.

Other signals

One more flag.

Each is a fact read straight from the app. The same checks run on every app we scan. Only the ones that apply here are shown.

!

It declares cross-app tracking

Its own App Store label says it tracks you across other companies apps and websites using your advertising identifier.

The evidence

What it's built from.

All 60 SDKs in the app, grouped by what they are for. 16 are third-party trackers.

9
7
1
43
9advertising
7analytics
1crash reporting
43standard libraries

16 of the 60 are third-party trackers. The rest are the app's own code and standard open-source building blocks.

Show the full SDK list
GoogleAnalytics · USA
Google AdMob · Firebase A/B Testing · Firebase Core · Firebase Performance · Firebase Remote Config · Firebase Remote Config Interop · Firebase Sessions · Google Data Transport
Other third partiesadvertising
Google Interactive Media Ads (IMA) · Open Measurement (Prebid) · Snap Kit · Google UMP (Consent)
MetaAdvertising · USA
Facebook AEM · Facebook SDK · Facebook Login
AppLovinAdvertising · USA
AppLovin
Standard libraries43 · on-device
The app's own code plus open-source interface, storage and networking libraries.

How we know this

Counterspy downloads the app from the App Store and statically analyzes its compiled binary. Embedded SDKs are matched against a signature database and resolved to the company that operates each. We also read the developer's App Store privacy label, which lists the data the app says it collects and links to you. We do not run the app or intercept its traffic, so we report capabilities present in the code and the developer's own disclosures, not proven transmission. We assess privacy and data collection, not malware, security flaws, or developer intent. Reports are automated and never edited for payment. Scan v10.62.0, 2026-04-05.

  1. Third-party trackers are advertising, analytics and attribution SDKs detected by static signature matching. Presence shows a capability is compiled in, not that it ran or transmitted data.
  2. "Data the app links to you" is the count of data categories the developer declares as Data Linked To You in its App Store privacy label. Labels are self-reported and not verified by Apple.
  3. Comparison across the 86 music in our corpus. Trackers: median 6. Data linked to you: median 3.