Journal · 9 November 2025

Why last-click attribution frays after opt-out

Last-click models were built on a person-shaped key that survived every screen. When that key is missing on purpose, the model does not “degrade gracefully.” It hallucinates.

Candlestick chart on a computer display

A last-click report needs a join: click identifier to install to in-app conversion. Consent-aware app analytics interrupts that join wherever the person has not allowed it. ATT, CMP rejects, and PDPA purpose limits all punch holes in the same place — the durable identity that made last-click look scientific.

Teams then reach for probabilistic graphs, IP+UA stitching, or “modelled conversions” that quietly reattach declined users. Those techniques may be attractive to a media buyer. They are not compatible with the practice we teach. If the user said no, the conversion does not belong on their row.

What still works

Channel-level experiments with geo or time splits. Store-reported conversion schemas with their known ceilings (including SKAdNetwork-style privacy thresholds). Opted-in cohorts analysed only inside that cohort. Incrementality tests that do not require a person key for every install.

None of these restore the old last-click dashboard. Finance will see a messier LTV chart. In the marketplace case study on our reviews page, that messier chart was accepted because the previous one could not be defended.

Operational advice

Split reporting into “instrumented, consented” and “store-reported, aggregated.” Do not blend them into a single ROAS cell without labelling the blend. When a vendor promises to “recover” opt-out traffic, ask which identifier they reconstruct and under which basis. If the answer is a fingerprint, the conversation is over for a Sensor Linkhub fellow.

Opt-In Cohort Literacy is the short programme for PMs who inherited a last-click shrine. Engineers who must rebuild the join key itself belong in Consent Architecture weeks six and nine.

See also: ATT strings without leaking identity.