Cherry Seed

Does iOS 26 strip gclid from all Safari browsing sessions?

ios-26 gclid safari link-tracking-protection click-id server-side

Quick Answer

iOS 26 extends Safari Link Tracking Protection to strip gclid and fbclid from all standard browsing sessions, not just Private Browsing. Previously, Apple only removed click identifiers in Private Browsing and links opened from Mail or Messages. The expansion means every Safari user on iOS 26 loses Google and Meta click attribution by default. An estimated 20% of Safari sessions already experienced gclid stripping under earlier defaults (WITHIN, 2026). UTM parameters remain unaffected — Apple classifies them as campaign-level, not user-identifiable. Server-side click ID capture at the landing page is the primary mitigation.

Full Answer

Apple's Link Tracking Protection has been incrementally tightening since iOS 17, but iOS 26 marks the biggest shift yet. The feature now strips known click identifiers — gclid, fbclid, msclkid, and others — from URLs across all standard Safari sessions. This is not a beta flag or an opt-in setting. It ships as the default behaviour for every iPhone and iPad that updates.

The mechanism works at the URL level before JavaScript executes. When a user taps a Google Ads link, Safari rewrites the URL to remove the gclid parameter before the destination page loads. The result: your landing page never receives the click identifier, so GA4 cannot attribute that session to the correct Google Ads campaign. The same applies to Meta's fbclid and Microsoft's msclkid. Attribution gaps widen with every iOS update cycle as adoption compounds.

What remains intact are UTM parameters. Apple draws a deliberate line between campaign-level identifiers (utm_source, utm_medium, utm_campaign) and user-level click identifiers. UTMs describe the campaign, not the individual — so they survive. This distinction matters for measurement strategy: campaign attribution still works, but individual click-level conversion attribution through client-side parameters does not.

The practical fix is [server-side click ID capture](https://seresa.io/blog/data-loss/ios-26-is-quietly-deleting-your-gclid-and-fbclid-before-the-page-loads). When the tracking endpoint reads the click ID from the HTTP request at the server level — before Safari's client-side stripping takes effect — the identifier is preserved and can be forwarded to Google Ads or Meta CAPI for proper conversion matching.

Sources

Programmatic Access

GET https://seresa.io/wp-json/cherry-tree-by-seresa/v1/seeds/1082

Cite This Answer

Cherry Tree by Seresa - https://seresa.io/seed/data-loss-recovery/does-ios-26-strip-gclid-from-all-safari-sessions