4.8 KiB
Privacy Triage: Apple - CPM Extension Health Pixels
Status: DRAFT
Name: Alex M
Email: amartemyanov@duckduckgo.com
Objective: O-E
PR: [Add PR link]
Project: https://app.asana.com/1/137249556945/project/1163321984198618/task/1216761517055116?focus=true
Pixels
| Pixel | Trigger | Frequency |
|---|---|---|
debug_web_extension_cpm_initialization_failed_after_session_restoration |
CPM fails after a restored-page navigation. | Daily |
debug_web_extension_cpm_initialization_failed_after_tab_crash |
CPM fails on the first eligible navigation after a tab crash. | Daily |
debug_web_extension_cpm_initialization_failed_after_extension_reload |
CPM fails on the first eligible navigation after an extension reload. | Daily |
debug_web_extension_cpm_initialization_failed_after_other |
CPM fails after another eligible navigation. | Daily |
debug_web_extension_cpm_messaging_stuck_session_restoration |
Messaging remains stuck after a restoration-originated failure. | Daily + count, once/episode |
debug_web_extension_cpm_messaging_stuck_tab_crash |
Messaging remains stuck across attempts associated with a tab crash. | Daily + count, once/episode |
debug_web_extension_cpm_messaging_stuck_other |
Messaging remains stuck across other independent navigations. | Daily + count, once/episode |
debug_web_extension_cpm_messaging_recovered_without_extension_reload |
A failed tab or stuck episode recovers without an extension reload. | Daily + count, once/episode |
debug_web_extension_cpm_messaging_recovered_after_extension_reload |
A failed tab or stuck episode recovers after an extension reload. | Daily + count, once/episode |
debug_web_extension_cpm_messaging_extension_reload_failed |
CPM still fails after a successful extension reload. | Daily + count, once/episode |
iOS and macOS send the exact same pixel names. Parameters distinguish platform=ios|macos and form_factor=phone|tablet|desktop.
appVersion is included; macOS also includes pixelSource and channel.
Detection Rules
- Check only finished, current, main-frame HTTP(S) document navigations after a grace period. A failure means the extension is loaded and the dashboard remains
.waiting;cpmStageis diagnostic data, not part of detection. - A redirected restored-page navigation remains classified as session restoration.
- After restoration, any independent eligible document navigation can be the next attempt: reload, typed URL, link, new-tab navigation, or a real back/forward load.
- Redirects do not count separately. Same-document, failed, non-HTTP(S), and BFCache navigations do not count when CPM is not expected to initialize again.
- A tab crash marks only the next eligible navigation in that tab.
- A successful extension reload marks only the next eligible CPM attempt.
stuckkeeps the reason of the first initialization failure; a later failure does not replace it.- Any successful CPM initialization breaks the failure sequence. Recovery is reported when that success belongs to a previously failed tab or follows a stuck state.
Privacy Questions
Do the pixels use transparent names?
Yes.
Do they share parameters with other pixels?
Yes. They use platform and form_factor to combine both apps under the same pixel names.
Could the parameters link pixels to the same user?
No. Both parameters are coarse enums and contain no identifier.
Do the pixels include a URL or search query?
No. They also exclude hostnames, page titles, tab IDs, document IDs, navigation types, errors, and CPM rules.
Are the pixels temporary?
The session-restoration and post-crash/reload pixels are diagnostics. The stuck-state and recovery pixels are permanent health monitoring.
Why are the permanent pixels needed?
To measure how often CPM messaging becomes stuck and whether extension reload recovers it.
Do any parameters or suffixes fall outside the standard criteria?
platform and form_factor are explicit enum parameters used instead of platform-specific pixel names.
Do the pixels fire on sensitive user events?
No. They report only CPM extension health states.
Can occurrences be tied to the same user or a small group?
No. There is no correlation identifier or browsing data.
Does this meet the self-service criteria?
Yes.