End-to-end flow
1
Consent
Users must opt in to personalized or non-personalized advertising before any ad matching occurs. Consent is stored as current state plus immutable timestamped history.
2
Classification
Raw events are minimized on the client before reaching the server. The server collector repeats validation to ensure no raw text or identifying keys survive.
3
Sensitive filter
Categories related to health, religion, politics, legal issues, race, ethnicity, sexual orientation, precise location, sensitive traits, and payment data are denied advertising eligibility.
4
Decaying interest
Interest scores decay over time. The
audience_engine_maintenance job applies a 30-day half-life to keep scores current.5
Minimum-size segment
Segments must meet a minimum size threshold before they can be used for targeting. This prevents individual identification.
6
Auction
select_ad runs inside the database, filtering by approval, schedule, budget, targeting, and frequency caps. Eligible creatives rank by bid_micros × quality_score.7
Impression
CPM is charged at impression creation. Rendering uses
SponsoredCard, which always displays “Sponsored”.8
Safe redirect
Clicks validate an opaque 256-bit token, record at most one click per impression, and redirect only to a validated public HTTPS creative URL.
9
Conversion
Conversions are recorded idempotently via the Advertising API. CPA is charged on eligible, non-duplicate conversions.
10
Aggregate reporting
Advertisers receive aggregate reports only. They never see individual user interests, events, or identities.
What advertisers can and cannot see
Organizations and members
Advertiser accounts are organized into organizations. Members belong to an organization and can read its resources, but they cannot query user-level data. Organization-level balances inadvertiser_balances fund campaigns, and advertiser_transactions records every deposit, charge, and refund.