Privacy
What we collect when we serve an advertisement, who receives it, how long we keep it, and what you can ask us to do about it.
Last updated August 27, 2026
PLUSONE ("we", "us") operates plusoneads.com, the ad serving domain for n+1 audience extension. When an advertisement carries this domain, we served it, ran the auction that selected it, and measured it on behalf of a publisher or an advertiser. This policy explains what that involves from a data perspective.
Two groups of people are covered here. Readers encounter advertising served through this domain on publisher websites and apps. Customers are the publishers, demand partners, and advertisers who hold accounts with us. Most of this policy concerns readers.
1. Consent comes before identity
Before an advertisement uses any persistent identifier, our tag reads the consent signals available on the page. We support the IAB Transparency and Consent Framework (TCF v2) and the IAB Global Privacy Platform (GPP). We independently honor Global Privacy Control and Do Not Track, both from the browser and from the request headers, and we honor the Limit Ad Tracking signal on mobile.
Every request resolves to three separate permissions, which are whether we may set a cookie, whether we may use an advertising identifier, and whether we may use precise location. If we cannot positively establish permission, all three default to denied. Our servers independently re-check the raw privacy signals and may only tighten the browser's decision, never loosen it. A request originating in the EEA or the UK is restricted unless a complete and readable TCF signal is present.
Consent governs identity, not whether an advertisement appears. A reader who has declined, or whose consent we cannot read, may still see an advertisement. When permission is absent we do not merely withhold cookies. Any tracking cookies already present are actively expired on the response, the reader's IP address is truncated before it reaches any demand partner, and city, latitude, and longitude are omitted.
2. Cookies and identifiers
Our cookies are set on our own domain rather than the publisher's, so from the publisher page they are third-party cookies. All are marked Secure and HttpOnly. We set none of them when permission is absent.
- Sync identifier, 365 days. A pseudonymous identifier used to coordinate with advertising demand partners.
- Frequency cap, 30 days. Records which campaigns a browser has already seen, so the same advertisement is not repeated excessively.
- Opt-out preference, 365 days. Contains no identifier. Its only content is the fact that you opted out.
We do not use browser local storage or session storage, and we do not fingerprint devices. We do not run canvas, audio, or font enumeration, and we use no third-party analytics software in our advertising units.
3. What an advertising request contains
When a publisher page asks us for an advertisement, the request carries the page address or app identifier, the placement, device type, operating system and browser information, approximate location, the applicable consent signals, and, only where permission exists, the sync identifier. Approximate location means country and region. City and precise coordinates are used only where permission for precise location was established.
Advertising requests are sent to demand partners so they can bid. Those requests contain the same fields, and they contain the sync identifier only where permission exists. Where permission is absent, the IP address in those requests is truncated and precise location is removed. Demand partners are contractually bound to use the request only to decide whether and how much to bid.
4. What we keep
- Request, bid, and delivery records are kept for reporting, billing reconciliation, and fraud prevention. They hold the fields described in section 3 together with the auction outcome. We do not store the raw IP address or the raw browser user-agent string in these records; both are used transiently while handling the request.
- Aggregate analytics, which contain counts and amounts but no identifiers, are retained on an ongoing basis for reporting and trend analysis.
- Cookies expire on the schedule in section 2.
5. Who else processes this data
We use Google Cloud for storage, analytics, and application hosting, OVHcloud for the servers that run the auction, and Cloudflare in front of our services. Demand partners receive advertising requests as described in section 3. Where an advertiser uses our AI creative generator, the brief they supply is sent to OpenAI to produce the creative. No reader data is involved in that step.
6. What customers receive
Publishers see reporting on the advertising served on their own properties. Advertisers and demand partners see reporting on their own campaigns, deals, and endpoints. Demand partners can inspect samples of the requests sent to their own endpoints and the responses they returned. Customer data is isolated per account, and no customer can retrieve another customer's records.
We do not sell reader data. No name, email address, telephone number, or account credential is collected from readers in the first place.
7. Your choices
You can decline through the consent prompt on the publisher's website, and we will honor it. You can enable Global Privacy Control in your browser, and we honor that signal independently of any publisher prompt. You can also clear or block our cookies in your browser settings, which stops user sync and frequency capping.
To opt out of identity and tracking across our platform, or to ask about the data associated with your browser, write to privacy@nplusone.ai. We handle these requests manually today rather than through a self-service portal. Because we hold no account, name, or email address for readers, we can generally only act on a request when you can supply the identifier from your browser, and a reader who has cleared cookies cannot be located in our records at all.
8. Children
Our platform is intended for advertising on general-audience publications and applications and is not directed to children. We do not knowingly collect information from children, and we honor the child-directed flag when it is supplied to us in an advertising request.
9. International transfers
We are based in the United States and our service providers process data in the United States and the European Union. If you are reading this from elsewhere, your information may be transferred there.
10. Changes and contact
If we change this policy we will update the date at the top of this page. For any privacy question, or to exercise a right described above, write to privacy@nplusone.ai. For anything else, programmatic@plusoneads.com.