Data firewall
Definition
A filtering boundary that turns prompt-adjacent input into a minimal delivery signal before anything reaches the ad market.
What leaves the app
In the recommended CS-S (S1/P0) setup, the firewall outputs only:
- Topic category: a coarse label such as travel, coding, finance, health.
- Language: used for localization and policy enforcement.
What stays inside
The firewall is designed so the ad market does not receive:
- Raw prompt text
- Conversation history
- User identifiers or account data
- Personal data
- Model output
Consent and failure mode
Topic-based matching requires explicit consent under Compute Sponsoring. Without consent, delivery falls back to context-free matching (CS-N).
If the config is missing/invalid or the firewall cannot validate the request, the sponsoring path blocks by default. See Safety.
Related
Last updated: 2026-04-03