Privacy and context
Current-turn context only. No identity fields. Unknown age or consent is no-fill.
What you may send
- Optional current user message (max 4000 characters). Transient. Not persisted.
- Optional locale and country.
- Optional ephemeral session.token (not a user id).
- Optional typed session.digest with no free text.
- Optional audience.age_band only when the product already knows it. Never infer age.
- Optional audience.contextual_offer_consent when the product has that consent.
Forbidden
Rejected keys: email, phone, tel, user_id, userid, userId, name, full_name, fullname, lat, lng, latitude, longitude, address, ip, conversation, conversation_history, messages, raw_message, app_id, placement, display_style, surface_id, capabilities. Also reject email, phone, advertising IDs, precise location, health, financial, biometric, and cross-app identity data.
Unknown becomes no-fill
Serving requires age_band 18_plus and contextual_offer_consent true. Missing, unknown, under-18, or blocked safety is a successful no-fill.