> ## Documentation Index
> Fetch the complete documentation index at: https://documentation.orbitdev.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Orbit Audience Engine: Privacy-First Advertising Overview

> Learn how Orbit Audience Engine delivers ads while protecting user privacy. Understand the end-to-end flow, what advertisers can access, and how organizations work.

Orbit Audience Engine is a privacy boundary around advertising, not a user-data export product. This page explains the complete ad delivery flow and what advertisers can and cannot see when running campaigns on Orbit.

## End-to-end flow

<Steps>
  <Step title="Consent">
    Users must opt in to personalized or non-personalized advertising before any ad matching occurs. Consent is stored as current state plus immutable timestamped history.
  </Step>

  <Step title="Classification">
    Raw events are minimized on the client before reaching the server. The server collector repeats validation to ensure no raw text or identifying keys survive.
  </Step>

  <Step title="Sensitive filter">
    Categories related to health, religion, politics, legal issues, race, ethnicity, sexual orientation, precise location, sensitive traits, and payment data are denied advertising eligibility.
  </Step>

  <Step title="Decaying interest">
    Interest scores decay over time. The `audience_engine_maintenance` job applies a 30-day half-life to keep scores current.
  </Step>

  <Step title="Minimum-size segment">
    Segments must meet a minimum size threshold before they can be used for targeting. This prevents individual identification.
  </Step>

  <Step title="Auction">
    `select_ad` runs inside the database, filtering by approval, schedule, budget, targeting, and frequency caps. Eligible creatives rank by `bid_micros × quality_score`.
  </Step>

  <Step title="Impression">
    CPM is charged at impression creation. Rendering uses `SponsoredCard`, which always displays "Sponsored".
  </Step>

  <Step title="Safe redirect">
    Clicks validate an opaque 256-bit token, record at most one click per impression, and redirect only to a validated public HTTPS creative URL.
  </Step>

  <Step title="Conversion">
    Conversions are recorded idempotently via the Advertising API. CPA is charged on eligible, non-duplicate conversions.
  </Step>

  <Step title="Aggregate reporting">
    Advertisers receive aggregate reports only. They never see individual user interests, events, or identities.
  </Step>
</Steps>

## What advertisers can and cannot see

| Can see | Cannot see |
| - | - |
| Their own organization resources | User interests or interest scores |
| Aggregate campaign performance | Individual event rows |
| Their creatives and campaigns | Raw user prompts, messages, or credentials |
| Billing and transaction history | Orbit user IDs (delivery uses a one-way advertising-key hash) |

## Organizations and members

Advertiser accounts are organized into organizations. Members belong to an organization and can read its resources, but they cannot query user-level data. Organization-level balances in `advertiser_balances` fund campaigns, and `advertiser_transactions` records every deposit, charge, and refund.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.