Skip to main content
Orbit Audience Engine is a privacy boundary around advertising, not a user-data export product. React surfaces call Supabase with the user’s existing authenticated session. High-trust work, including delivery, charging, redirects, and conversions, runs inside PostgreSQL functions or the advertising-api Edge Function.

Data flow

The flow moves from consent through classification to impression, redirect, and optional conversion. Each stage enforces a specific trust boundary.

Trust boundaries

React surfaces never perform high-trust operations. The browser role is limited to reading approved, aggregated results. Any operation that charges an advertiser, selects an ad, or processes a click must run inside the database or the Edge Function.

Policy helpers

src/lib/audience-engine.ts contains shared deterministic policy helpers. These utilities standardize how the system evaluates consent, schedule, targeting, budget, and frequency caps. They are imported by both database functions and the Edge Function so policy behavior stays consistent across surfaces.

Ad selection enforcement

select_ad enforces the full policy set inside the database:
  • Plan eligibility (ad-supported plans only)
  • Consent state (personalized or non-personalized)
  • Campaign schedule, approval, and budget
  • Targeting rules (country, device, placement)
  • Frequency caps (daily and weekly per user)
  • Segment qualification (for personalized campaigns)
A row lock protects the winning campaign during selection to prevent race conditions in spend accounting.

Advertiser access rules

Advertisers can read their own organization resources, such as campaigns, creatives, and balances. They cannot select user interests or event rows. Identifiable tables have no advertiser-facing policies.