See your projected iROAS, revenue, and conversions—in under a minute. Calculate my ROI

Last updated:  July 1, 2026

Yes, AI and machine learning are core to how we deliver performance. Our in-house ML models power targeting, audience segmentation, addressability, and optimization across Retargeting, Lookalikes, Optimized CRM, and Performance CTV. We build and own these models ourselves, which means we control how they work and how your data is handled inside them.

Only to make your campaigns perform better. We use brand-provided data, event signals, and licensed data to train and calibrate models, always under contractual, privacy, and security controls. Modeling operates on aggregated, pseudonymized, or derived signals. Direct identifiers only come back into play where they’re needed for activation and measurement on your behalf.

No. Your data, and your customers’ data, stay out of public AI tools entirely. We don’t send it to public LLMs for training, general use, or any other purpose. Internal policy prohibits sending confidential customer or non-public information into any unapproved generative AI tool.

Inside our walls. Production inference runs through PebblePost-hosted or Databricks-served model boundaries, not through external API calls to Anthropic, OpenAI, or any other public service. We use tools like Claude in controlled development contexts only, and never with raw brand PII.

This is something we take seriously by enforcing explicit anti-conquesting guardrails. Brands can’t query each other’s data, and no single brand’s data can materially drive another brand’s modeled audience. The hard cap we apply is 5% and is enforced at the platform level.

No. We don’t use protected characteristics (such as race, religion, or health) as model features, and brands can’t introduce latent sensitive targeting through our models either. If campaign-level parameters like that exist, they’re applied post-model during normal campaign operations and are separated from the modeling logic itself.

We validate models against documented criteria, monitor for drift and degradation, and review aggregate outcomes to catch unintended skew before it affects performance. Sensitive characteristics are excluded from model features by design, and brand campaign settings are kept separate from model logic so neither one bleeds into the other. This isn’t a one-time audit. It’s part of how we maintain model quality across the lifecycle.

No. Raw PII is prohibited in local development, local notebooks, and local test environments. R&D uses synthetic, hashed, or pseudonymized data.

We restrict external data egress and prohibit ad hoc, SQL-based transmission of brand data to external vendors or LLMs. We’re also rolling out validator-based controls, including PII detection, for data crossing our boundary to non-standard external entities.

Rarely, and never without controls. Our default is to run production inference through PebblePost-hosted or Databricks-served model boundaries, not external vendors. When a third-party capability is approved, it has to operate inside that same controlled serving environment and is subject to contractual and technical guardrails that prevent the vendor from training on your brand data.

Yes. We operate a multi-tenant Graph, but brand isolation is built into how it works. Anti-conquesting rules, suppression logic, and output guardrails ensure that one brand’s data doesn’t surface in another brand’s workflows. The only exception is explicitly approved aggregated benchmark views, where no individual brand’s data is identifiable.

We run a unified suppression framework that combines brand-provided suppression and deletion files with direct consumer requests. Suppressed identities are excluded from modeling, targeting, and activation. The suppression carries through the whole workflow. Consumers from California may also opt out of using their data in AI systems here.

Our AI and ML usage is scoped to marketing and measurement, not high-impact eligibility decisions, which is a key GDPR distinction. We use aggregated and pseudonymized signals where possible, support deletion and suppression workflows, and enforce geographic ingestion controls like blocking non-US CRM records and filtering non-US pixel traffic in prohibited contexts.

No, and it’s contractually prohibited. Our AI and ML is limited to marketing and performance workflows. High-impact eligibility decisions are outside the scope of what we do and what our Terms of Service permit.

Nothing ships without a review process. Before any new AI tool, workflow, or API goes live, we evaluate it for unintended downstream effects, document the architecture, review any external calls it makes, validate guardrails, and require stakeholder sign-off on non-deterministic outputs. We also maintain formal AI governance artifacts aligned to ISO-style risk management standards. This is how we make sure new capabilities don’t introduce risk to your campaigns or your data.

Have more questions or concerns?