Legal

Privacy

What we collect, why we collect it, how long we keep it, and what you can ask us to do about it.

Last updated July 21, 2026

n+1 is a product of Neuronic ("we", "us"). We operate an advertising and research platform. Advertisements served through our platform can hold a conversation with the reader, and brands can run short AI-moderated research interviews inside those advertisements. This policy explains how that works from a data perspective.

Two different groups of people are covered here. Readers encounter our advertising units on publisher websites. Customers are the advertisers, agencies, and publishers who hold accounts with us. Most of this policy concerns readers, because that is where the sensitive processing happens.

1. Consent comes before personalization

Before an advertisement uses any persistent identifier, our tag reads the consent signals available on the page. We support the IAB Transparency and Consent Framework (TCF v2) and the IAB Global Privacy Platform (GPP). We independently honor Global Privacy Control and Do Not Track, both from the browser and from the request headers, and we honor the Limit Ad Tracking signal on mobile.

Every request resolves to three separate permissions, which are whether we may set a cookie, whether we may use an advertising identifier, and whether we may use precise location. If we cannot positively establish permission, all three default to denied. Our servers independently re-check the raw privacy signals and may only tighten the browser's decision, never loosen it. A request originating in the EEA or the UK is restricted unless a complete and readable TCF signal is present.

We are not currently registered on the IAB Global Vendor List. In practice this means that where GDPR applies, our platform operates in its fully restricted mode. We set no cookies, use no advertising identifier, and use no precise location for those readers.

Consent governs identity and personalization, not whether an advertisement appears. A reader who has declined, or whose consent we cannot read, may still see an advertisement and may still choose to converse with it. That conversation is still recorded as described below, without the identifiers.

When permission is absent we do not merely withhold cookies. Any tracking cookies already present are actively expired on the response, the reader's IP address is truncated before it reaches any demand partner, and city, latitude, and longitude are omitted.

2. Cookies and identifiers

Our cookies are set on our own domain rather than the publisher's, so from the publisher page they are third-party cookies. All are marked Secure and HttpOnly. We set none of them when permission is absent.

We do not use browser local storage or session storage, and we do not fingerprint devices. We do not run canvas, audio, or font enumeration, and we use no third-party analytics software on our advertising units.

3. What we collect when you converse with an advertisement

If you type into one of our advertising units, we store the conversation. That record contains the messages exchanged, the interaction events, the page address the advertisement ran on, the publisher and placement, your approximate location, your device type and operating system, and timing information such as how long the unit was in view.

Approximate location means country and region. We record the city only where permission for precise location was established. We do not store your IP address in the conversation record, and we do not store your raw browser user-agent string. Both are used transiently while handling the request and then discarded from the stored record.

Before a conversation is written to storage, we scan it and replace detected telephone numbers, email addresses, payment card numbers, national identity numbers, and IP addresses with redaction markers. This applies to both what you wrote and what the assistant replied. We log that a redaction occurred and its type, never the value.

We want to be precise about the limits of that redaction. It is pattern-based, so it does not detect names or street addresses, and it may miss identifiers written in unusual formats. It also happens at the point of storage rather than before the message reaches the language model, which means the model provider receives what you actually typed. The assistant operates under a fixed instruction set that forbids it from requesting personal data, payment details, or credentials, but you should treat an advertising conversation as you would any public web form and avoid sending sensitive information. Individual messages are capped at 500 characters.

4. How long we keep it

5. Who else processes this data

We use OpenAI to generate the assistant's replies in real time and to summarize and index conversations afterwards. We use Google Cloud for storage, analytics, and application hosting, and Cloudflare in front of our services. Where a brand has enabled the relevant feature, a conversation may also call Google Places to answer a question about nearby locations, or a retrieval service to look up approved brand knowledge.

Advertising requests are also sent to demand partners so they can bid. Those requests contain the page address, device and browser information, approximate location, and the applicable consent signals, and they contain the sync identifier only where permission exists. Where permission is absent, the IP address in those requests is truncated and precise location is removed.

6. What advertisers and publishers receive

A brand running a study receives the conversations that study collected. That includes the text of what readers wrote, alongside the page, publisher, approximate location, and device context. Customer data is isolated per account, and one customer cannot retrieve another customer's evidence.

We do not sell reader data. Conversations are made available to the brand that funded the advertisement they occurred in, as the output of the research they purchased, and that output belongs to them. Our customer-facing tools do not display our sync identifier alongside conversations, and no name, email address, telephone number, or account credential is collected in the first place.

7. Your choices

You can decline through the consent prompt on the publisher's website, and we will honor it. You can enable Global Privacy Control in your browser, and we honor that signal independently of any publisher prompt. You can also clear or block our cookies in your browser settings, which stops recall and frequency capping.

To opt out of identity and tracking across our platform, or to ask about the data associated with a conversation you had, write to privacy@nplusone.ai. We handle these requests manually today rather than through a self-service portal, and we will tell you what we can and cannot locate. Because we hold no account, name, or email address for readers, we can generally only act on a request when you can supply the identifier from your browser, and a reader who has cleared cookies cannot be located in our records at all. Conversation records expire on their own within 365 days regardless.

8. Children

Our platform is intended for advertising on general-audience publications and is not directed to children. We do not knowingly collect information from children. We do not operate an age gate on the advertising unit, so we rely on publishers not to place our units on services directed to children, and we honor the child-directed flag when it is supplied to us in an advertising request.

9. International transfers

We are based in the United States and our service providers process data in the United States. If you are reading this from outside the United States, your information may be transferred there.

10. Changes and contact

If we change this policy we will update the date at the top of this page. For any privacy question, or to exercise a right described above, write to privacy@nplusone.ai. For anything else, contact us here.