TwinEthosRequest access

Control

Mental-health chatbot conversation content used to target or tailor ads

A mental health chatbot user's input is not used to decide whether to show an ad, what to advertise, or how an ad is presented (ads for the chatbot itself excepted).

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.chatbot-user-input-used-for-ad-targeting

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in Utah (US-UT).

The guard to add

Feed ad selection, targeting keys, and ad personalization only from non-conversation data, never from chat text or the topics a model extracts from it.

Keep the ad path separate from the conversation: the code that decides whether to show an ad, which ad, or how it is presented reads only non-conversation inputs (page section, placement, subscription tier) and has no access to messages, chat history, conversation embeddings, or topics and interests a model extracts from them. Ad-server calls (googletag setTargeting, Prebid ortb2 user keywords, an internal select_ad) are populated only from that allowlisted context. House ads for the chatbot itself and static rotation with no user features stay available.

Where it goes: 1 application source code, 6 API calls and integrations, 9 AI output handling.

What reviewers look for: no data flow from request messages, chat_history, extract_topics(messages), or a conversation embedding into googletag.pubads().setTargeting, slot.setTargeting, pbjs.setConfig({ ortb2 }), ortb2.user.keywords, select_ad, or ad_server.request; ad targeting built from a fixed allowlist of non-conversation fields.

Example (Browser + Google Publisher Tag), before:

const topics = await extractTopics(messages);          // LLM-derived interests
googletag.cmd.push(() => {
  googletag.pubads().setTargeting('interests', topics);
});

After:

googletag.cmd.push(() => {
  googletag.pubads().setTargeting('section', 'chat');   // page context only, nothing from the conversation
});

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)