Skip to content

Conversation

@andyleiserson
Copy link
Collaborator

No description provided.

[[#opt-out|disables]] the Private Attribution API.
It is recommended that any mechanism a user agent provides
to clear stored browsing data (history, cookies, etc.)
be extended to cover the impression store.
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

A possible open issue:

While clearing impressions when the browser clears all state is reasonable, what would we do for clearing the state for individual sites? Right now, if we attribute the stored impressions to the conversion site, we'll be in a pretty good state. I think. If that site clears state, then it loses impressions. Does that come with risks?

Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We should also make it obvious that clearing state from the browser DOES NOT clear privacy budget state. It might consolidate it though (for instance, it might say that all budgets for weeks prior to the clearing is consumed entirely).

@martinthomson martinthomson merged commit a1b3d45 into api Sep 21, 2024
@martinthomson martinthomson deleted the security-privacy branch September 21, 2024 15:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants