The Ad That Pays You, and Tells You Who Bought
Personalised advertising and private advertising are not opposites - they only look that way because of where the matching happens. Move the match to the person's own device, and the whole market inverts: you set the price, you see the buyer, and you get the receipt.

Here is a sentence the advertising industry has believed for twenty years, and which I think is simply false:
To show someone a relevant ad, you have to know who they are.
You don't. You have to know *what they want*. Those are not the same fact, and the entire surveillance apparatus of the modern web exists because we conflated them.
Where the match happens is the whole argument
Think about what an ad actually is: a match between a person's need and someone's offer. Somebody has to do that matching, and everything follows from where it gets done.
Today it's done on the buyer's side. So the buyer needs a copy of you. They assemble it from brokers, pixels, and inference, they store it, they trade it, and they match against it in a data centre you'll never see. Personalisation is the *reason* the shadow profile exists. Not a side effect — the whole justification.
But that's an implementation detail, not a law of physics.
Move the match to your side, and it disappears. Your agent already holds your profile. It's on your phone, on your Mac, on hardware you own. An ad network sends a set of candidate offers — *"we have these twelve things, here's who each is for"* — and your agent picks the one that fits. The network learns which ad you saw. It never learns why. It never gets the profile, because it never needed the profile. It needed a match, and the match came back.
That's it. That's the trick. It's not cryptography, it's not a policy, it's not a promise. It's an architecture where the sensitive thing never moves.
And here's the part that should make an ad buyer *happier*, not sadder: the match on your side is better. Your agent knows what you actually want, right now, from what you told it — not what a model inferred from your browsing at 2am. Better targeting, less data. The industry has assumed those trade against each other. They don't.
The three things that change for you
One: you set the price. Above a floor of a thousandth of a penny, the number is yours. A tenth of a cent for something you barely care about; two hundred dollars for something you don't want touched. Not because you'll retire on it — you won't — but because a price is the smallest real unit of ownership. Everything else called "owning your data" has been custody.
Two: you see who bought, and why. This is the one I think is genuinely new. Every read writes a receipt into a tamper-evident ledger that belongs to you: who asked, what they took, what purpose they stated, when. Not an aggregate. Not a dashboard. A list.
Nobody has ever had that. You have never once been able to open a page and read the sentence *"a retailer paid you 0.4 cents on Tuesday to learn your shoe size, in order to not send you shoes in the wrong size."* Give a person that page and something shifts permanently — because the moment the buyer is visible, the buyer starts behaving differently. Sunlight priced in millicents.
Three: you control the feed too. The same consent that decides which ads you see should decide what your feed shows you. The ranking of your attention is not a different problem from the targeting of an ad; it's the same problem wearing different clothes, and a person who owns one should own both.
Why an ad network should want this
I don't expect anyone to adopt this out of virtue, so let me argue it on their terms.
Signal loss is their actual problem. Third-party cookies, ATT, and every state privacy law point one direction. The industry's response has been modelling and inference — guessing harder about people who won't tell them. Consented, first-party, person-declared data is not a moral upgrade over an inferred profile. It is a better input. It's current, it's correct, it's structured, and it doesn't decay.
Compliance stops being a cost centre. Right now every platform maintains an enormous apparatus for proving it had a right to the data it used. If consent arrives as a signed grant with a receipt, that apparatus mostly evaporates. The audit trail is the protocol.
And the person shows up willing. A person who is confident about what they're revealing reveals more. The reason people are guarded is not that they hate being served well — it's that they have no control over what being served well costs them. Give them the dial and they turn it up.
Connecting the dots
Everything above only works if the underlying system can actually connect things — a person to a need, a need to an offer, an offer to a local human who can deliver it. That's the unglamorous half.
It means the backend has to be organised as a graph rather than a pile: people, products, services, professionals, wants, and the relationships between them, all addressable. It means a want is not a string in a form, it's an edge. It means "who near me does this" and "what would fit this person" are the same query shape.
We publish 263 named scopes and 15 purposes, and honestly the count is the least interesting part. What matters is that they're dot-addressable — wants.health.dentist is a *thing the system can reason over*, not free text. That's what makes the connection automatable, and connection is the whole product. Commerce and communication are what happens after two things are correctly joined.
What is actually built, and what is not
I said I'd stop making claims we can't show.
Live and public: the scope registry, the purpose bundles, the tier system that makes some things permanently unsellable, the hash-chained receipt ledger, and a one-URL integration manifest at /.well-known/pchp so an agent can integrate with no docs and no sales call.
Not built: on-device ad matching. Everything in the first section of this post is an architecture we intend and have not shipped. The server currently binds a fraction of the scopes we publish. There's no interface yet for a person to fill in the deeper parts of their profile. Money moves on exactly one rail.
Not agreed: we have no advertising partnership with anyone. Google, Meta, Apple, Amazon, AppLovin and The Trade Desk are named in our published mapping document because their public documentation defines the controls we map onto. None of them is a partner, customer, shareholder or investor of ours, and none has reviewed any of it. When that changes, we'll say so with a date.
I'd rather publish the argument and the gap than the argument alone. The argument is only worth anything if someone can check it.
The bet
Private and personal are not opposites. Neither are targeted and consented. They only look that way because of a decision made in the early 2000s about where to do the matching — and that decision is now the most expensive assumption in a two-hundred-billion-dollar industry.
Move the match to the person. Pay them. Show them the receipt.
The rest is engineering, and engineering is the easy part.
Related
- Ask Them. Ask Them Every Time. — Jobs specified this in 2010; nobody built it
- The First Knock Is Free — the handshake economics
- The Supercomputer in Your Pocket Wants a Job — the hardware that makes on-device matching possible
- The live scope registry — 263 scopes, 15 purposes, public and versioned
- What we have not done
*Companies named here are named because of their public documentation and public product decisions. None is a partner, customer, shareholder, or investor of HushOne, Inc. or Hushh Technologies Corporation, and none has reviewed or endorsed this piece. Our compliance certifications are in pursuit and not held.*
The 🤫 hussh magazine
Written by Manish Sainani, and built to read beautifully here — and to travel to 🤫 One on your phone, your glasses, and visionOS, as one immersive magazine you own.