
Privacy Policy
NO FAIT LLC (d/b/a Infinite Audience) • Effective Date: February 12, 2026
1. Who We Are
NO FAIT LLC, doing business as Infinite Audience ("NO FAIT," "Infinite Audience," "we," "our," or "us"), is a MadTech platform operator and data broker headquartered in Virginia. We operate nofait.ai, infiniteaudience.ai, and related advertising technology services (collectively, the "Services").
This Privacy Policy applies to:
- Visitors to our websites and users of our platform;
- Consumers whose personal information we receive from business clients for audience modeling, data enrichment, or advertising activation; and
- Individuals whose information is part of our Infinite Audience identity graph.
We are committed to transparency about how personal information flows through our platform. If you are a consumer whose data we hold — whether or not you have ever directly interacted with us — you have rights, and this Policy explains them.
2. Categories of Personal Information We Collect and Process
We collect and process the following categories of personal information, depending on context:
A. Identifiers
- Name, email address, phone number, postal address
- IP address, device identifiers (IDFA, GAID), cookie IDs
- Hashed email addresses (MD5/SHA-256) and other pseudonymous identifiers
- Account login credentials
B. Customer and Commercial Records
- Purchase history, transaction data, and order values
- Brand affinity, retail category interests, and purchase propensity scores
- Company information, job title, and industry (for B2B accounts)
C. Internet and Electronic Activity
- Browsing history, search queries, and page interaction events
- Advertisement interactions (impressions, clicks, conversions)
- Pixel and server-side event signals deployed by our clients
- Referring URLs, browser type, and operating system
D. Geolocation Data
- Coarse geolocation (state, DMA, ZIP code) derived from IP address
- Precise geolocation (GPS-level) only where a client's app or website provides this signal with appropriate user consent
E. Inferences and Derived Data
- Audience segment memberships and behavioral clusters
- Propensity and affinity scores generated by our AI/ML models
- Identity graph nodes and cross-device match keys
- Lookalike seed attributes and modeled behavioral profiles
F. Sensitive Personal Information
We do not intentionally collect sensitive personal information (such as Social Security numbers, precise health data, financial account numbers, biometrics, racial or ethnic origin, sexual orientation, or religious beliefs). If sensitive data is inadvertently received, we will delete it and notify the submitting client. Our platform is not authorized for use cases involving sensitive personal information without a separate written data processing agreement.
G. Connected AI Assistant and API Activity
If you connect an AI assistant or other application to Infinite Audience through our API or remote Model Context Protocol (MCP) server, we process the connection's client identifier, authorized scopes, account and organization identifiers, authorization and token records, tool requests and arguments, tool results, and related security and usage records. A tool result may include account data, audience or campaign information, or other information that your organization is permitted to access. Do not include information in a tool request that you are not authorized to disclose to the connected application.
3. Sources of Personal Information
We collect and receive personal information from the following sources:
- Directly from you — when you register, contact us, or submit a privacy request
- Connected applications — when an application you authorize sends API or MCP tool requests on your behalf
- Our B2B clients — first-party CRM uploads, data onboarding files, and pixel/tag deployments on client properties
- Third-party data providers — identity resolution partners, data exchanges, and licensed data brokers
- Cookies and tracking technologies — first-party and client-deployed pixels on our network
- Publicly available sources — public records, business directories, social media profiles
- Inference and modeling — attributes derived from combining the above sources through our AI/ML systems
4. Business and Commercial Purposes for Processing
We process personal information for the following business and commercial purposes:
- Constructing and maintaining the Infinite Audience identity graph and resolving consumer identities across devices and channels
- Building lookalike and similar-audience models for advertising clients
- Cross-device and cross-channel identity linking and match rate optimization
- Onboarding first-party client data to DSPs, ad exchanges, and clean rooms for programmatic activation
- Programmatic advertising bid optimization, frequency management, and campaign delivery
- Campaign measurement, attribution, and analytics reporting
- Training and improving AI/ML models for audience prediction and marketing optimization
- Fraud detection, invalid traffic prevention, and platform security
- Operating and improving our B2B SaaS platform for marketing clients
- Authenticating and authorizing connected applications, fulfilling requested API and MCP tools, recording usage, detecting abuse, and allowing access to be revoked
- Responding to consumer privacy requests and maintaining compliance records
- Complying with applicable laws and regulations
We do not process personal information for purposes materially different from those listed above without providing prior notice.
5. Disclosure and Sale of Personal Information
We may disclose, sell, or share personal information with the following categories of recipients. We may sell or share personal information as those terms are defined under the CCPA/CPRA and similar state privacy laws. See Section 9 for how to opt out.
- Demand-side platforms (DSPs) and programmatic ad exchanges — for advertising activation
- Identity resolution and data enrichment partners — to build and maintain the identity graph
- Our B2B clients — audience models, enriched segments, and analytics outputs delivered as part of our services
- Applications you connect — responses to API or MCP tool requests made under your authorized account and scopes. The application's provider, and any gateway you choose to place between it and our server, may receive and handle those requests and responses under its own privacy terms
- Data exchanges and licensed data marketplaces — for audience licensing and data monetization
- Analytics and measurement vendors — for campaign performance attribution
- Cloud infrastructure providers — Google Cloud Platform (data hosting and processing)
- Security and fraud prevention vendors — reCAPTCHA, IP reputation, and traffic validation
- Email delivery providers — AWS Simple Email Service (for transactional communications)
- Legal authorities — when required by law, court order, or to protect rights and safety
- Successors in interest — in the event of a merger, acquisition, or asset sale
We require all service providers and contractors to maintain appropriate confidentiality and security obligations by contract.
6. Data Broker Status and State Registrations
NO FAIT LLC (d/b/a Infinite Audience) qualifies as a data broker under applicable state laws, including the California Consumer Privacy Act (CCPA) and the Texas Data Privacy and Security Act (TDPSA), among others. We may collect and sell or license personal information about consumers with whom we do not have a direct relationship.
California Delete Act / DROP Program: As a registered California data broker, we are required to honor consumer deletion requests submitted through the California Privacy Protection Agency's (CPPA) accessible deletion mechanism ("DELETE REQUEST OPT-OUT PLATFORM" or "DROP") once it is operational, currently targeted for August 1, 2026. Consumers may submit deletion requests either through the CPPA's DROP portal or directly through our Privacy Request Portal.
No-Match Policy: If we receive a deletion request and cannot locate any records matching the submitted identity information, we will nonetheless honor the request as a permanent opt-out of the sale and sharing of personal information associated with those identifiers, consistent with CCPA § 7022(g).
Consumers in other states where we are registered as a data broker may also have deletion rights through applicable state programs.
7. Cookies, Tracking Technologies, and the Global Privacy Control
We and our clients use the following technologies to collect data on our websites and across our advertising network:
Technologies We Use
- Cookies — small files stored on your device. Categories: strictly necessary (site functionality), analytics (traffic measurement), advertising/targeting (ad personalization and retargeting), and preference/personalization cookies
- Tracking pixels and web beacons — single-pixel images embedded in web pages or emails to signal interactions
- Server-side event APIs — conversions API, enhanced conversions, and similar server-to-server signals
- SDKs and tag management containers — deployed via Google Tag Manager or client tag management systems
- Device fingerprinting signals — browser configuration and hardware signals used for fraud prevention
Global Privacy Control (GPC)
We recognize and honor the Global Privacy Control (GPC) signal. If your browser or browser extension transmits a GPC signal when you visit our websites, we will treat it as a valid opt-out of the sale and sharing of your personal information for that browser/device session, consistent with requirements under the California Consumer Privacy Act and the Colorado Privacy Act.
You may disable non-essential cookies via your browser settings. Note that disabling certain cookies may affect website functionality. For broader opt-outs from our advertising network, use the Privacy Request Portal.
8. AI, Profiling, and Automated Decision-Making
Our platform uses artificial intelligence and machine learning to generate audience segments, propensity scores, behavioral predictions, and identity graph linkages. These automated processes are central to our services and may affect the advertisements you see across the web, mobile, and connected TV environments.
AI Model Training: Personal information — including behavioral signals, identity attributes, and inferred characteristics — may be used to train and improve our AI/ML models. Consumers may opt out of having their data used for AI/ML model training by submitting a request through our Privacy Request Portal.
Profiling Opt-Out Rights: Consumers residing in Colorado, Connecticut, Virginia, Texas, Oregon, Minnesota, New Jersey, New Hampshire, Nebraska, Maryland, Rhode Island, Kentucky, Indiana, and other states with automated decision-making technology (ADMT) provisions may have the right to opt out of profiling used in the context of solely automated decisions that produce legal or similarly significant effects. To exercise this right, submit a request via our Privacy Request Portal.
Our AI-generated outputs are not used, and are not intended for use, as the sole basis for decisions about credit, insurance, employment, housing, or other FCRA-regulated determinations.
9. Your Privacy Rights by State
Depending on your state of residence, you may have some or all of the following rights regarding your personal information. To exercise any of these rights, use our Privacy Request Portal.
All U.S. Residents
- Opt out of the sale of personal information
- Opt out of sharing personal information for cross-context behavioral advertising / targeted advertising
- Appeal a denied or partially denied privacy request
California Residents (CCPA/CPRA)
- Right to Know — confirm whether we process your personal information
- Right to Know — categories of personal information collected, sources, purposes, and third-party disclosures
- Right to Access — specific pieces of personal information we hold about you
- Right to Data Portability — receive your information in a portable, machine-readable format
- Right to Delete — request deletion of personal information, including derived data and audience segments; and instruct service providers and contractors to delete
- Right to Correct — request correction of inaccurate personal information
- Right to Limit Use of Sensitive Personal Information (where applicable)
- Right to Opt Out of Sale and Sharing
- Right to Non-Discrimination for exercising rights
- California Delete Act / DROP — submit deletion requests through the CPPA's accessible mechanism (available August 1, 2026) or directly through our portal
- Authorized agent submission — with written authorization or power of attorney (CA Probate Code § 4000+)
Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Tennessee, Iowa, Delaware, New Jersey, New Hampshire, Nebraska, Minnesota, Maryland, Rhode Island, Kentucky, Indiana (and other states with comprehensive privacy laws)
- Right to Know / Access — confirm processing and access personal information
- Right to Delete — request deletion of personal information
- Right to Correct — request correction of inaccurate data
- Right to Data Portability — receive a portable copy
- Right to Opt Out of targeted advertising, sale of personal information, and (where applicable) profiling in furtherance of solely automated decisions
- Right to Appeal a denied request
The specific rights available to you depend on your state of residence and the nature of our processing. Our Privacy Request Portal allows you to select your state to see which rights apply.
10. How to Exercise Your Rights
Submit a Privacy Request
Use our secure, multi-step Privacy Request Portal to exercise any of the rights described above. The portal supports all request types, identity verification, and authorized agent submissions.
Go to Privacy Request Portal →Who May Submit
- Consumers directly — submit on your own behalf
- Authorized agents — may submit on a consumer's behalf with written authorization. For California residents: if the agent holds a valid power of attorney under California Probate Code § 4000 et seq., we will not require the consumer to separately verify their own identity. Otherwise, we may require the consumer to directly confirm the agent's authority.
Verification
To protect against unauthorized requests, we verify identity using information already in our records. We will ask you to confirm your name, address, and email address (via a one-time verification code). Higher-risk requests such as deletion or data portability require a stronger match. We will not ask you for information we do not already hold.
No-match policy: If submitted identity fields do not match any record in our systems, we will (a) inform you that we could not verify the request, and (b) treat any deletion request as a permanent opt-out of the sale and sharing of personal information associated with those identifiers, as required by CCPA § 7022(g).
Response Timelines
- Acknowledgment: within 10 business days of receiving a verified request
- Access, deletion, correction, portability: within 45 calendar days; extendable once by an additional 45 days with notice
- Opt-out of sale/sharing: within 15 business days
- Appeals: submit within 60 days of receiving our decision; we will respond within 60 days of receiving your appeal
Non-Discrimination
Exercising your privacy rights will not result in denial of goods or services, different prices, a different level of service quality, or any other retaliation.
11. Marketing Communications Opt-Out
You may opt out of specific marketing channels as follows:
- Email marketing: Every commercial email we send includes an unsubscribe link, as required by the CAN-SPAM Act. You may also submit an opt-out via our Privacy Request Portal.
- SMS / text marketing: Reply STOP to any text message we send to opt out of future SMS/MMS marketing. Standard message and data rates may apply.
- Telemarketing calls: To be placed on our internal do-not-call list, submit a request via our Privacy Request Portal. You may also register with the national Do-Not-Call Registry at donotcall.gov.
- Direct mail / postal marketing: Submit an opt-out via our Privacy Request Portal.
- Push notifications and in-app marketing: Manage via your device operating system settings (iOS or Android) or within the application.
- Lookalike and similar-audience modeling: To suppress your identifiers from being used as a seed for lookalike audiences, submit an opt-out request via our Privacy Request Portal.
- Identifier suppression from new marketing audiences: To prevent your identifiers from being added to new marketing audiences across our advertising network, submit a suppression request via our Privacy Request Portal.
12. Data Security
We implement administrative, technical, and organizational safeguards appropriate to the sensitivity and volume of personal information we process, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
- Role-based access controls and principle of least privilege
- Multi-factor authentication for platform access
- Continuous monitoring, logging, and anomaly detection
- Vendor security assessments and contractual data protection requirements
- Identity and access management (IAM) policies via Google Cloud
No security system is 100% impenetrable. In the event of a data breach affecting your personal information, we will notify affected individuals and regulators as required by applicable law.
13. Data Retention
We retain personal information only as long as necessary for the purposes described in this Policy, including:
- Account and platform data: for the duration of the account relationship, plus 3 years for dispute resolution and legal compliance
- Audience segment and identity graph data: 12 months from creation or last use, unless a client contract requires longer retention
- Privacy request records (including verification data and request outcomes): 24 months, as required by California and similar state regulations
- OTP and verification records: deleted within 90 days of request resolution or denial
- Server and access logs: 90 days
- Backup and disaster recovery copies: may persist for up to 12 additional months beyond the primary retention period
Verification data submitted with privacy requests is used solely to verify identity and locate records, and is deleted following the verification window, consistent with CCPA § 7060(d).
14. Children's Privacy
Our Services are directed exclusively to businesses and adult consumers (18+). We do not knowingly collect, process, or sell personal information from children under the age of 13, or under 16 for targeted advertising purposes. If we become aware that we have collected personal information from a child under 13, we will delete it promptly. To report a concern, contact us at [email protected].
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or platform capabilities. When we make material changes, we will post the updated Policy at this URL with a revised effective date. We encourage you to review this Policy periodically.
16. Contact Us
For privacy-related inquiries, to exercise your rights, or to report a concern:
NO FAIT LLC (d/b/a Infinite Audience)
Email: [email protected]
https://nofait.ai | https://infiniteaudience.ai
To submit a consumer privacy request, please use our Privacy Request Portal rather than email, as the portal enables identity verification and ensures timely processing.