Google now says personalized ads may continue after you reject cookies

Stani Mihov
Founder & CEO
·

TL;DR
What changed:
Google's cookie page now says you may keep seeing personalized ads after rejecting personalization cookies, through other identifiers.
The page names your IP address, and information you previously shared with a website, as identifiers used for personalized content.
It adds that removing or disabling cookies in your browser does not stop ad personalization unless you turn off personalized ads in your ad settings.
The Privacy Policy, effective October 1, 2026, now says search results and ads for signed-out users may be based on activity across devices.
What to do: If you count on rejecting or clearing cookies to avoid personalized ads, turn off personalized ads in My Ad Center as well, and check that your own site's cookie notice does not promise more than Google's page does.
The change
Google updated two of its core privacy pages at the start of October 2026. The Google Privacy Policy now carries an effective date of October 1, 2026, replacing the version of May 26, 2026, and differs from it by two words. The page How Google uses cookies, which explains what Google's cookies do and how to manage them, gained three new passages.
Taken together, the edits say one thing more clearly than before: rejecting or deleting cookies is not the control that stops personalized ads. A separate setting is.
What changed
Rejecting cookies. The cookie page already said that non-personalized content may still be shaped by things like location and language. It now adds that, even if you reject personalization cookies, "you may continue to see personalized ads using other identifiers" and that this applies "unless you turn off personalized ads."
Removing cookies. A new sentence in the section on browser controls says that "even if cookies are removed or disabled in your browser," Google may use "cookie-based information or other advertising technologies" to personalize ads unless you "change your ads settings."
Other identifiers. The old page said: "Cookies and similar technologies are used for the purpose of showing personalized content." The words "and similar technologies" were replaced by a parenthesis that names "other identifiers like your IP address" and "information you previously shared with the website."
Across devices. In the Privacy Policy, the paragraph about people who are not signed in used to end with ads "based on your activity." It now ends with "based on your activity across devices."
Rejecting cookies and turning off personalized ads are two separate controls
It is common to treat the cookie banner as the switch for ad tracking. Google's page now separates the two in plain terms. Rejecting cookies used for personalization, deleting cookies, or blocking them in the browser does not, by itself, end personalized ads. According to the page, that takes the personalized ads setting, which Google offers in My Ad Center.
One unchanged sentence on the same page is worth reading next to the new ones. It says that if you have turned off personalized ads, the "id" cookie "is used to remember this preference." The page does not explain how that preference is kept for a browser whose cookies are then removed. The difference between a control and a commitment is a theme we covered when Perplexity moved three protections out of its privacy policy.
The new wording also uses "may." It says you may continue to see personalized ads and that Google may use other technologies. It does not say that this happens in every case, and it does not list the other advertising technologies.
The IP address is now on the cookie page
Before this update, the cookie page did not mention IP addresses at all. The Privacy Policy already lists the IP address among the information Google collects, but the page about cookies described personalization only in terms of cookies and similar technologies. It now gives the IP address as an example of an identifier used "for the purpose of showing personalized content."
An IP address is different from a cookie in one practical way: it is not stored in the browser, so there is nothing for the user to reject or clear. This is not the first time IP addresses have come up in Google's advertising rules. Since February 2025, Google has no longer prohibited its advertising customers from using fingerprinting techniques, which rely on signals such as IP addresses, a change the UK data protection regulator publicly criticized, as TechRadar reported at the time. The October update is to the pages written for users, not to those advertiser policies.
Two words for people who are not signed in
The Privacy Policy change is small on the page. The paragraph explains what Google does with data that is not tied to an account: it stores it with unique identifiers linked to the browser, app, or device, so that it can keep preferences and decide whether to show more relevant results or ads. That decision used to be described as "based on your activity." It is now "based on your activity across devices."
Cross-device use is not new to the policy as a whole. An unchanged sentence already says Google may use information "across our services and across your devices." What is new is that the two words appear in the paragraph about signed-out use, which describes data stored with identifiers tied to the browser, application, or device you are using.
The policy also still contains this commitment, which did not change: "We will not reduce your rights under this Privacy Policy without your explicit consent."
What did not change
The rest of the Privacy Policy is word for word the same as the May 26, 2026 version, apart from the effective date.
The cookie names, purposes, and lifetimes listed on the cookie page are unchanged.
Signed-out users can still manage ad preferences, and the policy still says Google does not show personalized ads based on sensitive categories or on content from Drive, Gmail, or Photos.
The cookie page still points to g.co/privacytools for managing how cookies are used.
Google still offers archived versions of the Privacy Policy for comparison.
Why this matters
For a SaaS company, this is a vendor change that reaches two groups at once. The first is your own people, who use Google signed in and signed out, on work and personal devices. The second is your website visitors, because many company sites run at least one Google product, such as Analytics, Tag Manager, or Ads.
That second group is where the wording becomes your problem. A cookie banner and a cookie notice are statements your company makes. If yours tells visitors that rejecting cookies stops personalized advertising, Google's own page now describes its side of that differently. Ad-related wording has moved on other privacy pages this year too, for example when Uber said its ad partners may combine your data with other sources and when OpenAI widened what it does with data from advertisers.
On the pages themselves, the only visible sign of the update is a new effective date on the Privacy Policy. Edits of a few words on pages of this size are what continuous monitoring of vendor legal changes is for.
Potential impact
For a company that uses Google products on its site or in its work, the update raises five practical questions:
Does your cookie notice or banner say that rejecting cookies stops personalized ads, and is that still accurate for Google's products?
Does your privacy notice mention IP addresses as an identifier used for personalization, if your tools use them that way?
Have the people who manage your consent tooling read the new sentences, and do your settings for Google's ad products match what you tell visitors?
Do employees who use shared or signed-out browsers know that clearing cookies does not turn off personalized ads?
Who in your company would notice the next two-word change in a policy this long?
How Venpo detected it
Venpo monitors Google's privacy and cookie pages as part of continuous vendor risk monitoring. It flagged the three added passages on the cookie page and the two added words in the Privacy Policy, with the rest of both documents unchanged. Every quote in this article was checked against the redline and the live pages. The Privacy Policy redline is on the change page for YouTube, which is covered by the same policy.
Business outcome
Teams that track Google saw the exact sentences that were added, next to the text they replaced. That is enough to answer the two questions that matter in practice: whether anything a company tells its own visitors now needs rewording, and whether staff guidance about cookies and ads is still right. Without the redline, the only visible sign on either page is one new date, which is the practical difference between manual and automated vendor monitoring.
Key takeaway
Google's pages now say that personalized ads may continue after cookies are rejected, removed, or disabled, that an IP address can serve as an identifier, and that signed-out activity may be considered across devices. The control that stops personalized ads is the ad setting, not the cookie choice, and the way to catch edits like these is to monitor vendor terms and policies as a routine.
The change
Google updated two of its core privacy pages at the start of October 2026. The Google Privacy Policy now carries an effective date of October 1, 2026, replacing the version of May 26, 2026, and differs from it by two words. The page How Google uses cookies, which explains what Google's cookies do and how to manage them, gained three new passages.
Taken together, the edits say one thing more clearly than before: rejecting or deleting cookies is not the control that stops personalized ads. A separate setting is.
What changed
Rejecting cookies. The cookie page already said that non-personalized content may still be shaped by things like location and language. It now adds that, even if you reject personalization cookies, "you may continue to see personalized ads using other identifiers" and that this applies "unless you turn off personalized ads."
Removing cookies. A new sentence in the section on browser controls says that "even if cookies are removed or disabled in your browser," Google may use "cookie-based information or other advertising technologies" to personalize ads unless you "change your ads settings."
Other identifiers. The old page said: "Cookies and similar technologies are used for the purpose of showing personalized content." The words "and similar technologies" were replaced by a parenthesis that names "other identifiers like your IP address" and "information you previously shared with the website."
Across devices. In the Privacy Policy, the paragraph about people who are not signed in used to end with ads "based on your activity." It now ends with "based on your activity across devices."
Rejecting cookies and turning off personalized ads are two separate controls
It is common to treat the cookie banner as the switch for ad tracking. Google's page now separates the two in plain terms. Rejecting cookies used for personalization, deleting cookies, or blocking them in the browser does not, by itself, end personalized ads. According to the page, that takes the personalized ads setting, which Google offers in My Ad Center.
One unchanged sentence on the same page is worth reading next to the new ones. It says that if you have turned off personalized ads, the "id" cookie "is used to remember this preference." The page does not explain how that preference is kept for a browser whose cookies are then removed. The difference between a control and a commitment is a theme we covered when Perplexity moved three protections out of its privacy policy.
The new wording also uses "may." It says you may continue to see personalized ads and that Google may use other technologies. It does not say that this happens in every case, and it does not list the other advertising technologies.
The IP address is now on the cookie page
Before this update, the cookie page did not mention IP addresses at all. The Privacy Policy already lists the IP address among the information Google collects, but the page about cookies described personalization only in terms of cookies and similar technologies. It now gives the IP address as an example of an identifier used "for the purpose of showing personalized content."
An IP address is different from a cookie in one practical way: it is not stored in the browser, so there is nothing for the user to reject or clear. This is not the first time IP addresses have come up in Google's advertising rules. Since February 2025, Google has no longer prohibited its advertising customers from using fingerprinting techniques, which rely on signals such as IP addresses, a change the UK data protection regulator publicly criticized, as TechRadar reported at the time. The October update is to the pages written for users, not to those advertiser policies.
Two words for people who are not signed in
The Privacy Policy change is small on the page. The paragraph explains what Google does with data that is not tied to an account: it stores it with unique identifiers linked to the browser, app, or device, so that it can keep preferences and decide whether to show more relevant results or ads. That decision used to be described as "based on your activity." It is now "based on your activity across devices."
Cross-device use is not new to the policy as a whole. An unchanged sentence already says Google may use information "across our services and across your devices." What is new is that the two words appear in the paragraph about signed-out use, which describes data stored with identifiers tied to the browser, application, or device you are using.
The policy also still contains this commitment, which did not change: "We will not reduce your rights under this Privacy Policy without your explicit consent."
What did not change
The rest of the Privacy Policy is word for word the same as the May 26, 2026 version, apart from the effective date.
The cookie names, purposes, and lifetimes listed on the cookie page are unchanged.
Signed-out users can still manage ad preferences, and the policy still says Google does not show personalized ads based on sensitive categories or on content from Drive, Gmail, or Photos.
The cookie page still points to g.co/privacytools for managing how cookies are used.
Google still offers archived versions of the Privacy Policy for comparison.
Why this matters
For a SaaS company, this is a vendor change that reaches two groups at once. The first is your own people, who use Google signed in and signed out, on work and personal devices. The second is your website visitors, because many company sites run at least one Google product, such as Analytics, Tag Manager, or Ads.
That second group is where the wording becomes your problem. A cookie banner and a cookie notice are statements your company makes. If yours tells visitors that rejecting cookies stops personalized advertising, Google's own page now describes its side of that differently. Ad-related wording has moved on other privacy pages this year too, for example when Uber said its ad partners may combine your data with other sources and when OpenAI widened what it does with data from advertisers.
On the pages themselves, the only visible sign of the update is a new effective date on the Privacy Policy. Edits of a few words on pages of this size are what continuous monitoring of vendor legal changes is for.
Potential impact
For a company that uses Google products on its site or in its work, the update raises five practical questions:
Does your cookie notice or banner say that rejecting cookies stops personalized ads, and is that still accurate for Google's products?
Does your privacy notice mention IP addresses as an identifier used for personalization, if your tools use them that way?
Have the people who manage your consent tooling read the new sentences, and do your settings for Google's ad products match what you tell visitors?
Do employees who use shared or signed-out browsers know that clearing cookies does not turn off personalized ads?
Who in your company would notice the next two-word change in a policy this long?
How Venpo detected it
Venpo monitors Google's privacy and cookie pages as part of continuous vendor risk monitoring. It flagged the three added passages on the cookie page and the two added words in the Privacy Policy, with the rest of both documents unchanged. Every quote in this article was checked against the redline and the live pages. The Privacy Policy redline is on the change page for YouTube, which is covered by the same policy.
Business outcome
Teams that track Google saw the exact sentences that were added, next to the text they replaced. That is enough to answer the two questions that matter in practice: whether anything a company tells its own visitors now needs rewording, and whether staff guidance about cookies and ads is still right. Without the redline, the only visible sign on either page is one new date, which is the practical difference between manual and automated vendor monitoring.
Key takeaway
Google's pages now say that personalized ads may continue after cookies are rejected, removed, or disabled, that an IP address can serve as an identifier, and that signed-out activity may be considered across devices. The control that stops personalized ads is the ad setting, not the cookie choice, and the way to catch edits like these is to monitor vendor terms and policies as a routine.
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
Real-time change notifications
Stay ahead of every legal change
Get updates, product news and expert tips on navigating legal changes
Dispute resolution clause now requires mandatory arbitration in all regions
Data retention period extended from 2 years to 5 years for all services
New restrictions on AI-generated content in product descriptions
Third-party data sharing expanded to include analytics partners
