I think you need to clarify what you mean by at rest. You mention browser history but it's not clear to me if you mean that it's encrypted in the browser. If you mean it's encrypted within your data store on your servers, that's great for security but doesn't really address the ad concern. I'm assuming you hold the encryption keys. If that's the case, you can decrypt the users' data in your data store for ad targeting purposes.