adPluga
Legal · Invalid traffic

Invalid traffic policy

What we count as invalid traffic, how we filter it and what happens to a filtered event.

Last updated: October 3, 2026 · Version 1.0

What we filter

  • Requests with no user agent

    A request without a User-Agent header does not come from a real browser or app.

  • Declared bots

    User agents containing bot, crawler, spider, headless, phantomjs or puppeteer.

  • Addresses that are not people

    Loopback and private network addresses (RFC 1918 and IPv6 equivalents).

  • Data centres

    IP ranges published by Amazon Web Services and Google Cloud, refreshed every 24 hours.

Scope

Applies to every impression and click adPluga measures, through the tag, the SDKs (Web, Flutter, Android and iOS) and the API, in every account.

General invalid traffic

The filters above are general invalid traffic (GIVT, in Media Rating Council terms): deterministic rules applied to every impression and click before anything is charged.

Event integrity

Every ad served carries a signed token (HMAC-SHA256) that expires in 10 minutes. An event without a valid token is refused, and each impression or click counts once: repeats of the same event are ignored.

What happens to a filtered event

It is recorded as invalid, with the reason. It is never charged to the advertiser or credited to the publisher, and each account's dashboard shows it as filtered traffic next to the valid traffic.

What we do not do yet

We have no third-party accreditation (MRC or TAG). Sophisticated invalid traffic (SIVT) detection, from per-IP frequency patterns and abnormal click-through rates, exists but is not switched on. We do not use the IAB/ABC International Spiders & Bots List. We update this page when that changes.

Reporting suspicious traffic

Advertisers, publishers and partners can report suspicious traffic to hello@adpluga.com, with the account, the period and the signals seen. We reply and, when confirmed, correct the affected figures.