1. Authorized integration
Use only current Posto SDKs, APIs, credentials, and documented test paths. Register each app and placement accurately. Web apps must use a Developer backend relay with server HMAC; supported native apps must use required Apple App Attest or Google Play Integrity proof. Secrets may not be embedded in browser or mobile client code.
2. End-user experience
You control your app and must provide all notices, permissions, and legal basis required to submit context and display ads. Ads must be visually distinguishable from organic content and display the SDK-prescribed 'Sponsored' or similarly clear advertising label near the ad. Do not obscure disclosures, alter advertiser content materially, force clicks, or use deceptive placement.
3. Data minimization
Submit only the recent interaction messages and optional coarse demographic fields permitted by the SDK Data Handling Notice. Run the provided PII filter, do not disable or bypass server filtering, and do not submit names, email addresses, phone numbers, authentication secrets, payment data, precise location, street addresses, health information, or other sensitive data. Do not integrate Posto into child-directed or prohibited sensitive contexts without written approval.
4. Events and invalid traffic
Record an impression only when the ad is actually rendered and viewable under documentation. Record a click only from an intentional user action. You may not automate requests or clicks, replay tokens, conceal traffic sources, manipulate context, simulate conversions, or encourage invalid activity. Posto may classify traffic as valid, observe, held, or invalid and may delay or reverse related accounting according to the applicable agreement.
5. Earnings and floors
Valid publisher earnings are calculated from finalized billable impressions after the applicable Posto fee. A minimum CPM applies only when expressly shown in an executed order or eligible placement setting and only to finalized valid impressions. It is not a guarantee for test, observe, held, invalid, unsupported, or no-fill traffic. Simulation balances have no cash value.
6. Security and updates
Protect credentials, signing keys, app identifiers, and administrative access. Promptly install security-critical SDK updates and maintain supported app versions. Notify security@postoconnect.com of compromise, integrity-verification failure, or suspected invalid traffic. Posto may rotate credentials or suspend an unsafe integration.
7. App content and compliance
You represent that you own or have rights to your app and submitted content and that the integration complies with platform rules, privacy law, consumer-protection law, and your published notices. You are responsible for responding to your end users and forwarding processor-related requests to Posto when needed.
8. Indemnity
In addition to the Terms of Service, you will defend and indemnify Posto and advertisers from claims arising from your app, placements, data collection, disclosures, invalid traffic, modifications to ads, or breach of these Developer Terms.