Bot Installs Billed? Compare Credit Policies and MMP Controls

See when platforms may credit invalid activity, how partner terms govern payouts, and compare MMP controls, including Airbridge Growth fraud prevention.

Bot Installs Billed? Compare Credit Policies and MMP Controls

Start with the bill that changed.

  • Google Ads can credit invalid activity found after billing when a credit is appropriate and possible.
  • AppsFlyer, Adjust, Branch, Kochava, and Airbridge handle fraud signals in attribution workflows; those signals are separate from a media invoice.
  • Airbridge Growth includes Fraud Protection, with real-time blocking and configurable monitoring-only or auto-reject rules.

If attributed installs suddenly triple, the first question is which record tripled. An MMP report, an ad-platform invoice, and a CPI partner statement measure different things and have different owners.

For a Google Ads invoice, Google documents a conditional credit for invalid activity discovered after billing. Apple Ads terms allow discretionary credits, while affiliate and CPI claims turn on the written deal. An MMP can flag or change attribution records. Airbridge Growth adds real-time fraud blocking for a future spike, with rules a team can tune to its traffic.

First identify which bill increased

Match the charge to the account that issued it before asking for a credit. A founder who sees a 3x jump in attributed installs may be looking at a changed attribution report, a charge for paid media, or a partner payable; those are different claims.

Record that changedWhat to inspectWho controls the next decisionBest next action
Ad-platform media invoiceBilled account, invoice period, campaign, charge type, quantity, and any adjustmentThe ad platform named on the invoiceAsk that platform to review the particular invoice line and the underlying activity
Affiliate or CPI payableInsertion order, event definition, acceptance or rejection rules, and fraud clauseThe network or counterparty under the agreementSend a written dispute in the required format and within its stated notice period
MMP report or fee invoiceReport date range, attributed-install count, fraud status, and MMP service line itemThe MMP for its attribution record or its own service chargeRequest an attribution investigation from the MMP, and raise any service-fee question against the MMP invoice

An attributed install is a measurement outcome. A billing adjustment is a financial entry from the company that issued the charge. If an MMP changes an install’s source or marks it as fraudulent, keep that report as evidence, then submit it to the party that issued the disputed invoice or payable.

Google’s invalid traffic guidance distinguishes activity filtered before billing from activity identified later. Google says it filters invalid activity before an invoice when it detects it before the billing cycle ends, and the advertiser is not charged for that activity.

Google’s invalid-traffic category includes automated activity such as bots, accidental clicks caused by poor ad placement, and fraudulent placements such as clickjacking or ad stacking. The company says its traffic-quality team uses automated filters, machine learning, and manual review to detect and filter invalid interactions. Those examples help classify an anomaly for a support request, while Google’s own review determines how the account’s activity is treated.

Google also says it issues a credit when invalid activity is found after billing, when appropriate and possible. The adjustment appears on invoices and in account transactions. Google labels these credits “Invalid activity” on invoices; its Invalid Activity Credit Report lists credited clicks and adjusted campaign measures, including clicks, cost, and conversion rate.

A later credit can appear without changing past campaign metrics. Google says it freezes campaign metrics at month-end, so a credit for past invalid activity may affect billing records while the earlier campaign report remains as it was.

Google Ads billing and an MMP attribution report can show different counts for the same traffic. Google’s invalid-traffic page says third-party tools can flag activity, such as duplicate IP addresses, that Google has already excluded from billing.

For the request, anchor the question to a billable item: identify the Google Ads account, month, affected campaign, amount, and any existing “Invalid activity” adjustment. If the review concerns attributed installs rather than clicks, describe the install increase as supporting context, and ask Google to connect its billing decision to the relevant interaction records.

Apple Search Ads: credit terms are discretionary

Apple’s Apple Ads Terms of Service say Apple may offer or extend credits relating to its services at its discretion. The terms also make incentives subject to the applicable promotional-credit terms or other agreements with Apple.

Apple’s terms include credits among possible incentives, alongside promotions, discounts, and other monetary or non-monetary offerings. When you raise an Apple Search Ads billing issue, identify the campaign and billing period, quantify the charge in question, and ask Apple for a written account-level decision under the terms that apply to your account.

Keep the Apple charge record separate from MMP attribution exports. The campaign invoice tells you what Apple billed; the MMP export helps describe which installs or sources you are disputing. Attach both so the request links the measured spike to the particular Apple charge.

Affiliate or CPI payouts: the signed terms decide

A CPI or affiliate charge is usually a partner payable governed by the contract documents for that campaign. The clauses that matter are the definition of a valid event, the fraud standard, the evidence needed to reject events, any payment hold or clawback, the dispute notice window, and the person or address that must receive notice.

An Affiliati Network advertiser agreement provides a concrete example: it calls for immediate written notice and sufficient documentation when an advertiser claims or discovers campaign fraud. It also sets a written notice deadline of 21 days from when a claim or dispute arises, or the charge or invoice date, whichever happens first.

Calculate the notice deadline from the trigger stated in your agreement, and send written notice within that period. A delayed MMP report can arrive after the contract clock has started, so send notice as soon as the agreement requires and supplement it with later evidence if the terms allow.

A network’s fraud clause can define a different result for a disputed payout than an ad platform’s media-credit policy. The partner statement may concern payable installs or events; an ad invoice may concern media charges. Request a reversal or withholding only under the contract language that applies to the partner statement, and request media review from the platform that charged the spend.

When the clause gives a verification period, evidence threshold, or cap, capture the exact words and the related dates. For example, determine whether “invalid” means a bot event, a duplicate, an out-of-geo install, a device that fails a stated quality rule, or a conversion outside the insertion order. A broad statement that the traffic “looks fake” is harder to assess than event IDs matched to the agreed validation rule.

AppsFlyer: change attribution and preserve the rule trail

AppsFlyer’s Validation Rules documentation lets an advertiser define conditions to keep or block installs and in-app events. Its examples include installs outside the campaign’s target geography or operating system and installs that fail the advertiser-partner insertion order.

The rules run in real time. When a partner has rejection postbacks configured, AppsFlyer sends a rejection postback, a message reporting that an install or event was rejected. That gives the advertiser and partner a record to compare against the insertion order, which can help settle a CPI dispute.

AppsFlyer describes Protect360 as combining real-time fraud blocking with post-attribution fraud identification. For install attribution hijacking, its documentation says Protect360 blocks the install in real time and corrects attribution to the last valid source. Post-attribution fraud appears in dedicated reports, and some in-app event corrections apply for 30 days from the install.

These features affect the attribution record and partner signals. Use the changed attribution, rejection postback, or fraud report as evidence for the media payer or partner that issued a charge.

Adjust: use rejected-install callbacks as evidence

Adjust’s rejected-install callback guide says its Fraud Prevention Suite detects and rejects fraudulent engagements before attribution. The suite includes Anonymous IP Filter, Click Injection Filtering, and Distribution Modeling.

A team can add a rejected-install or rejected-reattribution callback parameter to a link URL. When the suite detects fraud, the callback can include the rejection reason. Adjust says the suite is available as an Adjust Growth Solution, and the suite must be active for the individual app to use the documented callbacks.

That callback gives a small team a timestamped rejection reason to compare with the campaign and partner data. Adjust’s Click Injection filtering guide explains that the control addresses fake ad engagement sent between an app download and the user’s first session, which can otherwise take attribution from another source.

Branch: score and withhold suspect attribution signals

Branch’s Fraud Analytics documentation describes RealScore as a model that scores how likely an install is to come from a real person rather than a bot, malware, or a false attribution claim. Branch also lists fraud metrics for patterns such as install hijacking, click flooding, and device-reset fraud.

Branch’s Fraud Analytics guide describes its legacy platform, which Branch says is slated for deprecation.

Branch’s fraud rules guide recommends rules that block erroneous attribution credit in real time. It says Branch can continue last-click attribution while withholding an ad-network postback when the attribution is flagged as fraudulent.

Branch’s in-depth fraud recommendations list rule types such as Suspicious Conversion Time, Geo Conflict, Device Conflict, Suspicious Device, and Young Persona or Device ID Reset. During triage, compare flagged events against the signals your own reports contain: a device conflict, for example, is a useful lead to test against device histories and campaign records. These rule names help organize the investigation; apply the agreement’s event definitions when deciding which partner events to contest.

For an incident, export the relevant score or fraud flag, source, campaign, and time range. A withheld postback can explain why Branch and a network report different attributed-install counts. Include that record in a partner dispute when the partner agreement defines postbacks or rejected events as part of its validation process.

Kochava: use its fraud reports to investigate network patterns

Kochava describes its fraud prevention on its official product page as flagging fraudulent installs and excluding them from attribution reporting. The page says it does not send ad-network postbacks for installs identified as fraudulent, and its fraud dashboards show networks and campaigns with high fraud rates.

The useful incident record is the install’s fraud status alongside its network, campaign, and time period. That record can help a team compare a sudden attributed-install surge with patterns across sources, then share the relevant evidence with the network or media platform responsible for the charge.

Airbridge Growth: configure prevention before the next spike

Airbridge Fraud Protection is available with the Growth Plan. It uses rule-based and machine-learning detection for click injection, SDK spoofing, and device farms, and Airbridge says fraudulent installs are flagged and blocked in real time.

Growth includes configurable thresholds suited to a team’s vertical and traffic patterns. A team can set each rule to monitoring-only or auto-reject and tune sensitivity by ad network; Fraud Protection is included with Growth at no additional charge.

Monitoring-only offers a practical starting point when a sudden change in traffic needs review. The team can compare flagged activity with campaign history and partner records, then move a suitable rule to auto-reject when its evidence supports that choice. That sequence gives a small team room to review a rule’s fit before it starts rejecting installs.

Airbridge’s role here is prevention and cleaner attribution data for future activity. Airbridge says its real-time blocking keeps attribution data clean and ROAS calculations accurate. Route a past billing claim to the named platform or network, and use the Airbridge fraud record to support the review.

Decide whether Growth prevention fits your budget

Airbridge Growth pricing is a custom quote based on monthly active users or install volume, arranged through sales. Growth contracts are negotiated with sales and can be structured on a monthly or yearly basis. The Fraud Protection feature adds no separate charge within that plan, so the decision depends on the total Growth quote, the contract term, and the expected cost of fraud to the business.

Use your actual figures, then separate the costs you can attribute from savings you merely hope to achieve.

  1. Estimate direct exposure. Total the recent disputed media charges and affiliate or CPI payouts that your records support. Keep the invoice and payout amounts separate because their rules and remedies differ.
  2. Estimate the recurring exposure. Use prior incidents to calculate a monthly or annual range for confirmed invalid events. Include only amounts your evidence and contract or platform decision support.
  3. Compare with the quote. Put Airbridge Growth’s quoted cost for the contract term beside that exposure. Add any implementation work your team expects to do, so the comparison reflects the full commitment.
  4. Compare annual totals. If the contract is annual, the relevant test is an annual exposure estimate against the annual quote, not a single bad month against one month of pricing.
  5. Choose the operating mode. If a false positive could disrupt valid campaign reporting, begin with monitoring-only on a rule that needs observation. If evidence supports rejection, configure auto-reject for that rule and monitor the resulting fraud reports.

For a made-up example, assume a team documents $18,000 in invalid payouts and media charges over the past year and receives a $24,000 annual Growth quote. The documented past exposure is $6,000 below the quote, so the team would need evidence of other value or higher forward exposure to justify that quote on direct fraud cost alone.

For a smaller team, the right question is whether prevention saves enough founder time and protects enough contribution margin to justify the actual contract commitment. A team with sporadic, low-value anomalies may prefer better partner notice discipline and existing MMP reports. A team that repeatedly faces click injection, SDK spoofing, or device-farm patterns may value per-rule thresholds and real-time blocking, especially when it can review results before enabling auto-reject.

Build a review packet while the incident is fresh

A useful packet connects the spike to the amount under dispute. Keep original exports and invoice files, preserve time zones, and note when each report was downloaded so a reviewer can compare the same date range. Include the account ID and transaction ID in each export filename so the files stay tied to the right case.

  1. Save the baseline and spike. Export attributed installs by day, campaign, source, and platform for the incident window and a comparable prior period. Mark the date the count changed, and record whether the jump appeared in all sources or a single channel.
  2. Save the actual charge. Download the invoice, account transaction, or partner statement. Record the issuer, account, invoice number, billing period, line item, currency, quantity, and disputed amount. For Google Ads, preserve the “Invalid activity” adjustment and credited-click report if present.
  3. Preserve event-level evidence. Keep install timestamps, campaign and source identifiers, device or IP patterns when available to your team, and post-install quality data such as trial starts or paid subscriptions. Match each event timestamp, source identifier, and post-install quality signal to the relevant platform policy or contract definition.
  4. Export the MMP decision trail. Save fraud flags, rejection reasons, validation-rule results, callbacks, postbacks, and report filters. Include the rule configuration and effective date so the recipient can see what the system evaluated during the spike.
  5. Match evidence to the payer. For an ad invoice, submit the charge record and related activity to the platform that issued it. For CPI or affiliate spend, match each disputed event to the insertion-order rule and send the notice to the contract’s named contact. For an MMP report dispute, give the MMP the event IDs and the attribution change you want reviewed.
  6. Meet the shortest written deadline. Put the applicable notice clause and its trigger date at the top of the packet. The Affiliati Network example uses 21 days from the dispute or from the charge or invoice, whichever occurs first; another counterparty’s agreement may set a different clock.
  7. Keep a decision log. Record submission date, recipient, case number, files sent, response, and any later adjustment. If the MMP updates its findings, send the new report as a dated supplement rather than replacing the original evidence.

This packet keeps three questions distinct: what activity the attribution system counted, what the billing record charged, and what the governing platform policy or contract allows. That separation makes the request easier to route and gives the reviewer a clear path from the spike to the requested adjustment.

FAQ

Does a tripled attributed-install count prove I was billed for three times as much?

No. It proves the attribution report counted more installs for its selected period and filters.

Can an MMP issue the credit for an ad-platform charge?

The MMP can change attribution records, issue fraud flags, and send rejection signals when its features support them. Ask the media platform or network that issued the charge to make the billing decision.

Does Google always credit invalid activity discovered after billing?

No. Google says it credits invalid activity when appropriate and possible.

Is Airbridge Fraud Protection part of Core?

No. Airbridge documents Fraud Protection as a Growth Plan feature. Growth includes configurable thresholds, monitoring-only or auto-reject settings, and ad-network sensitivity controls.

What should I send first in an affiliate fraud dispute?

Send written notice under the agreement’s stated process, with the disputed event IDs, the rule or clause involved, the affected dates, and the statement line. The Affiliati Network advertiser agreement sets a 21-day written notice period, measured from the claim or dispute date or the charge or invoice date, whichever occurs first.

Get Started Free

See how these criteria hold up on the real thing.

Get Started Free