Trust and safety
Onflow Ads is a marketplace. Real money and real audiences move between people who have usually never met, often across countries, usually without a contract. This page explains the system that makes that safe, and points you to the page that covers each part of it in full.
The problem this system solvesโ
Every placement on Onflow Ads has the same shape: one side pays first, the other side delivers afterwards. That gap is where every marketplace fraud lives โ the post that never goes up, the post that quietly comes down, the buyer who takes the delivery and then claims it never happened.
Four things close that gap:
- Money is held, not handed over. Payment sits in escrow until the placement runs as agreed.
- Delivery is verified, not asserted. A monitor checks the post is live and stays live, and the result is archived as proof.
- Conduct is scored and published. Every account carries one reliability number, moved only by confirmed outcomes and written to a ledger you can read.
- Disputes end with a person. Automated systems can pause money and apply published penalties; only a human resolves a concern, and every penalty can be appealed within 30 days.
Good-faith users should never be worse off for a problem that wasn't their fault, and bad-faith users should find abuse expensive.
Who does the checkingโ
The delivery monitor is @OnflowAdsBot, watching from its administrator position inside the channel. Checking what actually happened is one of the bot's three jobs โ the other two being notifying you and publishing what the website arranged โ and it is the whole reason a listed channel has to keep the bot as an admin.
- It verifies a channel is real and that you control it, by asking Telegram for the channel and its administrator list. Only an admin can appoint an admin, so the list is the proof, and that is why nobody is ever asked for a screenshot.
- It measures reach from recent public posts, so a listing can carry figures the platform counted rather than figures someone typed. Where a live reading cannot be taken, the owner's own stated figure is shown instead โ and it is labelled, in the product, "As stated by the owner โ not measured by us". A measured figure and a declared one never look the same.
- It watches that an agreed placement stays up for its full term, which is the check underneath escrow, insurance and the reliability score alike.
Whether the ad got the hours at the top it was sold is checked by reading a page of the channel's recent public history โ what else went up in that window โ through the platform's public-channel reader rather than the bot. It is a separate Telegram identity, it holds no admin position, and it sees only what any reader of a public channel sees. Full detail: the top-of-feed exclusivity check.
Both observe and report; neither decides anything. What they see is written to the same ledger as everything else, and the website is what then holds a payout, applies a penalty or pays compensation. That also means an automated check is not a separate appeal track: you contest an entry the same way wherever it came from, on Appeals and fraud concerns.
What is read is deliberately narrow, and all of it is public: channel details, counts, the posts the platform's own placements created, and โ while an ad's exclusive window is being checked โ the timing of the channel's own recent public posts. Neither reader is ever given your subscriber list, and neither messages your subscribers. Details in the Privacy Policy.
The four parts, and where each livesโ
| Part | What it does | Read the full page |
|---|---|---|
| The reliability score | The single 0-to-10 number every account carries, what moves it, what it unlocks and locks, and how to recover a drop | Your reliability score |
| Account standing | The distinct states your account can be in โ Under Review, below a floor, support restricted, suspended, banned, connection refused โ what each blocks, and how each ends | Account standing |
| Fraud and bot protection | The automated checks you can see: the delivery monitor, anti-cheat, payment verification, anti-abuse rules, the anti-spam challenge, rate limits, automated-access blocking | Fraud and bot protection |
| Appeals and concerns | The two things you can do: contest a penalty on your record, and report a deal that went wrong | Appeals and fraud concerns |
The rest of this page covers the pieces that belong to a deal itself rather than to an account: escrow, proof, moderation and disclosure.
How a paid placement is protected, step by stepโ
This is what happens around your money on a single paid placement, from booking to payout.
- You book and pay. The charge leaves your wallet and is held in escrow. The owner does not have it yet.
- The owner accepts. On higher-value bookings the owner also stakes a refundable good-faith deposit โ their own money, returned on clean delivery and forfeited to you if they cause the failure. It is the only mechanism that makes ghosting an accepted job cost an owner something immediately, rather than only costing them score.
- The post goes live. The delivery link is recorded and the creative is frozen into a proof archive โ the exact artefact a dispute would be argued over.
- It is watched for the purchased window. The bot checks the post is still there โ and still pinned, on a booking that was actually sold with a pin, whether that was the Pinned for the whole campaign extra or the 7 days in feed ยท pinned throughout format. Separately, once the window has closed, the exclusivity check reads the channel's recent public history to see whether the ad really was the newest post for the hours it was sold. See Fraud and bot protection.
- The window ends. If everything ran clean, the payout releases to the owner, both sides earn reliability credit, and you can leave a verified review.
- If something went wrong, one of three things happens instead: the monitor flags it and holds the payout automatically; your plan's Verified Delivery Insurance refunds you without a dispute; or you raise a fraud concern and a person resolves it.
When the payout actually releasesโ
The release rule is a plan benefit, not a fixed platform rule โ higher plans release sooner, and the fastest rungs release on the first successful delivery check rather than after the full run. The exact rule for each tier is in Comparing the tiers. Two things are true on every plan:
- You can always release it early yourself by confirming the placement from your orders page, once you have checked the post is live and correct.
- A flag or an open concern always beats the clock. A flagged order or one with an open fraud concern does not auto-release, regardless of plan.
The confirm action on your orders page pays the owner straight away and cannot be undone from the interface. Check the post is live, in the right channel, and unaltered before you confirm. If it is not, raise a concern instead.
Cancelling before it runsโ
Cancelling is not a dispute, and it is the right tool when nothing has gone wrong yet โ you simply changed your mind or your plans moved.
| When you cancel | What happens |
|---|---|
| Before the owner accepts | Withdrawn and refunded in full to your wallet, with no fee and no reliability effect |
| After the owner accepted, before it is posted | Cancelled by either side for a full refund to your wallet. The owner's good-faith deposit is returned, no fee is charged and nobody's reliability changes |
| Once it is live | Refused: "This ad is already live โ it can no longer be cancelled." A placement that has run cannot be un-spent |
The Cancel booking button on your orders page names the fee percentage, and arming it shows the exact refund and fee in the confirm label before anything is committed. Full detail: Refund Policy.
Delivery proofโ
Proof is what turns "he said, she said" into a decision.
- Every delivered placement is archived. The agreed creative and the delivered link are frozen at delivery, and proof captures are timestamped. This archive is what an Onflow Ads reviewer arbitrates on โ not the two parties' prose.
- You can open the archive yourself from the Delivery proof panel on the order in your orders page.
- Third parties can verify a placement without an account. Public placement-proof pages let a client or partner confirm that a placement really ran, with no sign-in.
- Higher plans add signed Placement Proof Certificates โ see Comparing the tiers.
- When a concern is raised, the evidence is frozen at that moment: what the monitor measured, the delivery figures, and the proof-capture trail. Neither party can change the record after the fact.
Proof and certificate pages are unlisted, but anyone holding the link can open one without signing in โ that is the point of them. Share the link with the client who needs it, and treat it the way you would treat any other link that discloses a deal.
Moderationโ
- Channels are reviewed before they join the network. A submitted or edited channel sits at Pending, shows Under review on its own page, and goes live only once approved. If the reviewer asks for changes the status reads Needs changes with their note attached, and you can edit and resubmit. Walkthrough: Verify your channel.
- Every creative is checked before it can run โ words, links, buttons and pictures โ on every rail except Boost. Prohibited content is refused with the exact reason, a picture the check cannot read is held for a person, and every refusal can be appealed. See Prohibited content.
- Campaigns and creatives may be reviewed against the acceptable-use rules.
- AI-assisted content is your responsibility. Copy the AI happily wrote can still breach platform rules โ you approve everything published from your channel. See Content rules for AI.
- Anyone can report content. Terms ยง16.6 sets out notice and takedown: email [email protected] or use the contact form with a link to the exact post or listing, what is wrong with it, the right you rely on if any, and how to reach you. Knowingly false reports are themselves a breach of the Terms.
Reporting a security issueโ
A vulnerability is not a support ticket. The support chat and the contact form are the wrong place for one: both open a ticket that is read by people helping with orders and payments, and a chat message reaches a model provider on its way โ so a report sent there sits in the open for longer than it should.
There is a published, machine-readable route instead. Onflow Ads serves an RFC 9116 security.txt at both of these addresses:
It is plain text and carries five fields:
| Field | What it is |
|---|---|
Contact | Where to send the report. This is the authoritative value โ read it off the live file rather than trusting a guide page, because an operator can change it |
Expires | Always about a year ahead, refreshed so the file never reads stale โ which is what tells an automated scanner the contact is still current |
Policy | The disclosure policy the report is handled under |
Canonical | The address the file is meant to be served from, so a copy found elsewhere can be checked |
Preferred-Languages | en |
Where an operator has not overridden it, Contact is mailto:[email protected]. That is plain email, read by the team: it opens no chat and no ticket, and no model reads it on the way. Put security in the subject line so the message is handed straight to whoever can fix the flaw. No individual's address is published, and if a dedicated security mailbox is ever provisioned it appears in the file first โ which is why the file, not this page, is the authority. Open it to see what the deploy you are using actually publishes today.
What to include, whatever the contact turns out to be: what you found, the exact URL or endpoint, the steps to reproduce it, and what an attacker could do with it. What not to do: test against other people's accounts, run automated scans that degrade the service for real users, or exfiltrate data to prove a point.
Good-faith researchers will not be pursued. That commitment is in the Privacy Policy's security section, and it applies to research that stays inside the boundaries above.
Support messages reach a model provider as part of drafting a reply, land in a ticket that support agents read, and are emailed to you in a transcript. None of that is where an unfixed flaw belongs. Use security.txt โ and if you have already sent one to support by mistake, say so there and follow up through the disclosure route.
Serious abuse โ beyond the scoreโ
The reliability system handles ordinary friction between honest people. Deliberate abuse is a different category.
For deliberate fraud, scams, chargeback abuse, coordinated manipulation, or anything that harms other members, Onflow Ads reserves the right โ at its sole discretion โ to:
- Freeze payouts and the account permanently โ every balance held, nothing released
- Delete the account and all of its data in full โ with no payout, no refund and no recovery
- Pursue legal action in extreme cases
A below-baseline reliability record does not vanish with the account. Deleting and re-registering with the same identity resumes at that record's floor rather than a fresh 8.0, for a period tied to how serious the mark was โ and the carried-over amount appears on the new ledger as its own entry, with its reason. An account in good standing leaves nothing behind at all (Terms ยง15.5).
Deliver what you promise, keep it up for the agreed time, and don't defraud anyone โ and you will never encounter any of these measures. They exist solely for people who set out to abuse the platform and the members on it.
Reporting a problemโ
| Problem | Where to go |
|---|---|
| A running campaign has gone wrong โ a breach of the deal, of your channel's rules, or of the platform's, on either side | Report the campaign from its own page. Every Paid Promotions order and booking and every cross-promotion campaign carries a Report button, named for the side you are reporting โ ๐ฉ Report channel on an advertiser's order, ๐ฉ Report advertiser on an owner's booking. (A Boost order's Report a problem opens a support ticket instead, and an exchange host's remedy for an ad they object to is Refuse on the hosting list, which takes it down.) Each side gets its own reasons and its own rules, printed above the form; see Reporting a campaign for both lists in full. Pick what went wrong, describe it in your own words, and attach screenshots โ the one place on the platform that takes uploads as evidence. You get an OFRP- reference and an emailed acknowledgement; a human reads it against our own delivery record and can stop the campaign, hold a payout, refund what was not delivered and record a Reliability penalty. Filing changes nothing by itself, your evidence is never shown to the party you reported, and a reply comes by email to whichever parties the reviewer decides to address |
| A paid deal went wrong | Raise a fraud concern โ Appeals and fraud concerns |
| A penalty on your record looks wrong | Appeal it from Your ledger, within 30 days โ same page |
| Your account is blocked or paused and you don't know why | Account standing |
| Content published through the platform is unlawful or infringing | Email [email protected] or use the contact form with the link and what is wrong with it (Terms ยง16.6) |
| A security vulnerability | The security.txt route above โ not the support chat or the contact form |
| An unauthorised charge, or a suspected account compromise | Email [email protected] immediately |
| A privacy or data-rights question | Email [email protected] |
| Anything else | onflowads.com/contact, which returns an OFM- reference, or the help widget where support chat is switched on |
Relatedโ
- Reporting a campaign โ the button, the two reason lists, and when a dispute is the faster door
- Fraud and bot protection โ one level down, into the checks themselves
- Account standing โ every state a decision can put your account in
- Refund Policy (summary) โ what being made whole actually pays out
- Privacy Policy (summary) โ what protects the data behind all of this
Next: Fraud and bot protection goes one level down, into the automated checks behind all of this โ what the delivery monitor can and cannot conclude, and the exact messages each check produces.