brigado adj. bound, obliged, indebted · int. thank you

Questions

The long form of most answers is on the transparency page and in the launch post.

Where does the money actually go?
70% of gross funds fixed-term grants to open source maintainers. The other 30% runs the business: processing, legal, infrastructure, salaries, and what is left reinvested in more ambitious bets on sustainable open source. Costs never touch the 70%, the fiscal host's fee included, so a grant arrives at the amount committed. Every grant is on the transparency page.
What do I get out of it?
You get to help build a sustainable open source ecosystem that everyone benefits from, with no technical skills or capital needed.
What's the best way to financially support open source projects?
Give directly to the maintainers, so they keep all of it: GitHub Sponsors takes no fee on a sponsorship from a personal account. If that's not possible, give through a platform like Open Collective or thanks.dev. Obrigado is a great option if you want to support open source and promote something at the same time.
What does this cost advertisers?
$2.18 CPM reserve. Below that nothing clears. It's published so advertisers bid against each other instead of against a rate card.
What does install actually touch?
One key. statusLine in your agent's own settings, written through the interface that agent documents. Nothing else, and no file belonging to another program gets read or rewritten. It also asks four targeting questions, all defaulting to no, and prints the JSON your answers produce. Uninstall puts it back.
What do you collect about me?

By default: the package names in your lockfile, your agent and OS, and whether anyone is at the keyboard. Never your hostname, your repo name, or a file path. It sits under a random install ID, not an account. Your lockfile counts toward the totals we publish either way; no package is named there until 5 separate installs report it.

Opt in and advertisers can also aim at those packages, your country, your IP range, and what your agent has been reading. This is the exact JSON a render sends, either way:

obrigado privacy

{
  "deps": [
    { "p": "npm:react", "d": 0 },
    { "p": "npm:scheduler", "d": 1 }
  ],
  "private_repo": false,
  "signals": {
    "ci": false,
    "tty": true,
    "display": true,
    "agent": "claude-code",
    "agent_version": "2.1.4",
    "client_version": "0.1.0",
    "surface_version": "0.1.0",
    "os": "linux",
    "sharing": {
      "packages": false,
      "region": false,
      "network": false,
      "activity": false
    },
    "docker": false,
    "container": false
  }
}
{
  "deps": [
    { "p": "npm:react", "d": 0 },
    { "p": "npm:scheduler", "d": 1 }
  ],
  "private_repo": false,
  "signals": {
    "ci": false,
    "tty": true,
    "display": true,
    "agent": "claude-code",
    "agent_version": "2.1.4",
    "client_version": "0.1.0",
    "surface_version": "0.1.0",
    "os": "linux",
    "sharing": {
      "packages": true,
      "region": true,
      "network": true,
      "activity": true
    },
    "retrieved": ["npm:react"],
    "docker": false,
    "container": false
  }
}

The sharing block is permission, not information. Your country and IP range come off the connection, get matched, and are never stored.

Once the line is shown, a second request confirms it. No prompt, no message, no filename, no model, no cost.

{
  "events": [
    {
      "type": "impression",
      "impression_id": "8f1c0e2a-5d77-4a31-9b0e-2c6f1d4e8a55",
      "nonce": "3Qk1r0Zp8vJt2mXq5Lw9Aw==",
      "signals": {
        "timing": { "session_s": 1840, "api_s": 412 }
      }
    }
  ]
}
{
  "events": [
    {
      "type": "impression",
      "impression_id": "8f1c0e2a-5d77-4a31-9b0e-2c6f1d4e8a55",
      "nonce": "3Qk1r0Zp8vJt2mXq5Lw9Aw==",
      "signals": {
        "timing": { "session_s": 1840, "api_s": 412 },
        "retrieved": ["npm:react"]
      }
    }
  ]
}
How does ad targeting work here?
Every campaign's rules are published on the live-ads page, ranges included. No other ad network shows you its advertisers' target lists; this one does, and that is the control that applies to it: a maintainer can see who is aiming at their package, and any maintainer can be excluded from targeting entirely within one business day, without giving a reason. Rules of different kinds combine with and, so npm:react plus region:DE reaches React users in Germany rather than both groups.
Can an advertiser target my packages, my location or my company?
Only if you turned it on. Your lockfile, your region, your IP range and what your agent has been reading reach only developers who enabled them; all four are off by default, none of them earns you anything, and obrigado privacy switches them off again, deleting what was stored rather than merely ceasing to read it. Say no to all four and the line still runs and still funds the same grants: the flag decides only whether an advertiser may aim at your lockfile, never whether it is worth anything. Impression counts are withheld for campaigns targeting an IP range, because a count beside an address is a measure of one company's working day.