Moderation policy
A person reads every ad before it runs. Here is what they are checking, all of it. It is a floor rather than a limit - the last rule is the one that says so, and it is the one we cite when we turn something down for a reason nobody wrote here. We always name a rule, and you never pay for what didn't run.
This is public because most of it exists to protect maintainers, and you can only hold us to rules you can read. "We" is Principle Stash Inc, which runs Obrigado.
The rules
Don't imply a package endorses you
Your copy can't say or suggest that a package, its maintainers, or the organisation behind it recommends you, works with you, or is connected to you at all.
Why. Nobody asked these maintainers anything. Their name is not ours to lend you.
Enforcement: applied by a human reviewer.
Name a package in targeting, not in the ad
You can target a package, and only you see that. You can't put its name in the line a developer reads, unless its maintainers have said in writing that you may.
Why. Choosing who sees your ad is between you and us. Printing somebody's project name beside your product pulls in a third person who never agreed to be there.
Enforcement: checked automatically on every submission.
Any maintainer can opt out, no questions
If you maintain a package, ask us to keep it out of targeting and we will, within one business day. You don't have to say why.
Why. Your package is in here because somebody else installed it. You were never asked and you get nothing from it, so the one thing you can ask for should cost you nothing.
Enforcement: honoured on request, within one business day.
Some things we don't carry at all
No adult content, gambling, weapons, tobacco or vapes, recreational drugs, payday lending, binary options, or crypto speculation. No health, income or investment claims we would have to take your word for. Nothing illegal where the ad runs, and nothing from an advertiser or a beneficial owner under sanctions.
Why. This line appears inside somebody's terminal while they are working, next to our name and a maintainer's project. Most of that list is ordinary advertising somewhere else. Not here.
Enforcement: applied by a human reviewer.
Don't wear the colour a terminal keeps for failure
Pick from default, cyan, blue, green or magenta. Red and yellow aren't on offer.
Why. Your line renders in the middle of somebody's build output, where red already means something broke. Borrowing that colour buys a couple of seconds of attention by making a developer think their own work failed.
Enforcement: checked automatically on every submission.
Don't shout over the label
Emphasise a word if you like. You can't emphasise enough of the line to compete with the `oss-sponsor` label beside it, and there is no bold-the-whole-line option.
Why. That label is what makes the line honest. A disclosure the ad can out-shout is decoration.
Enforcement: checked automatically on every submission.
We can refuse or stop an ad for a reason not on this list
These rules are a floor, not a limit. We might refuse a creative, or stop a campaign that is already running, for a reason nobody wrote down here. We'll tell you which. Nothing already served comes back; nothing you paid for and didn't get is kept.
Why. A list of rules is also a list of everything missing from it, and a network that had to cite one before refusing anything has published the specification for what it can be talked into carrying. Discretion is the honest answer, so it is written down rather than used quietly. What it costs you is money, and that part is not discretion.
Enforcement: applied by a human reviewer.
How the line is labelled
Every line runs behind oss-sponsor ·. A developer can turn that off in their own install with obrigado config label off. Their terminal, their call. Nobody else can: not you, not us, and there is no setting on this side that does it.
If we spot a typo
We fix typos and broken markup rather than send the line back. Nothing else - not the wording, not the link. Your campaign page shows the line exactly as you wrote it.
If we turn your ad down
We'll name the rule. If you think we got it wrong, reply and say so. Most of these are judgement calls, and a judgement call is something you can argue with.
If you maintain a package
Your package's page - /p/npm/your-package and the same for every other ecosystem - lists every advertiser targeting it under "Advertisers targeting this package". You can see who before deciding anything, and the opt-out above needs no reason once you have.