Seatext library / BotRefund evidence
Mobile Ad Fraud Refund: Evidence Checklist That Gets Your Money Back
To file a mobile ad fraud refund claim, you need documented proof that specific clicks or conversions came from bots. This includes timestamped behavioral logs, device and IP data, click IDs, and video capture....
✓ Built for advertisers who need clear, refund-ready traffic evidence.
Filing a mobile ad fraud refund claim requires more than a hunch. You need documented, timestamped proof that specific clicks came from bots, not humans. Platforms like Google and Meta have strict review processes. They only approve refunds when you provide clear, technical evidence that ties each fraudulent interaction to your campaign.
The strongest evidence comes from client-side detection. This means tracking what happens inside the user's browser or app. Signals like ghost clicks, superhuman input speed, unnatural session durations, missing human tremor, grid-aligned mouse paths, and honeypot interactions are gold standard proof. You also need click IDs like GCLID or FBCLID to link the activity to your ad spend.
In this guide, you'll learn exactly what evidence to gather, why each piece matters, and how to submit it to Google and Meta. You'll also see how automated tools like BotRefund can capture video proof and generate audit-ready logs. By the end, you'll know how to build a case that survives platform scrutiny.
Step 1: Set Up Client-Side Behavioral Tracking
Before you can prove fraud, you need to record what real humans do versus what bots do. Client-side tracking captures events from the user's device. This is where you catch the subtle patterns that separate people from automated scripts.
Install a tracking script on your website or app. This script should log every interaction. The key signals to record include:
- Ghost click detection: Clicks that occur without the natural sequence of human intent. For example, a click that happens instantly after page load, before any movement or thought.
- Honeypot trap interactions: Hidden form fields or links that humans never see. Bots fill them or click them because they scan the DOM. Log when these traps fire.
- Robotic linear mouse movements: Unnaturally straight pointer paths. Humans move with curves and micro-corrections. Bots often move in perfect lines.
- Absence of humanlike mouse tremor: Record the jitter in pointer coordinates. Humans have tiny hand movements. Bots typically have none.
- Superhuman input speed (<1ms): Interactions faster than any person could perform. For example, a mouse event fired in 0.3 milliseconds is impossible for a human.
- Grid-aligned movement patterns: Pointer movement that snaps to exact x/y coordinates, like a grid. Humans don't do that.
- Absence of clicks or scrolling: Sessions that stay completely static. Real users scroll, click, or move. Bots often load a page and do nothing.
- Unnatural session durations: Visit lengths that are too short, too long, or too uniform. Bots often have consistent session times.
Each signal is a clue. When you see multiple signals together, you have strong evidence. For example, a session with a click in 0.2ms, no scroll, and a straight mouse path is clearly bot-generated.
Why does this matter from a platform review perspective? Google's Click Quality team and Meta's Invalid Traffic team look for behavioral anomalies that cannot be explained by human error. They want technical signals that are difficult to spoof. Pointer movement and input speed are harder to fake than IP addresses. By capturing these signals, you give reviewers concrete data to evaluate.
Step 2: Collect Device, IP, and Click ID Data
Behavioral signals are powerful, but they need context. You must tie them to a specific ad click. This requires three types of identifiers: IP address, device fingerprint, and click ID.
For each suspicious session, log the following:
- IP address: The numeric address assigned to the device. Note the exact IP, including IPv4 or IPv6. This helps platforms see if the traffic comes from a known proxy or data center.
- Device fingerprint: A unique set of characteristics from the device. Key fields include the user agent string, screen resolution, time zone, language, installed fonts, and hardware concurrency. Bots often report impossible combinations, like a mobile user agent with desktop screen resolution.
- Click ID: The unique identifier that platforms assign to each ad click. For Google Ads, this is the GCLID. For Meta Ads, it's the FBCLID. These are critical because they let the platform look up the exact click in their logs.
Also capture the timestamp for each event. Use ISO 8601 format (e.g., 2025-03-20T14:30:00Z) with milliseconds. Consistent timestamps help you build a timeline that reviewers can follow.
Why does this matter? IP addresses alone are weak evidence. Bots can rotate through residential proxies. But a device fingerprint that mismatches the user agent is strong proof. For example, a session with a high-end iPhone user agent but a window size of 1024x768 and a time zone of UTC+5 from a US IP – that's suspicious. Platforms use fingerprint data to spot such inconsistencies.
Click IDs are non-negotiable. Without them, you cannot link the behavior to a billing charge. Google will not process a claim without a valid GCLID. Meta requires FBCLID for its disputes. Tools like BotRefund automatically log these IDs for you, as mentioned in their ad fraud trends guide.
Step 3: Record Video Proof and Export Logs
Video proof is the most compelling form of evidence. It shows exactly what happened in the browser. A short screen recording can make your case undeniable.
When you capture video, record the full session or the portion where the bot acts. Include the URL bar, the mouse pointer, and any visible page elements. Show the timing – if a click happens in under a millisecond, that's visible. Show the straight mouse path, the absence of scrolling, or the honeypot interaction.
Most automated tools, including BotRefund, capture video automatically. Their homepage states: "We detect every bot that clicks your ads and capture video proof for each one." This means you don't have to manually record sessions. The tool saves the video and associates it with the click ID.
After you have video, you need to export audit-ready behavioral logs. These logs should be structured and easy to read. Include the following columns:
- Timestamp (with timezone)
- Click ID
- IP address
- Device fingerprint hash
- Behavioral signals detected
- Session duration
- URL where the click occurred
Organize logs by campaign and date. Use CSV or PDF format, as these are accepted by both Google and Meta. The Google Ads refund guide from BotRefund says to "Export detailed client-side behavioral proof logs to win your Google invalid click dispute." This is the step where you turn raw data into a professional report.
Why is this step critical? Platforms deal with thousands of claims. A messy log or a vague description gets ignored. A clear, time-stamped, and well-formatted log shows you've done your homework. It also makes it easy for a reviewer to verify your claims. Video proof reinforces the log data, giving reviewers a visual confirmation.
Step 4: Submit the Refund Claim to the Right Platform
Now that you have your evidence, you need to file the claim. Google and Meta have different processes. You must follow each platform's official channel.
For Google Ads, you use the Click Quality investigation form. This form is part of Google's invalid click dispute process. You'll need to provide your customer ID, campaign IDs, and the specific clicks you're disputing. Attach your behavioral logs and any video evidence. Google typically reviews these claims within a few business days, but complex cases may take longer.
For Meta Ads, you use the Invalid traffic dispute process. This is accessed through your Ads Manager or through a direct support request. You'll need to provide your ad account ID, campaign details, and the same type of evidence. Meta's review process emphasizes user reports and behavioral anomalies. They may ask for additional information if your evidence is not clear.
Here's a quick comparison of their requirements:
| Criterion | Google Ads | Meta Ads |
|---|---|---|
| Official form | Click Quality investigation form | Invalid traffic dispute process |
| Required IDs | GCLID for each click | FBCLID for each click |
| Evidence format | Client-side behavioral logs, CSV or PDF | Behavioral logs, video, and report |
| Review time | Typically 2-5 business days | Can take up to 10 business days |
| Refund window | Backdated to 2017 for invalid clicks | Check with vendor for exact window |
Both platforms require proof that the clicks were invalid. They don't accept simple complaints. They want data that matches their own detection signals. That's why your evidence must be precise and technical.
Remember to check with the vendor for the latest form URLs and requirements. Platform policies change.
How to Interpret Behavioral Logs
Reading your logs correctly can be the difference between a successful claim and a rejection. Many advertisers look at a log and see a list of events, but don't understand what suggests bot behavior.
Start by looking for patterns. A single anomaly might be a coincidence. But if you see a session with a superhuman click, zero scroll, and a straight mouse path, that's a clear bot. Reviewers want to see multiple signals converging.
Pay attention to timing. If many sessions have identical durations, like exactly 4.5 seconds, that's unnatural. If clicks happen at the same millisecond across different IPs, that indicates a scripted attack. Look for bursts of activity with no human variation.
Device fingerprints are also revealing. A bot might report a user agent for Chrome on Windows but have a screen resolution of 1366x768 – that's common. But if it reports a Mac user agent and a resolution of 1920x1080 with a touch event, that's impossible. Scripts often mix fields incorrectly.
IP addresses help you spot proxies. If you see many IPs from a single subnet or from known data centers, that's suspicious. However, modern bots use residential proxies, so IP alone won't catch them. You need the behavioral signals in your logs to prove fraud.
When you interpret, also check the click path. Did the user land on a page and immediately click a link? That might be a bot following a script. Did they scroll through your content before clicking? That's more human. Logs should show the sequence of events.
Finally, compare the log against the video. If your video shows a mouse that never moves but the log says a click occurred, that's proof of a ghost click. Matching these together reinforces your case.
Limitations, Edge Cases, and FAQ
Even with strong evidence, your claim may be rejected. Understand the limitations before you file.
Common rejection reasons:
- Only IP-based evidence. Platforms rarely accept this alone because IPs can be spoofed.
- No click IDs. Without GCLID or FBCLID, you can't prove the clicks came from your ads.
- Inconsistent timestamps. If your logs don't have precise timestamps, reviewers may doubt their accuracy.
- Vague descriptions. Simply saying "bot traffic" without technical evidence is not enough.
Refund windows: Google allows claims for invalid clicks dating back to 2017. Meta's window may be different – check with the vendor for specifics. Act quickly to avoid missing deadlines.
Partial rejections: If only some of your disputed clicks are approved, you'll receive a partial credit. Review which ones were rejected and see if you can provide more evidence. You can sometimes appeal the decision.
Appeal process: You can usually appeal a denied claim by providing additional evidence. For Google, you may contact the Click Quality team again. For Meta, use the support channels. Be prepared to submit more detailed logs or a clearer explanation.
Now, here are more FAQs to guide you.
Do I need video proof for every refund claim?
No, but video proof significantly strengthens your case. It's the clearest way to show a bot's unnatural behavior. Tools like BotRefund automatically capture video for each bot click, so you don't have to record manually.
Can I use only IP addresses as evidence?
Rarely. IP addresses can be spoofed or belong to shared networks. Platforms want behavioral evidence that cannot be easily faked. Always combine IP with device fingerprint and behavior.
What is a GCLID and why do I need it?
GCLID is Google's Click ID that tracks each ad click. It ties the fraudulent activity to your campaign. Without it, Google cannot verify the click in their system. Same for FBCLID on Meta.
How far back can I claim refunds?
BotRefund mentions recovering refunds from Google Ads spend dating back to 2017. For Meta, check with the vendor for their retention policy. Act before you lose the data.
Do Meta and Google have different evidence requirements?
Yes, each platform has its own form and evidence preferences. Google's Click Quality team focuses on technical invalid clicks. Meta's process emphasizes user reports and behavioral anomalies. Both want detailed logs and click IDs.
Can I file a claim without a third-party tool?
Technically yes, but manually collecting and formatting behavioral logs is time-consuming and error-prone. Automated tools generate audit-ready reports that align with platform expectations. They also capture video proof, which is hard to get manually.
What if my claim is partially approved?
You'll get a credit for the approved portion. Review the rejected clicks. You can appeal by providing more evidence, such as clearer video or additional fingerprint data.
Are there any deadlines for filing?
Yes. Google allows claims dating back to 2017, but you should file soon after detection. Meta's window may be shorter. Always check the platform's policy.
How do I know if my evidence is enough?
A good rule: if you can show a bot-like behavior pattern, a click ID, and a timestamp, you have a strong case. If you can add video, it's even stronger. If you lack any of these, your claim may be rejected.
What should I do if my claim is denied?
Review the rejection reason. Often it's missing evidence. Gather more data, such as additional sessions or better video, and appeal. Tools like BotRefund can help you recover from denials.
Use this checklist as your guide. With the right evidence, you can recover wasted ad spend and protect your budget.
Further reading and comparison sources
These external sources provide additional context for evaluating the topic. Their inclusion is not an endorsement.
Learn more
Visit the website for more information.