Privacy
Everything this site handles, in the order it happens. It is a short page because MediaBid collects very little: no accounts, no logins, no advertising trackers, no analytics cookies. Most of what is here is the listings themselves, and those are public on purpose — that is the product.
Anyone can list any handle. Anyone can ask for it to come off.
Somebody can pay to list a handle they do not run, including yours. That is how the board works, so this is the part worth reading first.
What a lot shows is only what the public profile already shows: the display name, the bio, the profile photo, the follower count and a link to the account. Nothing private, nothing from behind a login, no email address, no messages. And a bid buys a place on the board, not the account — nothing here changes who owns a handle or who can log into it.
To have a listing removed, use the takedown route on the contact page and give the platform and the @handle, or a link to the lot. One line is enough. You do not have to be the person who paid, and you do not have to give a reason.
The lot then leaves both boards, the activity feed, Trending and the sitemap; its lot page and its outbound link stop resolving; and the handle cannot be listed again by anyone. Say so in the same message and the copied profile photo is deleted from our storage as well.
MediaBid is not affiliated with, endorsed by or connected to X Corp. or Meta, so reporting a lot to them does not reach us. Write to us and we act on it. The mechanics of a takedown are in how it works.
What is published, on purpose
A listing is the product, so everything in it is public by design. For each lot the board shows the platform, the @handle, the display name, the bio, the profile photo and the follower count, plus a link to the profile.
All of that is read from the public profile through public endpoints — the same details anyone sees without logging in. We never see a private account, a message or an email address, because nobody logs into anything here. Whoever pays can also type those fields in by hand when a platform does not answer.
The profile photo is copied once into our own storage and served from there. Both platforms expire their image URLs, so without a copy the picture on the board would break within days.
Bids are public too: the amount, the time it landed and the rank it produced. They show on the board, on the lot page and in the activity feed. No name and no email is attached to a bid anywhere on this site.
Clicks, and the value that stands in for an address
When somebody clicks from a lot through to the profile, the browser sends a short note to
/api/clicksaying which listing was clicked. We store the listing, the time, and one value derived from the network address the request came from.That value is a SHA-256 hash of the address, a server secret and the current date. The address itself is never written down. The hash cannot be turned back into an address, and because the date is mixed in, the same visitor becomes a different value tomorrow.
It exists for one job: telling one person clicking ten times apart from ten people clicking once, and spotting a script inflating a click count. That is all it can do. It identifies nobody, it is not joined to anything else, and it is not used to build a picture of a visitor.
Click rows are kept for 90 days and then cleared. The running total printed beside a lot survives; the rows behind it do not.
Payments happen at Stripe, not here
Checkout runs on Stripe’s own pages. No card number, expiry date or security code ever reaches MediaBid — not our servers, not our database, not our logs. There is nothing here to lose, because we never hold it.
Stripe receives what you give Stripe: your email address, your payment details and the amount. It handles those under its own privacy policy.
The listing details travel with the payment so the bid can be applied the moment it succeeds: platform, handle, amount, and the display name, bio, photo and follower count you saw in the preview. Those are the same public details the lot will then publish.
Afterwards we store the amount, the time, the rank and Stripe’s checkout session reference. The reference stops one payment being counted twice and lets a single payment be traced if something goes wrong. We do not store the payer’s name, email or card. MediaBid has no accounts and no passwords, so there is no profile of you on our side to keep.
Looking up a handle, and the rate limit behind it
Paste a handle and our server — not your browser — asks X or Instagram for the public profile. The platform sees a request from us. Nothing about you goes with it.
To stop a loop hammering those endpoints, the import route counts requests per network address for one minute at a time. That count lives in the memory of the running process. It is never written to a database or a file, and it is gone the moment the process restarts.
Profile photos on the board are served through this site rather than hotlinked, so reading a board does not make your browser call X or Instagram.
No trackers, no analytics cookies, no banner
There is no advertising pixel on this site. No analytics script, no marketing tag, no session recorder, no cross-site tracking, nothing that follows you after you leave. We do not set a cookie to remember you, because there is nothing to remember — there is no account to be logged into.
The fonts are served from this site, not fetched from a third party while you read.
The only cookies anywhere near this are Stripe’s own, set on Stripe’s pages during a checkout, to run the payment and keep it secure. Start no checkout and you never meet them.
That is why there is no cookie banner. A banner asking permission for tracking that does not happen would only cost you a click.
Where the data lives
Listings, bids, clicks and the copied profile photos sit in a hosted Postgres database and file storage run by Supabase. The site itself is served by a hosting provider. Like every website, that provider keeps its own short-term request logs, which can include network addresses; those sit outside our database and under that provider’s own retention.
Nothing here is sold, rented or handed to advertisers or data brokers. The only third parties involved are the ones needed to run the thing: the payment processor, the database host and the hosting provider.
How long things are kept
- A listing stays up until it comes off — by request, or because we removed it. Removal is done by hand, and quickly.
- Individual click rows: 90 days. The total beside the lot stays; the rows behind it go.
- Bid records are kept as the record of a payment, for accounting and for disputes. They are amounts and timestamps, not people.
- A takedown request is kept with the handle it concerns, so the handle stays blocked and so we can show what was asked and when.
What you can ask for
About any handle you are behind, you can ask us:
- what is held about it, and where it came from;
- to correct it, if the name, bio, photo or follower count is wrong or out of date;
- to take the listing off entirely.
Removal needs no reason and no proof — see the section above. Changing what a lot says is different: we may ask for something that shows you run the account, because otherwise anyone could rewrite anyone else’s row.
Write to the contact address published on this page once it is set or use the contact page, with the platform and the @handle, or a link to the lot. A person reads it and answers. None of this is automated.
Where you live may give you further rights over information about you, including the right to complain to a data protection authority. Ask and we will deal with it properly rather than point you at a form.
Under-18s
MediaBid is not intended for anyone under 18, and we do not knowingly collect anything from them. Nobody under 18 should bid. If a lot is a minor’s account and you want it gone, tell us — same route as any other takedown, no reason needed, and it comes down.
If this page changes
A material change to what we handle, or to how long we keep it, moves the effective date at the foot of this page. The version you are reading is always the current one.
Who runs this site, and when this page took effect
The operating entity and contact address for MediaBid are not published here yet, and this page will not invent either. Until they are set, reach us through the contact page. Everything described above is what the site does today, whether or not that line is filled in.
In effect since
The rules of the board itself — what a bid buys, how the links are marked, and how to come off — are in how it works.