This Privacy Policy explains what personal data AutoBidPilot (the "Operator", "we", "us") handles when you use AutoBidPilot at https://autobidpilot.com (the "Service"), why we handle it, who else sees it and what you can do about it. It describes how the Service really works today; if the Service changes, this page changes with it.
Who we are
The Operator of the Service and the controller of your personal data is AutoBidPilot. You can reach us at [email protected].
AutoBidPilot is an independent tool. It is not affiliated with, sponsored by or endorsed by Freelancer.com (Freelancer Technology Pty Limited and its group). Freelancer.com is a separate service with its own terms and privacy policy.
What we collect
Data you give us
- Account data: your name, email address and a password hash (we never store your password itself). If you sign up or sign in with Google or GitHub we receive your name, email address, profile picture and that provider's user ID from the provider, and we do not receive your provider password. Email verification is used to confirm your address.
- Settings and preferences: your skills, preferred countries, client filters, pricing ranges, bidding style and auto-bidding limits, proposal templates, and any local profile details you edit in the app (about text, portfolio items, experience entries).
- Support and contact messages: the content of support tickets and chat messages, any attachments (images and PDFs), and the contact form (name, email, optional phone number, subject, message). For contact-form submissions we also store the IP address and browser user-agent of the sender to deal with abuse.
- Referral data: your personal referral code and, if you were invited, the code you arrived with (see Referral program).
Data we create or receive while the Service runs
- Bids and proposals: each bid placed for you or by you, including the project it was for, the amount and period, the exact proposal text sent, the proposal style, the outcome and any error returned by Freelancer.com.
- Credits ledger: an append-only record of every credit granted, spent, refunded or adjusted on your account, with the reason and date.
- Activity and audit logs: a log of actions in your account (for example a bid placed automatically) and a separate administrator audit log recording changes administrators make (for example credit adjustments or settings changes).
- Auto-bidding run records: when runs started and stopped, why they stopped, and counters such as projects scanned, skipped and bid on.
- Technical data: standard server logs (IP address, browser type, requested pages, time) and the cookies described in Cookies and analytics. We do not store your raw IP address on your user record; see the referral section for the hashed value we keep.
Your Freelancer.com connection
The Service works by acting on your Freelancer.com account, so connecting it is the core of what we do. When you connect through Freelancer.com's OAuth sign-in (or paste an access token yourself):
- We receive and store an OAuth access token for your Freelancer.com account. We use it to search projects and to place bids on your behalf, and only on the instructions you give us (a manual bid you submit, or an auto-bidding run you start). The token is stored in our database and is not shown in the app after it is saved. While you have an auto-bidding run active (or one that ended recently), a copy of the token is passed to our bidding engine so that it can keep working, and a refreshed token is pushed to the engine as well.
- We sync profile data from your Freelancer.com account: your username and Freelancer user ID, display name, avatar, country, city and timezone, account status, registration date, reputation and rating figures, skills (jobs), default currency, portfolio items, and your bid allowance (plan and the number of bids remaining, where Freelancer.com provides it). You can refresh or change what is synced from the Profiles pages.
- We fetch projects from Freelancer.com (title, description, budget, skills, time posted) and the public client information Freelancer.com exposes with each project (such as the client's country, verification flags and rating). We cache these listings so we can match them to you.
- We write back to Freelancer.com only what you ask for: bids, and updates to your skills list when you choose to push them.
- One-to-one link. A Freelancer.com account can be linked to only one AutoBidPilot account. We keep a record of which AutoBidPilot account a Freelancer.com account was first linked to, and that record remains if you disconnect.
You can disconnect Freelancer.com at any time from the app; that removes the stored token. You can also revoke AutoBidPilot's access from within your Freelancer.com account settings. Your use of Freelancer.com remains subject to Freelancer.com's own terms and privacy policy.
How we use your data
- To create and secure your account, verify your email and keep you signed in.
- To run the Service: find projects that match your skills and filters, generate proposals, place bids you have asked for, track credits and show your history and statistics.
- To act on your instructions: auto-bidding places bids only when you start a run and only within the limits you set; each placed bid costs credits as described in the Terms of Service.
- To communicate with you: verification and password-reset emails, support replies, credit and referral notices, and replies to contact-form messages. We do not send marketing newsletters from the Service.
- To prevent abuse and fraud (including referral fraud), keep the platform stable and investigate problems.
- To meet legal obligations and to establish or defend legal claims.
Where the law requires a legal basis, we rely on performing our contract with you (running the Service you signed up for), our legitimate interests (security, fraud prevention, improving reliability), compliance with legal obligations, and your consent (analytics cookies, which are off unless you accept).
Proposal generation and third parties
To write a proposal, our engine sends the text of the project (its title and description), together with writing instructions built from your chosen style and the profile facts you have given us (for example your skills and portfolio links), to a third-party AI proposal-writing service. That service returns the proposal text. The service's own provider receives and processes that text on its own systems, and it may in turn use an AI model provider. We do not control that provider's retention or practices, and you should not put anything in your profile or templates that you do not want processed this way. We check the returned text ourselves before any bid is placed, and we discard text that fails our checks.
We send the project text and instructions only; we do not send your password, your Freelancer.com token or your payment details to that service. We may change the proposal provider at any time and will update this page when we do.
Who else handles data
We do not sell your personal data. We share it only with service providers that help us run the Service, and as the law requires.
| Who | Why | What they see |
|---|---|---|
| Freelancer.com | The platform you connect; we call its API on your behalf | Your token-authenticated requests, your bids and proposal text, project searches |
| Third-party proposal-writing service | Writes proposal text | Project title and description and our writing instructions (see above) |
| Email provider (a transactional email service, configured by us) | Sends verification, password-reset, support, credit and referral emails and contact-form notifications | Recipient address and the email content |
| Google and GitHub | Optional social sign-in | Your sign-in request; they tell us your name, email, avatar and ID |
| Cloudflare | DNS, CDN and secure tunnel in front of our servers | Traffic to the site, including IP addresses and request metadata, as a network intermediary |
| Hosting provider | Hosts our servers, database and Redis store | The data we store, on servers we control |
| hCaptcha (when enabled) | Bot protection on sign-up and sign-in forms | Browser and interaction signals needed to tell humans from bots |
| Google Analytics (only if you accept) | Aggregate page statistics | See the Cookie Policy |
| Font and script hosts (for example Bunny Fonts, jsDelivr, Tailwind CDN) | Deliver fonts and page scripts | Your IP address and browser details when your browser fetches them |
Our bidding engine processes data with Redis, a data store running on our own servers, where task state (for example the status, counters and settings of your auto-bidding runs) is held.
We may also disclose data if required by law or a valid legal process, to protect our rights, users or the public, or in connection with a merger, sale or reorganisation (in which case we will tell you if your data becomes subject to a different privacy policy).
Referral program
If someone invites you with a link containing a referral code, we set a cookie named abp_ref (and a session value) holding that code so the invitation can be credited when you sign up. We link the invitation to your new account and, once you first connect Freelancer.com, may grant referral credits to the person who invited you (and sometimes to you).
To detect abuse (for example one person creating many accounts), we store hashed network fingerprints on your account and on the referral record: a salted one-way SHA-256 hash of your IP address and of your browser user-agent. We never store the raw IP address for this purpose, and we cannot reverse the hash into your IP address. Suspicious referrals may be held for manual review by an administrator.
How long we keep data
| Data | Retention |
|---|---|
| Account, profile, settings, bids, proposals and credits ledger | While your account exists. The credits ledger and audit logs may be kept longer, in reduced form, where we need them for accounting, dispute handling or to prevent abuse. |
| Freelancer.com access token | Until you disconnect Freelancer.com, it is replaced, or your account is deleted. |
| Auto-bidding task records in the bidding engine | Ended runs are kept for 7 days in the engine, then forgotten there. Our run history in the main database stays with your account. |
| Cached project listings | Listings are refreshed continuously; older listings can be purged by administrators. Those you bid on stay linked to your bid history. |
| Freelance news digest items | Headlines and short excerpts are pruned after 90 days. This is not personal data. |
| Support tickets and attachments | Until the ticket is deleted or your account is deleted; attachments are deleted with their ticket. |
| Contact form messages | Until we delete them, normally once handled. |
| Session records and API tokens | Sessions expire after 120 minutes of inactivity; per-session API tokens expire after 72 hours and expired tokens are pruned. |
| Server and application logs | Kept for a limited period for troubleshooting and security, then rotated or deleted. |
Deleting your account. You can ask us to delete your account at any time (see Your rights). We will delete or anonymise your personal data, subject to anything we must keep by law or to protect against abuse, and will remove your stored Freelancer.com token. Deletion cannot be undone and unused credits are forfeited.
Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, receive a copy in a portable format (export), restrict or object to some processing, withdraw consent you gave (without affecting earlier processing), and complain to your data-protection authority. You can correct most of your data yourself in the app. For anything else, including access, export and deletion, contact us through a support ticket or at [email protected]. We may need to verify that the request comes from you, and we aim to respond within one month.
Security
We use measures appropriate to the risk: passwords are stored only as salted hashes, the Service is delivered over HTTPS through Cloudflare, sessions and API tokens expire, internal service-to-service calls (such as credit reservation and webhooks between the app and the bidding engine) are signed with a shared secret, the bidding engine is not exposed directly to the internet, access to administration is limited to administrator accounts and sensitive administrator actions are audit-logged. Referral fingerprints are one-way hashes. No system is perfectly secure, so please use a strong, unique password and tell us promptly if you suspect misuse of your account.
International transfers
Our servers, our providers (including the proposal-writing service, the email provider and Cloudflare) and Freelancer.com may be located in countries other than yours, which may have different data-protection laws. By using the Service you understand that your data will be transferred to and processed in those countries. Where the law requires it, we rely on appropriate safeguards for such transfers.
Children
The Service is for people aged 18 or over. It is not directed at children and we do not knowingly collect data from anyone under 18. If you believe a child has given us data, contact us and we will delete it.
Changes to this policy
We may update this policy as the Service changes (for example when card payments are introduced). We will change the "Last updated" date at the top and, for material changes, tell signed-in users in the app or by email. Continuing to use the Service after a change takes effect means you accept the updated policy.
Contact
Questions or requests about this policy or your data: [email protected]. You can also open a ticket from inside the app.
See also: Terms of Service · Cookie Policy