Last updated September 15, 2026

Privacy

This notice describes the information used to operate buymybody’s creator and sponsorship marketplace.

Accounts and profile information

Connecting with X imports your stable account ID, name, handle, avatar, biography, follower count and following count. We store an import timestamp and use an opaque session cookie to keep you signed in. Public profiles display the imported profile information and timestamp. X authorization tokens are not retained after the sign-in flow.

Photographs, models and artwork

Capture photographs and fulfillment evidence are stored privately. An accepted front photograph is sent to Meshy to generate a personal model. Generated outputs are imported into our storage. Explicitly published campaign models, campaign images and sponsor artwork can be viewed publicly. Private uploads are separate from public assets and require authorized access.

Analytics you choose to share

You can upload an analytics export or enter a period summary with a supporting screenshot. We retain the selected metric values, dates, source and any post IDs needed for the report. Raw CSV files and unused columns are not retained. Reports start as private previews and appear on your profile only when you publish them. Publishing a screenshot is a separate choice. Unpublishing or deleting the report removes public access to its data and supporting screenshot. Uploaded screenshots remain in private storage unless separately deleted through a data request.

Purchased sponsorship terms and explicitly shared deliverable evidence are available to the creator, purchasing sponsor and platform operator. Campaign evidence submitted for payout review stays separate.

Payments and service providers

Stripe processes payments and creator payout onboarding. We retain payment references and status information needed to reconcile sponsorships, credits, refunds and payouts. Our application does not store your full card details. X provides account connection, Meshy provides generation, and Cloudflare R2 provides object storage.

Website analytics

When enabled, DataFast measures page visits and referrals in cookieless mode. It derives a pseudonymous visitor identifier from technical signals including IP address and browser information, using a salt that rotates daily. Session-only browser storage may support continuity. We do not send account names, email addresses or payment identities to DataFast. The public visitor counter uses a rolling 24-hour aggregate, labelled “visitors today.” Recent activity displays only countries and session start times, without visitor identifiers, IP addresses, cities or coordinates. Sponsor-offer views and website clicks include internal campaign, spot and sponsorship IDs so each purchasing sponsor and creator can see interaction totals for that sponsorship’s measured period.

Printing partner applications

Applications contain business details, service regions, services, turnaround information and a contact email. Approved business details appear in the public directory. The application contact email is available to its owner and the review team, and is not included in the public listing.

Use, retention and requests

We use information to provide the marketplace, prevent misuse, process payments and handle service questions. Operational records may be needed for payment reconciliation and disputes. Contact [email protected] to ask about access, correction or deletion. We do not promise automatic deletion of records needed for ongoing obligations.

Published campaigns and assets are public and may be copied or shared by others. Avoid uploading information you do not want to include in your campaign.