Privacy

Last updated 14 August 2026

Short version: you can use most of bidkita without telling us who you are, we store the minimum needed to make the features work, we do not sell anything about you, and you can export or delete all of it from your settings.

Using the site without an account

Search, notice pages, supplier profiles and agency dossiers need no account. If you save a shortlist or start an AI conversation while signed out, we set one cookie (rfp_owner) holding a random identifier so that work is still there when you come back. It is not linked to a name, an email or an advertising profile, and it is not shared with anyone.

What we store if you sign in

  • Your Google account id, email address, display name and profile picture URL — that is the entire profile, and it is what Google returns for the 'openid email profile' scopes.
  • Your shortlists, the notices in them, your alerts and the matches they have found.
  • Your AI conversations, so you can reopen a thread.
  • A usage record per AI question and bid brief: when, which model, how many tokens, and what it cost.
  • Your credit balance, as a list of every movement: what you were granted, what you bought, and what each question or brief spent. Card and e-wallet details go to PayMongo and never touch our servers.

When you sign in for the first time, anything you saved anonymously in that browser is moved onto your account and the anonymous cookie is discarded.

What we do not do

  • We do not sell or rent your data.
  • We do not run advertising, and there are no third-party ad or tracking pixels.
  • We do not read your conversations for any purpose other than running the feature and debugging faults.
  • We do not ask Google for anything beyond your basic profile — no Drive, no contacts, no calendar.

Who else touches it

  • Fly.io hosts the application and its database, in Singapore.
  • OpenAI processes the text of your AI questions and the notice documents a bid brief is built from, in order to answer them.
  • PayMongo handles payment when you buy credits.
  • PostHog, if product analytics are switched on — and only after you have said yes to the banner. It receives which features get used, never your searches, saved lists or messages.
  • PostHog also records a session replay after you say yes, so we can see where the product confuses people. Everything you type is masked in the recording before it leaves your browser.
  • PostHog also receives what our model was asked and answered, so a bad answer can be debugged — but only after you have said yes. Whether or not you say yes, it receives what each AI answer cost us to produce: the model, the token counts, the price and how long it took, tied to the feature and not to you.
  • Sentry, if error reporting is switched on. It receives crash messages and the page path with the query string stripped. There is no banner for it: it holds no profile of you, and an app that cannot see its own crashes cannot be fixed.

Notice data

Procurement notices, awards and supplier records shown here are public information published by Philippine government bodies. A supplier or agency page is a view of that public record. If you believe something attributed to you is factually wrong, tell us and we will correct or remove it.

How long we keep it

  • Your account and its content: until you delete it.
  • The anonymous cookie: one year, or until you clear it.
  • Usage and billing records: kept after deletion only where we are required to for tax and accounting, and stripped of anything identifying beyond the amount and date.

Your control

Settings has a one-click export of everything on your account as JSON, and a delete that removes your account, your lists, your alerts and your conversations. Deletion is immediate and not reversible.

Contact

For a correction, a question, or anything about your data, get in touch through the contact on the site.