Last updated September 17, 2026
Data retention & deletion
Archiving a company pauses access and preserves its workspace. Deletion is a separate, verified request.
Pillar is operated by Kevin Bastien, operating as Pillar, based in Brooklyn, New York, United States. For questions or requests, email support@pillar.nyc.
What stays in Pillar
- Active workspaces: account, company, catalog, order, client, attachment, and team records are retained to provide the service. Pillar currently has no automatic age-based purge of these database records. Edits and order deletion can remove live content; storage limits below apply separately to uploaded files.
- Archived companies: the same database records are retained so an authorized administrator can restore the workspace. Archiving blocks normal workspace access, new invitation acceptance, and public client pages. It revokes support grants but does not erase records or intentionally delete files.
- Support history: permission grants, revocations, administrator identity and reasons, and session and page-view history remain with the workspace after access expires. A one-hour support permission is an access limit, not a one-hour retention period.
- Production sharing: client publication snapshots, generated work-order revisions, and fabricator messages and delivery records stay with their order until it is deleted. Editing an order does not rewrite previously published or sent versions. Archived fabricators remain in the workspace to preserve historical references. Deleting an order or fabricator record cannot remove copies already received by email or kept by the email provider.
- Sign-in and invitation records: access tokens have expiry and use limits, but token expiry does not automatically remove the associated account or invitation record.
- Email import records: sender addresses, subjects, provider message identifiers, status, processing times, source fingerprints used for duplicate detection, and links to created orders remain with the workspace. Historical confirmation records from the earlier import flow are also retained. Pillar does not save the full forwarded email body in its database or background-job arguments. Deleting imported orders does not remove their receipts. Receipts are included in a verified workspace deletion request; there is no automatic age-based receipt purge. Resend’s copies of incoming messages and OpenAI’s processing records follow the providers’ retention practices.
- Terms acceptance records: the account, document revision, published operator and contact details, acceptance and verification times, and sign-in context are retained to record which Terms of Service were accepted and which Privacy Policy was presented. These records do not expire with a sign-in link or support session. They are considered as part of an account deletion request, subject to any need to retain evidence for legal obligations or disputes.
- Operational records: technical, security, and email delivery logs follow the relevant service provider’s settings and policies. Pillar does not promise a single fixed deletion deadline for all provider records.
For information about the providers involved, see the privacy policy. Provider retention may differ from the time information remains visible in Pillar.
File storage and backups
Uploaded documents, studio logos, product photos, and bench photos use a persistent disk on Pillar’s Render server, so these files survive ordinary deployments and restarts. This does not guarantee recovery from deletion, corruption, or storage failure. Archiving and restoring a workspace does not restore missing files, including files lost before persistent storage was added. Keep your original files outside Pillar. Render explains its temporary and persistent storage.
Generated work-order PDFs are stored in PostgreSQL with their revisions, separately from uploaded files. Published photo references preserve the selected image against later edits; the image files remain subject to the storage and recovery limits above.
Pillar’s current free database hosting is time-limited and does not include database backups. The database can become inaccessible and then be deleted if the plan expires without an upgrade. See Render’s free PostgreSQL limits. These retention practices describe which records Pillar intentionally keeps; they are not a guarantee that deleted or lost information can be recovered.
Request access, correction, or deletion
Email support@pillar.nyc with your studio name, your account email, and what you would like accessed, corrected, or removed. Do not send sign-in links, passwords, or unnecessary copies of sensitive documents.
If you are a client of a studio, contact the studio first. The studio controls the order information it enters and can verify which records and instructions apply. You may also contact us if you need help identifying the appropriate route.
We verify the requester’s identity and authority, clarify the affected records, and coordinate with the studio where appropriate before processing a request. Removing a team member’s access is not the same as deleting that person’s account or earlier contributions. Deleting an order does not delete its studio, team accounts, email import receipt, or separate support and acceptance history. There is currently no self-service account or company deletion button or automatic company deletion process.
We respond and act as required by applicable law. Some information may need to be retained to meet legal obligations, resolve disputes, or protect service security. If a request cannot be fulfilled in full, we will explain the applicable limitation. We do not promise a deletion date before the scope, authority, and relevant retention requirements are verified.
Limits of removal and access revocation
Revoking support permission or archiving a company stops future access through the affected Pillar pages. It cannot recall screenshots, downloads, emails, or copies already made by authorized recipients or people who held a client link. Those copies must be addressed with their holders where applicable.
Deleting information from the live application does not necessarily remove every copy immediately. Provider records follow their own retention and deletion processes. Copies previously exported or downloaded are not erased by deleting the live record.
Keep the workspace focused
Studios should add only information needed to fulfill orders, review team access regularly, and share client links only with intended recipients. Owners can revoke support access from Settings as soon as help is complete. Contact us when records are no longer needed and a verified deletion request is appropriate.