Privacy Policy
Last updated 24 August 2026
Pillara reads business data you connect so an operating team of agents can draft and, within limits you set, take action on your behalf. This policy explains what we read, how we store it, how long we keep it, and the choices you have.
What we read
Pillara reads only the sources you connect, and only after you grant access to each one. Depending on what you connect, that can include:
- Email messages and their attachments (Gmail, Microsoft 365).
- Bank and card transactions (via Plaid).
- Accounting records and invoices (QuickBooks, Xero).
- Commerce orders and returns (Shopify).
- Files and spreadsheets you point us at (Google Drive, SharePoint).
- Messages in channels you select (Slack, WhatsApp via Twilio).
- Your name, email address, and profile picture from Google sign-in.
Every source is read-only until you explicitly grant an agent permission to act, and you can withdraw that permission or disconnect any source at any time.
How we use it
We use the data to operate the product for you: to surface exceptions, draft proposals, and — only under the autonomy guards you set — take actions such as sending a reply or creating a bookkeeping draft. Every action is recorded with its evidence and is reversible where the underlying system allows. We do not sell your data, and we do not use your business data to train third-party models.
How we store it
Data is encrypted in transit and at rest, stored in a per-tenant scope that fails closed (one organization can never read another’s records), and access is limited to the members you invite and to the operators who run the service. We rely on a small set of subprocessors to run — see the subprocessor list.
How long we keep it
We keep connected-source data for as long as your organization is active and the source is connected. Disconnecting a source stops new reads; records already formed remain until you delete them or close the account. On account closure we delete your organization’s data within 30 days, except where we must retain limited records to meet legal or accounting obligations.
Your choices
- Connect or disconnect any source at any time.
- Export a full copy of your organization’s data from Settings.
- Request deletion of your account and data.
- Access is through Google sign-in; losing access to your Google account means losing access to Pillara.
Contact
Questions about this policy, or a data request, go to privacy@pillara.app.