Privacy Policy
Effective date: October 10, 2026
Product Pillars is a flowchart editor operated by Robot Heart Studios ("Product Pillars", "we", "us"), 240 Kent Avenue, Brooklyn, NY 11249. This policy explains what we collect when you use productpillars.com, the Product Pillars editor, our MCP server and our HTTP API (together, the "Service"), how we use it, who we share it with, and the choices you have.
The short version
- We store your account details and the diagrams you and your agents create, because the Service can't work without them.
- We don't sell your personal information, and we don't use your diagrams to train AI models.
- When you connect an AI agent, it reads and edits your diagrams on your behalf. What the agent's provider does with that content is governed by their terms, not ours.
- We use PostHog for product analytics, including recordings of how people use the web app. Recordings are kept for 30 days.
- You can ask us for a copy of your data, or to delete it, at any time: jeremy@jeremybelcher.net.
What we collect
Information you give us
- Account details. Your email address and password, or, if you sign in with Google, the name, email address and account identifier Google shares with us. Passwords are stored by our authentication provider as a one-way hash; we never see them. We also record your plan (for example, the free plan).
- Diagrams and projects. Everything you put in a diagram: its name, description, status, nodes, edges, labels, notes, frames and layout, plus the names of your projects. To handle two people (or a person and an agent) editing at the same time, we also keep the 50 most recent saved versions of each diagram.
- Collaboration details. The email addresses of people you invite to a diagram or project, and the role you give them. While you have a diagram open, your display name (taken from your email address if you haven't set one) is shown to the other people viewing it.
- Messages to us. Anything you send us by email or another support channel.
Information created when you connect agents
- Connected AI clients. When you connect an AI client such as Claude, ChatGPT or Cursor through our sign-in flow, we store the client's registration details (its name and the address it returns to after sign-in), your approval, and the access tokens we issue to it.
- API keys. For each key you create, we store a one-way hash of it, its first few characters (so you can tell keys apart), and when it was last used. We never store the full key.
- Agent activity. Each agent you connect is recorded as a participant linked to your account, and changes it makes are attributed to it. For example, people viewing the diagram may see "Updated by Claude via MCP."
Information collected automatically
- Product analytics. We use PostHog to understand how the Service is used: pages you visit, which buttons and links you click (but not their text), your browser and device type, the referring site, page performance, browser console messages, your IP address and the approximate location derived from it.
- Session recordings. PostHog records sessions in the web app so we can see where people get stuck and fix bugs. Recordings show the layout of each page and where you click, scroll and type, but all text on the page and everything typed into fields is masked, so recordings don't contain your diagrams. Recordings are deleted after 30 days.
- Server logs. Our hosting and database providers log requests to the Service, including IP address, browser user agent, the address requested and the time, for security and debugging.
- Bot protection. When you sign up or sign in, Cloudflare Turnstile checks whether the request comes from a person, using signals from your browser and device.
- Cookies and similar technologies. We use cookies to keep you signed in, and PostHog uses cookies and browser storage to recognize returning visitors and link analytics to a session. We may also store small preferences in your browser, such as a dismissed banner.
How we use it
- To run the Service: create and secure your account, save and sync your diagrams, show live edits to collaborators, run share links, the MCP server and the API, and send emails the Service depends on, such as invitations.
- To keep it safe: prevent fake sign-ups and abuse, investigate misuse, and protect our users and systems.
- To improve it: understand which features are used, find bugs and measure performance. We are notified by email when a new account is created.
- To communicate with you: answer your messages and tell you about important changes to the Service or these terms. We don't currently send marketing email. If we start, you'll be able to opt out at any time.
- To meet legal obligations and enforce our Terms of Service.
We don't sell your personal information, and we don't share it for cross-context behavioral advertising. We don't use the content of your diagrams to train AI models.
AI agents you connect
- You decide which agents to connect. A connected agent can do anything your account can do on the diagrams you can access: read, create, edit, share and delete.
- Content an agent reads leaves Product Pillars. When an agent reads a diagram, that content is sent to the agent's provider (for example Anthropic or OpenAI) and handled under the provider's terms and privacy policy. We don't control what they do with it.
- You can disconnect an agent at any time: remove the connector in your AI client, or revoke its API key in Settings. To revoke access we granted through sign-in, contact us at jeremy@jeremybelcher.net.
Share links
If you create a share link for a diagram, anyone who has the link can view that diagram, its Markdown and an image of it without signing in. That includes people and agents you didn't send it to, if the link is forwarded or posted publicly. Messaging apps such as Slack may show an image of the diagram as a link preview. You can revoke a share link at any time, after which it stops working.
Who we share information with
We share information only as described here:
- People you collaborate with. Collaborators you invite see the diagrams you share with them, your display name and your edits. Invitation emails include your name and the name of the diagram or project.
- Anyone with a share link you create, as described above.
- AI clients you connect, as described above.
- Service providers that run parts of the Service for us, under contracts that limit how they can use the data:
| Provider | What they do for us | Data involved |
|---|---|---|
| Supabase | Database, authentication and live updates | Account details, diagrams, collaboration and agent records |
| Vercel | Hosting and server functions | Requests to the Service and server logs |
| PostHog | Product analytics and session recordings | Usage data, device data, IP address, recordings |
| Resend | Sending email | Recipient email addresses and email contents |
| Cloudflare | Bot protection on sign-up and sign-in | Browser and device signals |
| Sign in with Google, if you choose it | Sign-in details Google shares with us |
- Legal and safety reasons. If we believe in good faith that disclosure is required by law, or necessary to protect the rights, property or safety of our users, the public or Product Pillars.
- Business transfers. If Product Pillars is involved in a merger, acquisition or sale of assets, your information may be transferred as part of that deal. We'll tell you before it becomes subject to a different privacy policy.
Where your data is stored
The Service and its data are hosted in the United States. If you use the Service from outside the United States, your information will be transferred to, stored and processed in the United States. Where the law requires it, we rely on safeguards such as the European Commission's Standard Contractual Clauses, included in our service providers' data processing terms, for these transfers.
How long we keep it
- Your account and diagrams: for as long as your account is open. When you ask us to delete your account, we delete it and its diagrams within 30 days, except where we must keep information to meet legal obligations, resolve disputes or prevent abuse. Copies in database backups, if any, are removed as those backups expire, within 7 days.
- Deleted diagrams: deleting a diagram also deletes its saved versions and share links.
- Saved versions: only the 50 most recent per diagram.
- Session recordings: 30 days.
- Analytics events: kept by PostHog for the retention period of our plan with them (1 year on its free plan, up to 7 years on paid plans). PostHog doesn't offer a shorter period, so we delete a person's analytics data on request instead.
- Server logs: kept by our providers for their standard periods, typically no more than 30 days.
- Pending invitations: until the invitee signs up, or the invitation is removed.
Your choices and rights
- Access, export, correction and deletion. You can export any diagram as Markdown or Mermaid from the editor. To get a copy of your data, correct it, or delete your account, email jeremy@jeremybelcher.net. We'll respond within 30 days.
- Analytics. If your browser sends a Global Privacy Control or Do Not Track signal, we don't run analytics or session recordings for you. Your browser's tracking protection or a content blocker also stops them.
- Emails. Emails the Service depends on, such as invitations and security notices, can't be turned off while your account is open.
If you are in the European Economic Area or the United Kingdom, we process your information on these legal bases: to perform our contract with you (running the Service); our legitimate interests in securing and improving the Service, balanced against your rights; your consent, where the law requires it, which you can withdraw at any time; and compliance with legal obligations. You have the right to access, correct, delete, restrict or object to our processing of your information, and to data portability. You can also complain to your local data protection authority.
If you are a California resident, you have the right to know what personal information we collect, use and disclose, to ask us to delete or correct it, and not to be discriminated against for exercising these rights. We don't sell or share personal information as those terms are defined under California law. The categories we collect are listed under "What we collect" above.
To exercise any of these rights, email jeremy@jeremybelcher.net. We may need to verify your identity before acting on a request.
Children
The Service is not directed to children, and you must be at least 16 to use it. We don't knowingly collect information from children. If you believe a child has given us personal information, contact us and we'll delete it.
Security
We protect your information with encryption in transit (HTTPS), database access rules that limit each account to the diagrams it can access, hashed API keys, and access tokens bounded by the permissions of the person who approved them. No system is perfectly secure, so we can't guarantee absolute security. If we learn of a breach that affects your information, we'll notify you as the law requires.
Changes to this policy
We'll post any changes on this page and update the effective date. If a change is material, we'll also tell you by email or in the Service before it takes effect.
Contact
Robot Heart Studios, 240 Kent Avenue, Brooklyn, NY 11249. Email jeremy@jeremybelcher.net.