Pillar StudiosLegal & trust

Privacy Policy

Use what is needed. Protect what is entrusted.

This Policy explains what Pillar Studios processes when you use our Discord, Roblox, website, verification, entitlement, and administration services—and the controls available to you.

Effective August 27, 2026

On this page

  1. 01Scope
  2. 02Information we handle
  3. 03How we use information
  4. 04Legal bases
  5. 05Sharing and disclosures
  6. 06Retention and enforcement records
  7. 07Your choices and rights
  8. 08Children and younger users
  9. 09Security and transfers
  10. 10Changes
  11. 11Contact

01

Scope and responsibility

This Privacy Policy applies to services operated by Pillar Studios ("Pillar," "we," "us," or "our"), including our website, Discord bot and administration tools, Roblox verification, entitlement and nickname synchronization, Pillar Roblox experiences, and support interactions.

Discord and Roblox separately process information under their own privacy policies. This Policy describes Pillar's practices only. Pillar is not affiliated with or endorsed by Discord or Roblox.

02

Information we handle

Platform identifiers and profile information

We process Discord user, server, role, channel, and message identifiers; Discord username, display name, avatar, guild membership, roles, and permission information when needed for a feature; and Roblox user IDs, usernames, display names, group membership or rank, and relevant game-pass ownership. Platform identifiers are treated as personal information where applicable law treats them that way.

Verification and automation information

We store the link between a Discord account and a Roblox account, when it was verified, saved Roblox profile snapshots, server-specific verification configuration, entitlement rules, configuration revisions, the administrator responsible for a change, and limited records of roles or nicknames that Pillar automation successfully applied. Short-lived evaluation plans may temporarily describe a proposed role or nickname change so the bot can apply it safely.

OAuth and administrator sessions

Roblox authorization codes, state, PKCE values, and related security data are processed only to complete verification. Roblox OAuth access, ID, and refresh tokens are not retained after the callback is securely processed. When Discord administrator login is available, Pillar requests only theidentify and guilds scopes. Discord OAuth tokens and session credentials remain server-side and are never placed in browser storage, public URLs, screenshots, or logs.

Security, enforcement, and support information

We may process request times, IP address, user-agent, rate-limit events, errors, authentication events, relevant platform identifiers, command or interaction metadata, moderation or restriction category, timestamps, administrator identity, appeal history, and evidence you voluntarily provide. We do not routinely store Discord message content. If content is needed to investigate a specific safety report, we limit it to what is relevant and permitted by platform rules and law.

Information we do not seek

We do not ask for Discord or Roblox passwords. We do not sell personal information, use Discord or Roblox data for behavioral advertising, build cross-service advertising profiles, or intentionally collect precise location, government identifiers, health information, financial account information, or biometric data through these Services. Please do not send sensitive information through commands or ordinary support messages.

03

How we use information

We use the information described above to:

  • authenticate users and link Discord and Roblox accounts;
  • provide verification, roles, nicknames, entitlements, and Roblox experience functionality;
  • let authorized administrators configure independent server policies;
  • validate permissions, role hierarchy, ownership, and configuration revisions;
  • operate, troubleshoot, secure, and improve the Services;
  • prevent fraud, ban evasion, abuse, unauthorized access, and platform manipulation;
  • investigate reports, enforce rules, process appeals, and protect users;
  • respond to support, privacy, and legal requests; and
  • comply with applicable law and Discord and Roblox platform requirements.

Automated rules may determine whether configured Discord roles or nicknames should be added, retained, or removed based on verified platform facts. A server's administrators control its configuration. You may contact us to request review of an outcome.

04

Legal bases where required

Where laws such as the GDPR or UK GDPR require a legal basis, we process information as necessary to perform the Services you request and enforce our Terms; for legitimate interests such as service security, fraud and abuse prevention, reliable configuration, support, and legal claims; to comply with legal obligations; and with consent where consent is the appropriate basis. We balance legitimate interests against user rights and limit processing to what is reasonably necessary.

05

Sharing and disclosures

We may disclose limited information:

  • to Discord and Roblox through their approved APIs when necessary to provide a feature you or an administrator requested;
  • to hosting, network, security, and other service providers acting under instructions to operate or protect the Services;
  • to authorized server administrators, limited to configuration and operational information appropriate for their server;
  • when required by law, legal process, or a valid government request, or when reasonably necessary to protect rights, safety, and security; or
  • as part of a merger, financing, reorganization, acquisition, or transfer of the Services, subject to applicable privacy obligations.

We do not sell personal information or Discord/Roblox API data. We do not share it with data brokers or advertising networks. Service providers may use information only for the contracted service and must protect it appropriately.

06

Retention, deletion, and enforcement records

We retain each category only for as long as needed for its disclosed purpose, platform requirements, dispute resolution, security, or law. We periodically review retained information and delete or de-identify it when it is no longer needed.

  • OAuth transactions: expire after a short authorization window and are consumed once. Roblox OAuth tokens are discarded after verification processing.
  • Identity links and automation state: are retained while needed to provide verification and prevent unsafe role removal, then deleted or de-identified after a valid unlink/deletion request unless a narrower record must remain for an allowed reason below.
  • Server configuration and audit attribution: are retained while the server uses Pillar and for a reasonable period afterward to resolve configuration disputes, unless deletion is required sooner.
  • Ordinary technical logs: are generally retained for up to 90 days unless an event is promoted into a security investigation.
  • Security and enforcement records: are limited to the identifiers and facts needed to maintain an active restriction, prevent repeat abuse or fraud, investigate a safety or security incident, handle an appeal, comply with law, or establish or defend legal claims. We ordinarily retain a closed incident record for no more than 24 months. An active restriction or unresolved investigation may require longer retention, with periodic review and subject to applicable law and Discord or Roblox requirements.
  • Backups: may retain deleted information for up to 90 additional days before routine overwrite, unless isolated for a legal or security obligation.
A restriction does not authorize unlimited retention. We keep only what is reasonably necessary to enforce the restriction or protect the Services, and we will delete Discord or Roblox API data when required by the user, platform, or law unless a valid overriding obligation permits the specific limited record.

07

Your choices and privacy rights

You may stop using the Services, remove the bot where you have authority, revoke an OAuth authorization through the relevant platform, or request access, correction, unlinking, deletion, restriction, objection, or a portable copy where applicable. You may also withdraw consent where processing depends on consent, without affecting earlier lawful processing.

Send requests to support@pillar-studios.com. Identify the relevant Discord and/or Roblox account, but never send a password or token. We may ask you to verify control of the account before acting. We will respond within the period required by applicable law and explain any lawful limitation. You may appeal our response and may have the right to complain to your local data-protection authority.

We do not discriminate against users for exercising privacy rights. Some deletion or objection requests may prevent verification, entitlements, or other account-dependent functionality from continuing.

08

Children and younger users

Discord features are not intended for anyone below Discord's minimum age or the minimum age required by their jurisdiction. Pillar Roblox experiences may be used by younger Roblox users under Roblox's account, age, and parental-control framework.

We do not ask children to provide names, email addresses, phone numbers, precise location, photos, voice recordings, or other free-form personal information directly to Pillar. Platform identifiers used for authentication, security, feature operation, fraud prevention, or legal compliance are not used for behavioral advertising or to build unrelated profiles. If we learn that we collected a child's personal information in a way requiring authorization we do not have, we will delete it. A parent or guardian may contact us with a privacy request.

09

Security and international processing

We use administrative, technical, and organizational safeguards designed to protect information, including access controls, least-privilege service boundaries, protected secret files, encrypted transport, server-side OAuth processing, short-lived transaction records, sanitized logs, and database and service isolation. No security measure can guarantee absolute safety.

Pillar and its service providers may process information in countries different from yours. Where required, we use appropriate safeguards for international transfers and continue to apply the protections described in this Policy.

If a security incident affects your information, we will investigate, contain, and provide notices to affected users, platforms, or authorities when required by law or applicable platform terms.

10

Changes to this Policy

We may update this Policy when our Services, data practices, platform requirements, or law changes. We will update the effective date and provide additional notice for material changes where reasonably required. We will not use previously collected information for a materially different, incompatible purpose without an appropriate legal basis and notice.

11

Contact

Pillar Studios is responsible for the Pillar processing described in this Policy. Privacy questions, deletion requests, appeals, and parent or guardian inquiries may be sent to support@pillar-studios.com.

Pillar Studios
Terms of ServicePrivacy PolicyContact