Privacy Policy
Last updated August 13, 2026
The short version. Roster is a shared inbox that a talent management team uses to answer messages on behalf of the people it represents, with each person's permission. We hold the keys to those connections and very little else: messages stay with Instagram, Google, Bluesky and JotForm, and are fetched only when someone opens a conversation.
We never ask for or store an account password, we never sell or share data, we run no advertising or profiling, and we do not train any model on your information. Every message sent is typed by a person. You can withdraw access at any moment from your own platform settings, and section 10 explains how to have what we hold deleted.
1.Who we are
Roster ("Roster", "the console", "we") is operated by Pillar Technology LLC, a limited liability company established in Virginia, United States. Pillar Technology LLC is the controller of the information described in this policy. You can reach us at ryan@pillartechnologyllc.com.
Roster is a private, invitation-only tool. It has no public sign-up: accounts are issued to the management team that operates it and, while a platform review is in progress, to authorized reviewers who are given access to demonstration data only.
2.Whose information this covers
This policy describes two groups of people.
Account holders. The creators, clients and businesses who authorize Roster to connect one of their accounts — an Instagram professional account, a Gmail mailbox and calendar, a Bluesky account, or a JotForm account. They decide to connect, and they can disconnect at will.
People who correspond with them. If you send a direct message, an email, or a booking-form submission to a connected account, your message and the name or handle attached to it are shown to the management team inside the console, exactly as they would be shown in the platform's own app. We display that correspondence; we do not copy it into our database, build a profile from it, or use it for any purpose other than showing the team the conversation they are answering.
3.What we access, and why
Access is granted by the account holder through Instagram's and Google's official authorization flows, or by a revocable key they generate themselves. Roster never asks for, receives, or stores an account password. Each permission we request, and what it is used for:
| Platform | Permission | What it is used for |
|---|---|---|
instagram_business_basic | Reads the connected professional account's username, account ID and profile picture, so the console can show which account the team is acting for and label replies correctly. | |
instagram_business_manage_messages | Reads the direct-message conversations of the connected account and sends replies typed by a member of the management team. This is the permission that makes the shared inbox work. | |
Human Agent | Lets a person reply up to seven days after a message was received, when Instagram's standard 24-hour window has closed — for example over a weekend. Replies under this permission are always written by a human, never generated or automated. | |
gmail.modify | Reads email threads in the connected mailbox, sends replies typed by the team, and marks messages read or unread. We do not delete mail, and we do not read mail outside the connected account. | |
calendar.events | Reads the connected account's calendar so the team can see availability, and creates or edits events on the account holder's behalf when they ask us to book something. | |
| Bluesky | App password with direct-message access | Reads the connected account's direct messages and sends replies typed by the team. The app password is created by the account holder and can be revoked by them at any time in Bluesky settings. |
| JotForm | Read-only API key | Reads form submissions so booking inquiries appear in the console. The key is read-only — it cannot change or delete anything — and the account holder can revoke it in JotForm settings. |
We request no permission beyond this list. If we ever need an additional one, the account holder has to authorize it explicitly, and this policy will be updated before we ask.
4.What we store
Our database holds four things and nothing else:
- Workspace records — the display name the team gives each person they represent, and the labels they choose for that person's channels.
- Connection records — for each connected account: the platform, the account identifier, the username or email address, a profile-picture URL, the list of granted permissions, timestamps describing when the connection was made and last used, and the access and refresh tokens, encrypted.
- A short-lived record of a connection in progress — held between the moment you authorize an account and the moment the team confirms which person it belongs to, then discarded.
- Per-conversation read markers — for a conversation the team has opened or answered in Roster: a reference to the connection, the platform's conversation identifier, and a timestamp. This is how the console knows what still needs attention. No message content — and the markers are deleted with their connection.
Message bodies, email contents, calendar entries and form answers are not among them. Those are requested from the platform when a team member opens a conversation and are gone when the page is closed.
5.What we never do
- We do not sell, rent, or trade information to anyone.
- We do not share it with third parties for their own purposes, and we do not disclose it for advertising.
- We do not use it for advertising, profiling, scoring, or to train artificial-intelligence models.
- We send no automated messages. No bot replies, no scheduled sends, no bulk messaging — every outgoing message was typed by a person on the management team.
- We run no advertising trackers, no analytics service, and no third-party scripts on the pages behind sign-in.
- We do not ask for, receive, or store account passwords.
6.Service providers
Roster is a small piece of software and relies on two infrastructure providers, both of which act on our instructions only and neither of which may use anything for their own purposes:
- Vercel — hosts the application and serves it over HTTPS.
- MongoDB Atlas — stores the workspace and connection records described in section 4.
We also communicate with the platforms you connect — Meta, Google, Bluesky and JotForm — because that is where your messages actually live. Their own privacy policies govern what they do with your information on their side.
We may disclose information if the law requires it, but we will tell the affected account holder unless we are legally prohibited from doing so.
7.How we protect it
- Access and refresh tokens are encrypted with AES-256-GCM before they are written to the database. The encryption key is held separately from the data, in the hosting environment.
- Tokens are never sent to the browser, never appear in a URL, and are never written to logs.
- All traffic is served over HTTPS.
- Reaching any workspace requires an authenticated session, and every request that names a workspace is checked against the caller's access before any data is returned.
- Reviewer sessions are confined to demonstration workspaces and cannot reach a real client's data at all.
No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach affecting a connected account, we will notify the account holder promptly and describe what happened.
8.How long we keep it
Connection records, including encrypted tokens, are kept only while the connection is active. Disconnecting an account deletes its tokens and identifiers immediately. Deleting a workspace deletes every record associated with it. A connection in progress that is never confirmed expires on its own.
Because message content is never stored, there is no message archive to expire, export, or delete.
9.Your choices
If you are an account holder, you are in control of the connection at all times and do not need our cooperation to end it:
- Instagram — Settings → Apps and websites → remove Roster.
- Google — Google Account → Security → Third-party access → remove Roster.
- Bluesky — Settings → Privacy and security → App passwords → revoke.
- JotForm — Account settings → API → delete the key.
Revoking access invalidates our stored tokens the moment you do it. To have the records themselves erased as well, follow section 10.
Depending on where you live you may also have the right to ask what information we hold about you, to have it corrected, or to have it erased. Write to us and we will answer; we do not charge for this and we will not make you create an account to ask.
10.How to delete your data
Anyone whose information Roster holds can have it deleted. There are three routes, and any one of them is enough:
- Email us. Write to ryan@pillartechnologyllc.com from the address or with the account handle concerned, and say what you want deleted. We will delete it and confirm in writing within 30 days, usually far sooner. You do not need an account with us to make this request.
- Ask the team that manages the account to disconnect it in the console, under Workspace → Channels → Disconnect. That deletes the stored tokens and identifiers for that account straight away.
- Revoke access yourself using the platform settings listed in section 9. This immediately invalidates what we hold; email us afterwards if you also want the records erased.
Because we never store message content, a deletion request covers the identifiers, tokens and workspace records described in section 4 — which is everything we have.
11.Children
Roster is a business tool and is not directed at children. We do not knowingly hold information about anyone under 13, and connected accounts must belong to adults. If you believe a child's information has reached us, write to us and we will delete it.
12.Where data is processed
Roster is operated from the United States, and the providers in section 6 process data there. If you are writing to a connected account from elsewhere, your message is shown to the team in the United States — the same as it would be if they read it in Instagram's or Gmail's own app.
13.Changes to this policy
If this policy changes we will update the date at the top of the page, and we will not apply a materially different use to information we already hold without asking the account holder first.
14.Contact
Questions, requests, and deletion requests go to ryan@pillartechnologyllc.com, which reaches Pillar Technology LLC directly. We answer every message about data, including from people who have never used the console.
See also our Terms of Service.