
Pavilion
Private by design.
A project — its drawings, photos, documents and records — is visible only to the people invited to it, and to no one else.
Secure & Accessible
Your project is private. You control exactly who is invited, when they join, and what level of visibility they have.
Every request is verified against your project’s membership by row-level security at the database itself. All data is encrypted in transit and at rest, files live in private storage, and every Pavilion is invitation-only — nothing public, nothing indexed.
It is also resilient: every project is backed up weekly to separate, off-site storage, and you can export your full archive at any time.
And if you ever have a question about your data, you can reach us at any time at hello@pavilion.place.
How your project is protected
All traffic to Pavilion is encrypted in transit, and everything you store — photos, drawings, documents — is encrypted at rest.
Floorplans and photographs live in private storage and are served only to signed-in members of your project. There are no public links, and nothing is indexed.
Pavilion runs on a small number of vetted providers — for hosting, database, file storage, email and AI. We share only what each one needs to do its job.
Your data is never sold, and never used for advertising.
Every Pavilion is invitation-only, and each invitation is bound to a verified email address. Access is withdrawn the moment you choose.
Folders can be locked and cost figures hidden, so you decide exactly what each person sees.
Pavilion's AI features — the concierge, filing and the Design Wizard — are powered by OpenAI. Requests are processed one at a time, and are never stored by OpenAI or used to train models.
If you would rather not use AI at all, it can be switched off for your project in Settings. Nothing is then sent.
Your project's data, files and backups are hosted in the European Union.
The one exception is AI processing, which OpenAI handles in the United States — switch AI off (above) and your content never leaves the EU.
Every project is backed up weekly to separate, off-site storage — a complete archive of its data and media, kept apart from Pavilion's own systems.
You can also export your project yourself at any time: Settings offers the full archive — every photo, document and record — as a single download.

Privacy Policy
Effective 22 July 2026
1. Who we are
Pavilion is operated by Sanctuary Stories Ltd, a company registered in England and Wales (company number 16230261) with its registered office at 20 Wenlock Road, London, England, N1 7GU. For your account and, unless you have been told otherwise, your project data, Sanctuary Stories Ltd is the data controller. Contact us about privacy at hello@pavilion.place.
2. The information we hold
Account information — your email address, your name, and your role within a project. If you sign in with Google, Google gives us your verified email address and profile name; no project content is sent to Google.
Project content— what you and your fellow members put into a project: photographs, documents, floorplans, notes, decisions, costs, and emails you forward to your project’s own address. This can include personal information, such as photographs of a home.
Billing information— the email address used at checkout, the plan purchased, the amount paid, and Stripe’s references for the subscription. Card details are collected by Stripe on its own pages and never reach our systems.
Technical information — server logs needed to run and secure the service. We use privacy-preserving, cookie-free analytics that do not identify you.
Information about you can also reach us from other members of your project — for example, a photograph or document another member files that includes you, or an invitation sent to your email address.
3. Why we use it
We use your information to provide Pavilion under our contract with you: operating your account and projects, delivering invitations, notifications, and receipts, taking payment, and providing support.
We rely on our legitimate interests in keeping the service secure (for example, rate limiting and access logging) and in maintaining business records. We use billing records to meet our legal obligations, including tax law. We do not profile you, we do not sell your information, and we do not use your project content for advertising or to train AI models. We do not make automated decisions about you that have legal or similarly significant effects.
4. AI features
Pavilion’s concierge and Design Wizard send the relevant parts of your project to OpenAI to answer your question or generate an image. Each request is processed transiently: OpenAI does not store your content beyond handling the request, and it is not used to train models. The project’s creator can switch AI features off for the whole project in Settings, and every AI feature works only on what the requesting member is already allowed to see.
5. Who helps us provide Pavilion
We use a small number of service providers, each processing only what its role requires: Supabase (database, authentication, and file storage, hosted in London, United Kingdom), Cloudflare (encrypted off-site backups, stored under EU jurisdiction), Stripe (payments), Resend (transactional email), OpenAI (AI processing, as described above), ConvertAPI (converting Office documents into previews — files are processed transiently, not stored), and Vercel (hosting). Each is bound by a data-processing agreement.
6. Where your information lives
Your projects and account data are hosted in the United Kingdom. Backups are stored in the European Union. Some providers (OpenAI, Stripe, Resend, Vercel) process data in the United States; those transfers are protected by recognised safeguards, including the UK Extension to the EU–US Data Privacy Framework and standard contractual clauses, as applicable to each provider.
7. How long we keep it
Your account exists until you delete it, which you can do yourself at any time from account settings. Project content exists until the project is deleted by its creator; deletion is immediate in our live systems, and the project’s off-site backups are erased within 45 days. Billing records are kept for six years, as tax law requires. If a subscription lapses, the project is suspended rather than deleted, so nothing is lost if you return — you can ask us to delete a suspended project at any time.
8. Your rights
You have the right to access, correct, export, and erase your personal information, to object to or restrict certain processing, and to complain to the Information Commissioner’s Office (ico.org.uk). In practice: you can see and edit your project data in the product, delete your account yourself, and request a complete machine-readable copy of a project’s data from support@pavilion.place. For anything else, write to hello@pavilion.place and we will respond within one month.
9. Cookies
Pavilion uses only the cookies needed to keep you signed in. There are no advertising or tracking cookies, and our analytics are cookie-free — which is why there is no cookie banner.
10. Projects set up by professionals
Where an architect, designer, or other practice provisions a Pavilion for its client, the practice may be the data controller for the project’s content and we process it on their behalf. A data-processing agreement for practices is available on request at hello@pavilion.place.
11. Changes to this policy
When we change this policy, we will update the effective date above, and tell you by email or in the product if the change is material.