Privacy Policy
Last updated: 24 July 2026
1. What we collect
- ClickUp OAuth tokens — stored so the Service can read the source workspace and write to the target workspace you connect. We never receive your ClickUp password.
- Workspace data you migrate — tasks, comments, attachments and related records are read from the source to build the preview and are written to the target when you confirm. Attachment files are streamed through the Service during migration and are not retained afterwards. Job history and audit logs (what was created, old ID → new ID) are stored so you can review and undo migrations.
- Billing information — payments are processed entirely by Paddle.com, our merchant of record. We never see your card number. Paddle shares with us the transaction status and the email used at checkout.
2. What we do not do
- We do not sell or share your data with third parties for marketing.
- We do not use your workspace data for anything except the migration you request.
- We do not use advertising or cross-site tracking cookies.
3. Where data lives
The Service runs on Cloudflare's global network; application data is stored in Cloudflare D1. Payment data is held by Paddle. Your ClickUp data remains in ClickUp — we hold only the job history and audit records described above.
4. Retention and deletion
Revoking the Service's access from ClickUp cuts off our access immediately. Email support@microspear.app to have your stored tokens, job history and audit logs deleted; we complete deletion requests within 30 days.
5. Contact
support@microspear.app