The short version: we read your Workspace structure, tasks and users to build your report and to help you if you talk to us, we never keep your task content, and we delete our access to your Workspace as soon as the scan finishes. Everything below is the long version.
- Who is responsible
- ZenPilot, and not ClickUp, is responsible for the privacy, security and integrity of everything the Grader reads from your Workspace. ClickUp provides the connection; what happens to the data afterwards is on us. If anything below is not true, or stops being true, that is our problem to fix and our obligation to tell you about.
- What we read
- Connecting gives the Grader access through ClickUp's OAuth, which has no read-only setting to choose from: an approved app can do whatever the person who approved it can do. So the guarantee is ours rather than ClickUp's, and it is a plain one. Every call the Grader makes is a read, and there is no code in it that creates, edits, moves or deletes anything in your workspace. During a scan we read your Workspace structure, your open tasks, recent time entries, your users and your Custom Field definitions. We use it to build your report. We also keep the context a ZenPilot strategist would otherwise have to ask you for on a call: your Space names, which ClickUp plan you are on, and a list of the people on your Workspace with their names, email addresses and ClickUp roles. Only ZenPilot staff ever see that, it is never shown in your report, and it is never sold or shared. Task titles and descriptions are never stored: we measure how long a description is and discard the words.
- We hand access back when we're done
- The access token is encrypted while we hold it and erased as soon as the scan ends, whether it succeeded or failed. An hourly sweep clears anything a scan missed, so no working credential to your workspace is left sitting in our database. Running a second scan means connecting again, on purpose.
- Your report
- It lives at a private, unguessable link so you can share it. It stays out of search engines, and the link stops working 90 days after the scan. If you request a call, the details you enter are stored with your report and sent to our CRM so we can follow up.
- Benchmarks
- Each completed scan records one anonymous row: the scores, plus your team size and task count as broad ranges like 10-24 people. It carries no workspace name, no user and no link to your report, and the timestamp is rounded to the day. We use it to work out what normal looks like, and we may publish aggregate findings.
- Who else is involved
- Vercel hosts the site, Neon stores the database, Inngest runs the scan, and HubSpot is our CRM. When a scan finishes, the email on the ClickUp account that connected goes to HubSpot with the workspace name and grade, so we can follow up. Requesting a conversation sends what you typed there too. All of it is stored in the United States. The site loads HubSpot, LinkedIn and Meta tracking; a browser blocker will stop those and the Grader still works.
- Getting it removed
- Email support@zenpilot.com and we will delete your report, your contact record, or both. Revoking the Grader in ClickUp under Settings, Integrations, App Center cuts off access immediately, though the token is already gone by then.