Enjoyable

Privacy Notice

Last updated: September 4, 2026

Scope

This notice describes enjoyable.work (the “Website”), its unlisted MCP Doctor review-status page, and the public support and security channels linked from it. Enjoyable currently presents open-source command-line utilities and may share a project-level review record with a bearer-link holder. It does not offer website accounts, billing, or hosted check execution.

Cloudflare hosts and protects the Website, the review-status API, and its D1 records. The mcp-doctor and mcp-sync repositories, releases, issue trackers, and security-reporting features are hosted by GitHub and are also subject to GitHub’s notices and settings.

Enjoyable determines why and how information is used for its own Website operations, review coordination, and direct communications. Hosting, email, and repository providers process information for their services under their own or applicable provider terms. Enjoyable does not act as a processor for customer content through the current Website because the Website has no customer-content submission service.

Information handled

  • Website operations: Cloudflare may process ordinary request and device information such as IP address, user agent, requested URL, timestamp, and security signals.
  • Locale choice: the Website stores your selected language preference in your browser’s local storage.
  • Unlisted review records: a record may contain a project label, public target and version, MCP Doctor version, check states, timestamps, permission state, short project-level result notes, an inactivity deadline, and metadata showing when an admin code was successfully used to approve a check or change viewer-password settings. The admin-action metadata does not identify a person. The record does not contain the outreach contact’s name or email address, raw MCP traffic, tool inputs or results, or private repository content.
  • Unlisted review links: the complete link contains a random bearer key after #. The Website sends that key only as an authorization header to the review API. The API stores a one-way digest of the secret, not the plaintext secret. Anyone with the complete link can open an unprotected record or share the link with someone else.
  • Review access controls: a separate admin code can approve an offered check or set, replace, and remove a viewer password. A viewer password opens a protected report but does not authorize changes; the admin code can also open the report if the viewer password is forgotten. The API handles entered codes and passwords to verify the request, stores only a one-way digest of the random admin code and a salted password verifier, and does not store either plaintext value.
  • Communications: if you email Enjoyable, the message includes the address, content, and attachments you choose to send.
  • External services: following a GitHub, LinkedIn, or email link sends information directly to that service under its own terms and privacy notice.

Do not include credentials, private source code, private endpoints, regulated data, or other sensitive information in general email, public issues, or public discussions.

Purposes and legal bases

Information may be used to deliver and secure the Website and review API, show agreed review progress, verify review access, record a code holder’s requested scope or privacy change, remove inactive reports, diagnose availability or abuse, respond to communications, maintain the open-source projects, and meet applicable legal obligations. Where GDPR applies, the legal basis depends on context and may include legitimate interests in operating and protecting the Website and projects, steps requested before an agreement, compliance with legal obligations, or consent where law requires it. Consent can be withdrawn for future processing when it is the applicable basis.

Local storage and cookies

The Website code stores an explicit locale preference in browser local storage. It does not set an analytics identity or an authentication session, and it does not copy an unlisted review key, admin code, viewer password, or review record into local or session storage. A successfully entered admin code remains in memory for the current tab so later requested changes can be authorized; reloading clears it. A browser, bookmark service, password manager, or extension may retain a complete link or a credential under its own behavior. Cloudflare may inject bot-detection JavaScript and set strictly necessary security cookies such as cf_clearance to deliver and protect the Website. Enjoyable does not use those mechanisms for product analytics or cross-context behavioral advertising.

Open-source utilities

The published CLIs run on systems controlled by their users. The Website does not receive local configuration merely because a utility runs. mcp-doctor can contact the local process or remote MCP endpoint a user explicitly selects; mcp-sync reads and writes supported local configuration files. Consult each repository’s current safety, support, and release documentation before use.

Recipients and sharing

Information may be handled by Cloudflare for Website, API, D1, and security operations, GitHub for linked repositories and project activity, providers that deliver email, or disclosed where required by law or needed to protect rights and security. Public GitHub activity is visible according to the repository and GitHub settings. A person who receives a complete unlisted review link can share it; once a viewer password is set, another person also needs that password or the admin code to open the report. Anyone given the admin code can make the limited changes described above. Enjoyable does not sell personal information or share it for cross-context behavioral advertising.

Retention and security

Retention depends on the information’s purpose, sensitivity, provider settings, security needs, and applicable legal requirements; no fixed retention period is stated. An unlisted review link can be revoked. Its project-level record, access settings, checks, and admin-action metadata are automatically deleted after the configured period with no successful authorized activity, unless an applicable hold requires a different process. Reasonable safeguards can reduce risk, but no website, API, bearer link, password, email system, or open-source distribution channel is absolutely secure.

International transfers

Cloudflare, GitHub, email, and other linked-service providers may process information in countries other than the visitor’s own. Any required transfer mechanism or additional safeguard depends on the provider, service, and applicable law. Contact Enjoyable with questions about transfers connected with Website operations.

Rights and contact

Depending on location and context, privacy law may provide rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information. It may also provide the right to withdraw consent and complain to a data-protection authority. To ask a privacy question or make a request, email oliver@enjoyable.work. Identity and authority may need to be verified. Requests about data controlled by GitHub, LinkedIn, an email provider, or another third party should also be directed to that provider.

Children and changes

The Website and developer utilities are not directed to children. This notice may be updated when the Website, products, providers, or legal requirements change. The posted date identifies the current version.