Privacy Policy
Last updated: July 19, 2026
Scope and roles
This Privacy Policy applies to enjoyable.work, its related web and API surfaces, and Enjoyable's hosted MCP code-review service (collectively, the "Service").
Enjoyable Work ("Enjoyable", "we", "us", and "our") is the controller for personal information we use to operate our website, accounts, and direct customer relationships. When an organization submits Customer Data for the Service, that organization normally determines the purpose of the processing and Enjoyable acts as its processor or service provider under its instructions and any applicable written agreement.
For questions about this policy or a privacy request, contact [email protected].
Information we handle
Account and organization information
We may handle account identifiers, verified email addresses, authentication-provider subject identifiers, organization and role information, and communications you send to us.
Review Content
The Service accepts caller-supplied Git diffs and optional source-context snippets to produce a code review. That content can contain personal information, confidential information, or source code. Submit only the content that is necessary for the review, and do not submit credentials, private keys, payment-card data, or protected health information unless a separately approved agreement expressly permits it.
Technical, usage, and security information
We may collect browser and device information, IP address, request timestamps, authentication and authorization events, service status, rate-limit events, and metadata needed to prevent abuse, investigate errors, and operate the Service. We design this information to avoid including raw review content where it is not needed.
Commercial information
If you purchase a paid offering, we may receive billing contact details, transaction status, plan, and invoice-related records. A payment provider may process payment instrument details directly; we do not ask you to send payment-card numbers through the review interfaces.
How we use information
We use information to provide, secure, and improve the Service, including to:
- authenticate users, administer organizations, and honor access controls;
- receive, analyze, and return the requested code-review result;
- prevent abuse, enforce rate limits, diagnose reliability issues, and protect the Service;
- respond to support requests, communicate about the Service, and manage agreements; and
- meet legal obligations and resolve disputes.
Where GDPR applies and we are a controller, our legal bases depend on the context and may include contractual necessity, legitimate interests in operating and securing the Service, compliance with legal obligations, and consent where it is required. Where we act as a processor, we process Customer Data on the customer's documented instructions and under the applicable agreement.
AI and service providers
To provide a requested review, the Service may transmit Review Content to a model provider selected through an active model-routing policy. That provider processes the content needed to generate the review result. The selected provider can change as our approved routing policy changes, so organizations with processor or residency requirements should contact us before submitting regulated or restricted data.
We also use service providers for functions such as identity, hosting, infrastructure, databases, communications, and payment processing. We limit their access to the information needed to perform their role. Raw review diffs, source snippets, prompts, and model responses are not included in our product analytics or ordinary application logs.
Cookies and similar technologies
We use Cookies, local storage, and similar technologies to support authentication, security, session continuity, and basic Service operation. Your browser may allow you to control some of these technologies, but blocking required technologies can prevent the Service from functioning correctly.
Sharing and disclosure
We share personal information only as needed for the purposes described above, including:
- with authorized service providers and model providers that support the Service;
- with your organization and its authorized administrators when you use an organization account;
- when necessary to meet legal requirements, enforce our agreements, or protect rights, safety, and security; and
- as part of a corporate transaction, such as a financing, acquisition, or asset sale, subject to appropriate protections.
Retention
Review Content is handled transiently to provide the requested review. Raw diffs, source snippets, prompts, and model responses are not retained in our ordinary application logs. We retain account, organization, commercial, security, and service-usage metadata for the period reasonably necessary to operate the Service, meet legal and contractual obligations, resolve disputes, and protect against abuse.
Our retention criteria include the type and sensitivity of information, the purpose for which it was collected, the account or agreement lifecycle, and applicable legal or security obligations. We will delete or de-identify information when those criteria no longer require retention, subject to backups and records we must retain by law.
Security
We use reasonable administrative, technical, and organizational safeguards intended to protect information against unauthorized access, loss, misuse, or disclosure. No internet service or security control can provide absolute security, so you should use the Service only in accordance with your organization's approved data-handling rules.
International transfers
Enjoyable and its service providers may process information internationally. Where a law restricts a cross-border transfer, we will use an applicable transfer mechanism and supplementary safeguards when required. The available processing locations and contractual protections can depend on the providers and configuration in use.
Your rights and choices
Depending on your location and our role, you may have rights of access, correction, deletion, restriction, objection, and portability. You may also withdraw consent where we rely on it, without affecting processing completed before withdrawal.
To exercise a right regarding information for which we are the controller, email [email protected]. We may need to verify your identity and authority before completing a request. If we process the information on behalf of an organization, contact that organization first; we will assist it as required by the applicable agreement and law. You may also have the right to complain to your local data protection authority.
Children and policy changes
The Service is not directed to children, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us information, contact us so we can review and address the request.
We may update this Privacy Policy to reflect changes in the Service, applicable law, or our practices. We will post the updated version here and revise the Last updated date. Material changes may also receive additional notice when required.