Privacy
Effective July 25, 2026.
Data minimization
Agent Enhancer Utilities is designed to accept typed, bounded inputs. Coordination tools store opaque derived keys and short-lived values. Raw tool inputs are not retained in execution, idempotency, payment, receipt, self-test, or aggregate metric records.
Operational records
We retain the minimum records needed for safe replay, payment reconciliation, abuse prevention, audits, reliability measurement, and support. Retention and side effects are published in each tool manifest.
Discovery and execution analytics use monthly rotating HMACs for aggregate activation and repeat-use measurement. We do not retain raw search intent, IP addresses, user agents, tool inputs, or tool outputs in analytics records. Aggregate observation rows are automatically deleted after 90 days. Public effectiveness reporting suppresses low-volume per-module samples and never publishes actor hashes or discovery-source breakdowns.
Infrastructure providers and network data
Cloudflare provides DNS, TLS, abuse prevention, and edge delivery. It may process connection metadata such as IP address, user agent, request timing, and security signals. Cloudflare may set the necessary __cf_bm bot protection cookie, which expires after 30 minutes of inactivity. DigitalOcean hosts the application, PostgreSQL, and Valkey and may process connection metadata and bounded infrastructure logs needed to operate and secure those services. We do not sell this data or use it for advertising.
When a caller deliberately connects through ChatGPT, Claude, or another MCP client, that client sends only the selected tool name and declared tool fields to this service. We do not request or reconstruct the caller's full conversation. Those clients and infrastructure providers operate under their own published privacy terms.
Connector boundaries
The free Claude and ChatGPT connectors forward only bounded canonical module input and an optional retry identifier. They do not forward payment headers or return payment and execution-ledger metadata. Their abuse-prevention counters expire automatically.
Webhook Attempt Meter stores timestamp, method, byte count, content type, and request/user-agent hashes only. It discards the body, source IP, raw user agent, and arbitrary headers, and deletes the record on first retrieval or expiry.
Capability requests
Missing-capability submissions may temporarily retain the structured problem and evidence supplied by the requester. Submitters must not include credentials, contact information, personal data, uploads, or full conversation history. Supplied request text is deleted after 90 days while a non-identifying aggregate status may remain.
Retention and controls
Coordination records expire at the caller-selected bounded TTL published in each tool manifest. Replay records expire after at most 24 hours, aggregate observations after 90 days, and Cloudflare's bot cookie after 30 minutes of inactivity. You can stop processing by not invoking a tool, clear cookies in your browser, or contact us to request access to or deletion of support or capability-request data that can be located from the information you provide.
Contact
Privacy questions may be sent to [email protected].