Memberflow logo

Memberflow Privacy Policy

Local-first coaching and tagging, plus optional automation, for Skool community operators.

Effective Date: July 13, 2026
Want the plain-English version? Our Trust & Security page answers the questions operators actually ask — what Memberflow can read, who sees your posts, what's stored where, and how we handle GDPR. UK/EU operators can also read our Data Processing Agreement.

1. Overview

Memberflow is a Chrome extension that helps Skool community operators tag members, review visible community activity, and see local-first coaching, People, and growth insights on supported Skool pages.

Memberflow is built local-first: the insights it shows you are generated from data visible on the Skool pages you view and are stored on your own device. Some features send data to our backend — account access, and, if you turn them on, our optional automation features that can publish scheduled posts and send messages on your behalf, including while your browser is closed. This policy explains exactly what leaves your device, when, and why.

2. What Memberflow Does

Memberflow helps Skool community operators by:

The extension only operates on supported Skool domains.

3. Local-First Insights (no data leaves your device)

On supported Skool pages, Memberflow reads content that is already visible to your logged-in browser session to build the insights it shows you:

The results — tags, People/attention classifications, activity observations, and coaching, health, momentum, and growth snapshots — are stored on your device in Chrome storage. This category of data is not transmitted to our servers.

Local-first principle: Your community insights, member tags, and coaching snapshots stay on your device. Memberflow does not store this category of data in a cloud database. (Automation content is different — see Section 5.)

4. Account and Access Data (sent to Supabase)

To sign in and check your entitlement, Memberflow sends the following to our backend provider, Supabase:

5. Automation Features (stored on our servers when enabled)

Memberflow includes automation features that run on our servers so they can act while your browser is closed. When you use these features, data leaves your device and is stored on our backend. This applies only if the relevant feature is enabled for your account.

Scheduled posting is enabled by default (opt-out) as of July 7, 2026. Welcome DMs, broadcast DMs, and auto-approval of member requests are off by default (opt-in). You can change any of these at any time in the Memberflow dashboard.

When an automation feature is enabled, we store the following in Supabase:

If you never enable an automation feature, none of the data in this section is sent to or stored on our servers.

6. Use of Supabase (subprocessor and hosting)

Memberflow uses Supabase for authentication, access and entitlement checks, access code redemption, and (when you enable them) the automation features above. Supabase acts as our subprocessor and hosts our project in the United States (AWS us-west-2). Where automation sends personal data to our servers, that data may therefore be processed in the United States. To deliver scheduled actions, content may be proxied through Skool's and, for GIF search, Giphy's services. We do not sell this data.

7. Lawful Basis (UK/EU users)

8. Data Retention

9. Your Rights and Choices

You can:

To exercise any of these rights, contact us using the details below. We aim to respond within 30 days.

10. Complaints (UK users)

If you have a privacy concern or complaint, you can send it using the form below or email us directly. We acknowledge every complaint within 30 days, investigate it, and respond. UK users also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

11. Data Sharing and Security

We do not sell, rent, or share your data for third-party advertising. We share data only with the subprocessors needed to operate the service (Supabase for backend/hosting; Skool and Giphy where required to deliver an action you requested), or where required by law. All network requests use HTTPS, the stored session token is encrypted at rest, and local insight data is kept on your device by default.

12. Children

Memberflow is not directed to children and is intended for adult community operators.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.

14. Contact Information

Skool Nerds
Privacy contact and data-subject requests: brian@baddayexcellence.com