1. Overview
Memberflow is a Chrome extension that helps Skool community operators tag members, review visible community activity, and see local-first coaching, People, and growth insights on supported Skool pages.
Memberflow is built local-first: the insights it shows you are generated from data visible on the Skool pages you view and are stored on your own device. Some features send data to our backend — account access, and, if you turn them on, our optional automation features that can publish scheduled posts and send messages on your behalf, including while your browser is closed. This policy explains exactly what leaves your device, when, and why.
2. What Memberflow Does
Memberflow helps Skool community operators by:
- Detecting visible people and community context on supported Skool pages.
- Allowing you to tag and organize community members.
- Creating activity summaries from visible Skool page content.
- Providing coaching guidance and next-step suggestions.
- Optionally publishing scheduled posts and sending welcome/broadcast DMs, and auto-approving member requests, via our backend.
The extension only operates on supported Skool domains.
3. Local-First Insights (no data leaves your device)
On supported Skool pages, Memberflow reads content that is already visible to your logged-in browser session to build the insights it shows you:
- Visible content from Skool pages you are actively viewing.
- Community identifiers, page URLs, and member/interaction context.
- Local extension data you create, such as tags, preferences, and settings.
The results — tags, People/attention classifications, activity observations, and coaching, health, momentum, and growth snapshots — are stored on your device in Chrome storage. This category of data is not transmitted to our servers.
4. Account and Access Data (sent to Supabase)
To sign in and check your entitlement, Memberflow sends the following to our backend provider, Supabase:
- Email address and password for authentication.
- Access code redemption requests.
- Authenticated requests used to check entitlement and access status.
5. Automation Features (stored on our servers when enabled)
Memberflow includes automation features that run on our servers so they can act while your browser is closed. When you use these features, data leaves your device and is stored on our backend. This applies only if the relevant feature is enabled for your account.
Scheduled posting is enabled by default (opt-out) as of July 7, 2026. Welcome DMs, broadcast DMs, and auto-approval of member requests are off by default (opt-in). You can change any of these at any time in the Memberflow dashboard.
When an automation feature is enabled, we store the following in Supabase:
- Post and message content. The full content of any post or direct message you schedule or queue (text, links, and any attached images or GIFs), so it can be published or sent at the scheduled time.
- An encrypted Skool session token. So we can act on your behalf while your browser is closed, we capture the session cookie your browser would send to Skool and store it encrypted at rest. It is decrypted only inside our secured server process at the moment it is needed, is never exposed to other users, and is used only for the automation you enabled.
- Member and approval metadata. For welcome DMs, broadcast DMs, and auto-approval, the member names, identifiers, and request/queue records needed to deliver those messages or process those approvals.
If you never enable an automation feature, none of the data in this section is sent to or stored on our servers.
6. Use of Supabase (subprocessor and hosting)
Memberflow uses Supabase for authentication, access and entitlement checks, access code redemption, and (when you enable them) the automation features above. Supabase acts as our subprocessor and hosts our project in the United States (AWS us-west-2). Where automation sends personal data to our servers, that data may therefore be processed in the United States. To deliver scheduled actions, content may be proxied through Skool's and, for GIF search, Giphy's services. We do not sell this data.
7. Lawful Basis (UK/EU users)
- Account and access features: performance of our contract with you.
- Local-first insights: legitimate interest in operating your own community; this data does not leave your device.
- Automation features: your consent, given when you enable a feature or leave scheduled posting enabled. You can withdraw consent any time by turning the feature off, which stops future server-side processing.
8. Data Retention
- Local insight data remains on your device until you remove it, uninstall the extension, or clear extension storage.
- Account and access records are retained while you have an account and as needed for security and legal compliance.
- Automation content is retained until the action completes and for a limited period afterward for delivery confirmation and troubleshooting; you can request deletion at any time.
- The encrypted Skool session token is retained only while an automation feature is enabled and is deleted when you disable automation, disconnect your Skool connection, or delete your account.
9. Your Rights and Choices
You can:
- Choose whether to sign in or redeem an access code.
- Turn scheduled posting and other automation features on or off at any time in the dashboard.
- Request access to, correction of, or deletion of the personal data we hold about you, including queued content and the stored session token.
- Uninstall the extension at any time (locally stored data may persist until Chrome clears extension storage, which you can also do manually).
To exercise any of these rights, contact us using the details below. We aim to respond within 30 days.
10. Complaints (UK users)
If you have a privacy concern or complaint, you can send it using the form below or email us directly. We acknowledge every complaint within 30 days, investigate it, and respond. UK users also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
11. Data Sharing and Security
We do not sell, rent, or share your data for third-party advertising. We share data only with the subprocessors needed to operate the service (Supabase for backend/hosting; Skool and Giphy where required to deliver an action you requested), or where required by law. All network requests use HTTPS, the stored session token is encrypted at rest, and local insight data is kept on your device by default.
12. Children
Memberflow is not directed to children and is intended for adult community operators.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on this page with a revised effective date.
14. Contact Information
Skool Nerds
Privacy contact and data-subject requests: brian@baddayexcellence.com