Skip to main content

Privacy Concern: Member Enumeration in Private Communities

A few months ago, I reported an issue related to the Messages add-on and private communities.

As far as I can tell, users are still able to discover and search for members through the Messages interface, even when the community itself is configured as private.

For some communities this may not be a major concern, but for others (especially those operating under GDPR requirements in the EU) exposing membership information of a private community may create unnecessary privacy and compliance concerns.

This can be particularly relevant for professionals, consultants, coaches, membership sites, and companies that rely on private communities where membership itself may be considered sensitive or confidential information.

Could the team confirm whether this issue is already on the roadmap or if a fix is planned?

Thanks!

Privacy Concern: Member Enumeration in Private Communities

Example:

Imagine a business automates its entire onboarding process.

A customer purchases through FluentCart (or any other checkout solution), an account is created automatically, and the customer is added to a private community.

The community could be about healthcare, professional support, coaching, mental wellbeing, or even something completely non-sensitive like guitar lessons.

With the current behavior, another member may be able to discover and enumerate community members through the Messages search interface.

For open communities this may be less problematic. However, for private communities (where there is a reasonable expectation of privacy regarding membership) this becomes a much bigger concern.

In some cases, simply revealing that a person belongs to a particular private community may expose information that users reasonably expect to remain private.

This is why I believe the current behavior deserves attention from both a privacy and product-design perspective, especially for community owners operating under GDPR requirements.

Raiyan Marzan

Jorge de los ReyesΒ The issue has been fixed in dev and will be included in the upcoming release.

Raiyan MarzanΒ thank you Raiyan! πŸ˜„

That’s great to hear.

The reason I brought it up again is that I remember receiving a similar update a couple of months ago, and since then we’ve had several releases where the issue still appeared to be present. So I wasn’t sure whether it had been postponed, re-opened, or was still pending.

Really happy to hear it’s already fixed in development and coming in the next release. Thanks for the update!

Raiyan MarzanΒ Any ETA for this? Thank you!

Raiyan Marzan

Jorge de los ReyesΒ The release is ready and currently in the testing phase.