Alternatives

What Your Community Platform Keeps About Your Members: Circle, Skool, Discord and Mighty Networks

What Circle, Skool, Discord and Mighty Networks say they keep about your members, what you cannot take with you, and a one-hour audit.

·15 min read
A member profile card marked platform copy with partial export, beside an owner asking what is collected, who else sees it and what can be taken away

On a hosted community platform, your members agree to the platform’s terms as well as yours, and the platform keeps its own copy of what they type, click and pay. That does not make Circle, Skool, Discord or Mighty Networks careless, and each publishes real protections, but it does mean you share your members’ data with a company you do not run. This guide shows what each platform’s own documents say, what that means for you, and a one-hour audit that keeps you in control whichever platform you use.

We read each platform’s privacy policy, terms of service, data processing agreement or sub-processor list (where public) and its help pages on exporting and deleting, on 8 October 2026. Every platform fact below comes from those pages. Where a page is silent, we write “not stated on the pages we read”. This is general information, not legal advice; ask a lawyer who knows data protection law where your members live.

In this guide

  • The short answer: who holds what, and why it matters to you
  • A comparison table of the four platforms (verified cells only)
  • One short section per platform: Circle, Skool, Discord, Mighty Networks
  • What this means for you as the owner
  • The one-hour audit: read, list, remove, limit, delete, export
  • What a self-hosted community changes, and what still leaves your server
  • Questions people ask

Who actually holds your members’ data on a hosted platform?

Usually two parties: the platform, which stores accounts, posts, messages, payments and logs on its own systems, and you, who can see most of it in an admin screen and are often the one answerable to your members.

Three terms help. A data controller is the party that decides why and how personal data is used. A data processor (a “service provider” in some US laws) handles data on the controller’s behalf. A sub-processor is a company the processor hires, such as a cloud host. When a document says “the Host is the controller”, the legal duty to your members sits with you.

Most platforms are also a controller for their own purposes, such as security and improving the service. That is where questions about your members’ content live.

How do the four platforms compare?

The table uses only what the platforms’ own pages said when we read them. Documents change, so read the current versions before you decide anything.

Question

Circle

Skool

Discord

Mighty Networks

Who is the controller of member data?

In creator-managed communities, the creator is the controller and Circle the processor. Circle is the controller for its own services.

Skool is the controller of its own processing. Where it acts as a processor, the customer is the controller.

Discord: Discord Netherlands BV for people in the EEA, Discord Inc. for everyone else.

Usually the Host is the controller and Mighty the processor. Mighty is also a controller for its own limited purposes.

Public sub-processor list

Yes, in the data processing addendum (Schedule 4), with more than twenty companies.

Not stated on the pages we read.

Named examples (Stripe, PayPal, Google hosting). No full list on the pages we read.

Yes, on its trust centre: 32 entries.

Statement on AI training

Privacy notice: personal data is never used to train, fine-tune or improve any external AI models.

Not stated on the pages we read.

Public posts may be retained to help train models that detect rule-breaking content.

Privacy policy: personal data is not sent to train third-party large language models.

What the owner can export

Four CSV files on request to support: members, spaces, posts, comments. No uploaded media.

Membership question answers via an Export button. A full member or post export: not stated on the pages we read.

A data package for your own account. A server-wide owner export: not stated on the pages we read.

Member list as an Excel file on the Launch plan or higher; content export tools while the account is active.

After cancelling or deleting

Data is typically removed 90 days after cancelling.

Group is archived (read-only). Data after deletion: not stated on the pages we read.

Deleted content is removed from Discord’s systems, with exceptions. Backups kept 30 to 45 days.

Deleting a network is permanent. Backups and billing records are kept for set periods.

Age or identity checks on members

Not stated on the pages we read.

ID checks apply to payouts for admins and affiliates. Ordinary members: not stated on the pages we read.

Birthday required; extra age checks “in some cases” (face estimate, ID scan or card check).

Not stated for members. The Host is made responsible for age assurance.

What does Circle keep about members?

Circle’s privacy notice (last updated 1 September 2026) says it collects what members submit, plus device identifiers, IP addresses, browser type, usage information, geolocation and commercial information. On roles it says that for creator-managed communities “the Creator is the ‘data controller’ or ‘business,’ and we use such information as a ‘processor’ or ‘service provider.’”

The data processing addendum lists the companies Circle uses. Schedule 4 includes cloud hosts, payments, email delivery, support, video and AI providers (OpenAI, Anthropic). For the AI providers it says they process “prompts and user-submitted content when AI-enabled features are activated.”

On AI, the privacy notice is specific: “we will never use your personal data to train, fine-tune, or improve any external AI models.” The terms of service (last updated 1 September 2026) go further on content. They give Circle a licence to use what you submit, “in a form that does not identify you as the source thereof”, to “develop and improve Circle’s products and services and for all other lawful business practices, such as analytics, benchmarking, and reports.”

For exports, the help page (last updated 21 March 2022) says only admins can request a data export, by emailing support. It arrives as four CSV files for members, spaces, posts and comments, and the posts and comments files “won’t include any uploaded media.” The page on cancelling your plan (last updated October 2026) says that after cancellation “we typically remove the community data after 90 days”, that an export (members without passwords, spaces, posts without images, comments) can be requested from support, and that “it’s not easy to re-import this data.”

On age, the privacy notice says the service is not intended for anyone under 16, and the terms ask users to be at least 18 or to have a parent’s consent. A check on members’ identity or age: not stated on the pages we read.

What does Skool keep about members?

Skool publishes a privacy policy (last updated 29 September 2021) and terms and conditions (effective 1 July 2023). The privacy policy lists identifiers, geolocation data, professional or employment information, visual information, internet activity and “inferences drawn from any of these categories.” It says “Skool is the controller of your Personal Data as described in this Privacy Policy”, and that where it processes data as a processor for customers, the customer is the controller. It adds: “We are not responsible for the privacy or data security practices of our customers”, so the group owner is the party members would turn to.

The policy mentions “contracted service providers and any subcontractors” but names none. A sub-processor list: not stated on the pages we read.

The terms give Skool a licence to “use, reproduce, distribute, create derivative works of, display, and perform your content”, “for the limited purpose of providing, developing, and improving our services as permitted by applicable laws.” A statement on AI training: not stated on the pages we read.

For export, the help article on membership questions says the Export button on the Members tab exports members’ answers to your membership questions. A fuller member list or post export: not stated on the pages we read.

On leaving, the terms say that after cancelling, “Admin’s group will be archived, whereas then-current content will be available on a read-only basis.” The help page on deleting a group says you must be the only person left and the group must be archived, and adds that “in most cases, you’d just want to cancel your subscription to stop the billing.” What happens to the data after deletion: not stated on the pages we read.

On identity, the help centre says ID verification is required before a payout can be processed, for affiliates and community payouts. That concerns people who get paid.

What does Discord keep about members?

Discord’s privacy policy (effective 29 September 2025 when we read it) says it collects content you create (messages, posts, voice messages, files, profile information), the servers you join and your roles in them, device and network information such as your IP address, and logs of the pages, servers and channels you visit. It names Discord Netherlands BV as controller for people in the EEA and Discord Inc. for everyone else, and names Stripe and PayPal for payments and Google for cloud hosting. A complete sub-processor list: not stated on the pages we read.

On using content, the policy says Discord “may also use content posted in larger spaces to help us develop, improve and power our services, including features that help you catch up on conversations and safety features that identify harmful content.” Its page on how long Discord keeps your information adds that “public posts may also be retained for 180 days to two years for use by Discord as described in our Privacy Policy (for example, to help us train models that proactively detect content that violates our policies).” The terms give a licence to “use, reproduce, distribute, create derivative works of, display, and perform your content” for “providing, developing, and improving our services.”

For owners, the data package is, in Discord’s words, a ZIP of “all of your Discord data for your account.” It is a personal export. A server-wide owner export: not stated on the pages we read. For the practical routes, see Leaving Circle, Skool, Mighty Networks or Discord: How to Export Your Members and Content and Bring Them Home.

On deletion, the retention page says you can delete a server or channel if you have the permissions, and that deleted content “will also be deleted from Discord’s systems”, with exceptions for legal duties. Backups are kept 30 to 45 days.

On age, the privacy policy says every user provides a birthday and “in some cases, we may require additional information to verify your age.” The retention page names three methods: on-device facial age estimation, an ID scan and a credit card check, and says the provider sends Discord an “age signal only” and that selfie and ID data is “deleted once the process is completed.” The check is Discord’s process, not yours; we covered the background in Discord Wants Your Members’ Government ID: The Self-Hosted Alternative That Does Not.

What does Mighty Networks keep about members?

Mighty Networks publishes its documents in a trust centre. When we read it, the page announced “New Policies - Effective October 7, 2026”, and the privacy policy and Host Terms of Use were marked last updated 28 September 2026.

The privacy policy is the most direct about roles: “In most cases, your Host, not Mighty, is the party responsible for the Personal Data collected on Mighty.” Mighty is the Host’s processor, and also a controller “for our own limited purposes”, such as “operating, securing, improving, providing, and marketing the Service.” It tells members their Host can see their name, email, usage activity, course enrolments, event attendance and purchase history, and may keep their data after they leave.

The sub-processor page lists 32 entries, including AWS, Google, Stripe, Zapier and Mailgun, along with Anthropic (listed for engineering) and OpenAI (listed as machine learning, “text and image generation”). On AI, the privacy policy says Mighty may use personal data, with aggregated and de-identified data, to “provide, develop, evaluate, and improve features, models, and technologies”, which “may include machine learning and similar technologies”, and then: “We do not send Personal Data to train third party large language models (‘LLMs’) for either artificial intelligence or machine learning.” The Host Terms license Mighty to use Your Content “in connection with operating, providing, improving, and promoting the Service.”

For exports, the help page on downloading member data says that on the Launch plan or higher you can download an Excel file for your whole network, a Space you host, or each paid plan, with columns including name, email, location, last visit, space memberships and custom field answers. The Host Terms say that after termination “we have no obligation to export, return, or otherwise make Your Content available to you.”

The page on cancelling and deleting says deleting a network is permanent: “All content, data, and member activity will be removed and cannot be recovered.” The privacy policy lists what is kept afterwards: transaction, billing and tax records for 7 years, server logs for up to 12 months and routine backups for 12 months.

On age, the privacy policy says the service is not directed at children under 13, and the Host Terms make the Host responsible for “implementing any required age assurance, parental consent, and safety measures.” An identity or age check run by Mighty on members: not stated on the pages we read.

What does this mean for you as the owner?

Your own obligations do not go away when you rent a platform. Circle and Mighty Networks say the creator or Host is the controller of member data. Skool says it is not responsible for its customers’ privacy practices. Discord names itself as controller but leaves server owners to set permissions and choose bots. In every case, a lot is left to you.

  • You answer to your members first. When a member asks “what do you hold about me” or “delete my data”, they ask you, not the platform. You need to know what the platform lets you find and remove.
  • You choose the add-ons. Every integration, bot, Zapier connection or CRM sync you switch on sends member data to another company that the platform’s own sub-processor list does not cover.
  • Your members agreed to two sets of terms. If your privacy page and the platform’s policy disagree, members will notice.

The symptom of getting this wrong is a member asking what you hold, and you cannot say. The fix is the audit below. If you serve members in the EU or UK, data protection law (the GDPR and its UK version) applies to you as a controller wherever your platform is based. Our post on GDPR-safe community platforms covers that side.

What is the one-hour audit for a community on a hosted platform?

You can do this in about an hour with a spreadsheet. The aim: know what you hold, hold less, let fewer people and tools reach it, delete on a schedule, and keep your own copy.

Minutes 0 to 15: read the four documents

Open your platform’s privacy policy, terms, data processing agreement (or sub-processor list) and the help pages on exporting and deleting, using the links above. Answer six questions in a notes file, quoting the sentence where there is one:

  1. Who is the controller of the members’ data, and who is the processor?
  2. Which companies process it, and is there notice when that list changes?
  3. What may the platform do with members’ content, and does it say anything about AI?
  4. What can the owner export, and what is left out (media, messages, passwords)?
  5. What happens after a cancellation, and how long do copies survive?
  6. Does the platform run age or identity checks on members?

If a document does not answer one, write “not stated” and email the platform’s privacy contact.

Minutes 15 to 30: list what you collect

Make a table: the piece of data, where it comes from, why you need it. Include the obvious (name, email, payments) and the easily forgotten: signup questions, custom fields, location, birthday, notes about members, and anything synced to a CRM or email tool. How to check: download the member export and read the column headings. Every column is something you are holding.

Minutes 30 to 40: remove what you do not need

Mark each row keep or remove. Turn off signup questions you never read, delete unused custom fields, switch off location features members do not use, and clear old notes that describe people rather than what they bought. Confirm the columns are gone in your next export.

Minutes 40 to 50: limit admin and integration access

List every admin and moderator and every connected app: Discord bots, Zapier connections, CRM and email syncs, payment links, analytics tags. Remove what no longer needs access, and give moderators the lowest role that lets them work. The aim is least access: each person and tool sees only what its job needs. Repeat this every quarter.

Minutes 50 to 55: set a deletion routine

Write one sentence on how long you keep data about people who left or went inactive, for example: “We remove members who have not signed in for two years and have no open payment.” Set a calendar reminder to do it, and define how deletion requests are received, recorded and answered. Know your platform’s buttons: Circle’s help page on removing members (last updated 24 June 2025) says a deleted member’s profile and content are permanently erased, while a deactivated member’s content stays.

Minutes 55 to 60: export a backup on a schedule

Run the best export your platform offers, store it somewhere you control with limited access, and calendar the next one (monthly for an active community, quarterly for a quiet one). An export is personal data too, so protect it. Open it once to check members, posts and dates are there, and note what is missing (for example, uploaded media). A backup you have never opened is a hope, not a backup.

What moves into your control on a self-hosted community?

On a self-hosted WordPress community, the files and database sit on a server you pay for, the plugins are code you can read, and the list of outside companies that touch your members’ data is one you build. The change is not that data is safe by default. It is that every transfer is a choice you can inspect.

Our community engine is BuddyNext, a free community plugin for WordPress. Its readme describes “the social layer for WordPress”: an activity feed, spaces (groups), member profiles and a directory, connections and follows, direct messaging and media (powered by WPMediaVerse), notifications, onboarding with invites and social login, optional two-factor sign-in and a moderation queue. It states that BuddyPress is not required (BuddyPress is the older option, and remains a choice for existing sites). We claim only what the readme lists, and each other plugin you add needs the checks below.

  • Where the data lives. Members, posts, messages and uploads are in your database and uploads folder. A full backup is a database dump plus files, on your schedule.
  • Who the processors are. Your web host, plus anything you install or configure. There is no platform-wide list you cannot change.
  • Export and erasure. WordPress core has personal data export and erasure tools, and plugins can add to them. BuddyNext’s changelog says its GDPR export is derived from its erasure registry, so an erased table is also exported. Test this with a dummy account before relying on it.

You also take on what the platform did for you: updates, backups, security and spam control. For a small, free, low risk community, a hosted platform with a tight audit may be the better answer.

What still leaves your server on a self-hosted community?

A WordPress community is not a sealed box. Plugins call outside services, and a self-hosted site can send as much member data away as a hosted one if nobody checks. Typically leaving your server:

  • Email delivery. Notifications, receipts and password resets go through a delivery service that sees member email addresses and message content.
  • Payments. Stripe, PayPal or similar receive the member’s name, email, order and card details.
  • Analytics and marketing tags. Scripts in the member’s browser send page views and identifiers to analytics, advertising and chat-widget companies, bypassing your server.
  • Social login. Signing in with Google, Apple or Facebook sends a request to that provider.
  • AI features. Any plugin offering summaries, moderation help, search or chat from an AI service sends text to it. It is easily missed, because it arrives as a toggle and an API key.
  • Link previews, fonts, embeds, spam checks, CDNs and update checks. Each contacts another company, with details such as IP addresses or your site address.

How to check what your site sends out

Start with an inventory of active plugins, using WP-CLI (the official WordPress command line tool) or the Plugins screen:

wp plugin list --status=active --fields=name,version

Read each plugin’s readme and settings for words like “external service”, “API key”, “connect”, “analytics”, “email”, “payment” and “AI”. Then watch live traffic. The Query Monitor plugin has an HTTP API Calls panel showing outgoing requests made by PHP, which component made them and how long they took. Load a few pages and run a test signup, then read the panel. For browser-side calls, open your browser’s developer tools, choose the Network tab, reload a page as a logged-in member, and look at domains that are not yours.

To make a site fail loudly instead of leaking quietly, WordPress documents two constants for wp-config.php. WP_HTTP_BLOCK_EXTERNAL blocks outgoing requests from WordPress, and WP_ACCESSIBLE_HOSTS lists the hosts allowed through:

define( 'WP_HTTP_BLOCK_EXTERNAL', true );
define( 'WP_ACCESSIBLE_HOSTS', 'api.wordpress.org,*.stripe.com' );

Try this on a staging copy first, because it also stops update checks and any service you forgot you rely on. It covers only requests made by WordPress on the server, not scripts in the browser. To prevent drift, record each outside service with what it receives and why, check for new ones whenever a plugin is added or updated, and name them in your privacy notice.

Questions people ask

Is community data safer on WordPress than on a hosted platform?

Not automatically. The platforms run large security teams, and a poorly maintained WordPress site can be less safe than any of them. What changes is control, and safer means updates applied, backups tested and an audit like the one above.

Can the platform use members’ posts to train AI?

It depends, so read the current wording. Circle’s privacy notice says it never uses personal data to train external AI models, and Mighty’s says it does not send personal data to train third-party large language models. Discord’s pages say public posts may be retained to help train models that detect rule-breaking content. Skool’s documents we read do not address it.

Is the owner the data controller if the community is on a platform?

Often yes. Circle and Mighty both say the creator or Host is the controller for member data, with the platform as processor, and Skool says it is not responsible for its customers’ privacy practices. Being a controller carries duties, such as answering member requests. A lawyer can tell you what applies to you.

If a community moves to WordPress, does its data stop going to other companies?

No. It stops going to the platform, then goes only to the companies you add: your host, email delivery, payments, analytics and any AI service. Make the list, name it in your privacy notice and check it whenever a plugin changes.

Where to go from here

If you would like help moving a community onto WordPress, or building one that fits how your members work, our SaaS to WordPress migration page explains how we move members, content and payments, and our custom community development page covers building on BuddyNext. For the bigger picture on ownership, see Your Community Doesn’t Live on Discord. It Lives on Borrowed Land. A first conversation is a walkthrough of your community, with no commitment to build anything.

Part of the Wbcom Designs family

The all-in-one WordPress community stack

Also ours: wbcomdesigns.comvapvarun.combrndle.com