fellos Privacy Notice
Last updated: September 29, 2026 Effective: September 29, 2026
This notice explains how maClara, LLC ("fellos", "we", "us") handles personal data. It covers:
- organizations and their admins who sign up for and use fellos;
- anyone signed in to a fellos site, members included, who contacts fellos support or uses the "fellos AI" support chat; and
- visitors to fellos.app and signup.fellos.app.
If you are a member of an organization that uses fellos, your organization's own Privacy page on its site explains how it uses your member data. Section 2 explains our part. If your organization has not published one, contact its admins.
Sections
1. Who we are
fellos is a membership platform for clubs and associations. It is operated by maClara, LLC, a Virginia limited liability company. See Section 14 for how to contact us.
2. Our two roles
Where we decide (controller). We decide how data is used for:
- signing up for fellos;
- your organization's fellos account and subscription;
- our emails to organization admins;
- support tickets and the "fellos AI" support chat, whoever uses them; and
- our own websites, fellos.app and signup.fellos.app.
This notice covers that data in full.
Where your organization decides (processor). Each organization's site holds its members' data, including profiles, member records, posts, messages, events, dues and store orders. The organization decides what to collect and why, and we process that data on its behalf. Its site's Terms and Privacy pages govern that relationship. Members should send questions and requests about their member data to the organization. If a member writes to us, we will pass the request on, or ask the member to contact the organization.
Section 7 describes the processing we do for organizations, so that they and their members can see which services we use. Our Data Processing Addendum (DPA) sets the terms of that processing, and organizations accept it when they accept our Terms of Service. We list the service providers we use for it (our subprocessors) at fellos.app/subprocessors. We will tell site admins by email, and update that page, at least 30 days before we add or replace a subprocessor. An organization that objects may cancel its subscription with immediate effect, and we will refund any fees it prepaid for the rest of the period.
3. What we collect and why
When you sign up
| What | Why |
|---|---|
| Organization name, site address, starter template | To create your site |
| Your first and last name, email address and password | To create your admin account and verify your email. We store your password only in scrambled form (a bcrypt hash), so it can't be read back. |
| Your analytics choice when you verify | To decide whether we send signup events to HeyCatch (see below). You can change it during setup. After setup, write to privacy@fellos.app. |
Where you came from: the from and utm_* values in the link you followed to signup (which fellos.app button, and which campaign), and your answer to the optional "Where you heard about fellos" question during setup |
To learn how organizations find fellos. We keep them with your organization's record for as long as the account exists, and delete them with it. Only our staff see them. We send the link values to HeyCatch in the signup event only if you allowed analytics. Your "Where you heard about fellos" answer is not sent to HeyCatch. We never collect Google's ad click id (gclid). |
| Your acceptance of our Terms of Service when you tick the box: which version you accepted, and when | To keep a record that your organization accepted our Terms. We store it with your fellos user id when you verify your email. It holds no IP address or browser details. |
Until you verify your email, we hold these details in a temporary signup record.
Your site address is public. Every site's address, custom domains included, is listed in a security certificate. Certificates are published in public Certificate Transparency logs, so anyone can see that your site's address exists.
While you set up your site
- Invitations. You can enter email addresses for co-admins and for up to 200 members. Those addresses belong to your organization's member data (Section 7). We use them only to send the invitations you asked for.
- Website import (optional). If you ask us to, we fetch your club's existing website. We then send its content to our AI provider to suggest a theme and front-page text. The setup wizard asks for your consent first.
When you buy a plan
We create a Stripe customer record with the purchaser's name and email address. You enter card details on Stripe's page; they never reach fellos. We keep your plan, subscription status and billing history.
When someone accepts our Terms of Service while buying or changing a plan, moving to the Free plan included, we record who accepted (their fellos user id), which version of the Terms, and when. We also record the plan, the matching Stripe checkout or subscription if there is one, and whether the checkout opened or the change was made or scheduled, as far as we could confirm at the time. We do not update the record later, for example if a scheduled change is called off. The record holds no IP address or browser details. At checkout, Stripe receives the Terms version and the accepting person's fellos user id as well.
When you use your site as an admin
- Emails from us. We send your site admins service emails: billing, security, domain and member-cap notices. These are part of the service and cannot be turned off while your account is open. Separately, we send tips, a weekly digest, milestone emails and re-engagement emails. Those carry an unsubscribe link. We keep a log of the automated emails we send to admins, so that we don't repeat them.
- Sign-in and security. When you sign in, we record the session. Each session record holds your browser's user agent, your IP address, and an approximate location (country, region and city). We look up the location in a database on our own servers, not through a third-party service. Your account also records when you last signed in and when you were last active.
When you contact support or use the support chat
- Support tickets. We keep the subject, messages and attachments you send, whether you open a ticket in the app or email support@fellos.app. fellos support staff read the thread. A site admin with Admin Mode on can also read every ticket opened on that organization's site.
- Staff "AI suggest". To draft a reply, our staff can send a ticket's subject and its last two visible messages to our AI provider. That includes tickets that arrived by email.
- "fellos AI" chat. The in-app assistant sends your chat to our AI provider to draft answers. We keep the chat transcript and a per-person count of how often you use it.
- Engineering tracker. Our staff may copy details of a ticket into an issue in our private engineering tracker on GitHub.
When you visit fellos.app
- Product analytics (HeyCatch), only after you accept (see Section 5).
- Demo requests. The demo form asks for your name, email, organization, kind of organization, role, member count, whether you have chapters, and a free-text message. We send it as one email to hello@fellos.app, with your address as the reply-to. The mailbox is hosted by Google (Google Workspace). We do not store the request in a database. We use your IP address in memory to limit form submissions to 5 per hour.
When you visit signup.fellos.app
-
Product analytics (HeyCatch), only after you accept (see Section 5).
-
Signup events we send to HeyCatch from our servers, only if you allowed analytics:
- when you verify your email (with the starter template you chose, your site address, your signup date, and the link values described above);
- when your site goes live (with your site address and how many minutes it took);
- when you invite co-admins or members (counts and yes/no outcomes only); and
- when you finish setup.
Each event is labelled with your fellos user id (a random id, not your name or email). We send no personal names and no email addresses. Your site address often includes your organization's name.
Where the data comes from
We get most data from you. We get some from others: co-admin email addresses from the founder who invites them.
4. Legal bases (EEA, UK and similar laws)
- Contract. Creating and running your account and subscription, sending the invitations you ask for, and providing support.
- Steps before a contract. Replying to a demo request (together with our legitimate interest in replying).
- Legitimate interests.
- Keeping the service secure: session records, IP addresses and approximate location, and rate limits.
- Keeping billing records.
- Sending service emails, and the admin emails you can unsubscribe from.
- Copying ticket details into our engineering tracker to fix what you report.
- Learning how organizations find fellos, from the signup link values and your answer to "Where you heard about fellos".
- Improving fellos: working out which features are used, and finding and fixing faults, from support tickets and the analytics you allow.
- Consent. Analytics cookies, signup events sent to HeyCatch, and the website import. You can withdraw consent at any time.
- Legal obligation. Tax and accounting records.
We do not make decisions about you based only on automated processing that have legal or similarly significant effects.
7. Processing we do for organizations
On each organization's instructions, fellos stores:
- member profiles and history;
- secondary members, such as spouses;
- workflow requests;
- election records;
- posts, comments, reactions and documents, with their revisions;
- direct messages;
- event RSVPs, tickets and check-ins;
- dues and store orders;
- sign-in methods;
- session records; and
- an audit log of admin actions.
The audit log records who acted, what changed, and the IP address.
Election ballots. fellos stores each ballot together with the voter's identity, to stop anyone voting twice and to show members their own ballot. The product shows a member's choices only to that member. Everyone else, election conductors and site admins included, sees only totals. Staff with database access could technically see individual ballots. We never look at them, except where the law requires us to.
Staff access. Our staff can see your organization's member list, billing and support tickets in our admin tools, and a small number of engineers have database access. We look at your data only to give support you ask for, fix problems, keep the service secure, or meet a legal obligation.
Link previews. When a member posts a link, our server fetches the page to build a preview.
We use these providers on the organization's behalf:
| Provider | What it receives | When |
|---|---|---|
| Amazon Web Services, US East (Northern Virginia) | All site data and uploads | Always |
| Resend | Member email addresses and email contents | Every email the site sends |
| OTTO, powered by WATTER, Inc. | Group posts and comments, each with its author's name and member type, the group's name and the thread's title, for search. Up to 48 recent posts per member each week for the weekly digest (titles, text and group names, without author names). Group search text. Ask AI questions, with the organization's name and type, and the posts and whole threads Ask AI searches and reads, with each author's name and member type. The posts of a thread being summarized, by Summarize or a summary update, with their authors' names and member types. Page content for the page-writing and page-style helpers. | Automatically: search indexing, the weekly digest and summary updates. Otherwise when someone uses the feature. |
| Google Wallet | The ticket holder's name, the event, venue and address, the organization, ticket types, check-in time, the ticket id and its QR check-in code | When a member adds a ticket to Google Wallet |
| Apple Push Notification service | A push token, with no member details | To update an Apple Wallet pass. The pass itself is served by fellos. |
| Browser push services (Google, Mozilla, Apple, Microsoft) | Encrypted notification contents | When a member turns on push notifications |
| USPS, UPS, FedEx, DHL | Tracking numbers only | To track store shipments |
Payments from members are not on this list. When a member pays dues, buys a ticket or orders from a store, the payment goes through the organization's own Stripe account, which the organization connects to fellos. Stripe is the organization's provider, not ours: the organization is the merchant, and fellos is not a party to the payment. fellos sends that Stripe account the paying member's email address and ids that link the payment to the member and the item. For store orders it also sends the member's name and, where their profile has them, phone number and home address (as billing and shipping address).
Social sign-in is not on this list either. Sign-in with Google, GitHub or Apple uses sign-in apps the organization registers with those providers itself. They are the organization's providers, not ours.
Under contract with fellos, WATTER, Inc., which provides OTTO, keeps none of the content it receives and does not train on it. This covers every AI feature in this notice: search indexing, Ask AI, Summarize, the weekly digest, summary updates, the page helpers, the "fellos AI" support chat, staff "AI suggest" and the website import. That is a contractual commitment, not an audited one.
Group summaries can be turned off. A site cannot turn off the weekly digest summary, but each member can unsubscribe from the weekly digest. Search indexing and Ask AI cannot be turned off.
8. International transfers
We are based in the United States, and we store all data in the United States, with Amazon Web Services in US East (Northern Virginia). Our subprocessor list at fellos.app/subprocessors shows where each service provider processes data. If you are outside the US, your data will be transferred there.
For personal data transferred from the European Economic Area or the United Kingdom, we rely on the European Commission's Standard Contractual Clauses and, for the UK, the UK International Data Transfer Addendum. For organizations' data, both are incorporated in our DPA. We are not certified under the EU-US Data Privacy Framework.
9. How long we keep data
| Data | How long |
|---|---|
| A signup that is never verified | We send reminders after 24 hours and after 7 days. At 14 days the signup is marked abandoned. It is deleted 30 days later, with the name, email and password hash: about 44 days in all. |
| Founder details held in a verified signup record | As long as the account exists |
| Where a founder came from (the signup link values and the "Where you heard about fellos" answer) | As long as the account exists. Deleted with it. |
| Sign-in sessions | A session ends after 7 days idle, or after 90 days at most. The record is deleted 30 days after it ends. |
| Last sign-in and last-active times | As long as the account exists |
| Log of automated emails we send to admins | 400 days. Records of one-time emails are kept for as long as the account exists, so they are never sent twice. |
| Email bounce and complaint events | 365 days |
| Link previews | 180 days |
| Notifications and feed items on a site | 90 days and 180 days |
| Support tickets, "fellos AI" chat transcripts and usage counts | As long as the account exists |
| Audit log (including IP addresses), consent records, direct messages (including deleted ones), posts, documents, election records | As long as the organization's site exists |
| Billing records | As long as tax law requires |
| Records of who accepted our Terms of Service | As long as the organization's site exists. When the site is deleted, we keep a copy for 7 years. |
| Site-closure records: the email address of whoever asked for the closure, the request reference, and a copy of the site's subscription, billing history and Terms of Service acceptances | 7 years after the site is deleted, or after the closure is called off |
| Demo-request emails | Up to 2 years |
| HeyCatch analytics data | Up to 1 year |
When a site is paused, closed or ended
Section 13 of our Terms of Service and Section 11 of our Data Processing Addendum repeat this table word for word. To close a site and have its data deleted, a site admin can write to support@fellos.app from their own address.
| Situation | What happens to the data |
|---|---|
| Getting a copy of your data | A site admin can download the member roster (CSV, Excel or PDF) at any time. For the rest of the site's records, a site admin can write to support@fellos.app, and we will provide CSV files, with uploaded files as a zip, within 30 days, at no charge. |
| A paused site | When a paid plan ends, the site is paused at the end of the paid period. Nothing is deleted while it is paused, apart from routine clean-up, such as the expiry of old notifications, feed items, session records and email logs. Site admins can still sign in to reach Billing, the member-roster download and member deactivation; Comptrollers can reach Billing. We keep a paused site's data for 12 months, and email its site admins 30 days and 7 days before we delete it. Until then, they can export the data, resubscribe, or move to the Free plan if the site fits it. After 12 months, we delete the site and its data as for a closed site. |
| Closing a site | On a confirmed request from a site admin, we delete the site's database records and uploaded files within 30 days. Copies in backups expire on the backup schedule, within 35 days. We keep billing records for as long as tax law requires. |
| After termination by us | We keep the site's data for 12 months, as for a paused site, with the same warnings, and the data export stays available to its site admins. Unlike a paused site, it cannot be reopened by resubscribing or moving to the Free plan. After 12 months, we delete the site and its data as for a closed site. A site that was already paused keeps its original deletion date. |
| Backups | Up to 35 days. Data deleted from the service stays in backups until they expire. |
| Removing one member's data | Deactivating a member does not delete their data: the site keeps the member's profile and history. To have a specific member's data removed, a site admin can write to privacy@fellos.app. If a member asks us directly, we will pass the request to the site's admins. |
10. Security
- We store passwords only in scrambled form (bcrypt hashes).
- Every fellos site is served over HTTPS only.
- The passwords and keys fellos uses to connect to other services are stored encrypted.
- Organizations can require their admins, or all members, to set up a passkey.
- Card details go to Stripe and never reach fellos.
No system is perfectly secure. We hold no security certification, such as SOC 2 or ISO 27001.
If a personal data breach affects data we hold, we will tell the affected organizations' site admins without undue delay, and within 72 hours of becoming aware of it. Where the law requires, we will also tell the regulator.
11. Your rights
Depending on where you live, you may have the right to:
- access your data, or get a copy of it;
- receive your data in a portable format;
- correct it;
- have it deleted;
- object to or restrict our use of it;
- withdraw consent;
- appoint an authorized agent to act for you (California);
- appeal our decision on your request, by replying to it (some US states); and
- complain to your data-protection authority.
To use these rights, write to privacy@fellos.app. We confirm your identity by asking you to reply from the email address on the account. We will respond within 30 days, or within 45 days for requests under US state privacy laws. We will not treat you differently for using your rights.
- Members of an organization: send requests about your member data to your organization. We will help it respond. If you write to us, we will pass the request to its admins. Requests about your own support tickets or "fellos AI" chats come to us.
- Cookies: use Cookie settings on fellos.app or signup.fellos.app, or send a Global Privacy Control signal.
- Emails: use the unsubscribe link in tips, digests and other non-essential admin emails. Service emails (billing, security, domain and member-cap notices) are part of the service and cannot be turned off while your account is open.
- California and other US states: fellos does not sell personal data. We honor Global Privacy Control signals on fellos.app and signup.fellos.app. We offer the same rights to access, correct and delete your data to everyone, wherever they live. Your account password is sensitive personal information. We use it only to sign you in.
12. Children
Founders and site admins must be at least 18. fellos is not directed to children. We do not knowingly collect personal data from children for our own purposes: under 13 in the United States, and under the age set by local law, up to 16, in parts of the EU. If we learn that we have, we will delete it.
Organizations may add minors to their sites, for example in a youth auxiliary or as secondary members. The organization is responsible for getting any parental consent the law requires. If you believe we hold a child's data in error, write to privacy@fellos.app.
13. Changes to this notice
We will update this notice when our practices change, and change the date at the top. For a material change, we will email organization admins at least 30 days before it takes effect.
14. Contact
maClara, LLC (fellos), a Virginia limited liability company
| For | Write to |
|---|---|
| General questions | hello@fellos.app |
| Support, data exports and closing a site | support@fellos.app |
| Privacy requests | privacy@fellos.app |
| Security, compromised accounts and abuse reports | security@fellos.app |
| Legal notices | legal@fellos.app |
Our subprocessor list is at fellos.app/subprocessors. Our Data Processing Addendum, which organizations accept with our Terms of Service, sets the terms on which we process their members' data.