Skip to content

Privacy Policy

GHL Workflow Backup & Audit · Last updated 27 August 2026

This extension is built to back up and restore your own GoHighLevel workflow data for your own use. This policy explains exactly what data it touches, where it goes, and what it never does.

What the extension reads

When you use the extension on a GoHighLevel workflow page (app.gohighlevel.com), it reads the workflow's step-tree data (nodes, triggers, settings, and, if you provide an API token as described below, the human-readable names of things the workflow references, like pipelines, calendars, tags, and users). This is your own account's data, read directly from the page or GoHighLevel's own API; the extension does not access any other GoHighLevel account or any data outside the workflow(s) you choose to export.

How it reads workflow data (network response inspection)

GoHighLevel's workflow builder does not expose a workflow's full step-tree in the page's HTML, and its public API does not return one either. To assemble a complete export, the extension therefore does two things on GoHighLevel pages:

  • Reads the builder's in-memory state (its JavaScript application data) for the workflow you have open.
  • Inspects the responses of network requests the GoHighLevel page itself makes, as a fallback when in-memory state isn't available, and to learn the names of items referenced by the workflow. It does this by wrapping the page's own fetch and XMLHttpRequest so it can read response bodies as they arrive.

This inspection is limited to responses from GoHighLevel's own domains (gohighlevel.com, leadconnectorhq.com, msgsndr.com) and the Firebase datastore its builder uses. Requests to any other domain, and static assets (scripts, stylesheets, images, fonts, media), are ignored and never read.

Response data is used only to build the export file you asked for, is held in memory for the duration of the capture, and is never transmitted to us or to any third party. It goes only to the destination you choose below. The extension does not read, record, or transmit your browsing activity on any other site; its content scripts run only on the GoHighLevel domains listed in its manifest.

Where that data goes

You control the destination in the extension's Options page:

  • Local download (default): the exported JSON file is saved directly to your browser's Downloads folder on your own device. This data never leaves your computer.
  • Google Drive (optional): if you enable this, the exported JSON is uploaded to a folder named “GHL Workflow Exports” in your own Google Drive, using a Google sign-in you grant directly to the extension via Google's standard OAuth flow. The extension can only see files and folders it creates itself (Google's drive.file permission scope); it cannot browse, read, or modify any other file in your Drive.
  • Both: does both of the above.

In no case does the extension send your workflow data to the developer, to any analytics service, or to any third party other than the destination you explicitly choose above.

Restoring a workflow (import), and your GoHighLevel session

The restore feature writes a workflow file you previously exported back into a workflow in your own GoHighLevel account. It does this the same way the GoHighLevel builder itself does: by calling GoHighLevel's own application backend (backend.leadconnectorhq.com) as you, the signed-in user.

To do that it needs the session credential your browser is already sending. The extension reads the Authorization header from requests the GoHighLevel page itself makes to GoHighLevel's own domains, and keeps the most recent value in your browser's local extension storage (chrome.storage.local, never synced). Specifically:

  • It is read only from requests to GoHighLevel domains (leadconnectorhq.com, gohighlevel.com, msgsndr.com). Credentials for any other service, including the Google credentials on GoHighLevel's Firebase traffic, are deliberately excluded and never stored.
  • It is never logged, never displayed, and never transmitted to the developer, to any analytics service, or to any third party. It is sent only back to GoHighLevel, which issued it.
  • It lives only on your machine, and is discarded and re-read whenever GoHighLevel rotates it. Removing the extension removes it.

What restoring changes in your account. Importing a file replaces the steps and triggers of the workflow you target, and bulk restore can additionally create new draft workflows in the sub-account and folder you are viewing. The extension asks you to confirm before overwriting a workflow that already has content. It only ever writes to workflows in the account you are signed into, and it never deletes a workflow.

The GoHighLevel API token (optional)

If you add a GoHighLevel Private Integration Token in Options, it is stored only in your browser's local extension storage (chrome.storage.local, never synced to Google or anywhere else) and is sent only to services.leadconnectorhq.com (GoHighLevel's own official API) to resolve IDs (like a pipeline or tag ID) into human-readable names for your export. The extension never transmits this token anywhere else.

Licensing and payment (paid version)

If you purchase a license, checkout is handled entirely by a third-party payment processor. The extension never sees or stores your payment card details. After a successful payment they send us the email address you paid with, and we generate a license key tied to it.

To activate the extension you enter that email address and the key. Both are stored locally (chrome.storage.local) and both are sent to our license-verification server, which confirms the key is valid and that it belongs to the address you entered. We do not use the address for anything else: no mailing list, no marketing.

Alongside the key, the extension sends a random installation identifier. It is generated in your browser (crypto.randomUUID()), is not derived from anything about you, your device or your browsing, and identifies nothing except itself. We use it for one purpose: counting how many installations a single license key is in use on, so we can spot a key that has been shared beyond the one person it was sold to. A license covers one person on up to 5 devices; the count runs well above that before we contact you, because reinstalling or using a new browser profile counts as a new installation and we would rather not bother you over it.

If you have no license key, nothing is sent at all. The identifier only travels with a license check, and free-tier use never makes one. Removing the extension deletes the identifier along with the rest of its local storage.

We do not sell, rent, or share your email address or license information with any third party other than our payment provider (as required to process the transaction) and our license-verification infrastructure.

See the Terms of Sale & Refund Policy for pricing, delivery and refund terms.

What we never collect

  • No analytics or telemetry products, and no tracking of what you export, which workflows you open, or anything you do in the browser. The only thing we record about usage is the count of installations per license key described above, and only for licensed users.
  • No browsing history outside the specific GoHighLevel pages you use the extension on.
  • No data sold to advertisers or data brokers.

Data retention & deletion

Installation identifiers attached to a license key are kept on a rolling 30-day basis: an identifier that stops checking in is dropped automatically.

Local download and Drive-uploaded files are yours; delete them like any other file. Your GHL token and Drive-folder cache live only in your browser's local extension storage and are deleted automatically if you remove the extension, or manually via the Options page. To request deletion of license/email records tied to a purchase, contact us below.

This website

Everything above describes the Chrome extension. This section describes unfoldingdimensions.com itself, which the extension neither reads nor reports to. Last updated 4 September 2026.

The site runs two analytics tools, and one of them records what you do on the page:

  • Cloudflare Web Analytics: cookieless and aggregate. It counts page views, referrers, and rough country/device breakdowns. It sets no cookies, builds no profile, and cannot follow you to another site.
  • Microsoft Clarity: session replay and heatmaps. This one records your visit. It captures the pages you view, your clicks, scrolls and pointer movement, and enough of the page's structure to replay the visit as a video-like reconstruction, along with your approximate location (from your IP address), browser, operating system and screen size. Anything you type into an input field is masked by Clarity before it is sent and cannot be unmasked by us. We use it to see whether readers of the guides reach the extension link at the end of them, which a page-view count can never answer.

Cookies Clarity sets

Clarity sets non-essential cookies holding a pseudonymous ID: _clck and _clsk as first-party cookies on this domain, and CLID, MUID, MR, SM and ANONCHK as third-party cookies on Microsoft's own domains. MUID is a Microsoft browser identifier that Microsoft also uses for advertising and other operational purposes across its services. If your browser blocks cookies, Clarity sets none.

Who processes it, and for how long

Recordings are processed and stored by Microsoft Corporation as our processor, under the Microsoft Privacy Statement (opens in a new tab), and are retained for up to 30 days from the time of recording. Aggregate heatmap and insight data outlives the recording it came from. We do not sell or share this data with anyone else, and it is never joined to license or purchase records.

Since 31 October 2025, Clarity requires a consent signal before it will operate fully for visitors in the EEA, the UK and Switzerland; without one, its cookies are not used and sessions are not stitched together.

How to opt out

The site checks two browser-level signals before starting Clarity and skips it entirely if either is set: Global Privacy Control and Do Not Track. Enabling either one in your browser (in Firefox, “Tell websites not to sell or share my data” and “Send websites a Do Not Track request”; in other browsers, extensions such as Privacy Badger or DuckDuckGo Privacy Essentials set GPC for you) stops the recorder before it loads. Blocking clarity.ms in a content blocker, or blocking cookies for this site, works too. Cloudflare Web Analytics has nothing to opt out of; it never identifies you in the first place. To ask for a recording of your visit to be deleted, email us at the address below.

Changes to this policy

If what data we collect or how we use it changes, we will update this page and, for any material change, notify users through the extension or the Chrome Web Store listing before the change takes effect.

Contact

Questions about this policy: unfoldingdimensions@gmail.com