
How it works
Privacy operates on two levels:- Admin defaults — You set the starting point for all members
- Member overrides — Individual members can restrict their own data further
Setting admin defaults
Settings → Users & Profiles → Privacy DefaultsWhat each field controls
Recommended defaults by organization type
Member privacy controls
Members manage their own privacy at Profile → Settings & Privacy → Privacy.
The “completely private” toggle
Make my profile completely private is a master override. When a member enables this:- All their profile data is hidden from other members
- Only organization admins can see their information
- They essentially become invisible in the member directory
How defaults and overrides interact
The key rule: Members can only restrict, never expand. If you set email to admin-only, no member can make their email publicly visible — even if they want to.
Common scenarios
Members can't find each other in the directory
Members can't find each other in the directory
Check your privacy defaults. If Name and Profile Image are set to admin-only, members appear as anonymous entries in the directory. Set at least Name to community-visible so members can identify each other.
I need to comply with GDPR — what should I set?
I need to comply with GDPR — what should I set?
GDPR requires that members can control their own data visibility. Orgo’s privacy settings satisfy this:
- Members can restrict any field to admin-only
- Members can make their profile completely private
- Members can delete their account entirely
I changed the defaults but existing members aren't affected
I changed the defaults but existing members aren't affected
Admin defaults apply to new members and to anyone who hasn’t customized their personal settings. If a member has already set their own privacy preferences, changing the admin defaults won’t override their choices. The defaults only set the starting point.
Can members export the member directory?
No. Exporting members to CSV requires HR permissions or higher, so an ordinary member cannot download the directory even for fields they are allowed to see on screen. This is worth knowing when you are deciding how open your privacy defaults should be. Making a field visible to members means they can see it on a profile, not that they can extract it in bulk. The two are enforced separately. Administrators and anyone with HR permissions can export, so if you are concerned about bulk access to member data, the control you want is who holds those permissions rather than which fields are visible.Related
- Profile Fields — What data members can add (privacy controls who sees it)
- Custom Fields — Custom fields with admin-only option
- Account Deletion — Permanent data removal (the ultimate privacy option)

