Privacy Policy

Last updated: 12 May 2026

What the extension does

Porter allows GoHighLevel users to export individual workflows as JSON files and import them into other GoHighLevel accounts. It operates entirely within your browser.

Data we collect

None. The extension does not collect, store, or transmit any personal data, usage data, or analytics to us or any third party. There is no server component. There is no telemetry.

Data the extension accesses

The extension accesses your GoHighLevel workflow data (trigger configurations, action steps, workflow settings) solely for the purpose of exporting it to a local file on your computer or importing it from a local file into your GoHighLevel account.

The extension reads your GoHighLevel session token from browser requests to authenticate with GoHighLevel's API on your behalf. This token is held in browser session memory only (via chrome.storage.session), is automatically cleared when the browser closes, and is never transmitted to any server other than GoHighLevel's own backend (backend.leadconnectorhq.com).

Data stored locally

The extension does not write any data to persistent local storage. The only data held locally is your GoHighLevel session token in volatile browser session memory (chrome.storage.session), which is automatically cleared when the browser closes.

Where data goes

Exported workflow files are saved to your local computer via your browser's download function. Imported workflow files are read from your local computer and sent directly to GoHighLevel's own API (backend.leadconnectorhq.com). No data passes through any intermediary, third-party server, or Greymatter Solutions server.

Permissions explained

webRequest — Used to read your existing GoHighLevel session token from requests your browser is already making to GoHighLevel's servers. This allows the extension to authenticate with GoHighLevel's API on your behalf, using the same session your browser already has. The extension only observes requests to backend.leadconnectorhq.com — no other domains are monitored.

storage — Used solely to hold the GoHighLevel session token in volatile browser session memory (chrome.storage.session), which is automatically cleared when the browser closes. No persistent data is written to disk. No data from storage is ever transmitted externally.

Host permissions (backend.leadconnectorhq.com, gohighlevel.com, leadconnectorhq.com) — Required to observe GoHighLevel API requests for session authentication and to read and write workflow data via GoHighLevel's own REST API. The extension only communicates with backend.leadconnectorhq.com; the additional host permissions are required by Chrome so the extension can observe API requests originating from GoHighLevel's web application. No non-GoHighLevel websites are accessed.

Content scripts (gohighlevel.com, leadconnectorhq.com) — A lightweight content script runs on GoHighLevel pages to detect when you are viewing a workflow, by reading the page URL. It extracts the workflow ID so the extension knows which workflow to export or import. The content script does not read, modify, or interact with page content beyond URL detection.

Third-party services

The extension communicates only with GoHighLevel's own servers (backend.leadconnectorhq.com and app.gohighlevel.com). No other third-party services are used.

Changes to this policy

If this policy changes, the updated version will be published at this URL with a new date. Material changes will be noted in the extension's changelog.

Contact

For questions about this privacy policy or the extension, contact steven@greymatter.solutions.