askvortsov I realised the lack of GDPR functionality in March of this year, and in several discussions prior to that. I also can't agree with the philosophy that such an important feature isn't available in the core. It just doesn't make any sense to me as a security expert, and as a result means I've jumped off the Flarum train onto NodeBB with all of my forums - 2 completed, one remaining but in a development state. Security, privacy, and GDPR all have a fundamental basis in social media platforms, so why should any forum choose to behave differently ?
On a final note, there's no option to even opt out of emails via the message itself, which is also non compliance.
I'm not here to bash Flarum in any way. I greatly respect the product, it's ecosystem, the developers, and the community as a whole - I no longer use the Flarum application, but am here in an advisory capacity to ensure the Flarum Foundation doesn't land itself in unexpected hot water if discuss was ever breached and has no controls or framework in place to notify affected users - and even worse, have no ability to determine what data exactly is in scope.
Personally, the lack of any GDPR extension at this point means little to me given my move out, but as an act of courtesy, I'm using my knowledge and experience to bring this back to the table before it's too late.