Theory18 · Site, forum & CB Stats
Privacy policy
What we collect, why we use it, and the choices you have across Theory18, the forum and CB Stats.
Last updated
Who we are and how to contact us
Theory18 is operated by Onlinin, based in France. Onlinin is the controller of personal information covered by this notice, which applies to theory18.com, the Theory18 forum and CB Stats.
For questions about your information or to exercise your rights, contact [email protected] or the contact form. You do not need an account to make a request.
Information we use and why
Your account
We use your email address, public nickname, password verifier or connected sign-in identity, account status and preferences to create and secure your account, verify your email and provide access. Theory18, the forum and CB Stats share one public account. Your email address and password are not displayed on your public profile.
This processing is necessary to provide the account services you request. Security checks and records also serve our legitimate interest in preventing abuse and protecting accounts. Required fields are marked on forms; without them we cannot provide the requested feature. Profile details and connected sign-in providers are optional.
Forum posts and article comments
Your chosen nickname, public profile information, posts, replies and reactions can be visible to other visitors. Public discussions may be indexed by search engines. We store contributions, edits and moderation records to display discussions, handle reports and protect the community. Do not post private information about yourself or another person.
Publishing contributions is part of the service you request. Moderation and retaining a record of changes serve our legitimate interests in community safety and resolving disputes. A hidden or edited post can remain in restricted history; hiding it does not necessarily erase earlier copies held by other people or search engines.
CB Stats
When you connect an affiliate account, we use the export credentials you supply to retrieve its Chaturbate transaction history. Imports can include transaction dates, amounts, affiliate and campaign identifiers, and spender identifiers supplied in the export. We use this information to provide revenue, activity and retention reports for your account. It is not published as part of your forum profile.
Only connect data you are authorized to use. The export is the source of imported information about other people. Processing supports the analytics service you request and our legitimate interest in operating reliable reports. Treat export URLs as passwords. Deactivating an import stops collection for that source; it does not erase its existing history.
Messages and newsletters
When you contact us, we receive your name, reply address, topic and message to answer your request and keep a record of the conversation. Our basis is our legitimate interest in responding to support and other inquiries, or taking steps at your request before providing a service.
Newsletters require separate consent to the particular mailing list shown on the form. An account or Google sign-in does not subscribe you. We retain your email, list choices, consent wording and date, subscription changes and delivery records. You can withdraw consent using the unsubscribe link in a newsletter or by contacting us. We retain suppression records to respect opt-outs.
Security and technical information
Requests expose technical information such as IP address, browser details and request time to the servers and security services that handle them. We use security checks, rate limits and restricted operational records to prevent spam, investigate failures and protect the service. Some application checks use hashed identifiers. The basis is our legitimate interest in security and reliable operation.
Google sign-in
If you choose Google, we request your Google account identifier and email address, including its verification status, through the openid and email permissions. We verify Google’s response on the server and use the identity to sign you in or connect Google to your existing Theory18 account. We do not request access to Gmail messages, contacts, Drive files or your Google password.
We retain the connected identity reference and the account information needed for sign-in. Google access tokens are used to complete the sign-in exchange and are not stored for ongoing access to Google services. A matching email alone does not merge accounts. New members choose the nickname that appears publicly.
We use Google account information only for authentication, account management, security and providing the services you request. We do not sell it, use it for advertising or use it to train AI models. Theory18’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
You can review connected sign-in methods in your account settings and revoke Theory18’s access in your Google account. Revoking Google access does not automatically close your Theory18 account or remove contributions. Contact us if you need help with account closure or a data request.
Who receives information
Access is limited to the people and services involved in operating the site, supporting members, moderating content and fulfilling legal obligations. Public contributions are available to their readers. Private account and analytics data are not made public by joining the forum.
- Mevspace provides server hosting. Cloudflare provides security services, including Turnstile checks, and storage for encrypted backups.
- Amazon Web Services SES processes service emails and newsletters. Contact messages are delivered to the Theory18 support mailbox.
- Google processes authentication when you choose Google sign-in. Its own privacy terms also apply to its services.
- Piqo processes audience measurement as described above.
- Private Discord activity notifications can contain a new member’s public nickname and an administration link, or a public discussion title and link. These alerts exclude email addresses, IP addresses, post bodies and login tokens.
We may disclose necessary information to comply with applicable law or protect legal rights. External websites you visit through our links operate under their own privacy notices.
Some providers operate internationally and may process information outside your country, including outside the European Economic Area. Applicable protections depend on the provider, destination and service contract, such as an adequacy decision or approved contractual safeguards. Contact us for information about the safeguards applicable to your data and how to obtain a copy.
How long information is kept
Account information and imported analytics history are retained to provide ongoing access and historical reports. Public contributions, revisions and moderation history are retained for continuity and accountability. Newsletter consent, opt-out and delivery records help demonstrate your choices and prevent unwanted or duplicate messages. Support and security records support resolving requests, investigating abuse and legal claims.
There is currently no automatic account-history or backup deletion schedule. Deactivation, hiding a post or disconnecting a provider does not automatically erase stored records or backups. Retention is assessed against the purpose of the record, whether your account or request remains active, security and dispute needs, and applicable legal obligations. Contact us to request erasure or restriction; we assess the request and explain any information that must be retained and why.
Backups contain historical copies with restricted access; offsite backups are encrypted. Short-lived login and anti-spam proofs expire for use even when their control records are retained. Browser storage lifetimes and Piqo’s event retention are described above.
Your rights and choices
Depending on applicable law, you can request access to your personal information, correction, erasure, restriction of processing and a portable copy. You can object to processing based on legitimate interests and withdraw consent at any time without affecting earlier lawful processing. These rights are subject to the conditions and exceptions in applicable law.
Send requests to [email protected] or the contact form. Describe the account or information concerned. We may ask for proportionate verification to protect your information; do not send passwords, export credentials or identity documents in an initial message. Where the GDPR applies, the normal response period is one month; we will explain any permitted extension.
You may complain to your local data protection authority, including the CNIL in France. Automated security checks can temporarily block requests; contact us if you believe a check or moderation decision is incorrect.
Age and changes to this notice
Theory18 is intended for adults aged 18 and over. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
We update this page when our practices change and revise the date above. Material changes that require a new notice or consent will be communicated before the new processing begins.