Skip to main content
ThunderDebates home
Explore Suggest a topic How it works Sign in Choose a name
Home / Privacy notice

How we handle personal information

Privacy notice

This notice describes the personal information used by Thunder Debates and the controls currently implemented in the service.

Last updated 17 July 2026
! Publication blocker: the controller’s postal address and the exact OVHcloud contracting entity shown on the current hosting order are not yet present. Those details must be confirmed before this notice is complete.
On this page
  1. Who controls your information
  2. Information we collect
  3. Purposes and lawful bases
  4. Sensitive and offence-related information
  5. Automated moderation and voting checks
  6. Public visibility, recipients and transfers
  7. Retention
  8. Your rights
  9. Privacy reports and complaints
  10. Security
Need to report something? →
01

Who controls your information

Cameron Lobban, also known as Thunder, trading as Thunder Debates, is the controller for the personal information described here. The controller’s postal address is not yet present in the application. Data-rights requests and data-protection complaints can be sent through the secure privacy request form. The send-only no-reply mailbox is not a contact channel.

02

Information we collect

The service collects information you provide, information created by your use of the service and limited technical information needed for security and abuse prevention.

  • Account information: public pseudonym, encrypted email address, keyed email lookup, Argon2id password hash, verification state, authentication records and, for administrators, encrypted authenticator data and hashed recovery codes.
  • Remembered-device information, when you choose the option: keyed selector and validator hashes, a keyed user-agent hash, a general browser and device label, creation and last-use times, and a fixed expiry. The random trusted-device credential itself is held only in your browser cookie.
  • Public activity: displayed name, points, comments, evidence links, reactions, votes and publication times.
  • Private case information: topic suggestions, report details, appeal statements, moderation decisions, restrictions and tamper-evident administrator audit entries.
  • Data-protection case information: request type, public reference, encrypted contact address, encrypted statement and follow-up messages, identity-check state, deadlines, decisions and encrypted outcome.
  • Technical information: a signed random anonymous token held in your browser, its keyed database derivative, daily keyed address signals, keyed network-prefix signals, user-agent hashes, request metadata, security events and service logs. Public write forms can also use the first-party FurCaptcha service at furcaptcha.thunder.me for abuse prevention. FurCaptcha receives the registered site key, a broad action label, the parent site origin, challenge answers, one-time verification tokens and ordinary connection metadata. It does not receive the form text, email address or account password.
03

Purposes and lawful bases

The operator must maintain a written lawful-basis record. The intended Article 6 bases reflected by the current service are:

  • Contract, where processing is necessary to create and secure an account, publish a requested contribution, record a reaction or vote, or receive a moderation appeal under the Terms of use.
  • Legitimate interests, for proportionate security, fraud and abuse prevention, enforcing one-person participation, service integrity, moderation, complaint handling and establishing or defending legal claims. The interests are operating a safe and trustworthy discussion service. The operator must balance those interests against the rights of affected people.
  • Legal obligation, where processing or disclosure is necessary to comply with a specific duty, valid court order or lawful regulatory request. This basis is not used merely because processing is convenient.
  • Recognised legitimate interests may apply where processing is necessary for crime prevention, safeguarding or an emergency and the statutory conditions are met.
04

Sensitive and offence-related information

The service is not designed to collect health, sexuality, belief, biometric or criminal-offence information about identifiable people. The rules prohibit names, handles, private details and identifiable allegations. Automated checks may still detect and hold such material so it can be removed safely. Before deliberately retaining or otherwise processing special-category or criminal-offence information, the operator must document the applicable UK GDPR and Data Protection Act condition.

05

Automated moderation and voting checks

Rule-based checks examine submitted text and URLs. They can publish low-risk material, publish medium-risk material into priority review, hold high-risk material, or block critical prohibited content. Suspicious vote patterns can be quarantined and excluded from public totals. Moderators can review the resulting cases, and contributors can submit a moderation appeal. These checks do not fetch evidence links and are not used for advertising or cross-site profiling.

06

Public visibility, recipients and transfers

Published contributions, displayed names, reactions and timestamps can be read worldwide. Private reports, appeals and moderation records are limited to staff with the required moderation role. Data-protection cases are restricted to the Owner role and require recent reauthentication for a final decision. The live website, MariaDB database and mail service run on BackroomsHost node02 in Milan, Italy, using OVHcloud infrastructure. BackroomsHost and the first-party FurCaptcha service are operated by the same controller, not separate processors. FurCaptcha is served from furcaptcha.thunder.me on OVHcloud BHS infrastructure in Beauharnois, Quebec, Canada, and is limited to the abuse-prevention data described above. OVHcloud provides the underlying infrastructure as a service provider. Canada has partial UK adequacy only for transfers where Canada’s Personal Information Protection and Electronic Documents Act applies. The controller has not yet confirmed from the current OVHcloud order which legal entity contracts for node03 or obtained order-specific confirmation that this Canadian adequacy scope covers the hosted information. FurCaptcha must remain disabled until that evidence is recorded, or an appropriate safeguard and any required transfer risk assessment are completed. The control plane and current manual encrypted off-node backup copies are held on Main in London, United Kingdom. FurCaptcha’s nightly backup is encrypted on node03 before transfer to a dedicated restricted repository on Main; the restore procedure is verified and temporary plaintext restore material is removed after each verification. Cloudflare provides authoritative DNS only; its web proxy is disabled, so normal application requests are not routed through Cloudflare. The precise OVHcloud legal entity contracting with the controller must still be confirmed from the current order. Cloudflare and the applicable OVHcloud entity process the limited account, DNS or infrastructure information needed to provide their services under their published data-protection terms. Information may also be disclosed to advisers and public authorities where a lawful disclosure is necessary.

07

Retention

Automated retention currently applies the following limits. These periods may be shortened where information is no longer needed, or extended where a documented legal hold applies.

  • Daily exact-address signals in reactions, votes and reports: up to 7 days.
  • Network-prefix risk signals in contributions, reactions, votes and reports: up to 30 days. Expired or revoked network restriction signals are scrubbed after 30 days.
  • Rate-limit events and buckets: up to 7 days. Raw application logs: up to 14 days.
  • FurCaptcha challenge and one-time token records: up to 24 hours. Keyed network-prefix and verification events: up to 7 days. Sanitised FurCaptcha operational logs: up to 14 days. Aggregate abuse metrics without a cross-site identifier: up to 90 days. FurCaptcha application tables do not store raw IP addresses.
  • Expired or used email tokens: removed after 7 days. Sent mail-outbox records: up to 30 days. Failed mail-outbox records: up to 90 days.
  • Trusted-device cookies and their matching server records: no more than 30 days from issue. This is a fixed maximum, not a sliding or indefinite period. Signing out removes the credential for the current browser. A password reset, account restriction, relevant role or status change, or authenticator change revokes every remembered device for the account.
  • Resolved or dismissed reports: up to 180 days. Encrypted appeal contact details previously supplied: scrubbed 180 days after an appeal is resolved.
  • Unverified data-protection requests: closed after 90 days without activity. Expired private access hashes are removed.
  • Resolved data-protection cases: encrypted contact details, statements, messages and outcomes are scrubbed after one year. The remaining case metadata is deleted after two years. These are current operational periods, subject to a documented legal hold or a shorter erasure obligation.
  • Administrator audit entries: up to one year, with a signed chain anchor retained so later entries can still be verified.
  • Account, contribution, reaction, comment, unresolved report, appeal and moderation records do not currently have a fixed automatic deletion period. They remain while needed to provide and protect the service, apply moderation, resolve disputes or meet legal obligations.
08

Your rights

Depending on the purpose and lawful basis, you may have rights of access, correction, erasure, restriction, portability and objection. The right to object to processing based on legitimate interests is specifically brought to your attention here. A request may require proportionate identity checks, particularly because public aliases do not prove who controls an account or browser identity. A valid request should normally be answered without undue delay and within one month, subject to lawful extensions or exemptions.

09

Privacy reports and complaints

Use the Report control and choose Personal or private information if a point or comment exposes private information. Use the secure privacy request form for a data-rights request or a data-protection complaint. UK law requires a clear complaints route, acknowledgement within 30 days, appropriate investigation and communication of the outcome. You may complain to the Information Commissioner’s Office, but raising the matter with the controller first can help resolve it.

Send a privacy request or complaint →

10

Security

Account emails, legacy appeal contact details and data-protection case text are encrypted at rest. Passwords use Argon2id, one-time and private access secrets are stored as keyed hashes, administrator access requires an authenticator, final data-protection decisions require recent reauthentication, sessions are restricted and audit entries are chained. Remembered-device credentials are rotated when used, are tied to a keyed user-agent signal and are revoked when replay is detected. FurCaptcha is an additional abuse-prevention layer and does not replace same-origin checks, CSRF tokens, local rate limits, content controls or moderation. A successful solve grants only a 15-minute server-side clearance in the existing session. No service can guarantee absolute security. Do not include passwords, authenticator codes or unnecessary personal information in public content, reports or appeals.

Official UK sources

  • ICO: information a privacy notice must provide ↗
  • ICO: lawful bases for processing ↗
  • ICO: data-protection complaints requirements ↗
  • ICO: make a data-protection complaint ↗
  • ICO: Canadian partial adequacy and PIPEDA scope ↗
  • OVHcloud Canada: BHS in Beauharnois, Quebec ↗
  • OVHcloud Canada: data-protection agreement and contracts ↗
  • Cloudflare: customer data-processing addendum ↗
ThunderDebates

Compare arguments, react to individual points, and join the discussion.

Rules Safety Complaints & appeals Privacy Cookies Terms
Community moderated 18+ · Text only · No tracking ads
© 2026 Thunder Debates Anonymous participation with active moderation.