Privacy Policy
1. Who we are
CamWall is operated by the camwall.tv operator, established in Belgium (EU). For privacy matters, contact us at support@camwall.tv. We act as data controller under the GDPR for personal data processed in connection with camwall.tv.
2. What data we collect
Account data (if you register)
If you create a CamWall account, we collect and store in our database (Cloudflare D1):
- Username — required, used to identify your account.
- Email address — optional; used for password recovery and account management. Accounts without email are deleted after 3 years of inactivity.
- Hashed password — we never store your password in plain text.
- Account creation date and last-seen timestamp — used to apply inactivity policies.
- Saved preferences — your filter settings, bookmarks, and wall layout (stored server-side when you are signed in).
- Sign-in session data — when you sign in, we store the IP address and browser user-agent string you connected with alongside your session record. Sessions last up to 30 days and are refreshed while you stay active; this is standard behaviour of our authentication system (better-auth) and is used for account security.
Age verification
When you pass the age gate, we set a cookie containing a cryptographic token (HMAC-SHA-256). This token records that age was confirmed and the visitor's country code. It does not store your date of birth or any personal identifier.
Anonymous product analytics
We use Cloudflare Analytics Engine to collect aggregated usage events (for example: "a stream was opened", counted per day). Each event carries a pseudonymous visitor ID — a random identifier generated in your browser and kept in that browser's local storage — so repeat visits can be counted, alongside a truncated browser user-agent string, the referring site's hostname, the page path you were on, a coarse device class, a country code derived server-side from your connection, the streaming platform the event relates to (always "chaturbate" today) and, where one applies, a short fixed label saying which part of the app the action started from (for example "recent" for the Recently Watched list). Those last two are fixed values chosen from a small allow-list; they describe the app, not you. When the event is about opening or popping out a performer's stream, it also records which performer's stream that was, against the same visitor ID. This ID is not linked to your name, email or account and is not shared with anyone. There is no cross-site tracking and no advertising cookies, and we cannot tie these events back to a named individual.
Feedback messages
If you submit a feedback message via the in-app form, the message text, the feedback type, the optional contact field, the client-reported page path and browser string, and your username (or "Anonymous" if you are not signed in) are stored in our Cloudflare D1 database (table feedback) so the CamWall team can triage it.
The same submission is also forwarded to a private Discord channel via webhook, together with extra diagnostic fields that are not stored in the database: the browser viewport size, device information (operating-system platform, whether the device is touch-capable, device pixel ratio, screen size and browser language), the CamWall app version you were running (a build number that is identical for every visitor, so it describes the app and not you), and a summary of the CamWall configuration you were using (number of cells, how many were showing a live stream, the active layout preset, the view mode, and the filter settings applied). This configuration summary never includes performer or room names, other users' names, the contents of your bookmarks, or anything you typed into the name-search box. Any screenshot attached to the report is delivered to that Discord channel only and is likewise not stored in the database.
Push notifications (if you opt in)
Enabling bookmark notifications requires an account and stores the browser-supplied push endpoint URL plus two public subscription keys (p256dh and auth) in our Cloudflare D1 database, linked to your account. These are used only to deliver notifications about bookmarked performers going online. They are deleted when you turn notifications off, and are deleted automatically when your account is deleted.
3. Cookies
| Cookie name | Purpose | Duration |
|---|---|---|
age_verified |
HMAC token confirming age gate was passed. HttpOnly, Secure, SameSite=Strict. | 1 year |
| Auth session cookie (set by better-auth) | Keeps you signed in to your CamWall account. HttpOnly, Secure, SameSite=Lax. | Session / 30 days |
We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
CamWall also uses your browser's local storage — not cookies, never sent to a server on its own — for your saved preferences, walls and recently-watched list, for the analytics visitor ID described above, and for remembering that you passed the age gate.
4. Legal basis (GDPR)
- Contract performance — processing account data to deliver your account and saved preferences.
- Legitimate interest — anonymous analytics to understand how the product is used and improve it; age-gate enforcement to comply with legal obligations.
- Consent — feedback submission is voluntary, as is opting in to push notifications.
5. Data sharing and processors
We do not sell your personal data. We share data only with the following processors:
- Cloudflare, Inc. — infrastructure provider (Workers, D1 database, Analytics Engine, CDN). Cloudflare processes data on our behalf under a Data Processing Addendum. Cloudflare's privacy policy: cloudflare.com/privacypolicy/.
- Discord Inc. — feedback reports (message text, display name, the optional contact field, page path, browser, viewport, device information, app version and a CamWall configuration summary as described above, plus any attached screenshot) are delivered to a private Discord channel operated by the CamWall team. Discord's privacy policy: discord.com/privacy.
Stream content is served by Chaturbate (Various, Inc.), a third party. CamWall does not share your data with Chaturbate. When you open a performer's room on Chaturbate, you are subject to Chaturbate's own privacy policy.
6. Data retention
- Account data is kept as long as your account is active.
- Email-less accounts with no activity for 3 years are deleted.
- Anonymous analytics data is retained in aggregated form; it cannot be used to identify individuals.
- Feedback reports are kept in the database indefinitely. Marking a report "resolved" in our admin tool only flags it as handled — it does not delete the row. There is no automated deletion or retention window today. If you want a report you sent removed, email support@camwall.tv and we will delete it manually.
- Push notification subscriptions are kept until you turn notifications off or your account is deleted.
7. Your rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access — request a copy of personal data we hold about you.
- Rectification — ask us to correct inaccurate data.
- Erasure — ask us to delete your account and associated data.
- Portability — receive your data in a structured, machine-readable format.
- Restriction — ask us to restrict processing in certain circumstances.
- Objection — object to processing based on legitimate interest.
Exercise any of these rights by emailing support@camwall.tv. We will respond within 30 days. You also have the right to lodge a complaint with the Belgian Data Protection Authority (dataprotectionauthority.be).
8. Children
CamWall is strictly for adults aged 18 and over. We do not knowingly collect data from minors. If you believe a minor has provided data, contact us immediately at support@camwall.tv.
9. Changes to this policy
We may update this policy. Material changes will be noted on this page with an updated date. Continued use of CamWall after an update constitutes acceptance.
Contact
Privacy questions: support@camwall.tv