Legal
Privacy notice
Operator notice: This page describes the analytics built into NoirStream. The operator must add its legal identity, contact details, hosting providers, lawful basis, and jurisdiction-specific privacy rights before public launch.
Information NoirStream records
When you enter and use NoirStream outside Private Session, the server records your IP address, approximate country, a rotating IP-derived pseudonymous identifier, a random browser identifier, an account identifier when signed in, a random session identifier, the active profile identifier and chosen nickname, timestamps, searches and selected filters, result counts, videos displayed and their positions, player requests, successful provider-iframe loads and bounded load time, favorites and unfavorites, “More like this” and “Not for me” feedback, Recently Viewed use and deletion actions, provider-link opens, approximate post-load player time, and reported API, thumbnail, empty-result, and embed-loading failures.
NoirStream also records a coarse device class, browser family, and referrer hostname. It does not use GPS, canvas fingerprinting, cross-site advertising identifiers, or the complete browser user-agent string in its analytics database. Post-load player time and a 30-second player session are interaction estimates; the embedded provider does not give NoirStream exact watch progress or completion data.
Why this information is used
The operator uses these records to authenticate registered accounts, reconnect a guest browser to temporary viewing profiles, isolate each profile's state, rank videos that are popular within a country during a rolling seven-day period, personalize general discovery from that profile's searches, favorites, history, and explicit feedback, improve search, identify catalog gaps, measure the discovery funnel and retention, diagnose service failures, prevent abuse, and operate the service.
Regional PostHog analytics
PostHog analytics are separate from adult-access confirmation. In locations where opt-in is required, NoirStream disables PostHog until you explicitly allow it. In other locations, the privacy-minimized events described below are active by default. You can disable them at any time below. Disabling PostHog does not block entry, accounts, profiles, favorites, Recently Viewed, or video discovery.
When allowed, NoirStream sends events to PostHog from the server rather than loading a PostHog browser SDK. The allowlist includes page type, coarse device and browser class, search result-count ranges without the search text, impression-count ranges without video details, the distinct player_open and confirmed play lifecycle events, coarse load and engagement ranges, recommendation context, and bounded error categories. It excludes search terms, video IDs and titles, performer and studio details, profile and account IDs, email addresses, referrers, full URLs, IP addresses, and session recordings. A separately keyed opaque identifier rotates with NoirStream's 30-minute activity session, and PostHog person profiles are disabled for these events.
If you allow or disable PostHog, that preference is stored in a signed first-party HttpOnly cookie for up to one year. Where no choice is legally required, automatic analytics do not create a separate consent cookie. PostHog client-IP discarding must remain enabled, and the same global data-minimization controls apply in every location.
IP protection and retention
Raw IP addresses are encrypted with AES-256-GCM and stored in a table separate from searches and viewing events. Analytics rows retain a pseudonymous IP-derived identifier that rotates monthly plus the random anonymous-browser identifier. Raw IP records and exact analytics search rows are configured for 30-day retention, granular interaction events for 90 days, country-level daily aggregates for 365 days, inactive guest profiles for 365 days, and Recently Viewed for 90 days or 200 unique videos per profile. Registered accounts remain until the user deletes the account or the operator acts under an applicable policy. The operator can shorten analytics periods, purge expired records, or delete stored analytics from the private dashboard.
Adult access confirmation
NoirStream currently presents the same one-click 18+ self-attestation in every location. Yoti and other third-party secure age-verification providers are disabled, so NoirStream does not send identity documents, selfies, dates of birth, biometrics, or verification-session data to an age-verification provider.
After confirmation, NoirStream keeps the adult-confirmation level, time, and coarse country/state jurisdiction. The reusable result is stored in a signed first-party HttpOnly cookie and, for a signed-in account, in the private account record so it can be reused across that account’s devices.
Accounts, browser storage, and cookies
NoirStream keeps a local profile-state cache, filter-panel state, and a session-scoped discovery seed in browser storage. For registered accounts, the private server database stores the account email address, the minimum adult-access result described above, and a salted one-way password hash. Passwords are never stored in browser storage or returned by the API. A first-party HttpOnly, SameSite=Lax authentication cookie normally lasts 30 days, is marked Secure over HTTPS, and contains a random session token rather than the password. Changing the password closes other active sessions.
A separate signed browser cookie supports guest profiles and analytics attribution. Without authentication, recognition remains browser-specific. A second signed HttpOnly analytics-session cookie is bound to that browser identity, refreshes during activity, and rotates after 30 minutes of inactivity so separate visits are not combined into one week-long session. Both use SameSite=Lax and are marked Secure over HTTPS. Registering from a guest session claims the current browser profiles into the new account; later sign-ins make those profiles available on other devices. NoirStream does not join accounts or guest identities by IP address.
Deleting a registered account removes its email, password hash, authentication sessions, profiles, favorites, history, recent searches, feedback, and exact event/search rows linked to the account or its profile identifiers. Previously accumulated country-level daily aggregate counts may remain because they no longer contain the account or profile identifier.
Default discovery filtering
General browsing, recommendations, category cards, and default predictive suggestions suppress content when provider-supplied titles or keywords explicitly label it Black, ebony, BBC, interracial, or mixed race. This rule is enforced by the server for every profile and is not presented as a profile setting. A deliberate matching search or intentional related action can return matching results. Classification uses text metadata only; NoirStream does not analyze faces, skin tone, thumbnails, or video imagery. Provider metadata can be incomplete or inaccurate, so the rule can occasionally miss or hide a video incorrectly.
Deleting a profile permanently clears that profile’s current favorites, Recently Viewed list, recent-search cache, settings, and recommendation feedback. Previously recorded analytics remain only until the configured analytics retention period or an administrator purge.
Private Session
When Private Session is active, NoirStream does not send content analytics, add videos to Recently Viewed, save recent searches, or use stored personalization signals. Discovery, scene-detail, and recommendation requests do not resolve or mint a visitor/profile identity; approximate-country policy and the server-wide discovery rule still apply without profile personalization. “Not for me” is temporary for that browser session, “More like this” can open an immediate related search without teaching the profile, and favorites cannot be changed until Private Session ends.
Performer discovery
The performer directory can rank rights-approved profiles using existing first-party interest events associated with verified canonical scenes. Events are deduplicated by account profile, browser, or session and day before a scene signal is divided across its verified cast. A successful provider iframe load is a technical load signal, not proof that a video was watched. NoirStream does not create a new analytics event when you browse or filter the directory, does not expose raw interest scores or event totals in the directory API, and does not send performer identifiers to PostHog.
Third-party video provider
Search requests are sent through this website’s server to Eporner. When you play an embedded video or open the provider website, that provider may receive technical information and apply its own privacy practices.
Optional title translation
If the operator enables English title translation, provider-supplied video titles—not your saved favorites or browser-storage data—are sent from the NoirStream server to the configured DeepL API. Update this notice and the processor agreement before public use.
Approximate location
Country detection is performed automatically and locally from the visitor IP or accepted from country and US state-code headers supplied by an explicitly trusted reverse proxy. The country and state code select the applicable adult-access and PostHog consent rules; the precise location is not sent to PostHog. NoirStream does not request GPS or precise device location or expose a manual region override. If a required jurisdiction cannot be determined reliably, PostHog fails closed until the visitor chooses.
Backups and access
The private database is outside the public website directory. Automatic backups are encrypted and retained in a private server directory. Analytics reports require administrator authentication and do not display raw IP addresses or password hashes.
Contact
Replace this section with the operator’s privacy email, mailing address, request process, and applicable privacy-rights instructions before deployment.