Kerry,
You bring up some very good points. I'd like to add some as well...
You might want a terms of service - No personal info on the site.
Also, to my delight, you have "https" enabled - security.
I would HIGHLY suggest that all mods, log out, close your browser, log back in using:
https://www.projectavalon.net/forum/index.php
That S at the end of HTTP will put you in secure mode.
Then CHANGE your admin/mod password.
All other users should use the https, and never http, and change their passwords as well.