Currently, private discussions are displayed in the forum RSS feed. This is something that Xenforo needs to address as a priority.
It is a security risk. What is the point of a private forum if the content can be seen via the RSS feed?
One of the main uses of the RSS feed is to notify followers of new threads on social media services such as Facebook and Twitter. Even if a member does not have permission to view a thread , they will still be able to view the thread title and the beginning of the discussion via RSS or via their social media account.
One of the most common uses of private discussion rooms is a private room for staff and moderators. If a moderator created a thread about whether a member should be labelled as abusive or as a spammer, the title of the thread could be seen as everyone. That could cause a lot of problems.
Currently, the only way to remove private discussions from the RSS feed is to remove the forum room from the new posts list via the "Forum Options" tab (i.e. uncheck the option that says: Include threads from this forum when users click "New Posts"). This is, of course, less than ideal.
I have a private discussion room for moderators and another private discussion room for premium members of my forum. I am happy to remove moderator discussions from the new posts lists. That is not a huge inconvenience. However, I do not want to disable new post notifications from the premium members room as it would decrease activity in those discussions.
We need an option on a room by room level to remove discussions from the RSS feed. This should be a separate option from removing discussions from the "New Posts" page.
Preferably, if a discussion room is set to private, the default configuration should be that discussions are not displayed in the RSS feed but are displayed in the "New Posts" page to authorised members.
I have seen a couple of template fixes for this suggested in the forums. However, this is something I strongly believe should be incorporated into the core so that we do not need to apply manual edits every time a discussion room is set as private.