How TornChain uses faction and member data.
This notice applies when TornChain processes personal data to verify members, isolate faction workspaces, coordinate chains, and provide optional integrations. It should be read with the Cookie Notice and Security page.
Controller and contact
TornChain is operated by ChocolatePie [4370545], who determines why and how TornChain application data is processed. Privacy requests can be sent through the ChocolatePie Torn profile. Do not include a live Torn API key in a privacy or support message.
Data TornChain processes
- Torn ID, display name, verified faction membership, and application role.
- A server-side Torn API credential, its duplicate identifier, granted selections, validity, and polling timestamps.
- Personal energy returned by the connected member's key and cached faction, chain, war, travel, hospital, organized-crime, and roster data.
- Claims, watcher schedules and check-ins, targets, assists, participation choices, reports, alerts, and chronological faction events.
- Discord ID, OAuth connection state, notification preferences, and delivery results when Discord is connected.
- Entitlement, payment reconciliation, referral, and administrator audit records.
- Hashed session tokens, request-security data, service health information, and redacted error logs.
- An optional hashed, expiring TornChain Overlay connection token plus its creation, expiry, last-use, and rate-limited self-action times.
Purposes and legal bases
- Provide the requested service
- Identity verification, faction isolation, polling, claims, schedules, reports, access control, and account controls are processed to provide TornChain to the member.
- Legitimate security and operational interests
- CSRF protection, fraud and abuse prevention, entitlement reconciliation, fault diagnosis, rate-limit protection, and bounded audit records keep the service reliable and accountable.
- Consent and member choice
- Browser push, Discord connection, and optional external-stat displays are activated separately by the member and can be disabled.
- Legal obligations
- Records may be retained or disclosed when required to comply with applicable law or respond to a valid legal request.
Faction visibility
Verified members can see coordination data belonging to their current faction. This can include member names, roles, watcher attendance, claims, participation states, claimant-readiness indicators, and energy totals. Personal energy may be included in watcher or claimant views. Raw member API keys and raw personal battle stats are not shown to faction members or administrator screens. Membership is revalidated and access is revoked when a member leaves the faction.
TornChain Overlay
When a member connects from Torn, the submitted Torn API key is used once to verify identity, faction membership, permitted selections, and current energy, then is protected in TornChain's normal server-side credential store. The userscript clears the form before transmission and does not save the key in Tampermonkey. It saves only a separate revocable overlay token. The overlay receives a minimized faction coordination view and can submit only that member's own participation, current-hit claim or assignment release, and watcher check-in or check-out. TornChain stores keyed, non-reversible network fingerprints to limit repeated connection attempts without retaining the submitted key or a raw IP address in that rate-limit record. Failed-attempt buckets are removed after one day and successful verification clears the bucket.
Recipients and service providers
- The official Torn API receives the connected API key and the minimum request needed for the enabled feature.
- DigitalOcean and the configured hosting, database, backup, DNS, and delivery providers process technical data needed to operate TornChain.
- Discord receives OAuth and notification data only when the member or faction enables Discord features.
- FFScouter receives a member's separately connected FFScouter key and target IDs only when that optional integration is enabled; other stat providers receive only the identifiers and operational data required for their configured estimate.
- Faction data is not sold, and TornChain does not use it for third-party advertising.
Some providers may process data outside the EEA. Where EU data-transfer rules apply, TornChain will rely on an applicable adequacy decision, certified framework, or contractual safeguard supplied by the provider.
Retention
- Authentication sessions expire after 30 days and are removed earlier when the member disconnects or deletes the account.
- The Discord OAuth state cookie expires after 10 minutes and is deleted after the callback.
- The stored API credential remains until disconnection, replacement, invalidation, or account deletion.
- The optional TornChain Overlay token expires after 180 days or 30 inactive days and is removed or made unusable earlier when replaced by a reconnect, revoked, disconnected, or deleted.
- Live Torn values are refreshed or replaced as polling continues. Completed chain, attendance, reporting, entitlement, security, and audit records remain while needed for faction operations, dispute handling, and service integrity.
- Account deletion removes the member record and identity-linked child data. Aggregate faction events may remain after actor and subject identifiers are removed.
- Backups can retain deleted data until the applicable backup cycle expires.
Member choices and rights
Members can disconnect their Torn credential, revoke active sessions, reconnect or revoke the optional TornChain Overlay connection, disable optional notifications and integrations, or delete their TornChain account through Settings. Where applicable, a person may also request access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier processing. EU and EEA residents can complain to the data-protection authority in the country where they live, work, or believe an infringement occurred.
Changes to this notice
The last-updated date will change when this notice changes. TornChain will provide a prominent notice or request a new choice before a material change that depends on consent takes effect.