Third-Party Application Notice: Torn Command Center is an independent, community-built tool. It is not affiliated with, endorsed by, or sponsored by Torn Ltd in any way. All game data is retrieved through the official Torn Public API under your explicit authorization.

API Key & Data Disclosure

As required by the Torn API Terms of Service, here is exactly how your API key and the data it retrieves are handled:

Data Storage Data Sharing Purpose of Use Key Storage & Sharing Key Access Level
Persistent — retained until account deletion or API key revocation. Faction (leadership & members), the service owner (Acayib) for maintenance, and Discord servers your faction enables. Enemy public player IDs may be sent to FFScouter (optional, if your admin enables it). Never sold. Public community tools — faction war / chain / finance / OC dashboards and Discord notifications. Encrypted at rest on our server (and locally in your browser if you install our optional userscripts), never displayed in full anywhere. Pooled and used only within your own faction — never for another faction's data, including via our Discord bot — and never shared with other players or non-Torn services. Limited access or higher (a few features require Full).

Quick Summary

TopicDetails
Data Collected Torn player profile, battle stats, faction membership, attacks, crimes, travel status, personal stats, and chain/war contributions — as authorized by your submitted API key. If you are a company director, employee working stats, wages and effectiveness for your own company (see §3). Our optional userscripts additionally read public data (e.g. rival member status, abroad shop stock) from Torn pages you have open and are actively viewing, and may sync your own script preferences (quick-fill presets, watch lists, alert toggles) and travel trip journal to your account so they follow you across devices.
Data Storage Persistent — retained until account deletion or API key revocation.
Data Sharing Faction Leadership, Service Owner (Acayib), and Discord Server members where the bot is active. If you opt in, the bot will also DM you directly (energy/nerve/cooldowns full, travel landed, hospital release, OC ready, and target-tracking alerts) — configurable on My Stats or via /alert, and only possible if the bot shares a Discord server with you. Data is never sold to third parties.
Purpose Powering tactical dashboards (Ranked Wars, Chains, Finance, Armory, OC) and Discord Bot notifications/commands.
Key Storage Encrypted at rest on our server (symmetric encryption; a separate one-way hash is used to look up "which account owns this key" without ever decrypting the whole table). Never displayed in full — the Settings page shows only the last 4 characters. Never forwarded to external services except Torn's own API, and never pooled across factions. If you install our optional userscripts, your key is also stored locally in your browser (Tampermonkey storage) and sent only to acayib.cc.
Required Access Level Limited or higher. Specific features (e.g. battle stats sync) require Full Access.
External Services Torn API · Discord API · FFScouter · YATA · Prometheus Bot · Torn Intel · TornProbability · TornFlight.club · TornW3B / Weav3r · jsDelivr CDN. The travel-stock feeds (YATA, Prometheus Bot, Torn Intel) are public read-only endpoints — we send them nothing, not even an identifier.
Torn Compliance Keys pooled per faction; server-side caching applied; rate limits respected. Usage comment CmdCtr included on automated calls.

1. Torn API Usage

This service uses the official Torn Public API (api.torn.com) to retrieve real-time and historical game data. By connecting your Torn account you explicitly authorize us to make requests on your behalf using the API key you provide.

Data We Retrieve

  • User profile: Name, level, faction membership, status (Okay/Hospital/Traveling/Abroad).
  • Battle stats: Strength, speed, defense, dexterity — only when you trigger a manual sync from the personal stats page.
  • Personal stats: Attacks won/lost, hospital sends, nerve usage, xanax/refill counts, war score, and other in-game metrics used for leaderboards and personal dashboards.
  • Faction data: Member roster, chain progress, war scores, OC (Organized Crime) assignments, armory inventory, and ranked war reports — retrieved using the faction AA permissions.
  • Crime data: OC slot assignments and success/failure history for planning purposes.
  • Market & economy: Points market price, item-market floors, and faction bank balance — used for finance dashboards and the personal Market Watcher. Bazaar floors (when shown) come from TornW3B/Weav3r without using your key; see §2.
  • Travel: Your travel state, destination and landing time — used for flight boards, Air Traffic Control and travel alerts. Abroad shop stock is not read with your key at all; it comes from public community feeds and optional scout reports (see §2).
  • Company data (directors): If you connect the Company tools with a director-level key, your company's profile (funds, efficiency, environment, advertising, stock) and its employees' working stats, wages and effectiveness — the same data Torn shows you in-game as director. See §3 for who can see it.

How We Use Your Key

  • Your key is used solely for the purposes described above. It is never forwarded to third-party services (including Weav3r / TornW3B, YATA, Prometheus Bot, Torn Intel, or FFScouter). The travel-stock feeds in particular are read-only public endpoints that receive nothing from us — no key, no identifier, no request parameters about you.
  • Automated background tasks append the comment parameter CmdCtr to API calls, making our usage identifiable in your Torn API log.
  • Keys from multiple faction members are pooled so the total request rate stays within Torn's published limits. Your key contributes to, but is not the sole source of, faction-level data pulls — and only ever to your own faction's pulls. Command Center is multi-tenant (multiple factions can run it independently), and key pools are strictly isolated per faction, including in the Discord bot's background tasks — a key never contributes to, or is used to fetch data for, a different faction.
  • You can revoke access at any time by changing or deleting your Torn API key, or by removing it yourself on the Settings page. We will purge your stored key from our database upon account deletion.
Torn API ToS Compliance: Our servers retrieve data exclusively through the official Torn API — they never scrape the Torn website. Our optional userscripts may read public data from a Torn page you have manually loaded and are actively viewing — including the page's own real-time (websocket) feed — strictly while that tab is focused and visible, and they make no additional requests to Torn. We do not share raw API responses publicly, do not use your key beyond what you have authorized, and do not store data in ways that could harm Torn Ltd or its users. This application is a registered third-party tool and complies with the Torn API Terms of Service.

2. Third-Party Services & Credits

The following external services are integrated into Torn Command Center. Thank you to each service below. This is how your data may interact with them.

🎮 Torn API required
api.torn.com
The official Torn City game API. All core game data — members, stats, wars, chains, crimes, and economy — is sourced exclusively from here using your provided API key.
💬 Discord API optional
discord.com/api/v10
Used by our companion Discord Bot (Phoenix) to deliver automated faction-channel notifications — retaliation alerts, chain milestones, other warnings, bank requests, flight alerts, war push announcements — and, if you opt in on My Stats or with /alert, direct DMs to you personally (energy/nerve/cooldowns full, travel landed, hospital release, OC ready, target-tracking). The bot also verifies your Torn identity and syncs your faction position to Discord roles via /v. Only active if your faction administrator has invited the bot and linked your server; DMs additionally require the bot to share a server with you and you to opt in.
📊 FFScouter optional
ffscouter.com
A community-built Torn stat aggregator. When a faction admin provides an FFScouter API key, enemy player IDs are sent to this service to retrieve estimated Battle Stat Score (BSS). No personal keys or member data are forwarded — only enemy player IDs.

Credit: FFScouter is an independent community project.
✈️ DroQsDB historical
droqsdb.com
Previously used as an abroad stock / restock estimate feed. No longer called — travel stock now comes from YATA plus live scout reports and our own history-based restock models.

Credit: DroQsDB was a community abroad stock-tracking service (Droq).
🌐 YATA travel feed
yata.yt
Community abroad stock export (quantity, cost, country update time). Called about once a minute by our background worker; restock timing is computed from our own history. No user data is sent — public read-only export endpoint.

Credit: YATA (Yet Another Torn Application) is a popular community platform. yata.yt
🤖 Prometheus Bot travel feed
prombot.co.uk
A second community abroad-stock network, read once a minute alongside YATA. We use two things from it: the stock observation itself (whichever feed saw a country most recently wins, which cuts reporter-coverage lag), and its published nextRestock estimate — the latter is stored only to score its restock predictions against ours and the observed restock, and never feeds our own predictions or anything shown on the Travel Agent page.

No user data, API keys, or identifiers are sent. It is a public, unauthenticated read-only endpoint (GET /api/travel); the request carries nothing about you or your faction. Our servers make one bulk call per minute, cached, regardless of how many people are using the site.

Credit: Prometheus Bot is an independent community abroad-stock service.
🛰️ Torn Intel travel feed
torn-intel.com
A third community abroad-stock network, read on the same one-minute cycle and merged by whichever feed observed a country most recently. Used purely as corroboration and outage cover — if one network goes down, travel stock keeps working.

No user data, API keys, or identifiers are sent. Public, unauthenticated read-only endpoint (GET /api/foreign-stock/travel-table), one cached bulk call per minute.

Credit: Torn Intel is an independent community intel service.
🎯 TornProbability optional
tornprobability.com:3000
An OC (Organized Crime) success-rate calculator. We send anonymized role-value parameters (no player names or IDs) to calculate the probability of success for OC configurations used in the OC Planner feature.

Credit: TornProbability is a community OC modeling project.
🛒 TornFlight.club optional
tornflight.club
Provides NFS item tier rankings for abroad shopping. No user data is sent — public read endpoint.

Credit: TornFlight.club is a community trading platform.
🏪 TornW3B / Weav3r optional
weav3r.dev
Community bazaar price index used as a second price source for the personal Market Watcher (and for displaying bazaar floors alongside Torn item-market floors). Our servers call the public, unauthenticated TornW3B API (GET /api/marketplace) on a fixed schedule — typically one bulk request every few minutes, self-capped well under Weav3r’s published limit of 100 calls/min/IP. No user API keys, Discord IDs, or personal data are sent to Weav3r. We store only aggregated bazaar floor / average / listing-count fields for items we already track from Torn, and we attribute bazaar figures to TornW3B/Weav3r in the UI and in Discord market-watch alerts.

We use this feed only for personal price-threshold alerts and informational display — not as a commercial marketplace product, not for automated buy-mugging bots, and not to resell or republish Weav3r’s catalog as a competing service. Usage may be disabled instantly via an operator kill-switch if rate limits or terms require it.

Credit & attribution: Bazaar data © TornW3B / Weav3r (weav3r.dev). Independent community project by Weav3r. We comply with the TornW3B Terms of Service and Privacy Policy. Support / issues: TornW3B Discord · forum thread.

Frontend Libraries (CDN)

The following open-source libraries are loaded from public CDNs. No personal data is transmitted as part of these requests — they are standard static asset loads:

⚡ HTMX cdn
cdn.jsdelivr.net — htmx.org v1.9.12
Enables partial-page AJAX updates without writing JavaScript. Used throughout the dashboard for live roster syncing and form interactions.
📈 Chart.js cdn
cdn.jsdelivr.net — chart.js v4.4.2
Renders charts on the Personal Stats and Entertainment pages. Open source, MIT licensed.
🎉 canvas-confetti cdn
cdn.jsdelivr.net — canvas-confetti v1.9.3
Lightweight confetti animation used on the Entertainment page. Open source, ISC licensed.
✏️ Quill Editor cdn
cdn.jsdelivr.net — Quill v1.3.6
Rich-text editor used in the Faction Admin panel for message composition. Open source, BSD licensed.

CDN requests may cause your browser's IP address to be logged by jsDelivr, subject to its privacy policy.

Optional Userscripts (Browser Add-ons)

We offer optional Tampermonkey / Torn PDA userscripts (e.g. CommandCenter War Assist, Money Assist, Travel Scout, Director, Points Market, and CCSpys) that enhance Torn pages with Command Center data. They are entirely optional — the web dashboard works without them.

  • Key storage: When you set your API key in a userscript, it is stored locally in your browser's Tampermonkey storage and sent only to acayib.cc (over HTTPS) to authenticate you. It is never sent to any other site.
  • Reading the page you're viewing: War Assist may read public data from the Torn faction/war page you have open — including that page's own real-time (websocket) status feed — and forward public rival status (e.g. hospital/travel state) to acayib.cc so your faction's War-Intel stays current. This happens only while the tab is focused and visible, and the script makes no additional requests to Torn.
  • What is shared: Only public, in-game rival status visible to anyone viewing that war page — scoped to your own faction and the factions it is at war with. No private data and no other members' keys are transmitted.
  • Settings sync: Some scripts can optionally save your own preferences (quick-fill amount presets, watched-seller lists, alert toggles) to your account via /api/script-settings/, so they follow you across devices instead of living only in one browser's local storage. This is your own preference data — visible only to you and used only to pre-fill your own scripts — and is manageable on the Settings page.
  • Source is public: The scripts are open and served from acayib.cc, so their behavior can be audited at any time.

Travel & Abroad Stock Data

The Travel Agent page, the /flyme Discord command, and Air Traffic Control run on abroad shop stock. This is worth spelling out because it is the one area where data is deliberately shared beyond your faction:

  • Where stock comes from: three independent public community feeds — YATA, Prometheus Bot, and Torn Intel — polled about once a minute by our background worker, merged per country by whichever saw it most recently. All three are unauthenticated read-only endpoints; we send them no data of any kind — no API key, no player or faction ID, nothing that identifies you or that we could be asked to identify you by. Calls are made once for the whole site, not per user.
  • Live scout reports (optional userscripts): the Travel Scout and Travel Scout Light scripts read the abroad shop page you have manually opened and are actively viewing and report the shop's item list, price and quantity to acayib.cc, so everyone gets fresher numbers than a minute-old feed. What is transmitted is the shop's public stock, not your inventory, your money, or what you bought. The scripts make no additional requests to Torn and do not run in the background.
  • Scout reports are never attributed publicly: a stock reading is shown only as live, never with the name of whoever contributed it. Naming who is in an abroad shop right now would effectively publish a mugging target list, so reporter identity is not sent to the browser at all — it is retained server-side purely for operator-side abuse triage (e.g. tracing deliberately falsified stock).
  • Stock data is global, not faction-scoped: unlike war/faction data, abroad stock is shared across every faction using Command Center. It carries no personal information — only item, country, price, quantity and how recently it was seen.
  • Restock predictions are ours: predicted restock times are computed from our own recorded stock history (sellout → restock delays per item), not taken from any third party. Prometheus Bot's published estimate is logged alongside ours purely so we can measure whose model is more accurate; that comparison log holds item, country and timestamps only — no player data — and is visible only to the service operator.
  • Your own travel data: your travel status and destination come from your API key and are visible to your faction (as with any other status). If you use the optional trip journal, the country, items, quantities and amount spent on each completed round trip are saved to your account and shown only to you. Travel preferences and view settings are likewise your own.

3. Data Sharing & Visibility

Your data is shared only within the contexts described below. We do not sell, trade, or broker personal data.

  • Your Faction Leadership: Faction commanders and staff can view your active status, hospital timer, travel destination, chain contributions, OC assignments, and war hits through the tactical dashboards.
  • Discord Servers: If your faction administrator connects our Discord Bot, automated messages (e.g. retaliation alerts, flight updates, bank requests) may be broadcast to configured Discord channels. The content and frequency of these broadcasts is controlled by your faction admins.
  • Personal DM Alerts: Separately, and only if you opt in yourself (on My Stats or with /alert), the bot will DM you directly for personal events — energy/nerve/cooldowns full, travel landed, hospital release, OC ready, dibs/target tracking. Nobody else sees these DMs, they only go out while the bot shares a Discord server with you, and you can turn any of them off at any time.
  • The Service Owner (Acayib): Strictly for server maintenance, debugging, and infrastructure improvements. The owner does not access individual member data beyond what is necessary to resolve technical issues.
  • Enemy intel: When war intel features are active, enemy faction members' in-game public data (status, level, last action) is displayed to your faction's commanders. This data originates from Torn's API and, when a faction member uses the optional War Assist userscript, from the live war page they are actively viewing. It reflects publicly available game information only.
  • Company employees: If you are a company director and connect the Company tools, Torn returns your employees' working stats (manual labor, intelligence, endurance), wage, effectiveness breakdown and last-action time. This is information Torn already shows you in-game as director — we store it to power the crew optimizer, position P&L and training queue, and it is visible only to that company's director (and to employees of that same company, for their own row). It is not shared with your faction, other companies, or anyone else. Employees who leave stop being synced; ask the operator if you want a departed employee's record purged sooner.

4. API Key Security

  • Encrypted at rest: Your Torn API key is encrypted in our database using symmetric encryption (Fernet). A separate one-way hash is used to look up which account owns a key on incoming requests, so the key itself never has to be decrypted just to find you — only when it's actually needed to call the Torn API on your behalf.
  • No plaintext exposure: Once submitted, your key is never displayed in full anywhere — not in the UI, not in Discord, not in log files. The Settings page shows only the last 4 characters and access level so you can confirm which key is on file, and lets you replace or remove it yourself at any time — the full value is never shown back to you or anyone else, including us.
  • Faction-scoped usage: Your key is used only to pull data for your own faction's dashboards and is pooled only with other members of that same faction. Command Center serves multiple independent factions (multi-tenant); key pools, background bot tasks, and API pulls are strictly isolated per faction — your key never contributes to, or is used to fetch data for, a different faction. It is never forwarded to FFScouter or any other third-party service.
  • Revocation: Revoking or changing your Torn API key immediately invalidates our ability to make further requests. You can remove your stored key yourself on the Settings page, or request account deletion to purge all stored data.

5. Data Storage & Retention

Data retrieved from the Torn API is stored persistently in our database to power historical analytics (leaderboards, activity heatmaps, war debriefs, personal stat trends). The following retention rules apply:

  • API keys: Retained until account deletion or manual revocation.
  • Player stats & personal history: Retained while you remain a registered user. Purged on account deletion.
  • Enemy intel cache: Updated in real-time during active wars. Historical records (attack logs) are retained for faction-level post-war analysis.
  • Activity logs / heatmaps: Rolling 7-day activity data used to generate heatmaps. Older data is aggregated and anonymized.
  • Discord messages: We do not store the content of Discord messages sent by our bot. We store only the configuration (channel IDs, role IDs) needed to deliver them.
  • Abroad stock history: Per-item stock and price snapshots are kept on a rolling 45-day window and automatically pruned beyond that. They contain no player data. The restock prediction-comparison log (ours vs Prometheus Bot) holds item, country and timestamps only.
  • Travel trip journal: Retained on your account until you delete the entries or your account. Visible only to you.
  • Company employee records: Retained while the company remains synced, and purged with the company or on request. Training-ledger entries are director-entered records of trains given and payments made.

6. Torn API Compliance

This service is built in compliance with the Torn API Documentation and Terms. Specifically:

  • Not affiliated: We are an independent third-party application. We are not affiliated with, endorsed by, or sponsored by Torn Ltd.
  • Rate limiting: Faction API keys are pooled and requests are batched and cached server-side to stay within published rate limits. We do not hammer the API with redundant requests.
  • Usage comments: Automated background calls include the ?comment=CmdCtr parameter, making our usage visible and identifiable in your Torn API log.
  • No server-side scraping: Our servers use only the official public API and never scrape torn.com. Our optional userscripts read public data only from Torn pages you have manually loaded and are actively viewing (focused tab), and make no extra requests to Torn — as permitted by Torn's scripting rules.
  • Key access requirement: We require Limited access or higher. Features that read logs require Full Access. We do not request or store Torn API keys with unnecessary permissions.
  • No harmful use: We do not use API data to harass, dox, or harm players, or to disrupt Torn Ltd's services.
  • User consent: API keys are submitted voluntarily by users. We do not obtain keys through any automated, deceptive, or unauthorized means.

7. Your Rights & Contact

You have the right to:

  • Access: Request a summary of what data we hold about you.
  • Deletion: Request deletion of your account and all associated data, including your stored API key.
  • Revocation: Revoke access at any time by changing your Torn API key in your Torn settings. This immediately halts any further data collection on our end.

To exercise these rights, contact the service owner Acayib directly via Torn in-game message or the faction Discord.

This policy was last updated 24 July 2026 — adding the Prometheus Bot and Torn Intel travel feeds, the "Travel & Abroad Stock Data" section, and company employee-data handling. Scout reporter names are no longer displayed anywhere on the site. We will notify faction administrators of any material changes to data handling practices.
Return to Login