Privacy & Torn API data

What the tracker collects—and why

The short version: the site collects only what it needs to identify you, count carnival activity and show the results. It never asks for your Torn password.

Data collected

Purpose

The data is used solely to operate the AK Carnival: verify eligibility, calculate progress, resolve scoring questions, display the leaderboard and generate participant/admin reports. It is not sold, used for advertising or shared outside event administration except where required to operate the service or by law.

API key security

Your dedicated API key is encrypted before it is stored. The encryption secret is held separately in server configuration. Keys are sent only to Torn’s API over HTTPS, are never put in page URLs or exports, and are not shown back to admins. You can revoke the key at any time in Torn; the next sync will then ask you to provide a replacement.

Access

You can see your own scorecard, activity totals, riddle status and export. Other participants see leaderboard names and scores, not your raw records or key. Lone_Wanderer, Cassandra and Flying_Dutchman have administrator access to event reports, raw activity needed for verification, configuration and exports.

Storage and retention

Application data is stored in the configured MySQL database. The default retention period is 90 days after an event; admins can change that period. Backups and server logs may take additional time to expire. The deployment runbook includes a scheduled clean-up procedure.

Your choices

Participation is optional. You may revoke the key in Torn, ask an admin to withdraw you, request a copy through your own Excel export, or ask an admin to correct or delete your record where event verification no longer requires it.

Contact

Contact Lone_Wanderer, Cassandra or Flying_Dutchman through Torn for privacy, access or scoring questions. Do not send an API key in a Torn message.