TornGPT

Privacy policy

Last updated September 27, 2026

What this service does

TornGPT can connect a Torn API key to your ChatGPT connection for read-only Torn API requests. You can also choose demo mode, which needs no Torn key and uses fictional sample data.

Information we process

When you connect with a Torn API key, we receive the key and validate it with Torn. We store the key encrypted, alongside the Site-scoped ChatGPT account identifier and OAuth records needed to maintain the connection. A one-way Torn account identifier is used to apply Torn rate limits across that account’s connections. OAuth tokens and temporary authorization records are stored to authenticate standard MCP clients. When you invoke a live tool, the requested parameters and Torn API response pass through our service to fulfill the request; TornGPT does not store tool parameters or response contents in its application database. If you use torn_feedback, its title and details are stored privately under a one-way identifier for your Torn account so you can list, replace, or delete your feedback. Each account can keep up to 10 items.

If you have not connected a Torn API key to your ChatGPT account, MCP calls use clearly labeled fictional demo data; no Torn API key is collected and no request is sent to Torn.

How we use and protect it

The key is decrypted only on the server to send a request to Torn using its Authorization header. We do not intentionally put it in tool inputs, URLs, browser storage, or application logs. Encryption keys are held as runtime secrets separately from the database. Hosting providers may process ordinary service and network metadata to operate the site.

Retention and deletion

The encrypted key and Site-scoped account link are retained while the connection is active. Use Manage Torn connection on the site to remove that link. If Torn reports that a key is incorrect, inactive, or paused, TornGPT deletes that stored key and its associated OAuth grants. Revoke a standard MCP OAuth connection to delete its linked key and token and authorization-code records. Feedback is retained until you delete it or disconnect all TornGPT connections for that Torn account. The shared rate-limit schedule for a Torn account is deleted when that account has no other active TornGPT key connections. Pending OAuth requests are valid for 10 minutes, authorization codes for five minutes, access tokens for one hour, and refresh tokens for 30 days; refresh tokens rotate when used. Tool parameters and response contents are used to fulfill the request and are not retained in TornGPT’s application database. Disconnecting TornGPT does not delete existing ChatGPT conversations or disable the key in Torn; those are managed separately.

Visit the delete account data page for steps.

Data sharing

In live mode, we send your API key and requested API parameters to Torn to fulfill your request. Demo mode sends no request or key to Torn. We do not sell personal information or use Torn data for advertising. ChatGPT and Torn process information under their own privacy terms.

Passwords and security

TornGPT never asks for your Torn password. Only enter an API key on the TornGPT website, and use the minimum access level needed for the tools you want.

Contact

For service or privacy questions, visit our support page.

Terms of service