This will be a long read, with lots of nuance, detail and can get quite technical. I will try my best to keep it straightforward, and will provide answers as and when. You are of course entitled to ask anything, it is a public forum, but I will be responding to questions, not unfounded allegations or opinions, or anything already answered. Given I am quite limited on time between a personal issue, work and other responsibilities, it may take some time to do all of the responses, so bear with me.
This may be broken into several posts and reference material - when I first post this it may take me a few minutes to tie everything together if so with links and whatnot.
What data does TornPal collect?
For reference, the "selections" I mention here are based on the Torn API selections, check the bottom of the "Selection Access Levels" for more information on key levels etc and I will go through what each is used for. If you use your own API key on these selections at each level, you can see what is visible.
This is meant to be raw selection data. Explanations on how data is used is further down. All API requests from TornPal will be commented as TornPal.
TornPal may be used with any of the 4 main key levels, a public key, minimal key, limited key or full key. Some features may require higher key levels due to how a feature would work. Custom keys do not yet work as a relic of how TornPal was set up early on and I needed to get things moving quickly, so it was easier to make assumptions about the key based on level, than implement more advanced logic to iterate through keys to find the the ones with the correct combination of permissions for a particular task. This is likely to change in future to be accepted, but I have no date yet due to other commitments.
The overarching principle here is this: if another user can see something about you, such as your name, bazaar, display case etc - then this is not private data. Examples of private data, which cannot be obtained from the API key of anybody else (or a public API key you have provided), is things such as battle stats or bypassing the daily "personalstats" cache etc.
Personal Details
All Keys At Login
/key/ - Used to determine the access level the key has, so I am quickly aware the type of key it is (ie custom, public, minimal, limited or full) and who the key belongs to.
/user/basic - Used to get your name to fill out my Users table so it can greet you by name
/company selections - profile, timestamp
Public Keys (About You)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Public Keys (About Others)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Minimal Keys (About You)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads, workstats, bars
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Minimal Keys (About Others)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Limited Keys (About You)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads, workstats, bars, battlestats, stocks, attacks, hof
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Limited Keys (About Others)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Full Keys (About You)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads, workstats, bars, battlestats, stocks, attacks, hof, log
Exceptions: "Log" is used against my own API key to track incoming and outgoing payments for item deposits. "Log" is available for the research purposes section of my data policy - but this has not been used to date and there is no current plan to use it, but it was implemented in case a solution was needed to do research with trustworthy partners where I could gather and anonymise the data to investigate, for example, new crimes, OCs etc.
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Full Keys (About Others)
/v2/user selections - discord, personalstats, medals, profile, bazaar, timestamp, forumposts, forumthreads
/v2/faction selections - basic, members, timestamp, rankedwars
/company selections - profile, timestamp
Note on "forumthreads" and "forumposts". These selections are not routinely used except where doing data projects to retrieve public forum posts. The actual function that does this selects a random API key which could be any level is would be very unlikely to be your own key since it doesn't matter which it uses, but will only retrieve public information.
Only profile, bazaar and timestamp are requested in all API calls. The others regular requests do so periodically for yourself, which by default is:
Note that for data requested using your key about others, or where you are using a public or minimal key for yourself, this is a little different in that the "hof" and "personalstats" are requested once per day for that player at any time, and will not request it again until after 1am TCT due to the daily update cache making it pointless requesting any more frequently as it will not change.
Factions note: Due to a copy and paste error - there were a few requests sent out requesting "crimes" from factions if the faction leader or co-leader was registered on TP. This was an error, and as the program was not expecting the data as that function was not even started or built, it was never stored anywhere.
Global Details
All keys
/torn selections - timestamp, stocks, items, bank, companies, itemdetails
This updates the items available in Torn, the market values of items, bank interest rates and the Torn server time
/market selection - pointsmarket, timestamp
As above, updates the points currently for sale.
/v2/market/itemmarket selections - 'Bonus' => Any
/v2/market//itemmarket selections - n/a, just requests item market listings
/v2/torn/hof - category "workstats"
/v2/forum/threads - no selections for this, but usually sorted oldest to newest to gather all public forum threads
/v2/forum selections - posts
Neither of the above are routinely used, and only for occasional public data projects.
More following...