Privacy & Data Protection Policy
TellSG (Singapore business registration in progress; UEN to be shown here on issue) — operator of tell.sg.
Last updated: 29 July 2026. Draft pending legal review.
This policy is written to be checked, not skimmed. Where it makes a technical claim, the same claim appears in our threat model, which is maintained against the platform's actual code.
1. The two kinds of people we deal with
Senders — people who write to a box. We are built not to know who you are. We do not collect your name, email address, phone number, IP address, device identifiers, or any account information, because none of these exist in the submission path. What we hold is what you typed, any file you attached (sanitised of hidden metadata), and a one-way cryptographic fingerprint of your passphrase that cannot be reversed into the passphrase itself.
Console users — people at organisations that rent boxes. For you we hold: your email address, display name, a hash of your password, your role on each box, records of which cases you first opened, and billing details for your organisation's plan.
2. What we collect, and why (PDPA purposes)
| Data | Whose | Purpose |
|---|---|---|
| Message content and attachments | Sender's submission | Delivering it to the organisation you addressed — the entire point of the service |
| Passphrase fingerprint (one-way) | Sender | Letting you, and only you, return to your conversation |
| Console account details | Console user | Operating your account, authenticating you, sending service email |
| First-access and deletion records | Console user | The audit trail your organisation's governance relies on |
| Billing and verification records | Organisation | Charging for the plan; verifying the organisation's registered name via bank transfer |
We do not run analytics or advertising trackers, set no third-party cookies, and make no third-party requests from sender-facing pages. Our two cookies (a console session, and a sender's own case session) are strictly necessary and hold no identity beyond what they exist to do.
3. Where your data lives
Everything is stored in AWS Singapore (ap-southeast-1), encrypted at rest and in transit. The key protecting sender passphrases is held in a hardware key-management service and decrypted only into memory.
4. Message content: our role under the PDPA
For the content of messages, TellSG processes on behalf of the organisation that rents the box — the organisation decides how a report is handled, answered, and when a case is deleted. For console-user account data and billing data, TellSG is the collecting organisation. Questions about how a specific organisation handles reports should go to that organisation; questions about the platform come to us.
5. Retention — the actual numbers
- Unconfirmed signups: deleted after 7 days.
- Abandoned uploads (file attached, never submitted): removed after 1 hour.
- Duplicate-detection fingerprints (content-derived, not identity-derived): 30 days.
- Case content: held while the box exists. Box deletion runs through a notified safety window, then purges content, leaving only a tombstone so a returning sender is told the truth rather than shown an error.
- Backups: rolling window of at most 7 days, after which purged data is gone from backups too.
6. Disclosure
We disclose personal data only where the law compels us. What we can be compelled to produce is bounded by what we hold, and for senders we hold no identity: no name, no account, no IP record, no device data. Our threat model describes this boundary in detail, including its limits. We do not sell or share data for marketing — ours or anyone's.
We do not monitor or review message content — the receiving organisation is the reader. Where content is brought to our attention, typically by that organisation or by legal process, indicating a serious threat to life or safety or material whose report Singapore law mandates, we may be legally required to report what we hold to the authorities. Even then, what we hold about the sender is what they chose to type.
7. Access and correction requests
Console users may request access to or correction of their personal data by writing to the contact below.
Senders: we cannot honour an access request for sender data, and this is a feature, not an evasion — we have no way to verify that any person wrote any message, because we hold nothing linking people to messages. Your passphrase is your access: it opens your case and everything we hold about it.
8. Data breach notification
We maintain a breach response process and will notify the Personal Data Protection Commission and affected persons as required by the PDPA where a notifiable breach occurs. For sender content, note that the identity a breach could expose is limited to what senders chose to write.
9. Data protection officer
dpo@tell.sg — the DPO responds to PDPA enquiries, access and correction requests, and complaints. If you are unsatisfied with our response, you may complain to the Personal Data Protection Commission of Singapore.
10. Changes
We will not weaken this policy quietly. Material changes are posted here with a new date, and changes that reduce sender protections would be announced on the platform itself before taking effect.