tell.sg — Threat Model

What we hold, what we cannot do, and where the protection ends.


Who this is for

Mostly for the person deciding whether to write something.

It is also for the organisation renting a box, and for anyone doing security review on their behalf.

We have written this to be specific rather than reassuring. "Anonymous by design, with a documented threat model" is a claim we can defend. "Untraceable" is not, and you should distrust any service that says it.


1. The short version

  • We never ask who you are, and there is no account.
  • Your passphrase is the only way back into your conversation. We cannot recover it, reset it, or look it up.
  • We do not keep your IP address, your device details, or any record of when you read your own case.
  • The organisation sees your words. It does not see anything about you that you did not put in your words.

2. What we store when you send a message

Exhaustively — this is the whole list:

What Why How long
Your message text It is the message Until the case or box is deleted
Which box and which entry point (door) you used Routing With the case
Interface language you chose To reply in the same language With the case
Time the message was received Ordering, and the unread mechanism With the case
Files you attached, after transformation (see §6) Evidence With the case

3. What we never store

  • Your name, email address or phone number. Only if you chose to disclose them in your message.
  • Your IP address. It is never logged on our system.
  • Your device, browser fingerprint, or any advertising or analytics identifier. There are no third-party scripts on the pages you use. Fonts are served from our own domain, so not even a font request leaves.
  • Any record of your behaviour. We do not log that you opened your case, when, or how often. This is deliberate and structural: a timestamp showing when a sender read a reply is exactly the kind of detail that identifies someone in a team of six. The activity log the organisation can see records their actions only, and the database refuses writes to it from your side.

4. What the organisation sees about you

Your message, your chosen language, and the time it arrived. Nothing else, because nothing else exists.

5. Timing, and the limit we cannot remove

If you are one of four people in a department and you send a message ten minutes after a difficult meeting, the timing itself may identify you. No technical measure fixes that, and we will not pretend otherwise.

What we do:

  • Notifications to the organisation are digests by default, not instant alerts, so an arrival does not light up a shared channel at a knowable moment.
  • Notifications back to you carry no detail and are sent on a randomised delay; we suppress the one for your initial submission entirely, because you are already there and a buzz in your pocket at that moment is a signal.
  • Nothing on the public box page moves when a message arrives. The one status it shows — whether messages have gone unread for over a week — is recalculated on a schedule, never when something is submitted, so watching the page tells you when our scheduler ran and nothing more.

What you can do: write from a personal device on mobile data rather than the workplace network, and consider waiting. The address is printed on the poster in full precisely so you can type it later somewhere else, instead of scanning in a corridor where scanning can be seen.

6. Attachments

  • Only images and PDFs are accepted, decided by inspecting the file's actual contents, not its name.
  • Images are rebuilt from their pixels. Your original file is discarded, so GPS coordinates, camera serial numbers and edit history do not survive.
  • PDFs have embedded JavaScript, launch actions and attached files stripped.
  • Files are scanned before anyone can open them, in an isolated service with no route out to the internet.
  • If a file cannot be cleaned, your message still goes through and both you and the organisation are told an attachment was removed. Nothing you write is ever discarded because of a file.

One thing we cannot fix: documents can carry watermarks or identifiers placed there by whoever produced them. If a document is sensitive, retyping the relevant text into your message is safer than attaching it.

7. What third parties see

Being honest about the parts we do not control:

  • Our hosting and network providers (AWS in Singapore, and our CDN) see the connection: your IP address and the address you requested, transiently, in the ordinary course of routing traffic. Everyone using any website has this; we cannot remove it, and nobody honestly can.
  • No analytics, advertising, or tracking services run on the pages you use.
  • Nothing you write is sent to any third party for processing. No cloud spam filter, no machine translation, no AI service.

8. What we can be compelled to disclose

We are a Singapore business and comply with valid Singapore legal process. This section is about what that process can and cannot produce.

  • What can be handed over is bounded by §2. A court order reaches what exists: your message text, the transformed attachments, which box, which language, when it arrived. It cannot reach your name, your IP address, or your device details, because we never had them. Our strongest protection for you is not defiance — it is that there is nothing to give.
  • We can read what we store. The organisation is the intended reader of your message, so it is not encrypted against us; no service shaped like this can honestly claim otherwise. What compulsion obtains is what the organisation already has, not more.
  • Informal requests get nothing. The organisation renting the box cannot ask us who you are — there is no "who" for us to know — and a lawyer's letter is not a court order. We respond to legal process, not to pressure.
  • Some content we must report — but we are not reading. We do not monitor or review messages; the organisation you wrote to is the reader. If content is brought to our attention — usually by that organisation, or by legal process — indicating a serious threat to life or safety, or material Singapore law obliges us to report, we will report what we hold to the authorities. Even then, what we hold about you is what you chose to type.

9. What the organisation's name on the page does and does not mean

If a box shows an organisation's name and registration number, we checked that someone controlling that entity's bank account set it up. If it shows no name, we have checked nothing and we say nothing.

This does not vouch for the poster you scanned. Anyone can print a QR code with any words above it. Verification protects the address — nobody can take tell.sg/to/acme without controlling Acme — but a determined impersonator can register a company and print a misleading poster, as they could with any feedback form.

Your real check is where the link came from: a notice board at your workplace, something your employer told you about. Treat a tell.sg link from an unexpected source exactly as you would any other unexpected link.


Questions, or something here that does not match what you observe: security@tell.sg.


This page is written in English only for now. The box itself, and every message you send or receive, works in English, 中文, Bahasa Melayu and தமிழ்.