tell.sg — Threat Model

What we hold, what we cannot do, and where the protection ends.


Who this is for

Mostly for the person deciding whether to write something.

It is also for the organisation renting a box, and for anyone doing security review on their behalf.

We have written this to be specific rather than reassuring. "Anonymous by design, with a documented threat model" is a claim we can defend. "Untraceable" is not, and you should distrust any service that says it.


1. The short version

  • You are never required to identify yourself, whatever a box asks — and there is no account.
  • Your passphrase is the only way back into your conversation. We cannot recover it, reset it, or look it up.
  • We do not keep your IP address, your device details, or any record of when you read your own case.
  • The organisation sees your words. It does not see anything about you that you did not put in your words.

2. What we store when you send a message

Exhaustively — this is the whole list:

What Why How long
Your message text It is the message Until the case or box is deleted
Which box and which entry point (door) you used Routing With the case
Interface language you chose To reply in the same language With the case
Time the message was received Ordering, and the unread mechanism With the case
Files you attached, after transformation (see §6) Evidence With the case

3. What we never store

  • Your name, email address or phone number. Only if you chose to disclose them in your message.
  • Your IP address. It is never logged on our system.
  • Your device, browser fingerprint, or any advertising or analytics identifier. There are no third-party scripts on the pages you use. Fonts are served from our own domain, so not even a font request leaves.
  • Any record of your behaviour. We do not log that you opened your case, when, or how often. This is deliberate and structural: a timestamp showing when a sender read a reply is exactly the kind of detail that identifies someone in a team of six. The activity log the organisation can see records their actions only, and the database refuses writes to it from your side.

The one cookie, and why refusing a session log is what creates it. When you enter your passphrase to read replies, your browser is given a single cookie named tell_case. It lasts twelve hours, it cannot be read by JavaScript, and it is not sent to any other site.

What it contains is a sealed copy of the same one-way fingerprint of your passphrase described above — not your case number, not an account, not an identifier for you. It is a key you carry, not a name we gave you.

It exists precisely because of the last point in the list above. The normal way to keep someone signed in is a session record on the server: a row saying this person is reading this case, created at this time. That row is the behavioural record we refuse to hold, so there is no server-side record of your visit at all — which leaves the cookie doing the remembering, on your device, for one visit. Delete it, or close the browser and let it expire, and nothing on our side changes, because there was nothing on our side. Your passphrase remains the only way back in.

Console users at the organisation get a different cookie, tell_console, which does have a matching server-side record — they are not anonymous, and that asymmetry is deliberate. We set no other cookies, and no third party sets any.

4. What the organisation sees about you

Your message, your chosen language, and the time it arrived. Nothing else, because nothing else exists.

5. Timing, and the limit we cannot remove

If you are one of four people in a department and you send a message ten minutes after a difficult meeting, the timing itself may identify you. No technical measure fixes that, and we will not pretend otherwise.

What we do:

  • Notifications to the organisation are digests by default, not instant alerts, so an arrival does not light up a shared channel at a knowable moment.
  • Notifications back to you carry no detail and are sent on a randomised delay; we suppress the one for your initial submission entirely, because you are already there and a buzz in your pocket at that moment is a signal.
  • Nothing on the public box page moves when a message arrives. The one status it shows — whether messages have gone unread for over a week — is recalculated on a schedule, never when something is submitted, so watching the page tells you when our scheduler ran and nothing more.

What you can do: write from a personal device on mobile data rather than the workplace network, and consider waiting. The address is printed on the poster in full precisely so you can type it later somewhere else, instead of scanning in a corridor where scanning can be seen.

6. Attachments

  • Only images and PDFs are accepted, decided by inspecting the file's actual contents, not its name.
  • Images are rebuilt from their pixels. Your original file is discarded, so GPS coordinates, camera serial numbers and edit history do not survive.
  • PDFs are converted to images, page by page. Nothing of the original structure survives — no JavaScript, no launch actions, no attached files, no fonts, and none of the document properties that quietly carry an author's name or work email. The cost is real and worth knowing before you attach one: the text in a converted PDF can no longer be selected, searched or read aloud by a screen reader.
  • We do not scan for viruses. Nothing is compared against a list of known bad files. Rebuilding is the control instead, and it is the stronger one: matching a list cannot recognise something new, while a file rebuilt from its pixels has nothing left of whatever it was carrying. No scanner catches everything, and we would rather tell you that than let anyone believe a file arrived safe — the organisation reading your report is told the same, and told to check any attachment with their own tools before opening it.
  • The rebuilding happens in an isolated service with no route out to the internet, so a file built to attack the software that opens it arrives somewhere with nowhere to call.
  • If a file cannot be rebuilt, your message still goes through and the attachment is withheld. The organisation is told that a file was withheld and why. You can see the same, and what to do about it, on your own case page whenever you next open it — we hold no way to contact you, which is the point of the whole service, so nothing about your report ever arrives unprompted. Nothing you write is ever discarded because of a file.

One thing we cannot fix: documents can carry watermarks or identifiers placed there by whoever produced them. If a document is sensitive, retyping the relevant text into your message is safer than attaching it.

7. What third parties see

Being honest about the parts we do not control:

  • Our hosting and network providers (AWS in Singapore, and our CDN) see the connection: your IP address and the address you requested, transiently, in the ordinary course of routing traffic. Everyone using any website has this; we cannot remove it, and nobody honestly can.

  • No analytics, advertising, or tracking services run on the pages you use.

  • One AI model may read what you write — only if the organisation switched it on for the box you used. Some boxes turn on follow-up questions: an AI model reads your report and writes back a short list of questions. Answering any of them is optional, including anything it asks about who you are, and your report is already delivered either way.

    The model runs on Amazon Bedrock, inside our own AWS account. Nothing you write is used to train any AI model, and nothing is kept — it is read, answered, and gone. Amazon states that Bedrock stores no model inputs or outputs, that no operator of the service can read them, and that the company which built the model has no access to them either. Bedrock's optional logging of prompts and replies is switched off. The request may be served from an AWS region outside Singapore; nothing is stored there.

  • Nothing else you write is sent to any third party for processing. No cloud spam filter, no machine translation, no other AI service.

8. What we can be compelled to disclose

We are a Singapore business and comply with valid Singapore legal process. This section is about what that process can and cannot produce.

  • What can be handed over is bounded by §2. A court order reaches what exists: your message text, the transformed attachments, which box, which language, when it arrived. It cannot reach your name, your IP address, or your device details, because we never had them. Our strongest protection for you is not defiance — it is that there is nothing to give.
  • We can read what we store. The organisation is the intended reader of your message, so it is not encrypted against us; no service shaped like this can honestly claim otherwise. What compulsion obtains is what the organisation already has, not more.
  • Informal requests get nothing. The organisation renting the box cannot ask us who you are — there is no "who" for us to know — and a lawyer's letter is not a court order. We respond to legal process, not to pressure.
  • Some content we must report — but we are not reading. We do not monitor or review messages; the organisation you wrote to is the reader. If content is brought to our attention — usually by that organisation, or by legal process — indicating a serious threat to life or safety, or material Singapore law obliges us to report, we will report what we hold to the authorities. Even then, what we hold about you is what you chose to type.

9. What the organisation's name on the page does and does not mean

If a box shows an organisation's name and registration number, we checked it — usually that someone controlling the entity's bank account set it up; for organisations we onboarded in person, our own staff did the checking at their premises, against the public register. Either way the name shown is the registered name, never one they typed. If it shows no name, we have checked nothing — and the banner above the form says so in as many words, because an absent name only reads as "unverified" to someone who has seen a verified box before.

Words on the page are not a name. Whoever runs a box can write their own welcome line, and we do not review what it says. So a box could greet you with a company's name while showing no verified name above it. Those two things mean different things, and the page keeps them apart: anything the box owner wrote is set aside under "From the organisation", while the name at the top — when there is one — is ours, and we checked it.

This does not vouch for the poster you scanned. Anyone can print a QR code with any words above it. Verification protects the address — nobody can take tell.sg/to/acme without controlling Acme — but a determined impersonator can register a company and print a misleading poster, as they could with any feedback form.

Your real check is where the link came from: a notice board at your workplace, something your employer told you about. Treat a tell.sg link from an unexpected source exactly as you would any other unexpected link.


Questions, or something here that does not match what you observe: security@tell.sg.


This page is written in English only for now. The box itself, and every message you send or receive, works in English, 中文, Bahasa Melayu and தமிழ்.