Privacy

What data cwp.sg collects, what it doesn't, and why the tools on this site never send your lookups to us.

Last updated 2026-08-04

Draft — not legally reviewed

This is a working draft written by the team, not by a lawyer, and it has not been reviewed by one. It must be before signups open. The sections about this website and the tools describe how things actually work today.

The short version

Reading this site is anonymous. The tools run in your browser and never send us what you look up. If you create a hosting account, we keep what we need to run it and to stop abuse, and nothing else.

Who is responsible for your data

The data controller is the company being incorporated to operate cwp.sg.

Singapore law requires every organisation to name someone you can contact about data protection. Ours is reachable at (published once incorporation is complete).

Reading this website

There is no analytics on this site today. No analytics product, no cookies, no third-party scripts, no advertising, and no trackers of any kind. The only thing stored in your browser is your light/dark theme preference, in localStorage, which never leaves your device.

Our hosting provider keeps ordinary server logs, as every web server does.

If we add analytics later it will be a cookieless product that cannot single you out, this page will be updated before it goes live, and the revision date at the top will change. We would rather tell you what is true now than describe what we intend to do as though it were already running.

The tools

Nothing you type into a tool is sent to a CWP server. This is architectural, not a policy promise — the site is static and there is no server to receive it.

  • The DNS tools query public resolvers (Cloudflare, Google, DNS.SB) directly from your browser. Those providers see the lookup under their own privacy policies. We do not, and cannot.
  • The generators, the password generator and the calculator make no network requests at all. Turn off your network and they still work.

You can verify all of this in your browser’s network inspector, which is a better guarantee than anything we could write here.

The password generator deserves an explicit note: passwords are generated locally with crypto.getRandomValues(), are never transmitted, and are not stored anywhere. Reloading the page loses them.

If you create a hosting account

We collect what is needed to provide the service and to keep the platform from becoming a phishing farm:

Data Why
Email address Account recovery, limit warnings, deletion warnings
Chosen subdomain It’s your address
IP address at signup, and login IPs Abuse prevention, rate limiting
Which page you arrived from Understanding what’s useful
Server logs — requests to your site Enforcing limits, investigating abuse

We do not sell data, and we do not share it with advertisers.

We share data only with the infrastructure providers needed to run the service, where legally required, or where necessary to investigate abuse.

Retention: account data for as long as the account exists, plus 30 days. Server logs for 90 days. Records relating to a confirmed abuse case are kept longer, because we need them if the same person returns.

Why we are allowed to hold it

Basis What it covers
Providing the service you asked for Your email address, your chosen subdomain, the account itself
Our legitimate interest in preventing abuse Signup and login IP addresses, server logs, records of confirmed abuse
Legal obligation Anything we are required to keep or disclose by law

Where your data goes

The infrastructure providers that run the platform process data on our behalf. They handle it to provide the service to us and for nothing else.

Some of them operate outside Singapore, so your data may be handled outside Singapore. Where that happens we require a comparable standard of protection to the one the law here demands. The same handling applies to account holders in the UK and the EEA.

If there is a breach

If personal data is lost, exposed, or accessed without authorisation, we will contain it, work out what was affected, notify the Personal Data Protection Commission and the people affected where the law requires it, and tell account holders plainly what happened and what to do about it.

We would rather over-notify than quietly hope.

Children

The service is not aimed at children and we do not knowingly collect data from them. If you are a parent or guardian and think your child has given us personal data, tell us through the help page and we will delete it.

If our answer is not good enough

Come to us first, through the help page. If that does not resolve it, you can complain to the Personal Data Protection Commission in Singapore, or to your own data protection authority if you are in the UK or the EEA.

You are a data controller too

If you run a website on our hosting and it collects anything from your visitors — a contact form, comments, analytics, an account system — then you are responsible for that data, and we are processing it on your behalf.

That means your site needs its own privacy notice covering what you collect. We cannot write it for you and it is not covered by this page.

In that arrangement we are the processor: we hold your visitors’ data only to run the hosting, and we do not use it for anything of our own. If you need a written data processing agreement, ask through the help page.

Your rights

You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Deleting your account deletes your files and databases too, and we cannot recover them afterwards.

Requests go through the help page.

Changes

The revision date at the top changes when this page changes. Material changes affecting account holders will also be emailed.