Privacy
What data cwp.sg collects, what it doesn't, and why the tools on this site never send your lookups to us.
This is a working draft written by the team, not by a lawyer, and it has not been reviewed by one. It must be before signups open. The sections about this website and the tools describe how things actually work today.
The short version
Reading this site is anonymous. The tools run in your browser and never send us what you look up. If you create a hosting account, we keep what we need to run it and to stop abuse, and nothing else.
Who is responsible for your data
The data controller is the company being incorporated to operate cwp.sg.
Singapore law requires every organisation to name someone you can contact about data protection. Ours is reachable at (published once incorporation is complete).
Reading this website
There is no analytics on this site today. No analytics product, no cookies,
no third-party scripts, no advertising, and no trackers of any kind. The only
thing stored in your browser is your light/dark theme preference, in
localStorage, which never leaves your device.
Our hosting provider keeps ordinary server logs, as every web server does.
If we add analytics later it will be a cookieless product that cannot single you out, this page will be updated before it goes live, and the revision date at the top will change. We would rather tell you what is true now than describe what we intend to do as though it were already running.
The tools
Nothing you type into a tool is sent to a CWP server. This is architectural, not a policy promise — the site is static and there is no server to receive it.
- The DNS tools query public resolvers (Cloudflare, Google, DNS.SB) directly from your browser. Those providers see the lookup under their own privacy policies. We do not, and cannot.
- The generators, the password generator and the calculator make no network requests at all. Turn off your network and they still work.
You can verify all of this in your browser’s network inspector, which is a better guarantee than anything we could write here.
The password generator deserves an explicit note: passwords are generated
locally with crypto.getRandomValues(), are never transmitted, and are not
stored anywhere. Reloading the page loses them.
If you create a hosting account
We collect what is needed to provide the service and to keep the platform from becoming a phishing farm:
| Data | Why |
|---|---|
| Email address | Account recovery, limit warnings, deletion warnings |
| Chosen subdomain | It’s your address |
| IP address at signup, and login IPs | Abuse prevention, rate limiting |
| Which page you arrived from | Understanding what’s useful |
| Server logs — requests to your site | Enforcing limits, investigating abuse |
We do not sell data, and we do not share it with advertisers.
We share data only with the infrastructure providers needed to run the service, where legally required, or where necessary to investigate abuse.
Retention: account data for as long as the account exists, plus 30 days. Server logs for 90 days. Records relating to a confirmed abuse case are kept longer, because we need them if the same person returns.
Why we are allowed to hold it
| Basis | What it covers |
|---|---|
| Providing the service you asked for | Your email address, your chosen subdomain, the account itself |
| Our legitimate interest in preventing abuse | Signup and login IP addresses, server logs, records of confirmed abuse |
| Legal obligation | Anything we are required to keep or disclose by law |
Where your data goes
The infrastructure providers that run the platform process data on our behalf. They handle it to provide the service to us and for nothing else.
Some of them operate outside Singapore, so your data may be handled outside Singapore. Where that happens we require a comparable standard of protection to the one the law here demands. The same handling applies to account holders in the UK and the EEA.
If there is a breach
If personal data is lost, exposed, or accessed without authorisation, we will contain it, work out what was affected, notify the Personal Data Protection Commission and the people affected where the law requires it, and tell account holders plainly what happened and what to do about it.
We would rather over-notify than quietly hope.
Children
The service is not aimed at children and we do not knowingly collect data from them. If you are a parent or guardian and think your child has given us personal data, tell us through the help page and we will delete it.
If our answer is not good enough
Come to us first, through the help page. If that does not resolve it, you can complain to the Personal Data Protection Commission in Singapore, or to your own data protection authority if you are in the UK or the EEA.
You are a data controller too
If you run a website on our hosting and it collects anything from your visitors — a contact form, comments, analytics, an account system — then you are responsible for that data, and we are processing it on your behalf.
That means your site needs its own privacy notice covering what you collect. We cannot write it for you and it is not covered by this page.
In that arrangement we are the processor: we hold your visitors’ data only to run the hosting, and we do not use it for anything of our own. If you need a written data processing agreement, ask through the help page.
Your rights
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. Deleting your account deletes your files and databases too, and we cannot recover them afterwards.
Requests go through the help page.
Changes
The revision date at the top changes when this page changes. Material changes affecting account holders will also be emailed.