Privacy Policy
Your data, plainly.
How String handles personal data across string.sg, String ID and StringClaw. Last updated 5 October 2026.
Who we are
String is a volunteer-run educator community based in Singapore. In this policy, "String", "we" and "us" mean String, and "services" means string.sg, String ID (id.string.sg) and StringClaw, our community assistant on Discord, Telegram and WhatsApp. Products listed in our catalogue but run by other makers have their own terms and privacy practices; this policy does not cover them.
We follow Singapore's Personal Data Protection Act 2012 (PDPA). Our Data Protection Officer can be reached at kahhow@string.sg.
What we collect, by service
string.sg
You can browse string.sg without an account.
- Google Analytics. We use Google Analytics 4 to understand which pages are visited, roughly where visitors come from and what devices they use. It sets cookies and collects data such as pages viewed, referring site, approximate location, device and browser. We have turned off Google Signals and advertising personalisation, and we do not send names or email addresses to Google Analytics. Learn how Google uses information from sites that use its services ↗, or opt out with the Google Analytics opt-out browser add-on ↗.
- Hosting logs. Cloudflare serves the site and processes technical data such as IP address and browser details to deliver pages and protect against abuse.
- Fonts. Pages load fonts from Google Fonts, which receives your IP address and browser details.
- Partnership form. The form on our partnerships page is hosted by Notion. We receive what you choose to submit, such as your name, organisation, email and enquiry.
- Events. Event registration happens on Luma under Luma's own privacy policy. Luma shares guest details with us as the event host.
String ID
String ID is our community sign-in and directory. Depending on how you use it, we collect:
- Your email address and, if you choose, a mobile number, used to sign in with a one-time link or code.
- Passkeys you register. We store only the public key, never your device's private key.
- Your MOE email address, if you verify it, to confirm you are an educator. We ask you to re-verify periodically.
- Details from LinkedIn, such as your name and profile photo, if you connect it.
- Your account ID and username from Discord, GitHub or Telegram, if you choose to verify that account. We use these only to confirm the account is yours, and show the username on your profile only if you make it visible. We do not read your messages, servers or contacts on those platforms.
- Profile details you add, such as school or organisation, role and social links. You control which fields others in the directory can see.
- Records of String events you attended, imported from Luma guest lists.
String ID sets a sign-in cookie for string.sg sites so other String services can recognise that you are signed in.
StringClaw
StringClaw is an AI assistant that answers questions about String events, products and community knowledge. It is available only in chats, channels and servers where it has been added.
- We store messages in conversations where StringClaw is active, its replies, and basic account details from the platform, such as your display name and user ID.
- To generate answers, message content is sent to our AI provider, Anthropic. Under its commercial terms, Anthropic does not use this content to train its models.
- We use stored conversations to answer questions and to make past community discussions searchable for members. We do not use them to train AI models.
- On Discord, including for String ID account verification, we handle data received through Discord in line with Discord's Developer Terms and Policy. We do not sell it or share it with advertisers or data brokers.
- StringClaw may send String ID sign-in codes over WhatsApp. These messages are not processed by AI.
Please do not share students' personal data or other sensitive information with StringClaw.
How we use data
- To run the services: signing you in, showing the directory, answering questions and organising events.
- To verify that members are educators and keep the community safe.
- To understand usage and improve the services. We publish only aggregate figures, for example at reports.string.sg.
- To reply when you contact us and to send service messages. We do not send marketing without your consent.
We collect personal data with your consent, which you give by providing it or by using a feature that needs it, or where the PDPA otherwise permits. You can withdraw consent at any time; some features may then stop working for you.
Who we share it with
We do not sell personal data. We share it only with service providers that help us run String, under their terms, or where the law requires it:
- Google (Analytics, Fonts), Cloudflare and Vercel (hosting), and Neon (databases).
- Resend (sign-in emails) and Meta (WhatsApp messages).
- Anthropic (StringClaw's AI responses).
- Discord, Telegram and WhatsApp, the platforms StringClaw runs on, and Discord, GitHub, Telegram and LinkedIn when you verify an account with String ID.
- Notion (partnership enquiries) and Luma (events).
Directory profile fields you make visible can be seen by other signed-in members.
Where data is stored
Our String ID and community databases are hosted in Singapore. Some providers above, including Google, Anthropic, Vercel and Meta, may process data outside Singapore, mainly in the United States. Where data leaves Singapore, we rely on providers whose terms commit them to protect it to a standard comparable to the PDPA.
How long we keep it
- Analytics: under Google Analytics' retention setting, no longer than 14 months.
- String ID: until you delete your account or ask us to. Accounts with only a phone number are deleted if no email is added within three months.
- StringClaw conversations: while they are needed to answer questions and keep community knowledge searchable. They are deleted on request, and when StringClaw is retired.
- Enquiries and event records: for as long as they serve the purpose they were collected for.
Your choices and rights
Email kahhow@string.sg to ask for a copy of your personal data, to correct it, to delete it (including your String ID account or your StringClaw messages) or to withdraw consent. We aim to reply within 30 days. You can also block analytics cookies in your browser or use the opt-out add-on above. If you are not satisfied with our response, you can contact Singapore's Personal Data Protection Commission.
Children and students
Our services are for educators and partners. They are not directed at children under 13, and we do not knowingly collect their personal data. If you believe a child has given us personal data, contact us and we will delete it.
Security
We use encrypted connections, access controls and providers with established security practices. No system is completely secure. If a data breach is likely to cause significant harm, we will notify affected people and the Personal Data Protection Commission as the PDPA requires.
Changes
We will update this page when our practices change and revise the date at the top. For significant changes, we will also give notice through our services.
See also our Terms of Service.