SMID Research · Singapore & Asia small-mid cap library

Site policy · Effective 17 September 2026

Privacy notice

This notice covers My library, optional research-update alerts, email sent to SMID Research, the moderated “Reader questions & corrections” form on company pages, and the signed-in “Discussion” forum. It does not turn SMID Research into an advisory or customer-service business.

Discussion accounts

An account holds your email address, a display name you choose, the date you joined, and whether SMID Research has marked the account trusted or suspended. A fresh self-declaration is attached to each post rather than stored as a permanent profile position. Your email address is encrypted before storage and is never published. A keyed identifier derived from it prevents duplicate accounts.

An account is a standing record, not a one-off message. Unlike a question submitted through the private form, account data is kept for as long as the account is open, because it is what lets you sign back in and manage your own posts. The retention table below sets out what happens when an account falls dormant or is closed.

Signing in uses a single-use link sent to your email. Only a keyed representation of that link is stored, so the stored record cannot be replayed as a sign-in. Links expire shortly after they are issued and cannot be used twice. A signed-in session is a separate keyed record with its own expiry, and you can end it by signing out.

Saved companies, alerts and reading history

My library uses the same confirmed-email account as Discussion. Saving a company stores the company and the dates the preference was created or changed. Saving alone sends no email. Research-update alerts are a separate switch for each company and remain off until you explicitly enable them. Every alert explains why it was sent and provides links to turn it off or manage all preferences.

Reading history is off by default. Public and anonymous reading is not added to My library. If you switch history on, the private account record stores only the company and its first and most recent read times. It does not store the article section, scroll depth, browser fingerprint or a record of anonymous visits. Switching history off deletes the existing list.

Free-member transcript access

Transcript previews are public. Reading a full transcript requires a confirmed-email account. To provide your transcript library and enforce the allowance of 10 full transcript retrievals per Singapore calendar day, we store your internal account ID, the transcript ID and the time of each retrieval, including repeat retrievals. Every full retrieval requires sign-in and counts toward the daily limit. This necessary access record is separate from optional company reading history; it does not record scroll position or anonymous browsing.

Transcript access records are private and are retained while your account is open. They are deleted when the account is closed, including through the existing dormant-account cleanup. Signing in does not grant access to the separately protected private research vault.

What a discussion post collects

A post stores its text, its title if it starts a thread, its room (a company or Others), the thread, your self-declaration, the time, and the account that wrote it. It also stores a keyed representation of a coarse network prefix and a signed device cookie for rate limits and abuse prevention. Raw IP addresses, browser fingerprints and Turnstile tokens are not stored.

Discussion posts are public the moment they appear, together with your title, display name, self-declaration and the date. Treat a post as permanent and public. Do not put anything in one that you would not want indexed by a search engine.

Room requests. Asking for a room for another listed company stores the exchange, ticker, company name and listing link you give, an optional private note to SMID Research, the time and the account that asked, together with the first thread, which is held. Nothing about a request is published unless SMID Research approves the room; the room's name may be corrected against the listing first.

Reports. Reporting a post stores the post, the reason you chose, the time and the account that reported it, so misuse of reporting can also be handled. Reports are never published and the author is not told who reported them. SMID Research receives at most one email an hour saying how many requests, held posts and reported posts are waiting; it contains no reader text, names or email addresses.

What the question form collects

The form asks for a name or pseudonym, email address, question or correction, company, submission type and interest disclosure. It also uses a random signed device cookie and a keyed representation of a coarse network prefix for abuse prevention. Raw IP addresses, browser fingerprints and Turnstile tokens are not stored in the Q&A database.

Email addresses and original submissions are encrypted before storage. A keyed email identifier supports duplicate checks on the private question record, while separate keyed device and coarse-network identifiers support rate limits. These identifiers are still treated as pseudonymous personal data.

Why the data is used

Holding an account or saving a company does not subscribe you to email. Company alerts are sent only where you separately enable them, and can be switched off at any time. SMID Research does not sell submission or account data.

What may be published

From Discussion: your thread title, post text, display name, declared interest and date, and the name of a room you asked for once it is approved. From the question form: nothing is published automatically — only the edited question, chosen display name, relevant interest disclosure, SMID Research answer and publication date may appear, and only if selected. Email addresses, saved companies, alert choices, reading history, sign-in records, abuse signals and moderation notes are never published.

Service providers and transfers

The site is hosted on Cloudflare Pages. Cloudflare D1 stores account, reader-preference, post and Q&A records; email addresses and private question text are encrypted before storage. Cloudflare Turnstile checks whether a submission appears automated. Resend delivers sign-in links and reader-enabled research-update alerts; direct correspondence is handled through Google Gmail. These providers may process data outside Singapore under their respective safeguards.

Retention

Cloudflare D1 recovery features may retain recoverable database history for up to 30 additional days after an operational deletion.

Your choices

While signed in, you can remove saved companies, switch individual alerts off, clear or disable reading history, and withdraw your own posts; each new post asks for a fresh self-declaration. You may request a display-name change, account closure, access, correction, withdrawal or deletion by emailing [email protected].

On deleting posts: a request to remove personal data will be assessed alongside legal, security and record-keeping needs. For discussion, the ordinary remedy is to delete the personal data linking a post to you and leave the post itself in the thread under a neutral placeholder, because other readers have replied to it and removing it outright would misrepresent the conversation. Where a post is unlawful, unsafe or wrongly attributed, it is removed outright.

Cookies

Two strictly necessary, secure, HTTP-only cookies are used, neither for advertising or cross-site tracking:

Contact

Privacy and data-protection questions: [email protected].