Site policy · Effective 17 September 2026
Privacy notice
This notice covers My library, optional research-update alerts, email sent to SMID Research, the moderated “Reader questions & corrections” form on company pages, and the signed-in “Discussion” forum. It does not turn SMID Research into an advisory or customer-service business.
Discussion accounts
An account holds your email address, a display name you choose, the date you joined, and whether SMID Research has marked the account trusted or suspended. A fresh self-declaration is attached to each post rather than stored as a permanent profile position. Your email address is encrypted before storage and is never published. A keyed identifier derived from it prevents duplicate accounts.
An account is a standing record, not a one-off message. Unlike a question submitted through the private form, account data is kept for as long as the account is open, because it is what lets you sign back in and manage your own posts. The retention table below sets out what happens when an account falls dormant or is closed.
Signing in uses a single-use link sent to your email. Only a keyed representation of that link is stored, so the stored record cannot be replayed as a sign-in. Links expire shortly after they are issued and cannot be used twice. A signed-in session is a separate keyed record with its own expiry, and you can end it by signing out.
Saved companies, alerts and reading history
My library uses the same confirmed-email account as Discussion. Saving a company stores the company and the dates the preference was created or changed. Saving alone sends no email. Research-update alerts are a separate switch for each company and remain off until you explicitly enable them. Every alert explains why it was sent and provides links to turn it off or manage all preferences.
Reading history is off by default. Public and anonymous reading is not added to My library. If you switch history on, the private account record stores only the company and its first and most recent read times. It does not store the article section, scroll depth, browser fingerprint or a record of anonymous visits. Switching history off deletes the existing list.
Free-member transcript access
Transcript previews are public. Reading a full transcript requires a confirmed-email account. To provide your transcript library and enforce the allowance of 10 full transcript retrievals per Singapore calendar day, we store your internal account ID, the transcript ID and the time of each retrieval, including repeat retrievals. Every full retrieval requires sign-in and counts toward the daily limit. This necessary access record is separate from optional company reading history; it does not record scroll position or anonymous browsing.
Transcript access records are private and are retained while your account is open. They are deleted when the account is closed, including through the existing dormant-account cleanup. Signing in does not grant access to the separately protected private research vault.
What a discussion post collects
A post stores its text, its title if it starts a thread, its room (a company or Others), the thread, your self-declaration, the time, and the account that wrote it. It also stores a keyed representation of a coarse network prefix and a signed device cookie for rate limits and abuse prevention. Raw IP addresses, browser fingerprints and Turnstile tokens are not stored.
Discussion posts are public the moment they appear, together with your title, display name, self-declaration and the date. Treat a post as permanent and public. Do not put anything in one that you would not want indexed by a search engine.
Room requests. Asking for a room for another listed company stores the exchange, ticker, company name and listing link you give, an optional private note to SMID Research, the time and the account that asked, together with the first thread, which is held. Nothing about a request is published unless SMID Research approves the room; the room's name may be corrected against the listing first.
Reports. Reporting a post stores the post, the reason you chose, the time and the account that reported it, so misuse of reporting can also be handled. Reports are never published and the author is not told who reported them. SMID Research receives at most one email an hour saying how many requests, held posts and reported posts are waiting; it contains no reader text, names or email addresses.
What the question form collects
The form asks for a name or pseudonym, email address, question or correction, company, submission type and interest disclosure. It also uses a random signed device cookie and a keyed representation of a coarse network prefix for abuse prevention. Raw IP addresses, browser fingerprints and Turnstile tokens are not stored in the Q&A database.
Email addresses and original submissions are encrypted before storage. A keyed email identifier supports duplicate checks on the private question record, while separate keyed device and coarse-network identifiers support rate limits. These identifiers are still treated as pseudonymous personal data.
Why the data is used
- To operate accounts and sign-in, and to let you manage saved companies, alerts, optional reading history and your own posts.
- To display, moderate, edit for clarity, hold or remove discussion posts.
- To review, answer, edit and, where appropriate, publish useful research questions or factual corrections.
- To contact you about a correction, a moderation decision or a clarification.
- To prevent spam, ramping, coordinated posting, impersonation and other abuse.
- To keep an audit trail of publication, rejection, editing, removal and account decisions.
Holding an account or saving a company does not subscribe you to email. Company alerts are sent only where you separately enable them, and can be switched off at any time. SMID Research does not sell submission or account data.
What may be published
From Discussion: your thread title, post text, display name, declared interest and date, and the name of a room you asked for once it is approved. From the question form: nothing is published automatically — only the edited question, chosen display name, relevant interest disclosure, SMID Research answer and publication date may appear, and only if selected. Email addresses, saved companies, alert choices, reading history, sign-in records, abuse signals and moderation notes are never published.
Service providers and transfers
The site is hosted on Cloudflare Pages. Cloudflare D1 stores account, reader-preference, post and Q&A records; email addresses and private question text are encrypted before storage. Cloudflare Turnstile checks whether a submission appears automated. Resend delivers sign-in links and reader-enabled research-update alerts; direct correspondence is handled through Google Gmail. These providers may process data outside Singapore under their respective safeguards.
Retention
- Saved companies and alert choices: retained until you remove the company, disable the alert or close the account.
- Opt-in reading history: each entry is deleted 12 months after its last-read date; the entire list is deleted immediately when you switch history off or clear it.
- Alert campaign and delivery-status records: retained for up to two years to prevent duplicate sends and document delivery; they use an internal account ID rather than a raw email address.
- Open discussion accounts: retained while the account is open and in use.
- Dormant accounts: an account with no sign-in for 24 months is closed, and its encrypted email and sign-in records are deleted on the next daily cleanup.
- Closed accounts: encrypted email and sign-in records deleted on the next daily cleanup. Posts already public remain attached only to an anonymised tombstone record and are shown under the neutral label “Former member”; the encrypted email, sign-in records and prior display name are removed.
- Sign-in links: deleted 7 days after they expire. Sessions: deleted after expiry or sign-out.
- Discussion posts: public editorial content, retained while editorially useful, subject to correction, withdrawal or removal.
- Held or removed posts: their text and title, moderation note and abuse signals are deleted or replaced by a thread-preserving tombstone after 90 days on the next daily cleanup.
- Reports: deleted a year after SMID Research has decided the post, and in any case after two years; a closed or dormant account's reports are deleted with the account.
- Room requests: a declined request's details (the company's name, the listing link, the note and the link to the account that asked) are deleted 90 days after it was declined. Its posts, removed when the request is declined if they were not already, are redacted like any removed post; the tombstone that remains records the room (its exchange and ticker), the account that wrote the post and why it was removed. A request still waiting for a decision is kept until it is decided; its posts are held posts, redacted after 90 days like any held post. For an approved room, the private note and the request's record of which account asked are deleted 90 days after approval; the room and its listing link remain, and so do its published posts, each shown under its author's display name, the requester's own first post among them once it is released.
- Direct email correspondence: routinely reviewed for deletion after 12 months. A message may be kept longer only while needed to document a published correction or meet a legal or security obligation.
- Routine rate-limit events: deleted after 30 days on the next daily cleanup, normally within about 31 days.
- Unanswered pending submissions: deleted after 90 days on the next daily cleanup, normally within about 91 days.
- Rejected or hidden submissions: deleted after 90 days on the next daily cleanup, normally within about 91 days.
- Encrypted email, original private text, original private display name and duplicate hash for a published item: removed after 30 days on the next daily cleanup. The owner-approved public pseudonym or name remains with the published Q&A.
- Published Q&A: retained while editorially useful, subject to correction or removal.
- Pseudonymised moderation records: may be retained for up to two years.
Cloudflare D1 recovery features may retain recoverable database history for up to 30 additional days after an operational deletion.
Your choices
While signed in, you can remove saved companies, switch individual alerts off, clear or disable reading history, and withdraw your own posts; each new post asks for a fresh self-declaration. You may request a display-name change, account closure, access, correction, withdrawal or deletion by emailing [email protected].
On deleting posts: a request to remove personal data will be assessed alongside legal, security and record-keeping needs. For discussion, the ordinary remedy is to delete the personal data linking a post to you and leave the post itself in the thread under a neutral placeholder, because other readers have replied to it and removing it outright would misrepresent the conversation. Where a post is unlawful, unsafe or wrongly attributed, it is removed outright.
Cookies
Two strictly necessary, secure, HTTP-only cookies are used, neither for advertising or cross-site tracking:
__Host-qa_devicerecognises a browser for CSRF and rate-limit protection. It expires one year after issue; when it has expired, a new random cookie is created if the form is used again.__Host-qa_sessionkeeps you signed in after you use a sign-in link. It is removed when you sign out and expires on its own thereafter.
Contact
Privacy and data-protection questions: [email protected].