Privacy policy.
We collect as little as we can get away with: an email address if you subscribe, and whatever you type into the report form. No analytics, no advertising, no tracking cookies.
Effective 2026-07-28 · applies to aidigest.asia and cms.aidigest.asia
Who we are
AI Digest Asia is operated by [legal entity — being finalised before launch], at [registered address — being finalised before launch]. For the purposes of Singapore's Personal Data Protection Act 2012 we are the organisation; for Malaysia's Personal Data Protection Act 2010 we are the data user.
Our Data Protection Officer is [DPO — being finalised before launch], reachable at [email protected].
What we collect, and why
1. Newsletter subscription
If you subscribe, we collect the email address you give us, and the date and IP address of your confirmation. We use it for one thing: sending you the daily digest. We do not sell it, rent it, or hand it to the companies we cover.
Subscription is double opt-in — you get a confirmation email and nothing is sent until you click it. Every email carries an unsubscribe link, which takes effect immediately. We keep your address until you unsubscribe, and delete it within 30 days after.
2. Misinformation reports and corrections
The report form collects the article you're reporting, your description of what's wrong, and — optionally — your email address, so we can follow up. Leaving the email blank still submits a valid report.
Reports are stored as private records in our CMS and emailed to the editors. We keep them as part of the correction record, because a public corrections log is only credible if the underlying reports are retained. We do not publish your email address or your identity.
3. Anti-spam
The report form is protected by Cloudflare Turnstile, which analyses technical signals from your browser (including your IP address) to tell humans from bots. Turnstile is used instead of a tracking-based CAPTCHA precisely because it does not profile you across sites.
4. Server and CDN logs
The site is served by Cloudflare Pages. Cloudflare records standard request data — IP address, user agent, timestamp, URL requested — for delivery, security and abuse prevention. We use it only to keep the site up and to investigate abuse.
5. Fonts loaded from third parties
Our pages load typefaces from Fontshare and Google Fonts. Loading a font means your browser makes a request to those providers, which reveals your IP address and user agent to them. We disclose this because it is a real transfer of data, even though we receive nothing from it.
What we do not do
- No analytics or measurement product is installed on this site.
- No advertising, no ad networks, no retargeting pixels, no social media trackers.
- We set no cookies of our own. Turnstile may set a short-lived cookie to carry a challenge result.
- We do not build profiles of readers, and we do not enrich or append data to subscriber addresses.
Who processes your data
We use a small number of processors, each for a single stated purpose. Your data leaves Singapore and Malaysia when it reaches them.
- Moosend — newsletter delivery. Processes your email address. Servers in the European Union.
- Cloudflare — site hosting, CDN and Turnstile. Processes request data globally.
- Our own CMS at cms.aidigest.asia — stores misinformation reports on a server we control. Outbound mail from it is relayed by SendGrid.
Under the PDPA's Transfer Limitation Obligation (SG) and section 129 of the PDPA (MY), we transfer personal data outside Singapore and Malaysia only where the recipient is bound to a standard of protection comparable to the local law, through their data processing terms.
Your rights
In Singapore (PDPA 2012)
- Access — ask what personal data we hold about you and how it has been used or disclosed in the past year.
- Correction — ask us to correct an error or omission.
- Withdraw consent — at any time, for any purpose. Unsubscribing withdraws consent for the newsletter.
We respond to access and correction requests within 30 days. If we cannot, we will tell you when to expect a response.
In Malaysia (PDPA 2010, as amended)
- Access and correction — the same two rights, on written request.
- Withdraw consent — on written notice; we stop processing within a reasonable period.
- Prevent direct marketing — you may require us to stop processing your data for direct marketing at any time.
- Data portability — where technically feasible, you may ask us to transmit your data to another data user.
Supplying personal data to us is voluntary in every case. You can read the entire site without giving us anything. If you don't subscribe, we never learn your address; if you report an error without an email, we cannot reply but the report still counts.
To exercise any of these rights, write to [email protected].
Security and breaches
The site is static and holds no reader database. Reports live in an access-controlled CMS that is not indexed and not publicly reachable for writes without validation. Traffic is encrypted in transit. Where a data breach is likely to cause significant harm, we will notify the affected individuals and the relevant regulator — the PDPC in Singapore, the Commissioner in Malaysia — within the timeframes their rules require.
Children
This is a business publication and is not directed at children. We do not knowingly collect personal data from anyone under 13. If you believe we have, tell us and we will delete it.
Changes
If we change this policy we update the effective date at the top, and material changes are noted in the corrections log — the same place we log everything else we get wrong or change.
Contact
Privacy questions, access requests and complaints: [email protected]. If you are not satisfied with our response, you may complain to the Personal Data Protection Commission (Singapore) or the Department of Personal Data Protection (Malaysia).