interest.sg is currently owner-operated. The owner is the organisation responsible for personal data handled through the Service. The designated Data Protection Officer can be contacted at privacy@interest.sg.
1. Privacy summary
- Most calculator arithmetic runs in your browser and is not saved just because you enter it.
- We collect account or financial information only when you use a feature that needs it or choose to save it.
- We do not sell, rent or trade personal data and do not share it for advertising, data-broker, referral or partner-lead purposes.
- Service providers process limited data to host, secure and deliver user-requested functions.
- Financial Profile sections, saved cash Goals, check-ins, corrections, manual cash allocations, reminder preferences and prior plan revisions, scenarios, snapshots and saved calculation payloads are protected with application-layer encryption before storage. This is not zero-knowledge encryption.
- Property screenshots or listing text go to OpenAI only when you choose AI import. interest.sg does not intentionally store the uploaded image or AI extraction output in D1.
- You can access, correct, export and delete data using account controls or by contacting the Data Protection Officer, subject to applicable law.
2. Data we collect
Information you provide
Depending on the feature, this may include:
- account name, email address, password and language preference;
- optional Financial Profile information about household context, birth year, residency or employment context, income and spending, CPF/SRS, assets, property, debts and goals;
- calculator inputs, outputs, formulas, source snapshots, titles and notes that you choose to save;
- up to three cash Goals you explicitly save, including goal names, targets, dated self-reported balances, planned monthly additions, assumptions and prior plan revisions; dated post-save balance check-ins, optional stated movements and notes, correction history, lifecycle choices, manual cash-pool names and allocations, an optional monthly savings budget, review cadence and separate reminder preferences;
- a separately consented first-million scenario, sharing the three saved Goal slots: its selected eligible cash/investment starting balance and date, fixed monthly addition, target and nominal or today's-money view, illustrative inflation and selected net-growth assumption, optional whole-year age, model version, reviewed result and prior revisions. It is not added to Profile net worth or enrolled in cash check-ins, allocations or reminders;
- scenario titles and changes;
- a property-listing URL, screenshot or pasted image that you choose to import;
- a PDF report that you choose to email to your verified account address;
- messages and attachments you send to an interest.sg email address; and
- consent, acknowledgement and preference records, including document version, locale and time.
Do not provide an NRIC or passport number, bank password, one-time code, card number or full bank-account number. The Service is not designed to collect them.
Information created when you use an account
We create and store account identifiers, email-verification status, password hashes where password sign-in is used, OAuth links, session records, creation/update/last-login times, saved-item IDs, revision information, consent history and bounded audit events.
If you choose Google sign-in, we receive the Google account identifier, verified email, name and optional profile-image URL permitted by the openid, email and profile scopes. We do not receive your Google password.
Device, security and network information
Our hosting and security systems process information such as IP address, request time, requested route, headers, security tokens and device/browser signals. In our application database, session IP values are hashed and user-agent information is bounded. Rate-limit identities and session tokens are stored as hashes.
If you enable optional first-party analytics, we collect a random visitor identifier, session identifier, route, calculator ID, language, referring host, campaign tags, engagement time, broad device/browser/operating-system family, coarse country/region/city supplied by Cloudflare, bounded product actions, value-free Goals milestones and check-in actions, web-vital measurements and error codes. We preserve the first source/landing page, update the latest and latest non-direct source, and record a bounded ordered page/calculator journey. If you create or use an account in the same consented browser, we may link that pseudonymous journey to the account to measure aggregate signup and profile conversion. Analytics events do not include calculator inputs, Financial Profile values, screenshots, listing text, passwords, email addresses, raw IP addresses or raw user-agent strings.
Google Search Console supplies aggregate query and page performance. We do not claim that an exact organic-search query caused an individual signup. We may compare a consented first-party landing page with related aggregate search queries, but any relationship is labelled as an inference.
Aggregate business metrics and system alerts may be delivered to a private, allowlisted Telegram bot used by the operator. Telegram messages exclude calculator inputs, Financial Profile values, contact details, support-message bodies and individual account records. If the operator asks a natural-language business question, a bounded question may be sent to the OpenAI API only to select an approved read-only metrics function; official business numbers are calculated by our backend and are not sent to OpenAI for calculation.
3. When calculator data leaves your browser
Most calculations run locally. Data may leave your browser when you deliberately or necessarily use one of these functions:
- retrieving current reference data from our Worker;
- submitting entered property facts for comparison with cached official transactions;
- signing in, saving, renaming, duplicating, exporting or deleting an item;
- creating or using My Financial Profile or a scenario;
- choosing AI listing import;
- choosing to email a report;
- contacting us by email; or
- enabling optional analytics.
Each exceptional feature should also show a concise notice at the point of action.
4. How we use personal data
We use data only for purposes that a reasonable person would consider appropriate in the circumstances, including to:
- create, verify, secure and administer an account;
- provide a calculation, reference-data request, property comparison, saved item, Financial Profile, scenario, export or report that you request;
- send verification, reset, security, account-deletion and requested report emails, plus optional generic Goals review reminders only after a separate opt-in and operational activation;
- remember essential settings and maintain authenticated sessions;
- detect, prevent and investigate abuse, fraud, credential attacks, security incidents and service errors;
- operate and improve the Service using optional, minimised first-party analytics;
- respond to enquiries, rights requests and security reports;
- maintain consent, document-version and value-free audit evidence;
- comply with law, enforce the Terms and protect users, the Service and legal rights; and
- manage a genuine business-asset transaction, subject to applicable notice, purpose and disclosure limits.
We do not use saved financial values for advertising or partner leads. We do not send marketing emails at present. If that changes, marketing choice will be separate and this Policy will be updated before the new use begins.
5. Consent and choices
Creating an account requires acceptance of the Terms and acknowledgement of this Privacy Policy. Optional processing is separate:
- My Financial Profile: requires its own current notice and affirmative consent before values are saved.
- Saved cash Goals: require a separate current Goals storage notice, affirmative consent and your acknowledgement that you are at least 21. This acknowledgement is not age verification or bank verification. The V116 notice covers check-ins, corrections, optional movements and notes, manual allocations, review preferences and operational reminder delivery. Existing Goals stay readable, exportable and deletable while you review a newer notice; new financial writes need renewed consent. Optional reminder email is a further separate choice, off by default and independent of security email and analytics. You can turn off Goals saving and delete the live Goals, check-ins, allocations and reminder preferences without deleting your account or other Profile sections.
- Saved first-million scenario: requires a current Financial Profile workspace and consent, verified account, separate first-million storage notice, affirmative consent and age-21 acknowledgement. Earlier
save_cash_goalsconsent does not cover it. Saving is a separate choice after reviewing one scenario; analytics and reminders remain separate. The scenario stays readable, exportable and deletable when new writes are paused. You can delete one scenario, withdraw only first-million consent and delete its scenarios, or withdraw all Goals consent and delete all Goals. - Analytics: optional and off until you choose it. You can change the choice through “Privacy choices”. Withdrawal stops new collection and clears the analytics identifiers in your browser.
- AI import: begins only when you choose to send a listing link or screenshot after seeing the import notice. Manual entry remains available.
- Email report: begins only when you choose to email a report after seeing that the email provider will process the attachment.
You may withdraw consent by using the relevant control or emailing the Data Protection Officer. Withdrawal does not affect processing already lawfully performed and may prevent us from continuing a feature that needs the data. Where the law permits processing without consent—for example, necessary security, legal compliance or a properly assessed legitimate interest—we will still limit the data and purpose.
6. Disclosures and service providers
We do not sell, rent or trade personal data. We do not disclose it to advertisers, data brokers, financial advisers, property agents, lenders, insurers or other commercial partners.
We disclose only what is necessary to:
- Cloudflare: host and deliver the site, execute Workers, store D1 records, protect forms/accounts with Turnstile and support first-party analytics;
- Google: complete optional Google sign-in;
- OpenAI: extract editable listing facts when you choose AI import;
- OpenAI: route an operator's bounded natural-language business question to an approved aggregate, read-only metrics function;
- Telegram: deliver aggregate executive summaries and operational alerts to the allowlisted operator chat;
- Brevo: deliver account/security emails, a PDF report that you explicitly ask to email, and optional generic Goals review reminders after opt-in; reminders contain no Goal names, balances, targets or notes; and
- courts, regulators, law-enforcement or professional advisers: when disclosure is required or permitted by law and necessary to protect rights, safety or the Service.
Service providers may act as data intermediaries and are not permitted by us to use the data for their own advertising or partner-lead purposes. We require appropriate confidentiality, security, purpose and deletion controls where applicable.
7. Overseas processing
Some service providers may process data outside Singapore. Before using them for personal data, we take appropriate steps designed to ensure a standard of protection comparable to the PDPA, such as reviewing applicable law, contractual protections, data-processing terms, security controls and recognised certifications. Contact privacy@interest.sg for current information about the countries or safeguards relevant to your data.
8. AI listing import
When you choose AI import, the Worker sends either the screenshot or sanitised text from the supported listing page to the OpenAI API with storage disabled for the response object. interest.sg does not intentionally insert the uploaded image, source listing text or AI extraction output into D1.
OpenAI states that API inputs and outputs are not used to train its models by default and may be retained for up to 30 days to provide the service and identify abuse, unless a qualifying shorter-retention control applies or longer retention is legally required.
Listing images can contain names, phone numbers, faces or other personal data. Crop or obscure information that is not needed, do not upload identity or financial documents, and upload only material you are entitled to use. AI can misread a listing. You must review and correct every field. The automated estimated-value range is calculated from selected official HDB or URA transaction records, not from an AI-generated valuation.
9. Email reports
If you choose “Email PDF”, the selected report and its financial content are sent through the Worker to Brevo, our transactional-email provider for delivery to your verified account email. Use download or print instead if you do not want an email provider to process the report. We do not send a report to an arbitrary third-party address from this feature.
10. Browser storage and cookies
We use:
- an HttpOnly, Secure, SameSite session cookie for authenticated accounts;
- local or session storage for language, theme, motion/accessibility preference and short-lived pending actions; and
- optional local/session analytics identifiers only after your analytics choice.
A normal session lasts up to 12 hours. “Keep me signed in” lasts up to 30 days unless you sign out or revoke the session earlier. Security and provider systems may use strictly necessary cookies or short-lived identifiers to distinguish legitimate users from automated abuse.
11. Retention
We retain identifiable data only while its purpose or a legal/business need continues. Current principal periods are:
| Data | Retention |
|---|---|
| Account, saved calculations, active Financial Profile and scenarios | Until you delete the item/profile/account or the account is otherwise closed |
| Saved cash Goals, first-million scenarios, plans, check-ins, corrections, allocations and preferences | Until you delete one Goal, withdraw the applicable Goals consent and delete those Goals, delete the Profile or delete the account |
| Normal / remembered session | Up to 12 hours / 30 days, unless revoked earlier |
| Email verification / password reset / Google OAuth state | 24 hours / 30 minutes / 10 minutes |
| Value-free Goals reminder delivery ledger | Up to 180 days; withdrawn Goals/Profile/account deletion removes live linked rows |
| Detailed optional analytics and pseudonymous failed-login events | 90 days |
| Account-linked signup attribution and bounded journey metadata | Up to 24 months or account deletion, whichever occurs first |
| Aggregated analytics | 36 months |
| Private bot command/delivery audit metadata (without message bodies) | 12 months |
| Value-free profile/admin audit evidence | Up to 24 months, unless a documented incident or legal hold requires longer |
| Resolved direct enquiry | 12 months after resolution, unless a dispute, security incident or law requires longer |
| Uploaded AI image or listing text in interest.sg application storage | No intentional persistence after the request completes |
| OpenAI API input/output | Up to 30 days under the provider's current API policy, subject to stated exceptions |
Deleted live data may remain in isolated recovery copies until they age out, with a target maximum of 30 days. Recovery copies are not used for normal processing. If a recovery is performed, applicable deletions must be re-applied.
Deleting My Financial Profile also deletes its saved cash Goals, first-million scenarios, prior plans, check-ins, corrections, allocations, reminder preferences and both Goals consents. A single Goal deletion removes its linked history and allocation. A confirmed Goals withdrawal also stops queued optional reminder delivery. It does not delete separately saved calculations or the account. Deleting the account removes account-linked live records. Pseudonymous detailed analytics and aggregates may remain only for the separate periods above and are not used to recreate the deleted account.
12. Security
We use measures appropriate to the nature of the data, including HTTPS, secure/HttpOnly session cookies, password hashing and peppering, token hashing, rate limits, Turnstile, origin checks, least-privilege administration, bounded analytics, audit records and application-layer AES-GCM encryption for selected financial payloads.
Encryption is not zero-knowledge: the Worker can decrypt saved financial payloads to provide requested functions. Account email, consent/version records, timestamps and operational metadata are not inside those encrypted financial payloads. No internet service is completely secure; do not send credentials or identity documents to us.
If a data breach is notifiable under applicable law, we will notify the PDPC and affected individuals within the required timeframes.
13. Your access, correction, export, withdrawal and deletion rights
Subject to the PDPA and applicable exceptions, you may ask us to:
- provide access to personal data we hold about you and information about its use or disclosure;
- correct an error or omission;
- explain or change a consent choice;
- export available Financial Profile data, including saved cash Goals, check-ins, corrections, allocations and reminder preferences, or download a separate Goals JSON/CSV export;
- delete a saved item, Financial Profile or account; or
- address a concern about our handling of personal data.
Use Account → Data & Privacy where available or email privacy@interest.sg. Describe the request and the account email involved, but do not send a password or one-time code. We may verify identity and may decline or limit a request where the law requires or permits it. We respond as soon as reasonably possible; if we need more than 30 days, we will give a written timeframe within that period.
Where the PDPA permits a reasonable access fee, we will give you a written estimate before processing and will not charge for a correction request. If you remain concerned after contacting us, you may contact Singapore's Personal Data Protection Commission.
14. Children and legal capacity
The Financial Profile is for people aged 21 or older. The Service is not designed to collect personal data from a person who lacks legal capacity to provide it. A parent or guardian who believes a child has provided personal data should contact the Data Protection Officer.
15. Third-party pages
The Service links to official sources, listing sites and other third-party pages. Their privacy practices apply when you visit them. A link is not an endorsement, and this Policy does not govern a third party's independent processing.
16. Changes to this Policy
We may update this Policy to reflect law, providers or Service changes. We will change the version and effective date and provide reasonable notice of a material change. If a change introduces a new purpose that requires consent, we will obtain that consent before beginning the new use. A future company or registered business will not silently replace the current operator; the operator and any related transfer will be disclosed and handled under applicable law.
17. Contact the Data Protection Officer
Data Protection Officer — interest.sg Email: privacy@interest.sg
For product questions use hello@interest.sg; for account or security support use support@interest.sg.
This Policy is available in English and Simplified Chinese. Both are intended to communicate the same rules. If a translation inconsistency cannot be resolved, the English version prevails to the extent permitted by law.