Privacy Statement
What Visibly does with the documents you upload, how long anything is kept, who else touches it, and how to get it deleted. Written to be checked against, not skimmed.
Version 1.0 · Last updated 8 September 2026 · Singapore (PDPA)
01Who and what this covers
Visibly is a tool for vendors answering a bank’s third-party risk questionnaire. You upload your own evidence pack and the bank’s questionnaire; Visibly drafts an answer for each row, cites the document and section it rests on, and flags the rows your evidence does not support.
This statement covers both the Visibly application and this website. Where the two differ, we say so — the website is a static site that collects nothing about you unless you use the request form (section 11).
Visibly is operated from Singapore. For anything in this statement, including access and deletion requests, write to support@visibly.sg.
02Our role under the PDPA
Your evidence pack is your organisation’s material. Your organisation decides what goes into it and what it is used for; Visibly processes it on your instruction to produce your assessment. For any personal data inside those documents, Visibly acts as a data intermediaryunder Singapore’s Personal Data Protection Act.
That role is not a way of passing the parcel. Section 4(2) of the PDPA binds a data intermediary directly to the Protection and Retention Limitation Obligations — which is why the retention windows below are enforced by the system rather than promised by a policy.
For your account data — your name, company and work email — Visibly is the organisation responsible.
03What we collect
Account data
Your name, your company name, your work email address, a hashed password, and — if you enable it — a two-factor authentication factor. Visibly accepts work email addresses only; free webmail and disposable-address domains are refused at signup.
Assessment content
The documents you upload (your evidence pack and the bank’s questionnaire), the text extracted from them, the answers Visibly drafts, and the files Visibly generates for you to download. Whatever personal data your own documents happen to contain travels with them; we do not extract or index people.
Operational records
An append-only record of what happened to your assessments — created, run, edited, exported, deleted — plus processing volumes we use for billing and capacity. Emails we send you (notifications, reminders, deletion confirmations) are recorded as sent.
What we do not collect
- No advertising, analytics or tracking identifiers.
- No profiling of individuals. Visibly assesses companies and documents; it never scores a natural person, and no protected attribute is an input to anything.
- No payment card details — card data, when billing begins, is handled by the payment provider and never reaches us.
04How your documents are processed
Three service providers see assessment content, and no others. Your files are uploaded straight to a transient store, converted to text by a document-parsing service, and analysed by Anthropic’s Claude model, wrapped in Visibly’s own guardrails. The model runs with no tools, no autonomy and no memory across assessments: text in, structured text out.
Original uploaded files are not kept unless you choose to keep them.By default each file is deleted from the transient upload store the moment the parser has accepted its bytes, and if a run fails, every file from that session is swept. If you tick “Keep my original files with this assessment” when uploading, the originals are kept in a private Singapore store for exactly the assessment’s availability window, are downloadable only by your account, and are deleted together with the assessment (or sooner, if you delete it or delete an individual document). What persists for the availability window is the extracted text, your answers, the documents generated for you, and — only if you chose it — your original files.
Output is a draft you review, edit and own. Nothing reaches a bank because Visibly produced it — you send it.
05How long we keep it
Results are available for at least 14 days after completion, then permanently deleted within 24 hours after the availability period ends.
The window is counted from local midnight, so it is never shorter than the 14 days stated. You get reminder emails as it runs down, and you can delete any assessment yourself at any time — before the window ends, without waiting for it.
A purge removes the answers, the extracted document text, the generated summaries and the filenames. Account data is kept for as long as you have an account; delete the account and it goes with it. Operational records that carry no content — see the next section — are kept as proof that the deletion happened.
Retention beyond the 14-day window is designed but not yet available. When it is, it will be an explicit, time-limited choice you make per assessment — never a default, and never open-ended.
06Deletion, and what survives it
When an assessment is deleted — by you, or by the automatic purge — the content is removed from all live systems immediately, and you receive a confirmation email carrying a deletion reference. The same records are listed, and printable, in your account.
Two honest caveats, stated here in exactly the words the application uses:
Encrypted database backups expire automatically within 7 days, after which no copy remains in Visibly’s systems.
The deletion record and its reference are retained permanently as proof of deletion; they contain none of your content.
The second caveat has a consequence worth stating plainly. If you ask us to erase your personal data, we erase it — but the sealed audit log keeps an opaque random reference that no longer resolves to anyone. A tamper-evident log and zero residue cannot both be true. We keep the log, and we tell you so rather than let “permanently deleted” imply the audit anchor went too.
07Who else processes your data
The complete list. Adding to it requires a vendor review and a published update — it does not happen quietly.
| Provider | What for | Where | Their retention |
|---|---|---|---|
| Anthropic | Claude — drafts the answers | API | Not retained by default on the commercial API. Stated carve-outs: content flagged by trust-and-safety (up to 2 years) and legal holds. Contractually barred from training on customer content. |
| LlamaParse (LlamaIndex) | Converts your documents to text | API | Cached 48 hours to avoid duplicate charges, then permanently deleted. Never used for model training. |
| Vercel | Hosting, compute, transient upload store | Singapore region | Uploads deleted as soon as the parser accepts them (kept only if you tick the keep-originals box, and then only in the Singapore database store below, never here). |
| Supabase | Database — accounts and assessments | Singapore region | Per the windows in section 5. Encrypted daily backups expire within 7 days. |
| Resend | Transactional email — notifications, reminders, deletion confirmations — and the website request form relay to support@ | Sending from Tokyo; account data held in the US. AWS SES is its subprocessor. | 30 days of email logs. SOC 2 Type II, annual penetration test, data-processing agreement in force. |
Email is deliberately content-free. Visibly’s emails carry generic wording and a link — never document names, never findings, never company details. Assessment content never reaches the email provider at all.
08Transfers out of Singapore
Your assessments are stored and run in Singapore. Two flows leave it: the analysis and parsing APIs above, and the email provider’s US-held account data. Each is covered by a data-processing agreement with standard contractual clauses, which is how the PDPA’s Transfer Limitation Obligation is met.
For the email flow, the protection is structural as well as contractual: because bodies are generic and link-only, what actually crosses the border is your email address and a notification sentence.
09AI training — we do none
No AI is trained or fine-tuned on your data, by us or by anyone downstream. Visibly trains nothing: every assessment is context-only — your documents go in for that run and inform no other customer’s output. Both providers that see content commit contractually to the same, and those commitments are quoted in Visibly’s System Card rather than paraphrased.
11This website
The website is static. It runs no analytics, embeds no third-party scripts, and makes no calls to anyone while you read it — fonts included, which are downloaded once at build time and served from our own domain. Reading this page tells us nothing about you beyond ordinary server logs.
The one exception is the request form. If you ask for a free assessment, we collect what you type — your name, work email address, company, where you are in the bank’s process and, if you choose to give them, a phone number and a short message — for one purpose: to reply to you and set the assessment up. The form reaches us as an email to support@visibly.sg through Resend (listed under Processors, which keeps its copy for 30 days) and stays in that mailbox for as long as the conversation needs, then is deleted. Please do not paste confidential documents or other people’s personal data into the message box — the assessment itself is the place for your evidence pack. To limit automated traffic we also keep one content-free log entry per submission: a keyed hash of your email address and of your network address, the stage you selected, and the outcome — nothing you typed. Those hashes are still personal data to us, and are covered by your rights below.
12Security
- Data encrypted in transit and at rest; each customer’s data is isolated at the database level, enforced by the database rather than by application code.
- Accounts are work-email only, with a 12-character password minimum checked against known-breached password lists, and two-factor authentication that your organisation can require.
- Every material action on an assessment is written to an append-only log that cannot be edited after the fact.
- Suspected a problem? Write to support@visibly.sg and say so in the subject line. We would much rather hear it.
13Your rights, and how to use them
Under the PDPA you may ask for access to the personal data we hold about you and information on how it has been used, ask us to correct it, and withdraw consent for its use. Most of it you can do without asking us: your assessments are listed in your account, and each one has a delete button that works immediately.
For anything else, write to support@visibly.sg. We acknowledge requests promptly and respond within 30 days; if a request will take longer, we tell you why and when. There is no charge for a reasonable request.
Where the personal data sits inside a document your organisation uploaded, we will normally direct the request to that organisation — they decided what to upload, and we act on their instruction. We will help them answer it.
14Changes to this statement
This statement is versioned and dated at the top. Material changes — anything that alters what we collect, how long we keep it, or who processes it — are notified to account holders before they take effect, not applied retroactively and quietly.
Questions about any of it: support@visibly.sg.