Skip to main content
AI Web3 Services

Legal

Cookie notice

An instrument in thirteen Parts. Part 1 defines the terms; Parts 4 to 7 itemise every item of storage and every outbound request this website is capable of producing.

Effective 12 August 2026Version 2.0Privacy Act 1988 (Cth)

Part 1Interpretation and defined terms

Definitions governing every Part that follows

1.1 The terms defined here carry those meanings throughout this notice.

  • "we", "us" and "our" mean AI WEB3 SERVICES PTY LTD, ACN 696 596 406, ABN 43 696 596 406, registered in New South Wales, Australia.
  • "device storage" means any mechanism by which a value is written to and later read from your device by a website, including a cookie, local storage, session storage, an indexed database, a service worker cache and a cached font file.
  • "a first-party cookie" means device storage written under this domain. "A third-party cookie" means device storage written under another domain while you are reading a page of ours.
  • "strictly necessary" describes device storage without which a page could not be delivered or defended, as distinct from storage that improves measurement, personalisation or advertising.
  • "the delivery network" means the content delivery network through which this website is served.
  • "log data" means the record a web server or the delivery network writes when it answers a request, as defined in clause 1.4 of the privacy policy.
  • "the Act" means the Privacy Act 1988 (Cth), and "the APPs" means the Australian Privacy Principles in Schedule 1 to it.

1.2 A reference to a statute includes any instrument made under it. Headings do not affect meaning. "Includes" is not a word of limitation.

Part 2Scope of this notice

Australian Privacy Principle 5 — notification of collection

2.1 This notice describes every item of device storage and every outbound request that a visit to aiweb3.co.im is capable of producing. It forms part of the disclosure the APPs require and is incorporated into the privacy policy by reference.

2.2 It does not describe another operator's website reached from a link here. Nor does it describe a browser extension you have installed, which can write device storage on any page you visit and is outside our knowledge and our control.

2.3 The inventory in Parts 4 to 7 is exhaustive as at the effective date shown above. Part 12 governs what happens if it stops being exhaustive.

Part 3The obligation that actually applies here

Act, s 6(1); Australian Privacy Principles 3, 5 and 6

3.1 Australia has enacted no standalone consent regime for device storage. There is no domestic counterpart to the European ePrivacy Directive, and no Commonwealth statute obliges a website to obtain permission before writing a cookie.

3.2 The instrument that does bind us is the Act. Where device storage collects information about an individual who is identified or reasonably identifiable, that information is personal information; Australian Privacy Principle 3 governs whether it may be collected at all, Australian Privacy Principle 5 requires that the collection be notified, and Australian Privacy Principle 6 confines what may afterwards be done with it.

3.3 Three questions therefore decide whether this website is compliant: whether each item of storage is necessary, whether it has been disclosed, and whether it is used only for the disclosed purpose. Parts 4 to 8 answer all three, item by item.

3.4 A banner would answer none of them. Compliance here is a function of what the site does, and this notice exists to record that rather than to obtain a click.

Part 4Storage written by this website

First-party device storage: none

4.1 No cookie is written by this website. No first-party cookie of any kind is set, whether necessary, functional, preference, measurement or advertising.

4.2 Nothing is written to local storage, to session storage or to an indexed database. No service worker is registered, so nothing is cached under our control and nothing runs after the tab is closed.

4.3 One script is served from this domain. Its function is to reveal sections as they scroll into view and to operate the navigation control on a narrow screen. It reads no storage, writes no storage, makes no network request and transmits nothing anywhere. Disabling JavaScript leaves the site fully readable; the sections simply appear without the transition.

4.4 A browser will cache the stylesheet, the script, the images and the fonts, as it caches files from any website. That cache is your browser's, is governed by the cache lifetimes declared in our response headers, and is cleared by the ordinary controls described in Part 10.

Part 5Storage the delivery network may write

Strictly necessary storage, written by infrastructure rather than by us

5.1 The delivery network sits in front of this website and answers requests before they reach the origin. Where it forms the view that a request pattern is abusive, it may present a challenge, and passing a challenge requires that the outcome be recorded on the device. That is the only circumstance in which storage appears from a visit here.

Device storage attributable to the delivery network
NameWritten whenPurposeLifetime
__cf_bmOn a request the network assesses for automated trafficDistinguishing automated traffic from a person, so that a page can be served without a challengeAbout 30 minutes, refreshed on activity
cf_clearanceOnly where a challenge has been presented and passedRecording that the challenge was passed, so the same reader is not challenged again immediatelySet by the network, and expiring on its own schedule

5.2 Both entries are strictly necessary within the meaning given in clause 1.4. Neither measures your behaviour, neither builds a profile, and neither is read by us. A reader who is never challenged will ordinarily see neither.

5.3 We do not configure, extend or repurpose either entry, and we receive no report derived from them. They belong to the defensive layer, not to us.

Part 6The outbound font request

Australian Privacy Principle 8 — cross-border disclosure

6.1 This website uses three type families, and your browser requests them from Google's font hosts rather than from us. Making that request discloses your internet protocol address and user agent string to Google, and Google's own terms govern what it then does with them.

6.2 The disclosure is made by your browser under its own configuration. We neither receive it nor observe it, and no font file is proxied through our infrastructure. It is disclosed here because the practical effect on you is the same whoever initiates the request, and clause 10.3 of the privacy policy records the same fact in its own Part.

6.3 A content security policy restricts this website to loading resources from our own origin and from those two font hosts. A request to any other destination is refused by your browser, which makes the inventory in this notice enforceable rather than merely asserted.

6.4 The request is preventable at your end. Blocking those two hosts, or reading with a content blocker enabled, causes the page to render in a system typeface. Nothing else about the site changes and no functionality is lost.

6.5 Self-hosting the fonts would remove the disclosure entirely. It is the obvious improvement, it is on the list, and this Part will be rewritten when it is done rather than before.

Part 7Log data

Not device storage, but still collection

7.1 Log data is not device storage. Nothing is written to your device by it, and it cannot be deleted from your browser, because it never lived there. It is recorded here because a notice that itemised only cookies would give a misleading impression of what a visit produces.

7.2 A server cannot answer a request without receiving an address to answer to. The fields recorded are those defined in clause 1.4 of the privacy policy: the requesting address, the time, the method and path, the status code, the bytes returned, the user agent and any referrer the browser supplies.

7.3 Log data rests with the delivery network on its own cycle, currently under 30 days. It is used for delivering pages and for resisting abuse, and for nothing else. It is not indexed by identity, is not searchable by reference to a person, and is not combined with correspondence.

7.4 We run no analytics over log data. No dashboard, no visitor count, no session reconstruction and no report about who read what is derived from it by us.

Part 8Technologies absent from this website

Stated as an inventory of absences

8.1 The following are not present. The list is given in full because in this sector the absence of each is the thing worth verifying.

  • No analytics package of any kind, whether self-hosted or supplied by a third party, and no measurement identifier of any form.
  • No advertising tag, no conversion pixel, no retargeting list and no advertising identifier.
  • No session recording, no heat mapping, no scroll tracking and no form analytics.
  • No social embed, no share widget, no comment platform and no embedded video player.
  • No device fingerprinting, whether by canvas, by font enumeration, by audio context or by any other method.
  • No consent management platform, which is itself a common source of the third-party storage such platforms exist to manage.
  • No wallet connection request, no probe of the browser for an injected wallet provider, and no request that you sign anything. This site holds no signing capability of any description.

8.2 The final entry belongs in a cookie notice for a reason peculiar to this industry. A page that quietly enumerates wallet extensions is performing a fingerprinting operation, and a reader is entitled to know that this one does not.

Part 9Why no consent banner is displayed

A consequence of Parts 4 to 8, not a preference

9.1 A consent banner exists to obtain permission for storage that is not strictly necessary. Parts 4 to 8 establish that there is none, so a banner here would collect agreement to nothing.

9.2 Displaying one anyway would be worse than omitting it. It would train a reader to dismiss a control that carries real weight elsewhere; it would imply that this site does something it does not; and the interaction with the banner is itself commonly logged, so the banner would collect more than the page it guards.

9.3 If that position ever changes, Part 12 states the conditions that will apply before the change takes effect.

Part 10Controlling storage yourself

Controls that do not depend on us

10.1 Every current browser can block device storage, remove what is already stored, and restrict storage to a session. Those controls sit under the privacy or site-data section of the browser's settings and apply to every site, which makes them more reliable than a per-site control we could offer.

10.2 Blocking storage entirely does not break this website. Nothing here depends on a cookie. The only observable consequence is that the delivery network may present its challenge more often, because the record that you passed the last one has been removed.

10.3 Private or incognito browsing discards device storage when the window closes. A content blocker will additionally prevent the font request described in Part 6.

10.4 We provide no cookie preference centre. Offering a control over storage we do not set would be a piece of theatre, and the browser controls in clause 10.1 already do the job properly.

Part 11Do Not Track and Global Privacy Control

Signals a browser may send, and what they mean here

11.1 Some browsers transmit a Do Not Track header or a Global Privacy Control signal expressing an objection to tracking and to the sale or sharing of personal information.

11.2 Neither signal is given legal effect by Australian law at present. We nevertheless comply with both, and compliance costs us nothing, because there is no tracking to disable and nothing is sold or shared. A reader who sends either signal is treated exactly as a reader who does not, and both are treated as the signal asks.

11.3 If a measurement technology is ever introduced, an objection expressed by either signal will be honoured as an objection, and it will not be overridden by a later click on a banner.

Part 12Conditions on which this notice changes

Undertakings binding before any new technology loads

12.1 If device storage that is not strictly necessary is ever introduced, the following bind us in advance.

  • Consent will be sought before the technology loads, and not on the visit after it started running.
  • Declining will require the same number of interactions as accepting, presented with the same prominence.
  • Declining will not degrade the site, delay it, or cause the request to be repeated on the next page.
  • This notice will be amended, with a new version number and effective date, before the change goes live rather than after a reader discovers it.
  • The inventory in Parts 4 to 8 will be updated in the same amendment, so that the two never disagree.

12.2 A view published in future may need storage that this website does not, such as a preference for a chain or a block range. Any such storage will be first-party, functional, and itemised in Part 4 before it is used.

12.3 This notice carries a version number and an effective date beneath its title. A substantive change increments the version; a typographical correction does not.

Part 13Enquiries and complaints

Act, s 36 — complaints to the Commissioner

13.1 A question about this notice is answered within 5 business days. A privacy request is answered within 30 days. Write to [email protected].

13.2 A reader who believes this notice misdescribes what the site does is asked to say so. The inventory is verifiable: open the network panel of a browser's developer tools, load any page here, and every request the page makes is listed. A discrepancy between that list and Parts 4 to 8 is a defect we want reported.

13.3 A privacy complaint is handled under Part 23 of the privacy policy: acknowledged within 5 business days and determined within 30 days. If our answer does not satisfy you, the matter may be taken to the Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au. No filing fee is payable and legal representation is not required.

Summary of the inventory

No cookie written by this website. No analytics, no advertising, no fingerprinting, no wallet probe. Two strictly necessary entries that the delivery network may write if it challenges a request. One outbound request, for three type families, preventable at your end. One server log held under 30 days. That is the whole of it.