Privacy
Privacy policy
What we collect, which is very little, when public chain data becomes personal information, what we refuse to do with it, and how to make us delete what we hold.
Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)
1Who we are and what this policy covers
AI WEB3 SERVICES PTY LTD (ACN 696 596 406, ABN 43 696 596 406) is an Australian proprietary company in New South Wales. It builds read only analytical views over data that is already published on permissionless blockchains. In this policy "we", "us" and "our" mean that company, and "you" means whoever is reading it.
What this policy covers
- This website at aiweb3.co.im.
- Email sent to, or received from, our published address.
- Any analytical view we publish in future, once one exists.
What it does not cover
- Public blockchains themselves. Nobody operates them on your behalf, we did not write them to disk, and no entity can delete a block once it is final.
- Any website you reach by following a link from ours.
- Any third party claiming an association with us. We have no social accounts, no support agents and no partners.
Where things actually stand. No analytical view has been published, so there is currently no customer and no customer data. Today the only personal information AI WEB3 SERVICES PTY LTD holds is correspondence sent to its inbox and the request logs its hosting provider keeps. This policy is written for the position we are heading towards as well as the one we are in, so that the first person to use anything we build can read it beforehand rather than afterwards. The rights in it are live now for the information we hold now.
The four prohibitions, because they shape the data too
We take no custody of assets, give no financial or investment advice, operate no exchange, and have issued no token. Those are commercial commitments, and they are also the reason several categories of personal information that a company in this sector might be expected to hold are simply absent. There is no wallet balance because there is no wallet. There is no trading history because there is no venue. There is no identity verification file because there is nothing to verify anyone for.
2Our regulatory position, and why it belongs here
This section is not required by the Privacy Act. It is here because the sector this company sits in creates a specific risk of being misunderstood, and a privacy policy is one of the documents people actually read.
No financial product advice
Nothing in this policy, on this website, or in anything we publish is financial product advice within the meaning of the Corporations Act 2001 (Cth). None of it takes account of your objectives, financial situation or needs. AI WEB3 SERVICES PTY LTD holds no Australian Financial Services Licence and is not an authorised representative of a licensee.
No custody, no exchange, no token
We hold no assets, keys or funds for anybody. We operate no exchange, order book or matching facility, and we hold no AUSTRAC registration as a digital currency exchange provider because we do not carry on that business. We have issued and promoted no token.
Why this belongs in a privacy policy
Because the categories of personal information a business holds follow directly from what the business does. A custodian holds identity documents, proof of address and source of funds records. An exchange holds trading records and beneficial ownership information. A token issuer holds allocation lists. We hold none of those things, and the reason is structural rather than a matter of good intentions.
3The law this policy answers to
The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.
Australian Privacy Principle 1, and why this document exists
APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.
The small business threshold, and why it does not get us out of this
Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. AI WEB3 SERVICES PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.
We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.
If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.
Other Australian law that applies
- Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
- Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
- Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
- Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
- Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.
4What we collect
The tables in this section are the complete list. A category of personal information that does not appear here is not collected by us.
From this website
| Category | Fields | Why | Held by | Kept |
|---|---|---|---|---|
| Request logs | IP address, timestamp, requested path, user agent, response code, approximate country | Serving the page and defending against abuse and denial of service | Our hosting and edge provider | Provider cycle, under 30 days |
| Security cookie | A strictly necessary cookie the edge provider may set to separate automated traffic from human traffic | Abuse defence. Described in the cookie notice | Our edge provider | Minutes to 30 days |
| Font request | IP address and user agent, disclosed to Google's font servers by your browser when it fetches the typefaces | Rendering the page in the intended typefaces | Google's own retention |
There is no analytics on this website, no advertising, no tracking pixel, no session recording, no heat mapping and no attempt to recognise a returning visitor. There is therefore no consent banner, because there is nothing here that consent would be collected for.
From correspondence
| Category | Fields | Why | Kept |
|---|---|---|---|
| Message content | Whatever you choose to put in the message, including any attachment | Answering you | 24 months for ordinary support, 7 years for a complaint |
| Message metadata | Sending address, display name, timestamps, and the routing headers your mail provider attaches | Delivering, threading and answering the message | With the message |
| Anything you attach | Files, screenshots, exports | Understanding the point you are making | With the message, subject to the unsolicited information section below |
Writing to us subscribes you to nothing. Your address is not added to a list, because there is no list.
What we never collect
- No private key, seed phrase, keystore file or wallet signature. We have no use for one and no field anywhere is intended to hold one.
- No identity document, no photograph of a licence or passport, no proof of address, no source of funds record.
- No payment card details. Nothing is for sale on this website.
- No location beyond the country level approximation that comes free with an IP address.
- No biometric, health, racial or ethnic, political, religious, sexual orientation, criminal record or trade union information. None of the sensitive information categories in section 6 of the Privacy Act are collected.
- No advertising identifier, because there is no application and no advertising.
5Public blockchain data, and when it is personal information
This is the section that matters most for a company like ours, and it is the one most often written badly. It deserves a straight answer rather than a reassuring one.
The starting point
The Privacy Act defines personal information as information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. Nothing in that definition turns on whether the information came from a public source. Public information can be personal information.
Is a public blockchain address personal information
Sometimes. A public address is pseudonymous rather than anonymous. On its own it is a string, and standing alone the individual behind it is usually not reasonably identifiable by us. Combined with other information, whether held by us or readily available to us, the same string can become information about a reasonably identifiable individual. That is a question of fact about a particular address at a particular time, and any company that answers it with a blanket "blockchain data is public, so it is not personal information" is telling you something convenient rather than something true.
Our position, and what follows from it
We treat public chain data as capable of being personal information, and we design so that the combination which would make it so does not happen here.
- No identity attribution. We do not attempt to work out who is behind an address, and we publish no attribution of an address to a named individual or organisation.
- No purchased identity data. We do not buy, licence, scrape or accept a dataset that maps addresses to people, and we will not accept one as a gift. This is the single control that keeps everything else honest, because attribution is not something you can do accidentally.
- No off chain joining. We do not join chain data to exchange deposit lists, leaked databases, social media handles, domain registration records, or any other off chain identifier.
- No visitor to address linkage. We do not connect an address to the IP address, cookie or session of anybody who looked at it. There is no login, so there is nothing to link a query to.
- No clustering sold as identity. Heuristic clustering of addresses is a well known technique. Where a view we build ever uses one, the output will be labelled as a heuristic with its assumptions written down, and it will never be presented as a statement about a person.
What we cannot do, said plainly
We cannot delete anything from a public blockchain. Nobody can. A permissionless ledger is not ours to edit, no transaction we did not send is ours to reverse, and no correction we make can change what a node in another country will serve to the next person who asks it. Any company that offers to remove your data from a chain is either mistaken or lying.
What we can do is stop publishing a derived view, correct or remove anything in our own systems, and tell you exactly which of those two categories your request falls into rather than blurring them. If you believe a public address is your personal information and something we publish makes you reasonably identifiable, write to [email protected] and we will deal with the part that is ours.
Analysis is not surveillance, and the difference is a design decision
The same public data supports two very different products. One counts, reconciles and explains. The other attributes, scores and reports on people. The technical distance between them is short, which is why the prohibition on attribution is written into this policy and into our terms of use rather than left as a matter of taste.
6What we tell you when we collect
Australian Privacy Principle 5 requires us to tell you certain things at or before the time we collect personal information about you, or as soon as practicable afterwards. It lists what has to be said, including who we are, how to contact us, the purposes of collection, the consequences of not providing the information, who we usually disclose it to, and whether it goes overseas.
Where we meet it
- Here. This document is linked from the footer of every page of this website, before you have any reason to write to us.
- At the point of contact. The contact page says what happens to your correspondence, how long it is kept, and that writing to us subscribes you to nothing, on the same page as the address itself.
- In the cookie notice. The cookie notice lists everything this site can store on your device, which is two cookies neither of which we set.
Consequences of not providing information
There is nothing on this website you have to provide anything to use. Reading the site requires no account, no email address and no name. If you write to us and give us no way to reply, we cannot reply. If you make a privacy request and give us nothing that lets us find the information, we will have to ask, and until then we cannot answer the request. Those are the only consequences, because there is nothing else being collected.
Collection from someone other than you
Where we collect personal information about you from a third party rather than from you, APP 5 still applies and we will notify you unless it is impracticable to do so. In practice this happens in one situation, which is when somebody writes to us about somebody else, and it is dealt with in the unsolicited information section.
7Dealing with us anonymously
Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym, unless that is impracticable or we are required by law to deal with an identified individual.
Reading this site
Anonymity is the default and not a setting you have to find. There is no account, no sign in, no newsletter, no comment box and no form. Nothing on this website asks who you are, and the only record of your visit is a request log held by the hosting provider for under 30 days.
Anything we build
The views described on the home page read public chain data. None of them needs to know who is asking, and none of them will require an account to answer a question about a public block. If a view ever needs an account, for instance to save a saved query, that account will be optional, the anonymous path will keep working, and this paragraph will be updated before the feature ships rather than after.
Writing to us
You may write from a pseudonymous address and we will answer it. We do not require a real name, and we do not check one.
Where the option genuinely falls away
A request for access to, or correction of, personal information is the one place we have to be satisfied that you are the person the information is about, because handing your correspondence to somebody else would be a worse privacy outcome than a slightly inconvenient one. What that means in practice is set out in the access and correction section, and it does not involve identity documents.
8Information we did not ask for
Australian Privacy Principle 4 deals with personal information we receive without having asked for it.
This happens most often when somebody sends us a bug report and includes a full screen recording, a diagnostic export, or a message thread containing other people's details. When we receive personal information we did not solicit, we decide within a reasonable period whether we could have collected it under APP 3. If we could not, and the information is not contained in a Commonwealth record, we destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
Practically: unsolicited attachments containing third party personal information are deleted from the inbox and from any backup rotation on its ordinary cycle, and the substance of the bug is recorded without them.
9Use and disclosure
Australian Privacy Principle 6 governs what we may do with personal information once we hold it. The rule is that information collected for a particular purpose may be used or disclosed for that primary purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the primary one, where you have consented, or where a specific exception in the Act applies.
Every purpose we have
| Information | Primary purpose | Any secondary purpose |
|---|---|---|
| Your correspondence | Reading it and replying to it | Keeping a record of a complaint and how it was handled |
| Request logs | Delivering the page you asked for | Investigating abuse, denial of service and attempted intrusion |
| Security cookie | Separating automated traffic from human traffic | None |
That is the whole list. It is short because the business is small and because nothing has shipped.
What we do not do
- We do not sell personal information. Not to a broker, not to an advertiser, not as an audience or a dataset, and not as part of a bundle.
- We do not profile you, build an interest graph, or infer anything about you from what you read on this site. There is no analytics, so there is nothing to infer from.
- We do not use your correspondence to market anything to you, because we do not market anything to anyone.
- We do not use personal information to train a machine learning model, ours or anybody else's, and we do not paste correspondence into a third party model to help draft a reply.
- We do not attribute blockchain addresses to people, which is dealt with in its own section above.
Disclosure required or authorised by law
We may disclose personal information where the Act permits it: where required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A applies, including a serious threat to the life, health or safety of any individual, or to an enforcement body where reasonably necessary for an enforcement related activity.
Where we disclose to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law allows us to tell you a request was made, we will tell you. We will not volunteer information that has not been asked for, and we will not treat a politely worded email from an organisation with no power to compel as though it were a warrant.
10Direct marketing and the Spam Act
Australian Privacy Principle 7 restricts the use or disclosure of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime with three requirements: consent, accurate identification of the sender, and a functional unsubscribe facility that remains usable for at least 30 days and is honoured within 5 working days.
Our position
We do not run a marketing list. No marketing message has ever been sent under this company name. There is no newsletter, no announcement list, no product update email and no launch notification list on this website, and there is no hidden checkbox anywhere that would add you to one.
Writing to our address does not subscribe you to anything. That is the most common way a small company quietly builds a list out of its support inbox, and we do not do it.
If that ever changes
- It will be express opt in, from a form that does one thing and says so.
- The consent will be recorded with a timestamp and the exact wording you agreed to.
- The first message will say where the address came from and when you gave it.
- Every message will identify AI WEB3 SERVICES PTY LTD and carry a working unsubscribe link, honoured immediately and in any event within 5 working days.
- Unsubscribing will never require a login, a reason, or a reply to a human.
Nothing we build will carry advertising
There is no advertising on this website and none is planned in anything we build, so there is no advertising identifier, no ad network, no bidding request and no cross site profile. This is a design decision about what the product is, and it also happens to remove the largest single source of personal information leakage in consumer software.
Do Not Call
The Do Not Call Register Act 2006 (Cth) governs unsolicited telemarketing. We do not telemarket, we collect no telephone numbers, and we publish none.
11Recipients, and where they are
This is the complete list of who receives personal information from us, why, and where they are.
| Recipient | Purpose | What they receive | Where |
|---|---|---|---|
| Our hosting and edge provider | Serving this website and defending it from abuse | Request logs including IP address, user agent and requested path | Global edge network, including Australia |
| Google LLC and Google Ireland Limited | Serving the three typefaces this site uses, requested by your browser | IP address, user agent and referring page, disclosed by your browser rather than by us | United States, Ireland and other Google regions |
| Our email provider | Receiving, storing and sending correspondence | Whatever is in an email, including its metadata | Australia and the United States |
| Our accountant | Statutory accounts, business activity statements and tax | Transaction records, and correspondence only where a specific query requires it | Australia |
| Public blockchain nodes and archival data providers | Reading public chain data | Nothing about you. We send queries about public blocks and addresses, and no information about who is asking, because nobody is signed in | Various |
Who is deliberately not on this list
No analytics provider, no advertising network, no data broker, no enrichment service, no identity graph, no customer data platform, no marketing automation tool, no chat widget, no session recorder, no chain attribution vendor. Adding any of them means editing this table first and announcing it under the changes section, not afterwards.
Business transfer
If the company or a part of it is sold, personal information may transfer to the buyer as part of that sale. Where we are lawfully able to, we will publish notice on this website before the transfer completes. The buyer is bound by this policy until it publishes its own, and its own cannot reduce your rights in respect of information collected before the transfer without your consent.
12Sending personal information overseas
Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.
We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".
How we meet APP 8
Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.
We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.
Where the data actually goes
The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.
13Government related identifiers
Australian Privacy Principle 9 restricts an organisation from adopting, using or disclosing a government related identifier, which includes a tax file number, Medicare number, driver licence number or passport number.
We do not collect any government related identifier. We have no reason to, our products have no age verification or identity verification step that would need one, and no field in any system we operate is intended to hold one.
If you send us one anyway, for instance by attaching a photograph of a licence to an email, it is treated as unsolicited personal information under the section above and destroyed.
14Keeping information accurate
Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.
Most of what we hold is machine generated and therefore accurate in the narrow sense that it faithfully records what a device reported. The category most likely to go stale is anything you told us yourself, such as an email address in a support thread. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us.
The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.
15Security, and what we do not hold
Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.
What "reasonable steps" means for a company this size
- Transport encryption on every connection. The website and every app endpoint are served over HTTPS only.
- Encryption at rest for stored data, provided by the underlying platform.
- Multi-factor authentication on every administrative account that can reach production data or a store console.
- Access on a need to know basis. The number of people who can reach production data is small and is reviewed when anyone joins or leaves.
- Separate credentials for development and production, so a compromised development credential does not reach live data.
- Collecting less. The most reliable security control available to a small studio is not holding the data, which is why the collection tables are short.
What we do not have, stated plainly
AI WEB3 SERVICES PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.
We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.
16Retention
Australian Privacy Principle 11.2 requires us to destroy personal information, or to de identify it, once it is no longer needed for any purpose for which it may be used or disclosed under the Act, unless a law or a court order requires us to keep it.
| Category | Period | Reason |
|---|---|---|
| Website request logs | Under 30 days | The hosting provider's own cycle. Long enough to investigate an attack, short enough not to become a record of who reads what |
| Security cookie | Minutes to 30 days | Set by the edge provider and expiring on its own schedule |
| Ordinary correspondence | 24 months | Long enough to recognise a recurring question and to pick up a thread somebody returns to |
| Complaint correspondence | 7 years | Evidence of what was complained about and how it was handled, and it matches the general limitation period in New South Wales |
| Privacy request correspondence | 7 years | Evidence that a request was answered, and within what period |
| Impersonation and security reports | 7 years | Patterns of impersonation repeat, and an old report is often the thing that identifies a new one |
| Accounting and tax records | 7 years | Required by Australian tax and corporations law |
| Backups of the above | Overwritten on the ordinary rotation, complete within 35 days | We do not restore a deleted record from a backup |
| Public chain data we have read | Not personal information as we hold it, and not linked to any individual | Dealt with in the public chain data section above |
Destruction means removal from live systems and expiry from backups on the ordinary rotation. De identification means removing every identifier and any field that would let one be reconstructed, and we treat a record as de identified only where re identification is not reasonably possible rather than merely inconvenient.
17Access and correction
Australian Privacy Principle 12 gives you a right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you a right to ask us to correct it. Both are free, and neither requires a reason.
How to ask
Email [email protected] with Privacy request in the subject line. Tell us what you are looking for. Because we have no accounts, the practical starting point is almost always the email address you have written to us from, which is what most of our records are keyed to.
How we verify who you are
We will not ask you for identity documents, a photograph of a licence, a wallet signature or proof of anything. For correspondence, replying from the address the correspondence came from is what we can verify, and we will say that is what we have verified rather than implying a higher level of confidence. Where a request would give somebody access to another person's information, we will refuse the part that would, and explain which part and why.
Timing and cost
We respond within 30 days. Verifying who you are happens inside that period, not on top of it. There is no charge for making a request, no charge for access and no charge for correction. If giving access in a particular form would impose a genuine cost, we will tell you the amount before doing the work, and it will not be excessive.
How we give access
In the form you ask for where it is reasonable and practicable to do so. For correspondence that usually means the messages themselves, exported and sent back to you. If we cannot give access in the form requested, we will offer another way that meets the same need.
When access can be refused
The grounds in the Act are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of other individuals, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be accessible by the process of discovery, where giving access would reveal our commercially sensitive evaluative information in connection with a commercially sensitive decision, and where giving access would be unlawful.
If we refuse, in whole or in part, we will give you written reasons, identify the ground relied on, and tell you how to complain. Where part of the information can be given, or a summary would meet your need, we will offer that instead of a flat refusal.
Correction
If information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed it to somebody else and you ask us to tell them about the correction, we will take reasonable steps to do so unless that is impracticable or unlawful.
The right most people do not know about
If we refuse to correct something, you can ask us to attach a statement to the record saying that you consider it inaccurate, out of date, incomplete, irrelevant or misleading. We must then take reasonable steps to make that statement apparent to anybody who later looks at the record. That right is in APP 13.4, it is rarely mentioned, and it is worth knowing about.
Where the request touches a public blockchain
We can correct or delete what is in our systems. We cannot alter a public chain, and neither can anybody else. If your request covers both, we will do the first, say so, and be specific about which part of the request we are unable to satisfy and why, rather than answering the easy half and going quiet on the other.
18Deletion
Deletion is not a separate statutory right under the Privacy Act in the way it is under some overseas laws. It sits inside APP 11.2, which requires us to destroy or de identify information once it is no longer needed. We treat a deletion request as a request to bring that obligation forward, and we act on it.
How to ask
Email [email protected] with Delete my data in the subject line, from the address the information relates to.
What deletion covers
| What we hold | On a deletion request | Why |
|---|---|---|
| Ordinary correspondence with you | Deleted within 30 days | No reason to keep it once you have asked |
| Complaint correspondence | Retained for 7 years | It is the evidence of how a complaint was handled, including in your favour |
| Records of a privacy request | A minimal record retained for 7 years, being the fact that a request was made, the date and the outcome | So we can show the request was answered. The content is deleted with the correspondence |
| Accounting records | Retained for 7 years | Required by Australian tax and corporations law |
| Website request logs | Expire on the provider cycle, under 30 days | Already short lived, and not searchable by person |
| Backups | Overwritten on the ordinary rotation, complete within 35 days | We do not restore deleted records from a backup |
| Anything on a public blockchain | Cannot be deleted by us or by anybody | Explained in the public chain data section |
We confirm in writing when deletion is complete. We do not mark a record as deleted and quietly keep it, and we do not treat a deletion request as an opportunity to ask you to reconsider.
There are no accounts to delete
This site has no accounts, so there is no account deletion path and no dark pattern hiding one. If a future view ever offers an optional account, an in product deletion path and an email path will both exist from the first day it ships, and this section will say so before that day rather than after it.
19Children and young people
Nothing we publish is directed at children or designed to appeal to children. The subject matter is public ledger analytics, the audience is people with a professional or research interest in it, and there is no game, no reward, no social feature and no user generated content anywhere.
The Australian position on capacity
The Privacy Act does not set an age at which a person can consent for themselves. The OAIC's guidance is that an organisation should assess capacity individually where practicable, and that as a general rule a person aged 15 or over is presumed to have the capacity to consent unless something suggests otherwise. We apply that presumption.
The Children's Online Privacy Code
The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code, to be developed by the Information Commissioner and to apply to services likely to be accessed by children. We will comply with that Code to the extent it applies to us once it is registered and in force. We will update this section at that point rather than guessing now at what it will require.
In practice
- We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
- There is nothing on this website that asks anybody's age, because there is nothing that asks anybody anything.
- There is no advertising, so there is no child directed advertising question to answer.
If a child's information has reached us
Write to [email protected]. We will delete it without requiring you to prove a legal relationship beyond what is needed to be satisfied the request is genuine, and we will confirm in writing when it is done.
20Automated decisions, and the scoring we refuse to do
The Privacy and Other Legislation Amendment Act 2024 (Cth) inserts a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of decisions made. That requirement commences on 10 December 2026. This section is published in advance of it.
The disclosure
We make no automated decision that significantly affects any individual's rights or interests. Nothing we operate decides whether a person receives credit, a job, a service, a benefit, an insurance product or a legal entitlement, and nothing we operate produces an output that another organisation could use to make such a decision about a named person.
Why this section matters more here than elsewhere
Automated risk scoring of blockchain addresses is a real product category. Vendors produce a score for an address, and businesses use that score to freeze funds, refuse a withdrawal or close an account. Whatever the merits of that, it is a substantially automated decision with a serious effect on a person, it is frequently wrong, and the person affected usually cannot see the input, the model or the reason.
We do not do it. We produce no risk score, no sanctions determination, no taint or contamination rating, no "suspicious" flag and no output designed to be consumed by a compliance system as a decision about a person. This is a prohibition, not a gap in a roadmap.
What automation we do use
- Arithmetic over public data. Counting, summing, reconciling and decoding. The output describes blocks and transactions, not people, and it decides nothing about anybody.
- Spam filtering on the inbox. Standard mail filtering may divert a message. If you write and hear nothing within the stated period, write again, and we will check the filtered folder. That is the entire remedy and it involves a person.
- Abuse defence at the edge. Our hosting provider may present a challenge to traffic that looks automated. Failing it delays access to a public web page and affects nothing else. If it blocks you persistently, tell us and we will look at it.
Machine learning
We do not train models on personal information. We do not send correspondence to a third party model. If a view we build ever uses a model over public chain data, the output will be labelled as an estimate with its method described, and it still will not be a decision about a person.
21Data breaches and the notification scheme
Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.
The process we follow
- Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
- Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
- Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
- Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.
What a notification will contain
Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.
If you think a breach has happened
Write to [email protected] with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.
22The statutory tort of serious invasion of privacy
A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.
This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.
23Cookies and storage on this website
This website sets no cookies of its own, runs no analytics, and carries no advertising. A strictly necessary security cookie may be set by our edge provider to separate automated traffic from human traffic.
There is no consent banner, because nothing here requires consent. Australia has no separate cookie consent regime, and a banner that asks permission for nothing trains people to dismiss a control that matters elsewhere. The full reasoning, the complete list of what can be stored, and how to control it yourself are in the cookie notice.
There is also no wallet connection request on this site, and there never will be. No browser extension is probed, no accounts are requested, and no signature is asked for. That is a storage and security matter as much as a privacy one, and it is set out in the cookie notice too.
24Complaints
Step one: tell us
Email [email protected] with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.
Step two: the Commissioner
If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.
The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.
What we will not do
We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.
25If you are outside Australia
This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.
European Economic Area and United Kingdom
Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Send any such request to [email protected] and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.
California
Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. Personalised advertising is off unless you turn it on, which places us outside the sharing definition by default. Global Privacy Control signals sent by your browser to this website are honoured.
Everywhere else
If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.
26Changes to this policy
We may change this policy. When we do, we update the effective date and the version number in the header of this page.
Where a change materially reduces your rights or materially expands what we collect, we will give notice before it takes effect: a notice in the app on next launch, and a note at the top of this page for at least 30 days. We will not make a material change effective retrospectively.
Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.
This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances.
27How to contact us
Every privacy matter reaches one address, and a person reads it.
| Matter | Subject line | Response |
|---|---|---|
| Access to your personal information, under APP 12 | Privacy request | 30 days |
| Correction of your personal information, under APP 13 | Privacy request | 30 days |
| Deletion of what we hold | Delete my data | 30 days |
| A public address you say identifies you | Privacy request | 30 days |
| Complaint about how we handled personal information | Privacy complaint | Acknowledged in 5 business days, answered in 30 days |
| Suspected security incident or data breach | Security | Same or next business day |
| Somebody impersonating us | Impersonation | Same or next business day |
| Anything else | Anything sensible | 5 business days |
Email. [email protected]
Entity. AI WEB3 SERVICES PTY LTD, an Australian proprietary company, ACN 696 596 406, ABN 43 696 596 406, New South Wales, Australia.
Privacy officer. The company has not appointed a named privacy officer, and we will not invent a title to look larger than we are. Privacy correspondence is read and answered by the people who run the company.
We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 696 596 406 on the register maintained by the Australian Securities and Investments Commission, and that is the address with legal effect for service.
If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.