Skip to main content
AIDEOLOGY

Legal

Cookie notice

Most notices of this kind describe a long list of trackers and then ask you to agree to them. This one describes two Cloudflare cookies and a single font request, and invites you to check the whole of it in your own developer tools.

In force from 12 August 2026Revision 2.0Privacy Act 1988 (Cth)

What this site writes to your browser

We write nothing of our own into your browser's storage when you read these pages. There is no analytics package here, no advertising or measurement pixel, no session recorder, no heatmap, no embedded video or map or social widget carrying a third party's storage in with it, and no attempt of any kind to recognise you when you come back. Our own code writes nothing to local storage, session storage or IndexedDB.

That is a strong claim, and a claim like that is worth very little on the word of the party making it. So the useful version is the one you can check: open the developer tools your browser already has, look at the storage panel and the network panel, and reload this page. What you find there is the actual answer, and it will match the paragraphs below. A notice you can verify in thirty seconds beats a paragraph of assurances.

What Australian law actually asks

Readers who have spent time on European sites arrive expecting a consent regime that Australia does not have. There is no local counterpart to the ePrivacy Directive and no statute here that requires permission to be collected before a cookie is set. A banner on an Australian website is therefore a design decision rather than a compliance one, and quite a few of them exist mainly because someone assumed the obligation crossed the ocean along with the template.

The instrument that does apply is the Privacy Act 1988 (Cth). Should a cookie, or any technology doing a cookie's job, gather something about a person who can reasonably be singled out, what it gathered is personal information and the Australian Privacy Principles begin to bite — APP 3 governing what may be gathered at all, APP 5 governing whether you were told as it happened, APP 6 governing what may afterwards be done with it. The questions that actually matter are therefore narrower, and considerably more answerable, than a banner suggests: whether you were informed, whether the thing is necessary at all, and whether its use stays inside the purpose declared for it. This page answers all three, and the privacy policy carries the wider argument.

The case against a banner nobody needs

The whole function of a consent banner is to secure permission for storage that could not be defended as strictly necessary. None of that exists here, so a banner would be soliciting your agreement to nothing whatever — and that is meaningfully worse than leaving it out. Three harms follow from that. Visitors get trained to swat away a control that carries real weight elsewhere. A choice which never existed gets dressed up as though it had. And the site takes on the appearance of activity it does not engage in. A dialogue box that misrepresents the stakes is not a privacy feature.

Were analytics or advertising ever introduced here, three commitments would take effect at the same moment. Permission would be sought before any such script ran. Turning it down would cost you no more effort than accepting it, rather than one tap weighed against three. And this notice would be amended ahead of the change instead of trailing along behind it.

The two cookies that are not ours

Two cookies may nonetheless appear against this domain, and both belong to Cloudflare, the provider that serves these pages. We set neither one of them. Neither is legible to us as a means of picking you out. Both sit inside the strictly necessary bracket, which is the bracket that no consent regime in any country demands permission for.

The first is __cf_bm, which distinguishes automated traffic from human traffic so that abusive requests can be turned away before they reach the site. It lasts about thirty minutes and refreshes while you are active. The second, cf_clearance, materialises only where a challenge was put in front of you and you cleared it, and its job is to spare you being challenged over and over. It can linger for as long as thirty days. That is the complete inventory. There is no third entry withheld for brevity.

One request leaves this page

Typefaces for these pages come from Google's font service, hosted at fonts.googleapis.com and fonts.gstatic.com. Fetching them obliges your browser to open a single connection to machines that are not ours. What reaches Google is what reaches any host answering a request of that shape: the address the connection came from, the user agent string the browser announces, and a note of which page sent you. Google's own account is that the service stores no cookie and that these requests feed neither advertising nor profiling. We are in no position to confirm that independently. We can repeat it, and flag that what you are reading is a supplier's assertion rather than the finding of an audit.

Serving the font files from this domain would remove that request altogether, and it is the first change we would make to this page. Naming the dependency here beats letting silence imply no such request is made. Block those two hosts and the site still works; it simply renders in whatever your system provides.

Logs, which are a different thing

Every web server anywhere keeps a record of what it was asked for, and ours does the same. The provider's log holds an originating address, the moment of the request, the path sought, the user agent string announced, and the code returned. Not a byte of it lands on your hardware, which is exactly why none of it counts as a cookie. It remains personal information all the same, and a notice that confined itself to browser storage while saying nothing about logs would be accurate in the narrow sense and misleading in every sense that matters.

The provider cycles them on a rotation of its own, currently shorter than thirty days, and keeps them for delivering the site and fending off abuse. We do not join them to anything else, do not build profiles from them, and do not try to work out who any particular visitor is.

Control from your side

None of what this page promises rests on our continuing to behave well, because the controls already sit with you: any serious browser will refuse cookies outright, clear away whatever has accumulated, and show you precisely which entries a site put there. In Chrome the controls sit under Settings, then Privacy and security. Safari keeps them under Settings, then Privacy. Firefox groups them under Settings, then Privacy and Security. Edge places them under Settings, then Cookies and site permissions.

Blocking the two Cloudflare cookies described above has one practical consequence: you may be challenged more often, because the mechanism that remembers you already passed has been removed. The site itself continues to work.

Global Privacy Control, and Do Not Track

Both signals are honoured here, which costs us nothing whatever, since there is no tracking to switch off in the first place. Send either header and no additional storage or processing occurs — an outcome identical to sending neither.

The position is stated anyway. Any site that disregards these headers while keeping quiet about it has taken a decision it would rather nobody examined closely, and since the two behaviours look identical from outside, the burden of speaking up falls on the sites that do respect them.

Games do not use cookies

Cookies are a browser mechanism, so a mobile title has none. What a mobile application has instead are device and advertising identifiers, which sit under a different set of controls entirely and are dealt with at length in the privacy policy — including our commitment not to request tracking permission on iOS at all.

If you arrived on this page trying to stop a game from tracking you, this is the wrong document and the privacy policy is the right one. The short answer, given in advance so you need not go looking: personalised advertising is off unless you deliberately turned it on.

If any of this changes

Should something start putting data on your hardware beyond the two entries set out above, it gets written into this notice — carrying a fresh version number and a fresh effective date — ahead of going live, not once it already has. Where the law applying to you requires consent for it, you will be asked first. The value of a notice like this comes entirely from its being amended in advance, and a page updated after the fact is a page that has already broken its own promise.

Asking, and complaining

Questions about this page go to [email protected] and are answered within 5 business days; anything that amounts to a privacy request under the Privacy Act is answered within 30 days. If you looked at the network panel and saw something this page does not describe, that is worth an email, and we would treat it as a correction to make rather than an argument to win.

Where our answer leaves you dissatisfied, the next stop is the Office of the Australian Information Commissioner. The OAIC can be written to at GPO Box 5218, Sydney NSW 2001, telephoned on 1300 363 992, or reached online at oaic.gov.au. The company you would be complaining about is AIDEOLOGY TECHNOLOGIES PTY LTD, ACN 698 536 953, ABN 81 698 536 953, of New South Wales.