Legal
Cookie notice
Short version: we set nothing, measure nothing, and there is one request that leaves the page. The long version answers the questions somebody sceptical would actually ask.
Effective 12 August 2026Version 2.0Privacy Act 1988 (Cth)
1Does this site put anything on my device?
Nothing we put there. No cookie of ours, nothing in local storage, nothing in session storage, no IndexedDB entry written by code we wrote.
Two things still deserve naming rather than glossing over. A strictly necessary security cookie may come from our hosting provider. And the page reaches out to somebody else's servers for the typefaces it is set in. Questions 4 and 6 take each in turn.
Beyond that: no analytics package, no advertising, no tracking pixel, no recording of your session, and no profile of you sitting anywhere.
2Why am I not being shown a banner?
A banner exists to gather permission, and there is no permission to gather. Putting one up would amount to requesting your agreement to nothing whatsoever. That is worse than merely useless. It teaches people to dismiss consent screens unread, and that reflex is the single thing the whole mechanism relies on never taking hold.
Is there a second reason?
There is, and for this company it is the more interesting of the two. A consent modal is an accessibility failure of exactly the sort this lab exists to argue about. It arrives ahead of the content. It captures keyboard focus. It usually pairs a generous accept button with a decline buried two clicks further down. Somebody using a screen reader pays more for that arrangement than anybody else does, and somebody on switch access pays more still. Erecting one where it accomplishes nothing would be hard to justify on any page of this site.
What if you ever do add analytics?
Then you get asked before it loads. Refusing will be made exactly as easy as agreeing. The control will work by keyboard and by screen reader. And this page changes first rather than catching up afterwards.
3Is that allowed in Australia?
It is. No separate cookie consent regime operates here. Nothing in Australian law mirrors the European ePrivacy Directive, and no statute demands agreement before a cookie may be written, which makes a banner on an Australian site a design decision wearing the costume of a compliance step.
The statute that does reach it is the Privacy Act 1988 (Cth). Should a cookie or something like one gather information about a person who is reasonably identifiable, what has been gathered is personal information, and the Australian Privacy Principles clamp onto it. Three principles matter here. APP 3 sets what may be gathered at all. APP 5 sets the duty to tell you at the time. APP 6 sets what may be done with it afterwards.
Which reduces the legal question to three practical ones. Were you told? Is it needed? Does it get used only for the stated reason? Answering all three is what this page is for.
4So what exactly is stored?
| Name | Set by | What it does | Lifetime | Consent needed? |
|---|---|---|---|---|
| __cf_bm | Cloudflare | Tells machine traffic apart from people, which is how abuse gets shut out. Strictly necessary to serving the site at all | 30 minutes, refreshed while you keep browsing | No |
| cf_clearance | Cloudflare | Written only where a challenge was put to you and you passed it, so the challenge does not come back | Up to 30 days | No |
Two rows, and that is the table entire rather than a sample from it. Neither cookie functions as an identifier we could read you from, and neither originates in anything we wrote.
5What does the site definitely not run?
- Google Analytics. Plausible. Fathom. Matomo. Any other measurement product you care to name.
- Advertising in any form, and therefore no advertising cookies either.
- A Meta pixel, a LinkedIn Insight tag, a TikTok pixel, or conversion tracking of any description.
- Session recording, heatmapping, scroll tracking.
- Embedded video, maps, social widgets, comment systems.
- Fingerprinting, or any other attempt at recognising you on a return visit.
None of which you have to take on faith. Your browser's developer tools carry an Application panel and a Network panel. Open both, then hold whatever shows up against questions 4 and 6. Should the two disagree, that is a defect and worth an email.
6Does anything load from another company?
One thing does. When the page loads, the typefaces it is set in get requested from fonts.googleapis.com and fonts.gstatic.com.
Three items necessarily ride along with that request and land on Google's servers: the address you are browsing from, the user agent your browser announces, and whichever page sent you here. Google's own position is that the Fonts service writes no cookies, and that these requests feed neither advertising nor profiling.
Serving the font files ourselves would remove the request altogether, and it sits on the list of things to do. Until it is done, describing it accurately beats omitting it and hoping nobody opens the network panel. Block those two hosts and the site stays entirely readable in whatever font your system swaps in, which is a property we test for rather than assume.
7If it is not a cookie, is it still recorded?
Yes, and it belongs on this page regardless of the heading at the top.
Requests get written down by every web server there has ever been. The one our hosting provider runs notes an IP address, a timestamp, a path, a user agent and a response code. Since your device receives none of that, none of it is a cookie. Personal information is exactly what it remains. Omitting it from a page headed "what this site collects" would let a technicality do the work of a lie.
Those records stay with the provider on the provider's cycle, at present under 30 days. Delivering pages and holding off abuse is what they are for.
8How do I block or clear what is there?
Any major browser will block cookies, delete them, and show you precisely what a site has written. Blocking the two in question 4 may mean Cloudflare challenges you more often than it otherwise would, but the site keeps working.
| Browser | Menu path |
|---|---|
| Chrome | Settings → Privacy and security → Third-party cookies and Site data |
| Safari | Settings → Privacy → Manage Website Data |
| Firefox | Settings → Privacy and Security → Cookies and Site Data |
| Edge | Settings → Cookies and site permissions |
Those same panels show you what any site has stored, which is the more useful half of the feature. Checking a claim like the one on this page is roughly thirty seconds of work.
9Do you honour Do Not Track?
Do Not Track gets honoured here. So does Global Privacy Control. Honouring either costs us precisely nothing, because neither one has a thing on this site to switch off. Send a signal and no further storage or processing follows. Send none and the outcome is identical.
Saying so anyway is deliberate. A site quietly disregarding these signals has taken a decision it would rather nobody examined, and from the outside the two situations look the same. What separates them is whether anyone was prepared to state a position.
10Does the fade-in remember anything about me?
No. Making it work requires storing nothing.
A single animation runs on this site: sections ease into view as you scroll to them. Where your operating system reports a preference for reduced motion, that animation never starts and every element is simply there. The same happens where JavaScript is unavailable, because the reveal was built to fail open rather than to strand content behind a script that never arrived.
Your motion preference gets reported by the browser afresh on each page load and read in that instant. Nothing is written to your device, nothing is sent onward, and nothing carries over to your next visit. Strictly this is not a cookie question at all, but it is the page people open when they want to know what a site is doing to their browser, so here it is.
11What about inside a game?
Different mechanism, different page. Cookies belong to browsers, and an app has no use for one.
A released game would lean instead on the device identifiers described in the privacy policy, which sets out what each is for, how long it survives, and how to reset or delete it from the operating system. Since nothing has been released, none of that is running.
12What if any of this changes?
Should anything begin writing to your device beyond the two rows in question 4, this page gains a row and a fresh effective date, and gains them before the thing goes live rather than after. Where whichever law applies to you calls for consent, you will be asked first.
13Who do I ask, and who do I complain to?
Questions about this page go to [email protected] and come back inside 5 business days. A request concerning your own personal information comes back inside 30 days.
Where our answer leaves you unsatisfied, the regulator is next, and going there needs no permission from us.
| Route | Detail |
|---|---|
| Web | oaic.gov.au |
| Phone | 1300 363 992 |
| Post | OAIC, GPO Box 5218, Sydney NSW 2001 |
NIYA TECH LABS PTY LTD, ACN 698 379 145, ABN 26 698 379 145, Melton, Victoria, Australia.