Skip to main content
Scriptshift

Legal

Cookie notice

No cookies of our own and no analytics, so no banner. Two things still reach beyond the page and both of them are named here.

Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)

1The position in short

This website sets no cookies of its own. There is no analytics, no advertising, no tracking pixel, no session recording, no heat map and no attempt to build a picture of who is reading.

There is no consent banner either, because there is nothing here that consent would be for.

Two things nonetheless reach beyond the page, and an honest notice names them rather than stopping at the reassuring part. A strictly necessary security cookie may be set by the company that hosts this site, and two typefaces are requested from Google's font servers. Both are described below, with what each one discloses about you.

2The Australian rule, which is not the European one

Australia has no separate cookie consent regime. There is no local equivalent of the European ePrivacy Directive, no statutory requirement to obtain permission before setting a cookie, and no requirement to show a banner. A banner on an Australian website is a design decision, or an imported habit, rather than compliance with anything.

What does apply is the Privacy Act 1988 (Cth). Where a cookie or a similar technology collects information about an individual who is reasonably identifiable, that information is personal information and the Australian Privacy Principles apply to it in the ordinary way. APP 3 governs whether we may collect it at all, APP 5 governs telling you, APP 6 governs what we may then do with it, and APP 11 governs keeping it safe and destroying it when it is no longer needed.

So the questions that matter here are whether we told you, whether we actually need the thing, and whether we use it only for the purpose we stated. This page answers all three. A banner would answer none of them.

If you are reading from the European Economic Area or the United Kingdom, a stricter regime may apply to you. It makes no practical difference in this case, because the only storage described below is strictly necessary and would be exempt from a consent requirement under those regimes as well.

3Why there is no banner

A consent banner exists to collect permission for storage that is not strictly necessary. There is none of that here, so a banner would be asking you to agree to nothing at all.

That is worse than leaving it out, for two reasons. It trains people to dismiss a control that genuinely matters on other sites, one click at a time. And it implies that this site is doing something it is not, which is a strange thing to imply about yourself.

If analytics or advertising is ever added here, we will ask before it loads, we will make refusing exactly as easy as accepting, refusal will not degrade anything, and this page will be updated before the change goes live rather than after.

4Everything that may be stored on your device

The complete list of everything that may be written to your device by this website. There is no second list and there is nothing under a different heading.

Everything this website may store on your device
NameSet byPurposeLifetimeConsent
__cf_bmCloudflareTells automated traffic apart from human traffic so that abuse can be blocked. Strictly necessary for the site to stay available30 minutes, refreshed while you are activeNot required
cf_clearanceCloudflareSet only if you are shown a challenge and pass it, so that you are not asked again on every pageUp to 30 daysNot required

That is the whole of it. We set nothing ourselves. Neither cookie is readable by us as an identifier of you, neither is used for any purpose beyond keeping the site available, and neither is shared with anybody.

You can confirm all of this yourself. Open the Application panel of your browser's developer tools and look at the cookie list for this origin.

5What this site does not do

Stating what is absent is more useful than stating what is present, because the absences are what a reader cannot verify by looking at a short table.

  • No Google Analytics, Plausible, Fathom, Matomo, Umami or any other analytics product.
  • No advertising, no advertising cookies and no advertising identifiers.
  • No Meta pixel, no LinkedIn Insight tag, no X pixel, no TikTok pixel and no conversion tracking of any kind.
  • No session recording, no heat mapping, no scroll tracking and no rage click detection.
  • No embedded video, no embedded map, no social widget, no comment system and no chat bubble.
  • No local storage, no session storage and no IndexedDB written by our code.
  • No browser fingerprinting, and no attempt to recognise a returning visitor by any means.
  • No A/B testing framework and no feature flag service.

Open the Network panel alongside the Application panel and you will find exactly what is described on this page, which is the only assurance worth giving.

6The one outbound request

Two typefaces load from Google Fonts, from fonts.googleapis.com and fonts.gstatic.com. That is the only request this site makes to a host we do not control, and it is worth being precise about what it discloses.

Making that request tells Google's servers your IP address, your user agent string, and the page that referred you. Google states that the Fonts service sets no cookies and that the requests are not used for advertising or for profiling. We have no way to verify that from here, which is why the sentence names who is making the claim rather than presenting it as a fact we established.

Self hosting the two files would remove the request entirely and it is on the list of things to do. Until it is done, this paragraph is the honest description rather than an omission. Blocking those two hosts in your browser leaves this site working perfectly well in a system font.

7Server logs are not cookies

Every web server records the requests it receives, and a page about storage that ignored this would be telling half the story.

The company that hosts this site logs the IP address a request came from, the time, the path requested, the user agent string, the referring page and the response code. None of that is stored on your device, so it is not a cookie. It is still personal information under Australian law, and it belongs in an honest account of what visiting this site involves.

Those logs sit with the hosting provider on the provider's own retention cycle, currently under 30 days. They are used for delivering pages and for defending the site against automated abuse, and for nothing else. They are not exported to us, not joined to anything, and not searchable by identity. The same information appears in the collection tables in the privacy policy.

8Controlling storage yourself

Every major browser lets you block cookies, delete the ones you have, and inspect exactly what a site has set. Blocking the two described above may mean the hosting provider challenges you more often, and it will not stop the site working.

  • Chrome: Settings, then Privacy and security, then Third party cookies, and Site data for what is already stored.
  • Safari: Settings, then Privacy, then Manage Website Data.
  • Firefox: Settings, then Privacy and Security, then Cookies and Site Data.
  • Edge: Settings, then Cookies and site permissions.

Private or incognito browsing discards everything at the end of the session, which for this site changes almost nothing, since there is nothing here that persists between visits in the first place.

9Do Not Track and Global Privacy Control

Do Not Track and Global Privacy Control are both honoured here. That is an easy commitment to make, because there is nothing on this site to switch off in response to them. If either signal is present, no additional storage and no additional processing occurs, which is also exactly what happens if neither is.

We say so anyway. A site that ignores these signals and stays quiet about it has made a decision it would prefer you did not examine, and the honest version of that sentence is worth more than the technically identical outcome.

10The tooling does not use cookies

Cookies are a browser mechanism. The release tooling described elsewhere on this site has no browser, no session and no user interface in a page, so it has nothing that could set one.

What a released tool might send is described in the collection tables in the privacy policy. The short version is that any crash report or version ping would be off until switched on, and that nothing about your deployment, your hosts, your variables or your release file is sent anywhere at all.

11If any of this changes

Anything that stores information on your device beyond what is listed on this page gets added to this page, with a new effective date, before it goes live rather than afterwards. Where the law that applies to you requires consent for it, we will ask first, and refusing will not degrade anything on this site.

Previous versions of this notice are kept and are available on request.

12Questions and complaints

Email [email protected]. A question about this page is answered within 5 business days. A privacy request under the Privacy Act 1988 (Cth) is answered within 30 days.

If our answer does not satisfy you, complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au. There is no fee and you do not need our agreement.

SCRIPTSHIFT TECHNOLOGIES PTY LTD, ACN 698 500 542, ABN 21 698 500 542, an Australian proprietary company in Western Australia.