Cookie Policy

How cookies are used across Maelstrom AI's websites and support platform

Public

Cookie Policy

Last updated: 29 September 2026

Looking for an easier read? A plain English summary of this policy is available at Cookie Policy (plain English summary). The legal text below is the binding version.

Our Approach

Maelstrom AI runs one ISMS over its downpipes platform and its support platform.

  • downpipes, our no-custody backup and disaster recovery for the Cloudflare data layer.
  • Our support platform, used internally.

The cookie posture below is identical across the corporate and downpipes websites. Our own code does not set any cookies on the corporate website (maelstrom.au) or the downpipes website (downpipes.io). We do not use cookies for analytics, advertising, tracking, or personalisation.

The downpipes console is a special case because it is deployed inside the customer’s own Cloudflare account, under the customer’s own keys; it is covered in the Customer-operated consoles and deployments section below. Our support platform receives support email for downpipes through Cloudflare’s email routing; an email worker sets no cookies. Cloudflare Access protects our support platform’s operator interface. Access sets a session cookie, and the interface sets an anti-forgery cookie, for signed-in Maelstrom operators only. The visitor cookie tables below do not list these cookies. It sets no cookie for customers who only send support email.

Cloudflare Infrastructure Cookies

Cloudflare’s content delivery network serves the corporate website (maelstrom.au) and the downpipes website (downpipes.io). Cloudflare may set strictly necessary cookies at the infrastructure level to protect the websites from malicious traffic. These cookies are not set by our application. Cloudflare’s security systems manage them.

CookiePurposeDuration
__cf_bmCloudflare Bot Management. Distinguishes humans from automated traffic. Set only when Bot Fight Mode or equivalent protection is active.30 minutes
cf_clearanceSet after a visitor completes a Cloudflare security challenge. Confirms the visitor has passed the challenge so they are not challenged again for a period.30 minutes
__cflbCloudflare load balancer session affinity. Only set if load balancing with session affinity is enabled.Session

All Cloudflare cookies are classified as strictly necessary. The websites need them to function securely. They do not track you across websites, do not contain personal information, and cannot be used for advertising or profiling.

These cookies are strictly necessary for security. Because of this, they are exempt from consent requirements under both Australian privacy law and the EU ePrivacy Directive (Article 5(3)).

Customer-operated consoles and deployments

The downpipes console is deployed inside the customer’s own Cloudflare account, under the customer’s own keys. It is not a service Maelstrom hosts on the customer’s behalf. Consequently, any cookies the console sets are set within the customer’s own Cloudflare tenant. They are governed by the customer’s own deployment of the console, not set by Maelstrom, and so they fall outside the cookies enumerated in this policy. Maelstrom holds no customer keys, data, or Cloudflare tokens, and keeps no standing inbound path into the customer’s tenant.

The signature-pinned update channel for the downpipes engine is a read-only file store. It exposes no login and no session, and the engine pulls updates from it; it sets no cookies at all.

Analytics Cookies

We do not currently use analytics cookies. If we enable analytics in the future, those cookies will only be set after you give explicit consent.

Changes to This Policy

We may update this Cookie Policy from time to time. We will post the updated policy on this page with a revised “Last updated” date.

Version history

VersionDateSummary
1.33 September 2026Named the in-scope systems and added the support-platform disclosure. Editorial update.
2.04 September 2026Document re-scoped to downpipes and the support platform. Editorial update.
2.14 September 2026Editorial update.
2.24 September 2026Editorial update.
2.324 September 2026Editorial update. No change to obligations.
2.425 September 2026Factual corrections: the cf_clearance lifetime, the operator cookies and browser storage. No change to obligations.
2.529 September 2026Plain English rewrite. No change to any commitment, right or obligation.

More Information

For details on Cloudflare’s cookie practices, see Cloudflare’s cookie documentation.

For questions about this Cookie Policy, contact us at support@maelstrom.au.