Cookie Policy
Last updated: 19 June 2026
Looking for an easier read? A plain English summary of this policy is available at Cookie Policy (plain English summary). The legal text below is the binding version.
Our Approach
Maelstrom AI operates two platforms under one set of rules: Provii, our zero knowledge age verification service, and downpipes, our no-custody backup and disaster recovery for the Cloudflare data layer. The cookie posture is identical for both. Our own code does not set any cookies on the corporate website (maelstrom.au), the Provii Wallet website, or the downpipes website (downpipes.io). We do not use cookies for analytics, advertising, tracking, or personalisation. Your theme preference (light or dark mode) is stored in your browser’s localStorage, which is not a cookie.
The downpipes operator console (console.downpipes.io) is a special case because it runs inside the customer’s own Cloudflare account, under the customer’s own keys; it is covered in the downpipes Operator Console section below.
Cloudflare Infrastructure Cookies
The corporate website (maelstrom.au), the Provii website, and the downpipes website (downpipes.io) are served through Cloudflare’s content delivery network. Cloudflare may set strictly necessary cookies at the infrastructure level to protect the websites from malicious traffic. These cookies are not set by our application. They are managed by Cloudflare’s security systems.
| Cookie | Purpose | Duration |
|---|---|---|
__cf_bm | Cloudflare Bot Management. Distinguishes humans from automated traffic. Set only when Bot Fight Mode or equivalent protection is active. | 30 minutes |
cf_clearance | Set after a visitor completes a Cloudflare security challenge. Confirms the visitor has passed the challenge so they are not challenged again for a period. | Up to 24 hours |
__cflb | Cloudflare load balancer session affinity. Only set if load balancing with session affinity is enabled. | Session |
All Cloudflare cookies are classified as strictly necessary. They are required for the websites to function securely. They do not track you across websites, do not contain personal information, and cannot be used for advertising or profiling.
Because these cookies are strictly necessary for security, they are exempt from consent requirements under both Australian privacy law and the EU ePrivacy Directive (Article 5(3)).
Docs Sandbox Session Cookie
The developer documentation site at docs.provii.app exposes an interactive sandbox for evaluating Provii integrations. The sandbox maintains short-lived session continuity for the in-browser API explorer, credential generators, and styler preview using a single first-party cookie.
| Cookie | Purpose | Attributes | Duration |
|---|---|---|---|
__Host-docs_session | Binds a developer’s sandbox requests to an ephemeral session so the API explorer can issue follow-up calls without re-authenticating per request. Holds an opaque session identifier only; no personal data, no account identifier, no tracking value. | Secure, HttpOnly, SameSite=Strict, Path=/, no Domain attribute (the __Host- prefix pins the cookie to the docs origin and prevents subdomain scope). | 15-minute sliding TTL, 4-hour hard cap from first issuance. |
This cookie is strictly necessary for the service the developer has explicitly requested (the interactive sandbox). Under the EU ePrivacy Directive Article 5(3) and the corresponding UK PECR Regulation 6(4), storage that is “strictly necessary for the provision of an information society service explicitly requested by the subscriber or user” is exempt from prior consent. It is not used for analytics, cross-site tracking, profiling, or advertising, and is never read by the production wallet, verifier, or issuer services. The cookie is scoped to the docs origin only.
The sliding TTL is refreshed only while the sandbox UI is actively used. The 4-hour hard cap is enforced server-side: after four hours from first issuance the sandbox rejects the cookie and issues a fresh one on the next sandbox action. Closing the browser or clearing site data for docs.provii.app removes the cookie immediately. No equivalent cookie is set on the marketing website or the wallet app.
downpipes Operator Console
The downpipes operator console (console.downpipes.io) is run inside the customer’s own Cloudflare account, under the customer’s own keys. It is not a service Maelstrom hosts on the customer’s behalf. Consequently, any cookies the console sets are set within the customer’s own Cloudflare tenant — they are governed by the customer’s own deployment of the console, not set by Maelstrom — and so they fall outside the cookies enumerated in this policy. Maelstrom holds no customer keys, data, or Cloudflare tokens, and keeps no standing inbound path into the customer’s tenant (“runs dark”).
The static, signature-pinned update channel for the downpipes engine (updates.downpipes.io) is a read-only file store. It exposes no login and no session, and the engine pulls updates from it; it sets no cookies at all.
Functional Cookies
We set one functional cookie to remember your cookie preferences:
| Cookie | Purpose | Duration |
|---|---|---|
cookie_consent | Stores your cookie preference choice. Used as a fallback when browser localStorage is unavailable. | 1 year |
This cookie is classified as strictly necessary because it records your consent preferences, and is exempt from consent requirements under the ePrivacy Directive.
Analytics Cookies
We do not currently use analytics cookies. If we enable analytics in the future, those cookies will only be set after you give explicit consent.
More Information
For details on Cloudflare’s cookie practices, see Cloudflare’s cookie documentation.
For questions about this Cookie Policy, contact us at privacy@maelstrom.au.