Cookie Policy
Last updated: 29 September 2026
Looking for an easier read? A plain English summary of this policy is available at Cookie Policy (plain English summary). The legal text below is the binding version.
Our Approach
Maelstrom AI runs one ISMS over its downpipes platform and its support platform.
- downpipes, our no-custody backup and disaster recovery for the Cloudflare data layer.
- Our support platform, used internally.
The cookie posture below is identical across the corporate and downpipes websites. Our own code does not set any cookies on the corporate website (maelstrom.au) or the downpipes website (downpipes.io). We do not use cookies for analytics, advertising, tracking, or personalisation.
The downpipes console is a special case because it is deployed inside the customer’s own Cloudflare account, under the customer’s own keys; it is covered in the Customer-operated consoles and deployments section below. Our support platform receives support email for downpipes through Cloudflare’s email routing; an email worker sets no cookies. Cloudflare Access protects our support platform’s operator interface. Access sets a session cookie, and the interface sets an anti-forgery cookie, for signed-in Maelstrom operators only. The visitor cookie tables below do not list these cookies. It sets no cookie for customers who only send support email.
Cloudflare Infrastructure Cookies
Cloudflare’s content delivery network serves the corporate website (maelstrom.au) and the downpipes website (downpipes.io). Cloudflare may set strictly necessary cookies at the infrastructure level to protect the websites from malicious traffic. These cookies are not set by our application. Cloudflare’s security systems manage them.
| Cookie | Purpose | Duration |
|---|---|---|
__cf_bm | Cloudflare Bot Management. Distinguishes humans from automated traffic. Set only when Bot Fight Mode or equivalent protection is active. | 30 minutes |
cf_clearance | Set after a visitor completes a Cloudflare security challenge. Confirms the visitor has passed the challenge so they are not challenged again for a period. | 30 minutes |
__cflb | Cloudflare load balancer session affinity. Only set if load balancing with session affinity is enabled. | Session |
All Cloudflare cookies are classified as strictly necessary. The websites need them to function securely. They do not track you across websites, do not contain personal information, and cannot be used for advertising or profiling.
These cookies are strictly necessary for security. Because of this, they are exempt from consent requirements under both Australian privacy law and the EU ePrivacy Directive (Article 5(3)).
Customer-operated consoles and deployments
The downpipes console is deployed inside the customer’s own Cloudflare account, under the customer’s own keys. It is not a service Maelstrom hosts on the customer’s behalf. Consequently, any cookies the console sets are set within the customer’s own Cloudflare tenant. They are governed by the customer’s own deployment of the console, not set by Maelstrom, and so they fall outside the cookies enumerated in this policy. Maelstrom holds no customer keys, data, or Cloudflare tokens, and keeps no standing inbound path into the customer’s tenant.
The signature-pinned update channel for the downpipes engine is a read-only file store. It exposes no login and no session, and the engine pulls updates from it; it sets no cookies at all.
Analytics Cookies
We do not currently use analytics cookies. If we enable analytics in the future, those cookies will only be set after you give explicit consent.
Changes to This Policy
We may update this Cookie Policy from time to time. We will post the updated policy on this page with a revised “Last updated” date.
Version history
| Version | Date | Summary |
|---|---|---|
| 1.3 | 3 September 2026 | Named the in-scope systems and added the support-platform disclosure. Editorial update. |
| 2.0 | 4 September 2026 | Document re-scoped to downpipes and the support platform. Editorial update. |
| 2.1 | 4 September 2026 | Editorial update. |
| 2.2 | 4 September 2026 | Editorial update. |
| 2.3 | 24 September 2026 | Editorial update. No change to obligations. |
| 2.4 | 25 September 2026 | Factual corrections: the cf_clearance lifetime, the operator cookies and browser storage. No change to obligations. |
| 2.5 | 29 September 2026 | Plain English rewrite. No change to any commitment, right or obligation. |
More Information
For details on Cloudflare’s cookie practices, see Cloudflare’s cookie documentation.
For questions about this Cookie Policy, contact us at support@maelstrom.au.